mirror of
https://git.yoctoproject.org/meta-arm
synced 2026-07-22 17:57:05 +00:00
Compare commits
206 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 8aa8a1f17f | |||
| 3574ae46d7 | |||
| 7889ce0206 | |||
| f9025699f7 | |||
| 950e191d7b | |||
| 54b5c5d1da | |||
| 53b3781a59 | |||
| db28829ff8 | |||
| 1d122b18f2 | |||
| 013dded5a4 | |||
| 0e3fc3d87b | |||
| 3b97565103 | |||
| eed6bc24d1 | |||
| 1fd614e545 | |||
| 67f9756fa0 | |||
| 97e0c91f79 | |||
| e20aac1b6b | |||
| 25eec5ced2 | |||
| 12711d5734 | |||
| 5d9e53af10 | |||
| aeade01bb7 | |||
| b5b7b8e523 | |||
| 3b74bb36fd | |||
| c43f173276 | |||
| 70e7f64af6 | |||
| ba315f7242 | |||
| d450786667 | |||
| 1dad884ac0 | |||
| 0923cc8a20 | |||
| 8399d913a9 | |||
| d89d05d9aa | |||
| 9649cdcf77 | |||
| e89cd1fe41 | |||
| b6a47cd180 | |||
| fef5eafc08 | |||
| 68fe673cc9 | |||
| f63c043ba7 | |||
| db2284fc01 | |||
| 798c0a8257 | |||
| 2d46f21731 | |||
| fa05df1611 | |||
| b972dabc1b | |||
| 0f955984ec | |||
| 31de2fada2 | |||
| 41a848cc93 | |||
| 26d48f7322 | |||
| 0bc288f0f2 | |||
| 6e9525115b | |||
| 0fabb8c3dd | |||
| 10e23fe1df | |||
| a86f62f144 | |||
| 9c6330a0b1 | |||
| 77ebe8b8cc | |||
| 196caca51b | |||
| 11b8298439 | |||
| a1b5347b39 | |||
| 75d6fc1916 | |||
| ecb0b05148 | |||
| eeb6441ac6 | |||
| a130541e92 | |||
| 34f1c74092 | |||
| 7f30d19df1 | |||
| 954975813a | |||
| 97be7e3fa3 | |||
| 6b64cd3704 | |||
| 39d31fff7f | |||
| 08474f5ce4 | |||
| 527475c354 | |||
| d0d1b96b0a | |||
| e6ff022d6d | |||
| 2a579f5f54 | |||
| 115196939f | |||
| 463aa8fe14 | |||
| 80f3b85bbd | |||
| 04187be11d | |||
| b6843e30d3 | |||
| 888a527676 | |||
| 3715c698ec | |||
| 14f32eef69 | |||
| 1370190ac5 | |||
| b26148e9de | |||
| faea66de04 | |||
| 17df9c4ebc | |||
| ee8933dff1 | |||
| 46ee22faeb | |||
| 7df4fb66ab | |||
| ab4bf2700f | |||
| 0af53c6453 | |||
| 2021b81dc5 | |||
| 603d9dbfe4 | |||
| 9a479aed90 | |||
| 5cd5f3442a | |||
| 2007767dd5 | |||
| d9e18ce792 | |||
| 8d308aac02 | |||
| 7163b472ab | |||
| b5f2a793ea | |||
| 2271e33766 | |||
| c652a09b32 | |||
| f9bc290fc9 | |||
| d36afba0ca | |||
| 3877284730 | |||
| 0aeec5472c | |||
| 81e3864bee | |||
| 5705ede03d | |||
| 362e7d6f05 | |||
| 6bc5f4ff2d | |||
| a77c2859d1 | |||
| da97414dfb | |||
| 59b79d5e92 | |||
| a19c7d7b76 | |||
| 6cd998d411 | |||
| c93a1459da | |||
| 299003f7fc | |||
| 1c35b69b6e | |||
| 67901eb5cb | |||
| 0792a314f6 | |||
| fb1a85a43c | |||
| ab6e5f4788 | |||
| de57703654 | |||
| a8f47e9504 | |||
| 74ac722826 | |||
| 2bfbb33518 | |||
| e867b0aa6a | |||
| 9ea97cf4f5 | |||
| 6e2a547482 | |||
| f6f616c38d | |||
| 697fcf4394 | |||
| a01f272149 | |||
| aba9250494 | |||
| 1231e54ae8 | |||
| 1e972c5637 | |||
| 02a7283944 | |||
| a45dc44ab7 | |||
| c156893334 | |||
| 1560fbe0c9 | |||
| 5fb0044f03 | |||
| 025f76a14f | |||
| 036274b3fb | |||
| 79c809ab57 | |||
| 39ceb87324 | |||
| 9975a3b3d9 | |||
| 238a6f1ebf | |||
| 73dae39ad2 | |||
| 12e3e2b9c6 | |||
| 145bb34865 | |||
| 60202ad84d | |||
| 8b94fee205 | |||
| c5e288d1bb | |||
| a91ddf4869 | |||
| 827129b05b | |||
| d1f0597822 | |||
| 5a78c75f35 | |||
| b422688735 | |||
| 6bb1fc8d8c | |||
| 1ef1b0ab25 | |||
| 1cad3c3813 | |||
| 1c21b457db | |||
| 4ada485283 | |||
| 3d3cf56dc9 | |||
| c538ae49ee | |||
| 8127e49f6b | |||
| 83df70e181 | |||
| 5712422011 | |||
| 98cf1495db | |||
| 2f9112a8fd | |||
| bcabc921f6 | |||
| 0d71ca11c6 | |||
| 450e42e7c2 | |||
| 6de882ae93 | |||
| 2cc6f05f3e | |||
| 01e60aa0e3 | |||
| ad9eadb70e | |||
| 4d22f982bc | |||
| aec92016d2 | |||
| b59c60c03a | |||
| 65460e5310 | |||
| e6e7ac4d99 | |||
| 553cadc720 | |||
| 32dfb759cd | |||
| 560075f050 | |||
| 3835b78f03 | |||
| f0d7b9db31 | |||
| 310cd898ba | |||
| 0b61cc659a | |||
| 1dff3300fb | |||
| db658a77af | |||
| 5f8b6a2d26 | |||
| 222544ae97 | |||
| 9033f88bb0 | |||
| 938572f5fc | |||
| e1424f8ac6 | |||
| 86e2984459 | |||
| 166551f05f | |||
| a6348c814d | |||
| b7cda5d084 | |||
| 560f2c1de5 | |||
| d5dc432df0 | |||
| 5720e02f11 | |||
| da41dd43f4 | |||
| 63bb9a306e | |||
| b99e5f3c1b | |||
| 17f6cf33ba | |||
| 8ea0a61add | |||
| 63f98dc2e8 | |||
| d868eea7af |
+217
-163
@@ -1,14 +1,26 @@
|
|||||||
image: ${MIRROR_GHCR}/siemens/kas/kas:4.0
|
image: ${MIRROR_GHCR}/siemens/kas/kas:4.3.2
|
||||||
|
|
||||||
variables:
|
variables:
|
||||||
CPU_REQUEST: ""
|
# These are needed as the k8s executor doesn't respect the container
|
||||||
DEFAULT_TAG: ""
|
# entrypoint by default
|
||||||
CACHE_DIR: $CI_BUILDS_DIR/persist
|
|
||||||
MIRROR_GHCR: ghcr.io
|
|
||||||
# These are needed as the k8s executor doesn't respect the container entrypoint
|
|
||||||
# by default
|
|
||||||
FF_KUBERNETES_HONOR_ENTRYPOINT: 1
|
FF_KUBERNETES_HONOR_ENTRYPOINT: 1
|
||||||
FF_USE_LEGACY_KUBERNETES_EXECUTION_STRATEGY: 0
|
FF_USE_LEGACY_KUBERNETES_EXECUTION_STRATEGY: 0
|
||||||
|
# The default value for KUBERNETES_CPU_REQUEST
|
||||||
|
CPU_REQUEST: ""
|
||||||
|
# The default machine tag for the build jobs
|
||||||
|
DEFAULT_TAG: ""
|
||||||
|
# The machine tag for the ACS test jobs
|
||||||
|
ACS_TAG: ""
|
||||||
|
# The directory to use as the persistent cache (the root for DL_DIR, SSTATE_DIR, etc)
|
||||||
|
CACHE_DIR: $CI_BUILDS_DIR/persist
|
||||||
|
# The container mirror to use
|
||||||
|
MIRROR_GHCR: ghcr.io
|
||||||
|
# Whether to run the SystemReady ACS tests
|
||||||
|
ACS_TEST: 0
|
||||||
|
# The list of extra Kas fragments to be used when building
|
||||||
|
EXTRA_KAS_FILES: ""
|
||||||
|
# The NVD API key to use when fetching CVEs
|
||||||
|
NVDCVE_API_KEY: ""
|
||||||
|
|
||||||
stages:
|
stages:
|
||||||
- prep
|
- prep
|
||||||
@@ -59,7 +71,8 @@ stages:
|
|||||||
# Catch all for everything else
|
# Catch all for everything else
|
||||||
- if: '$KERNEL != "linux-yocto-dev"'
|
- if: '$KERNEL != "linux-yocto-dev"'
|
||||||
script:
|
script:
|
||||||
- KASFILES=$(./ci/jobs-to-kas "$CI_JOB_NAME"):lockfile.yml
|
- KASFILES=$(./ci/jobs-to-kas "$CI_JOB_NAME" $EXTRA_KAS_FILES):lockfile.yml
|
||||||
|
- echo KASFILES=$KASFILES
|
||||||
- kas dump --update --force-checkout --resolve-refs --resolve-env $KASFILES
|
- kas dump --update --force-checkout --resolve-refs --resolve-env $KASFILES
|
||||||
- kas build $KASFILES
|
- kas build $KASFILES
|
||||||
- ./ci/check-warnings $KAS_WORK_DIR/build/warnings.log
|
- ./ci/check-warnings $KAS_WORK_DIR/build/warnings.log
|
||||||
@@ -67,8 +80,8 @@ stages:
|
|||||||
name: "logs"
|
name: "logs"
|
||||||
when: always
|
when: always
|
||||||
paths:
|
paths:
|
||||||
- $CI_PROJECT_DIR/work/build/tmp/work*/**/temp/log.do_*.*
|
- $CI_PROJECT_DIR/work/build/tmp*/work*/**/temp/log.do_*.*
|
||||||
- $CI_PROJECT_DIR/work/build/tmp/work*/**/testimage/*
|
- $CI_PROJECT_DIR/work/build/tmp*/work*/**/testimage/*
|
||||||
|
|
||||||
#
|
#
|
||||||
# Prep stage, update repositories once.
|
# Prep stage, update repositories once.
|
||||||
@@ -107,135 +120,18 @@ update-repos:
|
|||||||
# VIRT: [none, xen]
|
# VIRT: [none, xen]
|
||||||
# TESTING: testimage
|
# TESTING: testimage
|
||||||
|
|
||||||
corstone1000-fvp:
|
arm-systemready-ir-acs:
|
||||||
extends: .build
|
extends: .build
|
||||||
|
timeout: 12h
|
||||||
parallel:
|
parallel:
|
||||||
matrix:
|
matrix:
|
||||||
- TESTING: [testimage, tftf]
|
# arm-systemready-ir-acs must be specified after fvp-base for ordering
|
||||||
|
# purposes for the jobs-to-kas output. It is not enough to just have it
|
||||||
corstone1000-mps3:
|
# in the job name because fvp-base.yml overwrites the target.
|
||||||
extends: .build
|
- PLATFORM: fvp-base
|
||||||
parallel:
|
ARM_SYSTEMREADY_IR_ACS: arm-systemready-ir-acs
|
||||||
matrix:
|
|
||||||
- TESTING: [none, tftf]
|
|
||||||
|
|
||||||
|
|
||||||
fvp-base:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- TESTING: testimage
|
|
||||||
- FIRMWARE: edk2
|
|
||||||
|
|
||||||
fvps:
|
|
||||||
extends: .build
|
|
||||||
|
|
||||||
generic-arm64:
|
|
||||||
extends: .build
|
|
||||||
|
|
||||||
juno:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- TOOLCHAINS: [gcc, clang]
|
|
||||||
FIRMWARE: [u-boot, edk2]
|
|
||||||
|
|
||||||
musca-b1:
|
|
||||||
extends: .build
|
|
||||||
|
|
||||||
musca-s1:
|
|
||||||
extends: .build
|
|
||||||
|
|
||||||
n1sdp:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- TESTING: [none, n1sdp-ts, n1sdp-optee, tftf]
|
|
||||||
|
|
||||||
qemu-generic-arm64:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
|
||||||
TOOLCHAINS: [gcc, clang]
|
|
||||||
TESTING: testimage
|
|
||||||
|
|
||||||
qemuarm64-secureboot:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
|
||||||
TOOLCHAINS: [gcc, clang]
|
|
||||||
TCLIBC: [glibc, musl]
|
|
||||||
TS: [none, qemuarm64-secureboot-ts]
|
|
||||||
TESTING: testimage
|
|
||||||
|
|
||||||
qemuarm64:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- DISTRO: poky
|
|
||||||
KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
|
||||||
TOOLCHAINS: [gcc, clang]
|
|
||||||
FIRMWARE: [u-boot, edk2]
|
|
||||||
TESTING: testimage
|
|
||||||
- DISTRO: poky-tiny
|
|
||||||
TESTING: testimage
|
|
||||||
- VIRT: xen
|
|
||||||
|
|
||||||
qemuarm-secureboot:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
|
||||||
TOOLCHAINS: [gcc, clang]
|
|
||||||
TCLIBC: [glibc, musl]
|
|
||||||
TESTING: testimage
|
|
||||||
- TOOLCHAINS: external-gccarm
|
|
||||||
TESTING: testimage
|
|
||||||
|
|
||||||
qemuarm:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- DISTRO: poky
|
|
||||||
KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
|
||||||
TOOLCHAINS: [gcc, clang]
|
|
||||||
FIRMWARE: [u-boot, edk2]
|
|
||||||
TESTING: testimage
|
|
||||||
- DISTRO: poky-tiny
|
|
||||||
TESTING: testimage
|
|
||||||
- VIRT: xen
|
|
||||||
|
|
||||||
qemuarmv5:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- DISTRO: poky
|
|
||||||
KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
|
||||||
TESTING: testimage
|
|
||||||
- DISTRO: poky-tiny
|
|
||||||
TESTING: testimage
|
|
||||||
|
|
||||||
sgi575:
|
|
||||||
extends: .build
|
|
||||||
|
|
||||||
tc1:
|
|
||||||
extends: .build
|
|
||||||
parallel:
|
|
||||||
matrix:
|
|
||||||
- TESTING: testimage
|
|
||||||
tags:
|
tags:
|
||||||
- x86_64
|
- ${ACS_TAG}
|
||||||
|
|
||||||
toolchains:
|
|
||||||
extends: .build
|
|
||||||
|
|
||||||
selftest:
|
|
||||||
extends: .setup
|
|
||||||
script:
|
|
||||||
- KASFILES=./ci/qemuarm64.yml:./ci/selftest.yml:lockfile.yml
|
|
||||||
- kas shell --update --force-checkout $KASFILES -c 'oe-selftest --num-processes 2 --select-tag meta-arm --run-all-tests'
|
|
||||||
|
|
||||||
# Validate layers are Yocto Project Compatible
|
# Validate layers are Yocto Project Compatible
|
||||||
check-layers:
|
check-layers:
|
||||||
@@ -247,35 +143,23 @@ check-layers:
|
|||||||
matrix:
|
matrix:
|
||||||
- LAYER: [meta-arm, meta-arm-bsp, meta-arm-toolchain]
|
- LAYER: [meta-arm, meta-arm-bsp, meta-arm-toolchain]
|
||||||
|
|
||||||
pending-updates:
|
corstone1000-fvp:
|
||||||
extends: .setup
|
extends: .build
|
||||||
artifacts:
|
parallel:
|
||||||
paths:
|
matrix:
|
||||||
- update-report
|
- FIRMWARE: corstone1000-firmware-only
|
||||||
script:
|
TESTING: [testimage, tftf]
|
||||||
- rm -fr update-report
|
- FIRMWARE: none
|
||||||
# This configuration has all of the layers we need enabled
|
TESTING: testimage
|
||||||
- kas shell --update --force-checkout ci/qemuarm64.yml:ci/meta-openembedded.yml:ci/meta-secure-core.yml:lockfile.yml --command \
|
- SYSTEMREADY_FIRMWARE: arm-systemready-firmware
|
||||||
"$CI_PROJECT_DIR/scripts/machine-summary.py -t report -o $CI_PROJECT_DIR/update-report $($CI_PROJECT_DIR/ci/listmachines.py meta-arm meta-arm-bsp)"
|
|
||||||
# Do this on x86 whilst the compilers are x86-only
|
|
||||||
tags:
|
|
||||||
- x86_64
|
|
||||||
|
|
||||||
# What percentage of machines in the layer do we build
|
corstone1000-mps3:
|
||||||
machine-coverage:
|
extends: .build
|
||||||
extends: .setup
|
parallel:
|
||||||
script:
|
matrix:
|
||||||
- ./ci/check-machine-coverage
|
- FIRMWARE: corstone1000-firmware-only
|
||||||
coverage: '/Coverage: \d+/'
|
TESTING: [none, tftf]
|
||||||
|
- FIRMWARE: none
|
||||||
metrics:
|
|
||||||
extends: .setup
|
|
||||||
artifacts:
|
|
||||||
reports:
|
|
||||||
metrics: metrics.txt
|
|
||||||
script:
|
|
||||||
- kas shell --update --force-checkout ci/base.yml --command \
|
|
||||||
"$CI_PROJECT_DIR/ci/patchreview $CI_PROJECT_DIR/meta-* --verbose --metrics $CI_PROJECT_DIR/metrics.txt"
|
|
||||||
|
|
||||||
documentation:
|
documentation:
|
||||||
extends: .setup
|
extends: .setup
|
||||||
@@ -299,3 +183,173 @@ documentation:
|
|||||||
artifacts:
|
artifacts:
|
||||||
paths:
|
paths:
|
||||||
- build-docs/
|
- build-docs/
|
||||||
|
|
||||||
|
fvp-base:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- TS: [none, fvp-base-ts]
|
||||||
|
TESTING: testimage
|
||||||
|
- FIRMWARE: edk2
|
||||||
|
- SYSTEMREADY_FIRMWARE: arm-systemready-firmware
|
||||||
|
|
||||||
|
arm-systemready-ir-acs:
|
||||||
|
extends: .build
|
||||||
|
timeout: 12h
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
# arm-systemready-ir-acs must be specified after fvp-base for ordering
|
||||||
|
# purposes for the jobs-to-kas output. It is not enough to just have it
|
||||||
|
# in the job name because fvp-base.yml overwrites the target.
|
||||||
|
- PLATFORM: [fvp-base, corstone1000-fvp]
|
||||||
|
ARM_SYSTEMREADY_IR_ACS: arm-systemready-ir-acs
|
||||||
|
tags:
|
||||||
|
- ${ACS_TAG}
|
||||||
|
|
||||||
|
fvps:
|
||||||
|
extends: .build
|
||||||
|
|
||||||
|
genericarm64:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- TOOLCHAINS: [gcc, clang]
|
||||||
|
TESTING: testimage
|
||||||
|
- KERNEL: linux-yocto-dev
|
||||||
|
TESTING: testimage
|
||||||
|
|
||||||
|
juno:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- TOOLCHAINS: [gcc, clang]
|
||||||
|
FIRMWARE: [u-boot, edk2]
|
||||||
|
|
||||||
|
# What percentage of machines in the layer do we build
|
||||||
|
machine-coverage:
|
||||||
|
extends: .setup
|
||||||
|
script:
|
||||||
|
- ./ci/check-machine-coverage
|
||||||
|
coverage: '/Coverage: \d+/'
|
||||||
|
|
||||||
|
metrics:
|
||||||
|
extends: .setup
|
||||||
|
artifacts:
|
||||||
|
reports:
|
||||||
|
metrics: metrics.txt
|
||||||
|
script:
|
||||||
|
- kas shell --update --force-checkout ci/base.yml --command \
|
||||||
|
"$CI_PROJECT_DIR/ci/patchreview $CI_PROJECT_DIR/meta-* --verbose --metrics $CI_PROJECT_DIR/metrics.txt"
|
||||||
|
|
||||||
|
musca-b1:
|
||||||
|
extends: .build
|
||||||
|
|
||||||
|
musca-s1:
|
||||||
|
extends: .build
|
||||||
|
|
||||||
|
n1sdp:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- TESTING: [none, n1sdp-ts, n1sdp-optee, tftf]
|
||||||
|
|
||||||
|
pending-updates:
|
||||||
|
extends: .setup
|
||||||
|
artifacts:
|
||||||
|
paths:
|
||||||
|
- update-report
|
||||||
|
script:
|
||||||
|
- rm -fr update-report
|
||||||
|
# This configuration has all of the layers we need enabled
|
||||||
|
- kas shell --update --force-checkout ci/qemuarm64.yml:ci/meta-openembedded.yml:ci/meta-secure-core.yml:lockfile.yml --command \
|
||||||
|
"$CI_PROJECT_DIR/scripts/machine-summary.py -t report -o $CI_PROJECT_DIR/update-report $($CI_PROJECT_DIR/ci/listmachines.py meta-arm meta-arm-bsp)"
|
||||||
|
# Do this on x86 whilst the compilers are x86-only
|
||||||
|
tags:
|
||||||
|
- x86_64
|
||||||
|
|
||||||
|
qemuarm64-secureboot:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- KERNEL: [linux-yocto, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
|
TCLIBC: [glibc, musl]
|
||||||
|
TS: [none, qemuarm64-secureboot-ts]
|
||||||
|
TESTING: testimage
|
||||||
|
- KERNEL: linux-yocto-dev
|
||||||
|
TESTING: testimage
|
||||||
|
|
||||||
|
qemuarm64:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- DISTRO: poky
|
||||||
|
KERNEL: [linux-yocto, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
|
FIRMWARE: [u-boot, edk2]
|
||||||
|
TESTING: testimage
|
||||||
|
- DISTRO: poky-tiny
|
||||||
|
TESTING: testimage
|
||||||
|
- VIRT: xen
|
||||||
|
- KERNEL: linux-yocto-dev
|
||||||
|
TESTING: testimage
|
||||||
|
|
||||||
|
qemuarm-secureboot:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- KERNEL: [linux-yocto, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
|
TCLIBC: [glibc, musl]
|
||||||
|
TESTING: testimage
|
||||||
|
- TOOLCHAINS: external-gccarm
|
||||||
|
TESTING: testimage
|
||||||
|
- KERNEL: linux-yocto-dev
|
||||||
|
TESTING: testimage
|
||||||
|
|
||||||
|
qemuarm:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- DISTRO: poky
|
||||||
|
KERNEL: [linux-yocto, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
|
FIRMWARE: [u-boot, edk2]
|
||||||
|
TESTING: testimage
|
||||||
|
- DISTRO: poky-tiny
|
||||||
|
TESTING: testimage
|
||||||
|
- VIRT: xen
|
||||||
|
- KERNEL: linux-yocto-dev
|
||||||
|
TESTING: testimage
|
||||||
|
|
||||||
|
qemuarmv5:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- DISTRO: poky
|
||||||
|
KERNEL: [linux-yocto, linux-yocto-dev, linux-yocto-rt]
|
||||||
|
TESTING: testimage
|
||||||
|
- DISTRO: poky-tiny
|
||||||
|
TESTING: testimage
|
||||||
|
|
||||||
|
sbsa-ref:
|
||||||
|
extends: .build
|
||||||
|
parallel:
|
||||||
|
matrix:
|
||||||
|
- KERNEL: [linux-yocto, linux-yocto-rt]
|
||||||
|
TOOLCHAINS: [gcc, clang]
|
||||||
|
TESTING: testimage
|
||||||
|
- KERNEL: linux-yocto-dev
|
||||||
|
TESTING: testimage
|
||||||
|
|
||||||
|
selftest:
|
||||||
|
extends: .setup
|
||||||
|
script:
|
||||||
|
- KASFILES=./ci/qemuarm64.yml:./ci/selftest.yml:lockfile.yml
|
||||||
|
- kas shell --update --force-checkout $KASFILES -c 'oe-selftest --num-processes 2 --select-tag meta-arm --run-all-tests'
|
||||||
|
|
||||||
|
sgi575:
|
||||||
|
extends: .build
|
||||||
|
|
||||||
|
toolchains:
|
||||||
|
extends: .build
|
||||||
|
|||||||
@@ -0,0 +1,79 @@
|
|||||||
|
From 42358d889ed652a8c386862f8c65e5fbe7484de2 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Ross Burton <ross.burton@arm.com>
|
||||||
|
Date: Fri, 26 Apr 2024 10:38:28 +0000
|
||||||
|
Subject: [PATCH] procps: fix build with new glibc but old kernel headers
|
||||||
|
|
||||||
|
If you're building procps with a newer glibc (with pidfd_open()) but
|
||||||
|
older kernel headers (say 4.x, before __NR_pidfd_open) then procps will
|
||||||
|
fail to build because of a typo in configure.ac.
|
||||||
|
|
||||||
|
Signed-off-by: Ross Burton <ross.burton@arm.com>
|
||||||
|
---
|
||||||
|
.../procps/procps/pidfd.patch | 42 +++++++++++++++++++
|
||||||
|
meta/recipes-extended/procps/procps_4.0.4.bb | 1 +
|
||||||
|
2 files changed, 43 insertions(+)
|
||||||
|
create mode 100644 meta/recipes-extended/procps/procps/pidfd.patch
|
||||||
|
|
||||||
|
diff --git a/meta/recipes-extended/procps/procps/pidfd.patch b/meta/recipes-extended/procps/procps/pidfd.patch
|
||||||
|
new file mode 100644
|
||||||
|
index 00000000000..f5e8183e547
|
||||||
|
--- /dev/null
|
||||||
|
+++ b/meta/recipes-extended/procps/procps/pidfd.patch
|
||||||
|
@@ -0,0 +1,42 @@
|
||||||
|
+From c8f625e085b8249cc009e8b19c3a19100217eb35 Mon Sep 17 00:00:00 2001
|
||||||
|
+From: Ross Burton <ross.burton@arm.com>
|
||||||
|
+Date: Thu, 25 Apr 2024 13:33:15 +0000
|
||||||
|
+Subject: [PATCH] Fix pidfd_open detection
|
||||||
|
+
|
||||||
|
+This check for pidfd_open uses AC_CHECK_FUNC which just runs the specified code, but
|
||||||
|
+src/pgrep.c checks HAVE_PIDFD_OPEN which will only be defined by AC_CHECK_FUNCS.
|
||||||
|
+
|
||||||
|
+Also pidfd_open is defined in sys/pidfd.h so that needs including.
|
||||||
|
+
|
||||||
|
+Upstream-Status: Pending
|
||||||
|
+Signed-off-by: Ross Burton <ross.burton@arm.com>
|
||||||
|
+---
|
||||||
|
+
|
||||||
|
+diff --git a/configure.ac b/configure.ac
|
||||||
|
+index fec27e3f..024731c7 100644
|
||||||
|
+--- a/configure.ac
|
||||||
|
++++ b/configure.ac
|
||||||
|
+@@ -170,7 +170,7 @@ AC_TRY_COMPILE([#include <errno.h>],
|
||||||
|
+ AC_MSG_RESULT(yes),
|
||||||
|
+ AC_MSG_RESULT(no))
|
||||||
|
+
|
||||||
|
+-AC_CHECK_FUNC([pidfd_open], [enable_pidwait=yes], [
|
||||||
|
++AC_CHECK_FUNCS([pidfd_open], [enable_pidwait=yes], [
|
||||||
|
+ AC_MSG_CHECKING([for __NR_pidfd_open])
|
||||||
|
+ AC_COMPILE_IFELSE([AC_LANG_SOURCE([
|
||||||
|
+ #include <sys/syscall.h>
|
||||||
|
+diff --git a/src/pgrep.c b/src/pgrep.c
|
||||||
|
+index d8e57dff..c5211aec 100644
|
||||||
|
+--- a/src/pgrep.c
|
||||||
|
++++ b/src/pgrep.c
|
||||||
|
+@@ -44,7 +44,9 @@
|
||||||
|
+
|
||||||
|
+ #ifdef ENABLE_PIDWAIT
|
||||||
|
+ #include <sys/epoll.h>
|
||||||
|
+-#ifndef HAVE_PIDFD_OPEN
|
||||||
|
++#ifdef HAVE_PIDFD_OPEN
|
||||||
|
++#include <sys/pidfd.h>
|
||||||
|
++#else
|
||||||
|
+ #include <sys/syscall.h>
|
||||||
|
+ #endif /* !HAVE_PIDFD_OPEN */
|
||||||
|
+ #endif
|
||||||
|
diff --git a/meta/recipes-extended/procps/procps_4.0.4.bb b/meta/recipes-extended/procps/procps_4.0.4.bb
|
||||||
|
index 800384f22f7..ec8c4b0261b 100644
|
||||||
|
--- a/meta/recipes-extended/procps/procps_4.0.4.bb
|
||||||
|
+++ b/meta/recipes-extended/procps/procps_4.0.4.bb
|
||||||
|
@@ -14,6 +14,7 @@ inherit autotools gettext pkgconfig update-alternatives
|
||||||
|
|
||||||
|
SRC_URI = "git://gitlab.com/procps-ng/procps.git;protocol=https;branch=master \
|
||||||
|
file://sysctl.conf \
|
||||||
|
+ file://pidfd.patch \
|
||||||
|
"
|
||||||
|
SRCREV = "4ddcef2fd843170c8e2d59a83042978f41037a2b"
|
||||||
|
|
||||||
|
--
|
||||||
|
2.34.1
|
||||||
|
|
||||||
@@ -29,6 +29,13 @@ Other Directories
|
|||||||
|
|
||||||
This directory contains scripts used in running the CI tests
|
This directory contains scripts used in running the CI tests
|
||||||
|
|
||||||
|
Mailing List
|
||||||
|
------------
|
||||||
|
To interact with the meta-arm developer community, please email the meta-arm mailing list at meta-arm@lists.yoctoproject.org
|
||||||
|
Currently, it is configured to only allow emails to members from those subscribed.
|
||||||
|
To subscribe to the meta-arm mailing list, please go to
|
||||||
|
https://lists.yoctoproject.org/g/meta-arm
|
||||||
|
|
||||||
Contributing
|
Contributing
|
||||||
------------
|
------------
|
||||||
Currently, we only accept patches from the meta-arm mailing list. For general
|
Currently, we only accept patches from the meta-arm mailing list. For general
|
||||||
@@ -49,6 +56,13 @@ The component being changed in the shortlog should be prefixed with the layer na
|
|||||||
|
|
||||||
arm-toolchain/gcc: enable foobar v2
|
arm-toolchain/gcc: enable foobar v2
|
||||||
|
|
||||||
|
Releases and Release Schedule
|
||||||
|
--------------
|
||||||
|
We follow the Yocto Project release methodology, schedule, and stable/LTS support timelines. For more information on these, please reference:
|
||||||
|
https://docs.yoctoproject.org/ref-manual/release-process.html
|
||||||
|
https://wiki.yoctoproject.org/wiki/Releases
|
||||||
|
https://wiki.yoctoproject.org/wiki/Stable_Release_and_LTS
|
||||||
|
|
||||||
Reporting bugs
|
Reporting bugs
|
||||||
--------------
|
--------------
|
||||||
E-mail meta-arm@lists.yoctoproject.org with the error encountered and the steps
|
E-mail meta-arm@lists.yoctoproject.org with the error encountered and the steps
|
||||||
|
|||||||
+37
@@ -0,0 +1,37 @@
|
|||||||
|
# Reporting vulnerabilities
|
||||||
|
|
||||||
|
Arm takes security issues seriously and welcomes feedback from researchers and
|
||||||
|
the security community in order to improve the security of its products and
|
||||||
|
services. We operate a coordinated disclosure policy for disclosing
|
||||||
|
vulnerabilities and other security issues.
|
||||||
|
|
||||||
|
Security issues can be complex and one single timescale doesn't fit all
|
||||||
|
circumstances. We will make best endeavours to inform you when we expect
|
||||||
|
security notifications and fixes to be available and facilitate coordinated
|
||||||
|
disclosure when notifications and patches/mitigations are available.
|
||||||
|
|
||||||
|
|
||||||
|
## How to Report a Potential Vulnerability?
|
||||||
|
|
||||||
|
If you would like to report a public issue (for example, one with a released CVE
|
||||||
|
number), please contact the meta-arm mailing list at
|
||||||
|
meta-arm@lists.yoctoproject.org and arm-security@arm.com.
|
||||||
|
|
||||||
|
If you are dealing with a not-yet released or urgent issue, please send a mail
|
||||||
|
to the maintainers (see README.md) and arm-security@arm.com, including as much
|
||||||
|
detail as possible. Encrypted emails using PGP are welcome.
|
||||||
|
|
||||||
|
For more information, please visit https://developer.arm.com/support/arm-security-updates/report-security-vulnerabilities.
|
||||||
|
|
||||||
|
|
||||||
|
## Branches maintained with security fixes
|
||||||
|
|
||||||
|
meta-arm follows the Yocto release model, so see
|
||||||
|
[https://wiki.yoctoproject.org/wiki/Stable_Release_and_LTS Stable release and
|
||||||
|
LTS] for detailed info regarding the policies and maintenance of stable
|
||||||
|
branches.
|
||||||
|
|
||||||
|
The [https://wiki.yoctoproject.org/wiki/Releases Release page] contains a list of all
|
||||||
|
releases of the Yocto Project. Versions in grey are no longer actively maintained with
|
||||||
|
security patches, but well-tested patches may still be accepted for them for
|
||||||
|
significant issues.
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
|
header:
|
||||||
|
version: 11
|
||||||
|
includes:
|
||||||
|
- kas/arm-systemready-firmware.yml
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
|
header:
|
||||||
|
version: 11
|
||||||
|
includes:
|
||||||
|
- kas/arm-systemready-ir-acs.yml
|
||||||
|
|
||||||
|
env:
|
||||||
|
ACS_TEST: "0"
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
testimage: |
|
||||||
|
TESTIMAGE_AUTO = "${ACS_TEST}"
|
||||||
|
|
||||||
|
target:
|
||||||
|
- arm-systemready-ir-acs
|
||||||
|
- arm-systemready-linux-distros-debian
|
||||||
|
- arm-systemready-linux-distros-opensuse
|
||||||
+7
-2
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
@@ -5,7 +7,7 @@ distro: poky
|
|||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
repos:
|
repos:
|
||||||
branch: nanbield
|
branch: scarthgap
|
||||||
|
|
||||||
repos:
|
repos:
|
||||||
meta-arm:
|
meta-arm:
|
||||||
@@ -19,6 +21,10 @@ repos:
|
|||||||
layers:
|
layers:
|
||||||
meta:
|
meta:
|
||||||
meta-poky:
|
meta-poky:
|
||||||
|
patches:
|
||||||
|
procps:
|
||||||
|
path: 0001-procps-fix-build-with-new-glibc-but-old-kernel-heade.patch
|
||||||
|
repo: meta-arm
|
||||||
|
|
||||||
env:
|
env:
|
||||||
BB_LOGCONFIG: ""
|
BB_LOGCONFIG: ""
|
||||||
@@ -32,7 +38,6 @@ local_conf_header:
|
|||||||
PACKAGECONFIG:remove:pn-qemu-system-native = "gtk+ sdl"
|
PACKAGECONFIG:remove:pn-qemu-system-native = "gtk+ sdl"
|
||||||
PACKAGECONFIG:append:pn-perf = " coresight"
|
PACKAGECONFIG:append:pn-perf = " coresight"
|
||||||
INHERIT += "rm_work"
|
INHERIT += "rm_work"
|
||||||
DISTRO_FEATURES:remove = "ptest"
|
|
||||||
extrapackages: |
|
extrapackages: |
|
||||||
CORE_IMAGE_EXTRA_INSTALL += "perf opencsd"
|
CORE_IMAGE_EXTRA_INSTALL += "perf opencsd"
|
||||||
CORE_IMAGE_EXTRA_INSTALL:append:aarch64 = " gator-daemon"
|
CORE_IMAGE_EXTRA_INSTALL:append:aarch64 = " gator-daemon"
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,15 +1,13 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
- ci/base.yml
|
- ci/base.yml
|
||||||
- ci/meta-openembedded.yml
|
- ci/meta-openembedded.yml
|
||||||
- ci/poky-tiny.yml
|
|
||||||
- ci/meta-secure-core.yml
|
- ci/meta-secure-core.yml
|
||||||
|
- kas/corstone1000-image-configuration.yml
|
||||||
local_conf_header:
|
|
||||||
extrapackages: |
|
|
||||||
# Intentionally blank to prevent perf from being added to the image in base.yml
|
|
||||||
|
|
||||||
target:
|
target:
|
||||||
- corstone1000-image
|
- core-image-minimal
|
||||||
- perf
|
- perf
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
|
header:
|
||||||
|
version: 14
|
||||||
|
includes:
|
||||||
|
- kas/corstone1000-firmware-only.yml
|
||||||
|
|
||||||
|
target:
|
||||||
|
- corstone1000-flash-firmware-image
|
||||||
|
- perf
|
||||||
@@ -1,12 +1,9 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
- ci/corstone1000-common.yml
|
- ci/corstone1000-common.yml
|
||||||
- ci/fvp.yml
|
- ci/fvp.yml
|
||||||
|
|
||||||
local_conf_header:
|
|
||||||
fvp-config: |
|
|
||||||
# Remove Dropbear SSH as it will not fit into the corstone1000 image.
|
|
||||||
IMAGE_FEATURES:remove = " ssh-server-dropbear"
|
|
||||||
|
|
||||||
machine: corstone1000-fvp
|
machine: corstone1000-fvp
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
+21
@@ -0,0 +1,21 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
|
header:
|
||||||
|
version: 14
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
cve: |
|
||||||
|
INHERIT += "cve-check"
|
||||||
|
|
||||||
|
# Allow the runner environment to provide an API key
|
||||||
|
NVDCVE_API_KEY = "${@d.getVar('BB_ORIGENV').getVar('NVDCVE_API_KEY') or ''}"
|
||||||
|
|
||||||
|
# Just show the warnings for our layers
|
||||||
|
CVE_CHECK_SHOW_WARNINGS = "0"
|
||||||
|
CVE_CHECK_SHOW_WARNINGS:layer-arm-toolchain = "1"
|
||||||
|
CVE_CHECK_SHOW_WARNINGS:layer-meta-arm = "1"
|
||||||
|
CVE_CHECK_SHOW_WARNINGS:layer-meta-arm-bsp = "1"
|
||||||
|
CVE_CHECK_SHOW_WARNINGS:layer-meta-arm-systemready = "1"
|
||||||
|
|
||||||
|
# Ignore the kernel, we sometime carry kernels in meta-arm
|
||||||
|
CVE_CHECK_SHOW_WARNINGS:pn-linux-yocto = "0"
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
@@ -6,6 +8,6 @@ local_conf_header:
|
|||||||
SKIP_RECIPE[gcc-cross-arm] = "Using external toolchain"
|
SKIP_RECIPE[gcc-cross-arm] = "Using external toolchain"
|
||||||
TCMODE = "external-arm"
|
TCMODE = "external-arm"
|
||||||
EXTERNAL_TOOLCHAIN = "${TOPDIR}/toolchains/${TARGET_ARCH}"
|
EXTERNAL_TOOLCHAIN = "${TOPDIR}/toolchains/${TARGET_ARCH}"
|
||||||
# Temporary workaround for a number binaries in the toolchains that are using 32bit timer API
|
# Disable ptest as this pulls target compilers, which don't
|
||||||
# This must be done here instead of the recipe because of all the libraries in the toolchain have the issue
|
# work with external toolchain currently
|
||||||
INSANE_SKIP:append = " 32bit-time"
|
DISTRO_FEATURES:remove = "ptest"
|
||||||
|
|||||||
@@ -0,0 +1,34 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
|
header:
|
||||||
|
version: 14
|
||||||
|
includes:
|
||||||
|
- ci/fvp-base.yml
|
||||||
|
- ci/meta-openembedded.yml
|
||||||
|
- ci/testimage.yml
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
trusted_services: |
|
||||||
|
# Enable the needed test suites
|
||||||
|
TEST_SUITES = " ping ssh trusted_services"
|
||||||
|
# Include all Secure Partitions into the image
|
||||||
|
MACHINE_FEATURES:append = " arm-ffa ts-crypto ts-storage ts-its"
|
||||||
|
MACHINE_FEATURES:append = " ts-attestation ts-smm-gateway optee-spmc-test"
|
||||||
|
MACHINE_FEATURES:append = " ts-block-storage ts-fwu"
|
||||||
|
# Include TS demo/test tools into image
|
||||||
|
IMAGE_INSTALL:append = " packagegroup-ts-tests"
|
||||||
|
# Include TS PSA Arch tests into image
|
||||||
|
IMAGE_INSTALL:append = " packagegroup-ts-tests-psa"
|
||||||
|
CORE_IMAGE_EXTRA_INSTALL += "optee-test"
|
||||||
|
# Set the TS environment
|
||||||
|
TS_ENV="sp"
|
||||||
|
# Enable and configure semihosting
|
||||||
|
FVP_CONFIG[cluster0.cpu0.semihosting-cwd] = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
FVP_CONFIG[cluster0.cpu1.semihosting-cwd] = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
FVP_CONFIG[cluster0.cpu2.semihosting-cwd] = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
FVP_CONFIG[cluster0.cpu3.semihosting-cwd] = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
FVP_CONFIG[cluster1.cpu0.semihosting-cwd] = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
FVP_CONFIG[cluster1.cpu1.semihosting-cwd] = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
FVP_CONFIG[cluster1.cpu2.semihosting-cwd] = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
FVP_CONFIG[cluster1.cpu3.semihosting-cwd] = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
FVP_CONFIG[semihosting-enable] = "True"
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
@@ -5,3 +7,7 @@ header:
|
|||||||
- ci/fvp.yml
|
- ci/fvp.yml
|
||||||
|
|
||||||
machine: fvp-base
|
machine: fvp-base
|
||||||
|
|
||||||
|
target:
|
||||||
|
- core-image-sato
|
||||||
|
- boot-wrapper-aarch64
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
+2
-1
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
# Simple target to build the FVPs that are publically available
|
# Simple target to build the FVPs that are publically available
|
||||||
|
|
||||||
header:
|
header:
|
||||||
@@ -22,4 +24,3 @@ target:
|
|||||||
- nativesdk-fvp-corstone1000
|
- nativesdk-fvp-corstone1000
|
||||||
- nativesdk-fvp-n1-edge
|
- nativesdk-fvp-n1-edge
|
||||||
- nativesdk-fvp-sgi575
|
- nativesdk-fvp-sgi575
|
||||||
- nativesdk-fvp-tc1
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
header:
|
|
||||||
version: 14
|
|
||||||
includes:
|
|
||||||
- ci/base.yml
|
|
||||||
|
|
||||||
machine: generic-arm64
|
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
|
header:
|
||||||
|
version: 14
|
||||||
|
includes:
|
||||||
|
- ci/base.yml
|
||||||
|
|
||||||
|
repos:
|
||||||
|
poky:
|
||||||
|
layers:
|
||||||
|
meta-yocto-bsp:
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
bootloader: |
|
||||||
|
# If running genericarm64 in a qemu we need to manually build the bootloader
|
||||||
|
EXTRA_IMAGEDEPENDS += "virtual/bootloader"
|
||||||
|
|
||||||
|
machine: genericarm64
|
||||||
@@ -2,7 +2,7 @@
|
|||||||
set -u -e
|
set -u -e
|
||||||
|
|
||||||
BASENAME=arm-gnu-toolchain
|
BASENAME=arm-gnu-toolchain
|
||||||
VER=${VER:-12.2.rel1}
|
VER=${VER:-13.2.Rel1}
|
||||||
HOST_ARCH=${HOST_ARCH:-$(uname -m)}
|
HOST_ARCH=${HOST_ARCH:-$(uname -m)}
|
||||||
|
|
||||||
# Use the standard kas container locations if nothing is passed into the script
|
# Use the standard kas container locations if nothing is passed into the script
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
+21
-5
@@ -3,17 +3,28 @@
|
|||||||
# This script is expecting an input of machine name, optionally followed by a
|
# This script is expecting an input of machine name, optionally followed by a
|
||||||
# colon and a list of one or more parameters separated by commas between
|
# colon and a list of one or more parameters separated by commas between
|
||||||
# brackets. For example, the following are acceptable:
|
# brackets. For example, the following are acceptable:
|
||||||
# corstone1000-mps3
|
# corstone1000-mps3
|
||||||
# fvp-base: [testimage]
|
# fvp-base: [testimage]
|
||||||
# qemuarm64-secureboot: [clang, glibc, testimage]
|
# qemuarm64-secureboot: [clang, glibc, testimage]
|
||||||
|
# This argument should be quoted to avoid expansion and to be handled
|
||||||
|
# as a single value.
|
||||||
|
#
|
||||||
|
# Any further arguments will be handled as further yml file basenames.
|
||||||
#
|
#
|
||||||
# Turn this list into a series of yml files separated by colons to pass to kas
|
# Turn this list into a series of yml files separated by colons to pass to kas
|
||||||
|
|
||||||
set -e -u
|
set -e -u
|
||||||
|
|
||||||
FILES="ci/$(echo $1 | cut -d ':' -f 1).yml"
|
# First, parse the GitLab CI job name (CI_JOB_NAME via $1) and accumulate a list
|
||||||
|
# of Kas files.
|
||||||
|
JOBNAME="$1"
|
||||||
|
shift
|
||||||
|
|
||||||
for i in $(echo $1 | cut -s -d ':' -f 2 | sed 's/[][,]//g'); do
|
# The base name of the job
|
||||||
|
FILES="ci/$(echo $JOBNAME | cut -d ':' -f 1).yml"
|
||||||
|
|
||||||
|
# The list of matrix variations
|
||||||
|
for i in $(echo $JOBNAME | cut -s -d ':' -f 2 | sed 's/[][,]//g'); do
|
||||||
# Given that there are no yml files for gcc or glibc, as those are the
|
# Given that there are no yml files for gcc or glibc, as those are the
|
||||||
# defaults, we can simply ignore those parameters. They are necessary
|
# defaults, we can simply ignore those parameters. They are necessary
|
||||||
# to pass in so that matrix can correctly setup all of the permutations
|
# to pass in so that matrix can correctly setup all of the permutations
|
||||||
@@ -24,4 +35,9 @@ for i in $(echo $1 | cut -s -d ':' -f 2 | sed 's/[][,]//g'); do
|
|||||||
FILES+=":ci/$i.yml"
|
FILES+=":ci/$i.yml"
|
||||||
done
|
done
|
||||||
|
|
||||||
|
# Now pick up any further names
|
||||||
|
for i in $*; do
|
||||||
|
FILES+=":ci/$i.yml"
|
||||||
|
done
|
||||||
|
|
||||||
echo $FILES
|
echo $FILES
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
@@ -5,7 +7,7 @@ repos:
|
|||||||
meta-secure-core:
|
meta-secure-core:
|
||||||
url: https://github.com/Wind-River/meta-secure-core.git
|
url: https://github.com/Wind-River/meta-secure-core.git
|
||||||
layers:
|
layers:
|
||||||
meta:
|
meta-secure-core-common:
|
||||||
meta-signing-key:
|
meta-signing-key:
|
||||||
meta-efi-secure-boot:
|
meta-efi-secure-boot:
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
@@ -5,4 +7,4 @@ header:
|
|||||||
|
|
||||||
repos:
|
repos:
|
||||||
meta-virtualization:
|
meta-virtualization:
|
||||||
url: git://git.yoctoproject.org/meta-virtualization
|
url: https://git.yoctoproject.org/meta-virtualization
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,14 +0,0 @@
|
|||||||
header:
|
|
||||||
version: 14
|
|
||||||
includes:
|
|
||||||
- ci/generic-arm64.yml
|
|
||||||
|
|
||||||
local_conf_header:
|
|
||||||
failing_tests: |
|
|
||||||
DEFAULT_TEST_SUITES:remove = "parselogs"
|
|
||||||
|
|
||||||
machine: qemu-generic-arm64
|
|
||||||
|
|
||||||
target:
|
|
||||||
- core-image-sato
|
|
||||||
- sbsa-acs
|
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
@@ -7,6 +9,8 @@ machine: qemuarm-secureboot
|
|||||||
|
|
||||||
target:
|
target:
|
||||||
- core-image-base
|
- core-image-base
|
||||||
- optee-examples
|
|
||||||
- optee-test
|
local_conf_header:
|
||||||
- optee-os-tadevkit
|
optee: |
|
||||||
|
IMAGE_INSTALL:append = " optee-test optee-client optee-os-ta"
|
||||||
|
TEST_SUITES:append = " optee ftpm"
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
@@ -7,6 +9,8 @@ machine: qemuarm64-secureboot
|
|||||||
|
|
||||||
target:
|
target:
|
||||||
- core-image-base
|
- core-image-base
|
||||||
- optee-examples
|
|
||||||
- optee-test
|
local_conf_header:
|
||||||
- optee-os-tadevkit
|
optee: |
|
||||||
|
IMAGE_INSTALL:append = " optee-test optee-client optee-os-ta"
|
||||||
|
TEST_SUITES:append = " optee ftpm"
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -0,0 +1,12 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
|
header:
|
||||||
|
version: 14
|
||||||
|
includes:
|
||||||
|
- ci/base.yml
|
||||||
|
|
||||||
|
machine: sbsa-ref
|
||||||
|
|
||||||
|
target:
|
||||||
|
- core-image-sato
|
||||||
|
- sbsa-acs
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
|
header:
|
||||||
|
version: 14
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
sstate_mirror: |
|
||||||
|
BB_HASHSERVE_UPSTREAM = "hashserv.yocto.io:8687"
|
||||||
|
SSTATE_MIRRORS = "file://.* http://cdn.jsdelivr.net/yocto/sstate/all/PATH;downloadfilename=PATH"
|
||||||
|
BB_HASHSERVE = "auto"
|
||||||
|
BB_SIGNATURE_HANDLER = "OEEquivHash"
|
||||||
-11
@@ -1,11 +0,0 @@
|
|||||||
header:
|
|
||||||
version: 14
|
|
||||||
includes:
|
|
||||||
- ci/base.yml
|
|
||||||
- ci/fvp.yml
|
|
||||||
- ci/meta-openembedded.yml
|
|
||||||
|
|
||||||
machine: tc1
|
|
||||||
|
|
||||||
target:
|
|
||||||
- core-image-minimal
|
|
||||||
+3
-1
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
@@ -12,7 +14,7 @@ local_conf_header:
|
|||||||
slirp: |
|
slirp: |
|
||||||
TEST_RUNQEMUPARAMS = "slirp"
|
TEST_RUNQEMUPARAMS = "slirp"
|
||||||
sshd: |
|
sshd: |
|
||||||
IMAGE_FEATURES:append = " ssh-server-dropbear"
|
IMAGE_FEATURES += "ssh-server-dropbear"
|
||||||
sshkeys: |
|
sshkeys: |
|
||||||
CORE_IMAGE_EXTRA_INSTALL += "ssh-pregen-hostkeys"
|
CORE_IMAGE_EXTRA_INSTALL += "ssh-pregen-hostkeys"
|
||||||
universally_failing_tests: |
|
universally_failing_tests: |
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
@@ -16,5 +18,3 @@ target:
|
|||||||
- nativesdk-gcc-aarch64-none-elf
|
- nativesdk-gcc-aarch64-none-elf
|
||||||
- gcc-arm-none-eabi
|
- gcc-arm-none-eabi
|
||||||
- nativesdk-gcc-arm-none-eabi
|
- nativesdk-gcc-arm-none-eabi
|
||||||
- gcc-arm-none-eabi-11.2
|
|
||||||
- nativesdk-gcc-arm-none-eabi-11.2
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
|
# yaml-language-server: $schema=https://raw.githubusercontent.com/siemens/kas/master/kas/schema-kas.json
|
||||||
|
|
||||||
header:
|
header:
|
||||||
version: 14
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
|
|||||||
@@ -18,17 +18,18 @@ features for each [Secure Partition][^2] you would like to include:
|
|||||||
| ----------------- | --------------- |
|
| ----------------- | --------------- |
|
||||||
| Attestation | ts-attesation |
|
| Attestation | ts-attesation |
|
||||||
| Crypto | ts-crypto |
|
| Crypto | ts-crypto |
|
||||||
|
| Firmware Update | ts-fwu
|
||||||
| Internal Storage | ts-its |
|
| Internal Storage | ts-its |
|
||||||
| Protected Storage | ts-storage |
|
| Protected Storage | ts-storage |
|
||||||
| se-proxy | ts-se-proxy |
|
| se-proxy | ts-se-proxy |
|
||||||
| smm-gateway | ts-smm-gateway |
|
| smm-gateway | ts-smm-gateway |
|
||||||
| spm-test[1-3] | optee-spmc-test |
|
| spm-test[1-4] | optee-spmc-test |
|
||||||
|
|
||||||
Other steps depend on your machine/platform definition:
|
Other steps depend on your machine/platform definition:
|
||||||
|
|
||||||
1. For communications between Secure and Normal Words Linux kernel option `CONFIG_ARM_FFA_TRANSPORT=y`
|
1. For communications between Secure and Normal Words Linux kernel option `CONFIG_ARM_FFA_TRANSPORT=y`
|
||||||
is required. If your platform doesn't include it already you can add `arm-ffa` into MACHINE_FEATURES.
|
is required. If your platform doesn't include it already you can add `arm-ffa` into MACHINE_FEATURES.
|
||||||
(Please see ` meta-arm/recipes-kernel/arm-ffa-tee`.)
|
(Please see ` meta-arm/recipes-kernel/arm-tstee`.)
|
||||||
|
|
||||||
For running the `uefi-test` or the `xtest -t ffa_spmc` tests under Linux the `arm-ffa-user` drivel is required. This is
|
For running the `uefi-test` or the `xtest -t ffa_spmc` tests under Linux the `arm-ffa-user` drivel is required. This is
|
||||||
enabled if the `ts-smm-gateway` and/or the `optee-spmc-test` machine features are enabled.
|
enabled if the `ts-smm-gateway` and/or the `optee-spmc-test` machine features are enabled.
|
||||||
@@ -44,6 +45,10 @@ Other steps depend on your machine/platform definition:
|
|||||||
and in `meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-n1sdp.inc` and
|
and in `meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-n1sdp.inc` and
|
||||||
`meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-corstone1000.inc` for N1SDP and Corstone1000 platforms.
|
`meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a-corstone1000.inc` for N1SDP and Corstone1000 platforms.
|
||||||
|
|
||||||
|
4. Trusted Services supports an SPMC agonistic binary format. To build SPs to this format the `TS_ENV` variable is to be
|
||||||
|
set to `sp`. The resulting SP binaries should be able to boot under any FF-A v1.1 compliant SPMC implementation.
|
||||||
|
|
||||||
|
|
||||||
## Normal World applications
|
## Normal World applications
|
||||||
|
|
||||||
Optionally for testing purposes you can add `packagegroup-ts-tests` into your image. It includes
|
Optionally for testing purposes you can add `packagegroup-ts-tests` into your image. It includes
|
||||||
|
|||||||
@@ -8,10 +8,5 @@ env:
|
|||||||
# The full testimage run typically takes around 12-24h on fvp-base.
|
# The full testimage run typically takes around 12-24h on fvp-base.
|
||||||
TEST_OVERALL_TIMEOUT: "${@ 24*60*60}"
|
TEST_OVERALL_TIMEOUT: "${@ 24*60*60}"
|
||||||
|
|
||||||
local_conf_header:
|
|
||||||
systemready-ir-acs: |
|
|
||||||
IMAGE_CLASSES:append = " testimage"
|
|
||||||
|
|
||||||
|
|
||||||
target:
|
target:
|
||||||
- arm-systemready-ir-acs
|
- arm-systemready-ir-acs
|
||||||
|
|||||||
+11
-11
@@ -1,14 +1,11 @@
|
|||||||
header:
|
header:
|
||||||
version: 11
|
version: 14
|
||||||
|
|
||||||
env:
|
distro: poky
|
||||||
DISPLAY: ""
|
|
||||||
|
|
||||||
distro: poky-tiny
|
|
||||||
|
|
||||||
defaults:
|
defaults:
|
||||||
repos:
|
repos:
|
||||||
refspec: master
|
branch: master
|
||||||
|
|
||||||
repos:
|
repos:
|
||||||
meta-arm:
|
meta-arm:
|
||||||
@@ -19,29 +16,32 @@ repos:
|
|||||||
|
|
||||||
poky:
|
poky:
|
||||||
url: https://git.yoctoproject.org/git/poky
|
url: https://git.yoctoproject.org/git/poky
|
||||||
refspec: 31dd418207f6c95ef0aad589cd03cd2a4c9a8bf2
|
# commit: 2e9c2a2381105f1306bcbcb54816cbc5d8110eff
|
||||||
layers:
|
layers:
|
||||||
meta:
|
meta:
|
||||||
meta-poky:
|
meta-poky:
|
||||||
meta-yocto-bsp:
|
|
||||||
|
|
||||||
meta-openembedded:
|
meta-openembedded:
|
||||||
url: https://git.openembedded.org/meta-openembedded
|
url: https://git.openembedded.org/meta-openembedded
|
||||||
refspec: 5a01ab461c9bcabcbb2298236602373948f8f073
|
# commit: 1750c66ae8e4268c472c0b2b94748a59d6ef866d
|
||||||
layers:
|
layers:
|
||||||
meta-oe:
|
meta-oe:
|
||||||
meta-python:
|
meta-python:
|
||||||
|
meta-perl:
|
||||||
|
|
||||||
meta-secure-core:
|
meta-secure-core:
|
||||||
url: https://github.com/wind-river/meta-secure-core.git
|
url: https://github.com/wind-river/meta-secure-core.git
|
||||||
|
# commit: e29165a1031dcf601edbed1733cedd64826672a5
|
||||||
layers:
|
layers:
|
||||||
meta:
|
meta-secure-core-common:
|
||||||
meta-signing-key:
|
meta-signing-key:
|
||||||
meta-efi-secure-boot:
|
meta-efi-secure-boot:
|
||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
base: |
|
base: |
|
||||||
CONF_VERSION = "2"
|
CONF_VERSION = "2"
|
||||||
|
|
||||||
|
setup: |
|
||||||
PACKAGE_CLASSES = "package_ipk"
|
PACKAGE_CLASSES = "package_ipk"
|
||||||
BB_NUMBER_THREADS ?= "16"
|
BB_NUMBER_THREADS ?= "16"
|
||||||
PARALLEL_MAKE ?= "-j16"
|
PARALLEL_MAKE ?= "-j16"
|
||||||
@@ -50,4 +50,4 @@ local_conf_header:
|
|||||||
machine: unset
|
machine: unset
|
||||||
|
|
||||||
target:
|
target:
|
||||||
- corstone1000-image
|
- corstone1000-flash-firmware-image
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
---
|
||||||
|
header:
|
||||||
|
version: 14
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
firmwarebuild: |
|
||||||
|
BBMULTICONFIG:remove = "firmware"
|
||||||
|
|
||||||
|
# Need to ensure the rescue linux options are selected
|
||||||
|
OVERRIDES .= ":firmware"
|
||||||
|
|
||||||
|
# Need to ensure we build with a small libc
|
||||||
|
TCLIBC="musl"
|
||||||
|
|
||||||
|
mass-storage: |
|
||||||
|
# Ensure the Mass Storage device is absent
|
||||||
|
FVP_CONFIG[board.msd_mmc.p_mmc_file] = "invalid.dat"
|
||||||
|
|
||||||
|
test-configuration: |
|
||||||
|
TEST_SUITES = "_qemutiny ping"
|
||||||
|
# Remove Dropbear SSH as it will not fit into the corstone1000 image.
|
||||||
|
IMAGE_FEATURES:remove = "ssh-server-dropbear"
|
||||||
|
CORE_IMAGE_EXTRA_INSTALL:remove = "ssh-pregen-hostkeys"
|
||||||
@@ -1,16 +1,23 @@
|
|||||||
header:
|
header:
|
||||||
version: 11
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
- kas/corstone1000-base.yml
|
- kas/corstone1000-base.yml
|
||||||
|
- kas/corstone1000-image-configuration.yml
|
||||||
|
- kas/corstone1000-firmware-only.yml
|
||||||
- kas/fvp-eula.yml
|
- kas/fvp-eula.yml
|
||||||
|
|
||||||
machine: corstone1000-fvp
|
env:
|
||||||
|
DISPLAY:
|
||||||
|
WAYLAND_DISPLAY:
|
||||||
|
XAUTHORITY:
|
||||||
|
|
||||||
local_conf_header:
|
local_conf_header:
|
||||||
fvp-config: |
|
testimagefvp: |
|
||||||
# Remove Dropbear SSH as it will not fit into the corstone1000 image.
|
LICENSE_FLAGS_ACCEPTED += "Arm-FVP-EULA"
|
||||||
IMAGE_FEATURES:remove = " ssh-server-dropbear"
|
IMAGE_CLASSES += "fvpboot"
|
||||||
INHERIT += "fvpboot"
|
|
||||||
|
|
||||||
target:
|
mass-storage: |
|
||||||
- corstone1000-image
|
# Ensure the Mass Storage device is absent
|
||||||
|
FVP_CONFIG[board.msd_mmc.p_mmc_file] = "invalid.dat"
|
||||||
|
|
||||||
|
machine: corstone1000-fvp
|
||||||
|
|||||||
@@ -0,0 +1,49 @@
|
|||||||
|
header:
|
||||||
|
version: 14
|
||||||
|
|
||||||
|
local_conf_header:
|
||||||
|
extrapackages: |
|
||||||
|
# Intentionally blank to prevent perf from being added to the image in base.yml
|
||||||
|
|
||||||
|
firmwarebuild: |
|
||||||
|
# Only needed as kas doesn't add it automatically unless you have 2 targets in seperate configs
|
||||||
|
BBMULTICONFIG ?= "firmware"
|
||||||
|
|
||||||
|
distrosetup: |
|
||||||
|
DISTRO_FEATURES = "usbhost ipv4"
|
||||||
|
|
||||||
|
initramfsetup: |
|
||||||
|
# Telling the build system which image is responsible of the generation of the initramfs rootfs
|
||||||
|
INITRAMFS_IMAGE_BUNDLE:firmware = "1"
|
||||||
|
INITRAMFS_IMAGE:firmware ?= "corstone1000-recovery-image"
|
||||||
|
IMAGE_FSTYPES:firmware:pn-corstone1000-recovery-image = "${INITRAMFS_FSTYPES}"
|
||||||
|
IMAGE_NAME_SUFFIX:firmware = ""
|
||||||
|
|
||||||
|
# enable mdev/busybox for init
|
||||||
|
INIT_MANAGER:firmware = "mdev-busybox"
|
||||||
|
VIRTUAL-RUNTIME_init_manager:firmware = "busybox"
|
||||||
|
|
||||||
|
# prevent the kernel image from being included in the intramfs rootfs
|
||||||
|
PACKAGE_EXCLUDE:firmware += "kernel-image-*"
|
||||||
|
|
||||||
|
# Disable openssl in kmod to shrink the initramfs size
|
||||||
|
PACKAGECONFIG:remove:firmware:pn-kmod = "openssl"
|
||||||
|
|
||||||
|
imageextras: |
|
||||||
|
# Don't include kernel binary in rootfs /boot path
|
||||||
|
RRECOMMENDS:${KERNEL_PACKAGE_NAME}-base = ""
|
||||||
|
|
||||||
|
# all optee packages
|
||||||
|
CORE_IMAGE_EXTRA_INSTALL += "optee-client"
|
||||||
|
|
||||||
|
# TS PSA API tests commands for crypto, its, ps and iat
|
||||||
|
CORE_IMAGE_EXTRA_INSTALL += "packagegroup-ts-tests-psa"
|
||||||
|
CORE_IMAGE_EXTRA_INSTALL:firmware += "packagegroup-ts-tests-psa"
|
||||||
|
|
||||||
|
# external system firmware
|
||||||
|
CORE_IMAGE_EXTRA_INSTALL:firmware += "external-system-elf"
|
||||||
|
|
||||||
|
capsule: |
|
||||||
|
CAPSULE_EXTENSION = "uefi.capsule"
|
||||||
|
CAPSULE_FW_VERSION = "6"
|
||||||
|
CAPSULE_NAME = "${MACHINE}-v${CAPSULE_FW_VERSION}"
|
||||||
@@ -1,6 +1,8 @@
|
|||||||
header:
|
header:
|
||||||
version: 11
|
version: 14
|
||||||
includes:
|
includes:
|
||||||
- kas/corstone1000-base.yml
|
- kas/corstone1000-base.yml
|
||||||
|
- kas/corstone1000-image-configuration.yml
|
||||||
|
- kas/corstone1000-firmware-only.yml
|
||||||
|
|
||||||
machine: corstone1000-mps3
|
machine: corstone1000-mps3
|
||||||
|
|||||||
@@ -9,7 +9,7 @@ BBFILE_COLLECTIONS += "meta-arm-bsp"
|
|||||||
BBFILE_PATTERN_meta-arm-bsp = "^${LAYERDIR}/"
|
BBFILE_PATTERN_meta-arm-bsp = "^${LAYERDIR}/"
|
||||||
BBFILE_PRIORITY_meta-arm-bsp = "5"
|
BBFILE_PRIORITY_meta-arm-bsp = "5"
|
||||||
|
|
||||||
LAYERSERIES_COMPAT_meta-arm-bsp = "nanbield"
|
LAYERSERIES_COMPAT_meta-arm-bsp = "nanbield scarthgap"
|
||||||
|
|
||||||
LAYERDEPENDS_meta-arm-bsp = "core meta-arm"
|
LAYERDEPENDS_meta-arm-bsp = "core meta-arm"
|
||||||
# This won't be used by layerindex-fetch, but works everywhere else
|
# This won't be used by layerindex-fetch, but works everywhere else
|
||||||
@@ -24,3 +24,7 @@ BBFILES_DYNAMIC += " \
|
|||||||
meta-arm-systemready:${LAYERDIR}/dynamic-layers/meta-arm-systemready/*/*/*.bb \
|
meta-arm-systemready:${LAYERDIR}/dynamic-layers/meta-arm-systemready/*/*/*.bb \
|
||||||
meta-arm-systemready:${LAYERDIR}/dynamic-layers/meta-arm-systemready/*/*/*.bbappend \
|
meta-arm-systemready:${LAYERDIR}/dynamic-layers/meta-arm-systemready/*/*/*.bbappend \
|
||||||
"
|
"
|
||||||
|
|
||||||
|
WARN_QA:append:layer-meta-arm-bsp = " patch-status"
|
||||||
|
|
||||||
|
addpylib ${LAYERDIR}/lib oeqa
|
||||||
|
|||||||
@@ -14,7 +14,13 @@ TEST_SUITES = "fvp_boot"
|
|||||||
# FVP Config
|
# FVP Config
|
||||||
FVP_PROVIDER ?= "fvp-corstone1000-native"
|
FVP_PROVIDER ?= "fvp-corstone1000-native"
|
||||||
FVP_EXE ?= "FVP_Corstone-1000"
|
FVP_EXE ?= "FVP_Corstone-1000"
|
||||||
FVP_CONSOLE ?= "host_terminal_0"
|
FVP_CONSOLES[default] = "host_terminal_0"
|
||||||
|
FVP_CONSOLES[tf-a] = "host_terminal_1"
|
||||||
|
FVP_CONSOLES[se] = "secenc_terminal"
|
||||||
|
FVP_CONSOLES[extsys] = "extsys_terminal"
|
||||||
|
|
||||||
|
#Disable Time Annotation
|
||||||
|
FASTSIM_DISABLE_TA = "0"
|
||||||
|
|
||||||
# FVP Parameters
|
# FVP Parameters
|
||||||
FVP_CONFIG[se.trustedBootROMloader.fname] ?= "bl1.bin"
|
FVP_CONFIG[se.trustedBootROMloader.fname] ?= "bl1.bin"
|
||||||
@@ -32,7 +38,7 @@ FVP_CONFIG[se.nvm.update_raw_image] ?= "0"
|
|||||||
FVP_CONFIG[se.cryptocell.USER_OTP_FILTERING_DISABLE] ?= "1"
|
FVP_CONFIG[se.cryptocell.USER_OTP_FILTERING_DISABLE] ?= "1"
|
||||||
|
|
||||||
# Boot image
|
# Boot image
|
||||||
FVP_DATA ?= "board.flash0=${IMAGE_NAME}.wic@0x68000000"
|
FVP_DATA ?= "board.flash0=corstone1000-flash-firmware-image-${MACHINE}.wic@0x68000000"
|
||||||
|
|
||||||
# External system (cortex-M3)
|
# External system (cortex-M3)
|
||||||
FVP_CONFIG[extsys_harness0.extsys_flashloader.fname] ?= "es_flashfw.bin"
|
FVP_CONFIG[extsys_harness0.extsys_flashloader.fname] ?= "es_flashfw.bin"
|
||||||
@@ -46,13 +52,24 @@ FVP_TERMINALS[extsys0.extsys_terminal] ?= "Cortex M3"
|
|||||||
# MMC card configuration
|
# MMC card configuration
|
||||||
FVP_CONFIG[board.msd_mmc.card_type] ?= "SDHC"
|
FVP_CONFIG[board.msd_mmc.card_type] ?= "SDHC"
|
||||||
FVP_CONFIG[board.msd_mmc.p_fast_access] ?= "0"
|
FVP_CONFIG[board.msd_mmc.p_fast_access] ?= "0"
|
||||||
FVP_CONFIG[board.msd_mmc.diagnostics] ?= "2"
|
FVP_CONFIG[board.msd_mmc.diagnostics] ?= "0"
|
||||||
FVP_CONFIG[board.msd_mmc.p_max_block_count] ?= "0xFFFF"
|
FVP_CONFIG[board.msd_mmc.p_max_block_count] ?= "0xFFFF"
|
||||||
FVP_CONFIG[board.msd_config.pl180_fifo_depth] ?= "16"
|
FVP_CONFIG[board.msd_config.pl180_fifo_depth] ?= "16"
|
||||||
|
FVP_CONFIG[board.msd_mmc.support_unpadded_images] ?= "true"
|
||||||
|
FVP_CONFIG[board.msd_mmc.p_mmc_file] ?= "${IMAGE_NAME}.wic"
|
||||||
|
|
||||||
# MMC2 card configuration
|
# MMC2 card configuration
|
||||||
FVP_CONFIG[board.msd_mmc_2.card_type] ?= "SDHC"
|
FVP_CONFIG[board.msd_mmc_2.card_type] ?= "SDHC"
|
||||||
FVP_CONFIG[board.msd_mmc_2.p_fast_access] ?= "0"
|
FVP_CONFIG[board.msd_mmc_2.p_fast_access] ?= "0"
|
||||||
FVP_CONFIG[board.msd_mmc_2.diagnostics] ?= "2"
|
FVP_CONFIG[board.msd_mmc_2.diagnostics] ?= "0"
|
||||||
FVP_CONFIG[board.msd_mmc_2.p_max_block_count] ?= "0xFFFF"
|
FVP_CONFIG[board.msd_mmc_2.p_max_block_count] ?= "0xFFFF"
|
||||||
FVP_CONFIG[board.msd_config_2.pl180_fifo_depth] ?= "16"
|
FVP_CONFIG[board.msd_config_2.pl180_fifo_depth] ?= "16"
|
||||||
|
FVP_CONFIG[board.msd_mmc_2.support_unpadded_images] ?= "true"
|
||||||
|
FVP_CONFIG[board.msd_mmc_2.p_mmc_file] ?= "corstone1000-esp-image-${MACHINE}.wic"
|
||||||
|
|
||||||
|
# Virtio-Net configuration
|
||||||
|
FVP_CONFIG[board.virtio_net.enabled] ?= "1"
|
||||||
|
FVP_CONFIG[board.virtio_net.hostbridge.interfaceName] ?= "eth1"
|
||||||
|
FVP_CONFIG[board.virtio_net.hostbridge.userNetworking] ?= "true"
|
||||||
|
FVP_CONFIG[board.virtio_net.hostbridge.userNetPorts] ?= "5555=5555,8080=80,2222=22"
|
||||||
|
FVP_CONFIG[board.virtio_net.transport] ?= "legacy"
|
||||||
|
|||||||
@@ -4,9 +4,7 @@
|
|||||||
#@NAME: Armv8-A Base Platform FVP machine
|
#@NAME: Armv8-A Base Platform FVP machine
|
||||||
#@DESCRIPTION: Machine configuration for Armv8-A Base Platform FVP model
|
#@DESCRIPTION: Machine configuration for Armv8-A Base Platform FVP model
|
||||||
|
|
||||||
require conf/machine/include/arm/arch-armv8a.inc
|
require conf/machine/include/arm/arch-armv8-4a.inc
|
||||||
|
|
||||||
TUNE_FEATURES = "aarch64"
|
|
||||||
|
|
||||||
ARM_SYSTEMREADY_FIRMWARE = "trusted-firmware-a:do_deploy"
|
ARM_SYSTEMREADY_FIRMWARE = "trusted-firmware-a:do_deploy"
|
||||||
ARM_SYSTEMREADY_ACS_CONSOLE = "default"
|
ARM_SYSTEMREADY_ACS_CONSOLE = "default"
|
||||||
@@ -49,6 +47,10 @@ FVP_CONFIG[bp.virtio_net.hostbridge.userNetworking] ?= "1"
|
|||||||
FVP_CONFIG[bp.virtio_net.hostbridge.userNetPorts] = "2222=22"
|
FVP_CONFIG[bp.virtio_net.hostbridge.userNetPorts] = "2222=22"
|
||||||
FVP_CONFIG[bp.virtio_rng.enabled] ?= "1"
|
FVP_CONFIG[bp.virtio_rng.enabled] ?= "1"
|
||||||
FVP_CONFIG[cache_state_modelled] ?= "0"
|
FVP_CONFIG[cache_state_modelled] ?= "0"
|
||||||
|
FVP_CONFIG[cluster0.check_memory_attributes] ?= "0"
|
||||||
|
FVP_CONFIG[cluster1.check_memory_attributes] ?= "0"
|
||||||
|
FVP_CONFIG[cluster0.stage12_tlb_size] ?= "1024"
|
||||||
|
FVP_CONFIG[cluster1.stage12_tlb_size] ?= "1024"
|
||||||
FVP_CONFIG[bp.secureflashloader.fname] ?= "bl1-fvp.bin"
|
FVP_CONFIG[bp.secureflashloader.fname] ?= "bl1-fvp.bin"
|
||||||
FVP_CONFIG[bp.flashloader0.fname] ?= "fip-fvp.bin"
|
FVP_CONFIG[bp.flashloader0.fname] ?= "fip-fvp.bin"
|
||||||
FVP_CONFIG[bp.virtioblockdevice.image_path] ?= "${IMAGE_NAME}.wic"
|
FVP_CONFIG[bp.virtioblockdevice.image_path] ?= "${IMAGE_NAME}.wic"
|
||||||
@@ -60,3 +62,4 @@ FVP_TERMINALS[bp.terminal_0] ?= "Console"
|
|||||||
FVP_TERMINALS[bp.terminal_1] ?= ""
|
FVP_TERMINALS[bp.terminal_1] ?= ""
|
||||||
FVP_TERMINALS[bp.terminal_2] ?= ""
|
FVP_TERMINALS[bp.terminal_2] ?= ""
|
||||||
FVP_TERMINALS[bp.terminal_3] ?= ""
|
FVP_TERMINALS[bp.terminal_3] ?= ""
|
||||||
|
FVP_CONFIG[bp.secure_memory] ?= "1"
|
||||||
@@ -2,81 +2,64 @@ require conf/machine/include/arm/armv8a/tune-cortexa35.inc
|
|||||||
|
|
||||||
MACHINEOVERRIDES =. "corstone1000:"
|
MACHINEOVERRIDES =. "corstone1000:"
|
||||||
|
|
||||||
|
# TF-M
|
||||||
|
PREFERRED_VERSION_trusted-firmware-m ?= "2.0.%"
|
||||||
|
|
||||||
# TF-A
|
# TF-A
|
||||||
TFA_PLATFORM = "corstone1000"
|
TFA_PLATFORM = "corstone1000"
|
||||||
EXTRA_IMAGEDEPENDS += "trusted-firmware-a"
|
PREFERRED_VERSION_trusted-firmware-a ?= "2.10.%"
|
||||||
PREFERRED_VERSION_trusted-firmware-a ?= "2.9.%"
|
PREFERRED_VERSION_tf-a-tests ?= "2.10.%"
|
||||||
PREFERRED_VERSION_tf-a-tests ?= "2.8.%"
|
|
||||||
|
|
||||||
TFA_BL2_BINARY = "bl2-corstone1000.bin"
|
TFA_BL2_BINARY = "bl2-corstone1000.bin"
|
||||||
TFA_FIP_BINARY = "fip-corstone1000.bin"
|
TFA_FIP_BINARY = "fip-corstone1000.bin"
|
||||||
|
|
||||||
# TF-M
|
# optee
|
||||||
EXTRA_IMAGEDEPENDS += "virtual/trusted-firmware-m"
|
PREFERRED_VERSION_optee-os ?= "4.1.%"
|
||||||
|
|
||||||
# TF-M settings for signing host images
|
# Trusted Services
|
||||||
TFA_BL2_RE_IMAGE_LOAD_ADDRESS = "0x62353000"
|
TS_PLATFORM = "arm/corstone1000"
|
||||||
TFA_BL2_RE_SIGN_BIN_SIZE = "0x2d000"
|
TS_SP_SE_PROXY_CONFIG = "corstone1000"
|
||||||
TFA_FIP_RE_IMAGE_LOAD_ADDRESS = "0x68130000"
|
# Include smm-gateway and se-proxy SPs into optee-os binary
|
||||||
TFA_FIP_RE_SIGN_BIN_SIZE = "0x00200000"
|
MACHINE_FEATURES += "ts-smm-gateway ts-se-proxy"
|
||||||
RE_LAYOUT_WRAPPER_VERSION = "0.0.7"
|
|
||||||
TFM_SIGN_PRIVATE_KEY = "${libdir}/tfm-scripts/root-RSA-3072_1.pem"
|
|
||||||
RE_IMAGE_OFFSET = "0x1000"
|
|
||||||
|
|
||||||
# u-boot
|
# u-boot
|
||||||
PREFERRED_VERSION_u-boot ?= "2023.07%"
|
PREFERRED_VERSION_u-boot ?= "2023.07%"
|
||||||
EXTRA_IMAGEDEPENDS += "u-boot"
|
MACHINE_FEATURES += "efi"
|
||||||
|
EFI_PROVIDER ?= "grub-efi"
|
||||||
|
|
||||||
UBOOT_CONFIG ??= "EFI"
|
# Grub
|
||||||
UBOOT_CONFIG[EFI] = "corstone1000_defconfig"
|
LINUX_KERNEL_ARGS ?= "earlycon=pl011,0x1a510000 console=ttyAMA0,115200"
|
||||||
UBOOT_ENTRYPOINT = "0x80000000"
|
GRUB_LINUX_APPEND ?= "${LINUX_KERNEL_ARGS}"
|
||||||
UBOOT_LOADADDRESS = "0x80000000"
|
IMAGE_CMD:wic[vardeps] += "GRUB_LINUX_APPEND"
|
||||||
UBOOT_BOOTARGS = "earlycon=pl011,0x1a510000 console=ttyAMA0 loglevel=9"
|
|
||||||
UBOOT_ARCH = "arm"
|
|
||||||
UBOOT_EXTLINUX = "0"
|
|
||||||
|
|
||||||
#optee
|
|
||||||
PREFERRED_VERSION_optee-os ?= "3.22%"
|
|
||||||
PREFERRED_VERSION_optee-client ?= "3.22%"
|
|
||||||
EXTRA_IMAGEDEPENDS += "optee-os"
|
|
||||||
OPTEE_ARCH = "arm64"
|
|
||||||
OPTEE_BINARY = "tee-pager_v2.bin"
|
|
||||||
|
|
||||||
# Include smm-gateway and se-proxy SPs into optee-os binary
|
|
||||||
MACHINE_FEATURES += "ts-smm-gateway ts-se-proxy"
|
|
||||||
TS_PLATFORM = "arm/corstone1000"
|
|
||||||
TS_SP_SE_PROXY_CONFIG = "corstone1000"
|
|
||||||
|
|
||||||
# External System(Cortex-M3)
|
|
||||||
EXTRA_IMAGEDEPENDS += "external-system"
|
|
||||||
|
|
||||||
# Linux kernel
|
# Linux kernel
|
||||||
PREFERRED_PROVIDER_virtual/kernel:forcevariable = "linux-yocto"
|
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
||||||
PREFERRED_VERSION_linux-yocto = "6.5%"
|
PREFERRED_VERSION_linux-yocto ?= "6.6.%"
|
||||||
KERNEL_IMAGETYPE = "Image.gz"
|
KERNEL_IMAGETYPE = "Image"
|
||||||
|
KERNEL_IMAGETYPE:firmware = "Image.gz"
|
||||||
INITRAMFS_IMAGE_BUNDLE ?= "1"
|
|
||||||
|
|
||||||
#telling the build system which image is responsible of the generation of the initramfs rootfs
|
|
||||||
INITRAMFS_IMAGE = "corstone1000-initramfs-image"
|
|
||||||
IMAGE_NAME_SUFFIX = ""
|
|
||||||
|
|
||||||
# add FF-A support in the kernel
|
# add FF-A support in the kernel
|
||||||
MACHINE_FEATURES += "arm-ffa"
|
MACHINE_FEATURES += "arm-ffa"
|
||||||
|
|
||||||
# prevent the kernel image from being included in the intramfs rootfs
|
|
||||||
PACKAGE_EXCLUDE = "kernel-image-*"
|
|
||||||
|
|
||||||
# enable this feature for kernel debugging
|
# enable this feature for kernel debugging
|
||||||
# MACHINE_FEATURES += "corstone1000_kernel_debug"
|
# MACHINE_FEATURES += "corstone1000_kernel_debug"
|
||||||
|
|
||||||
# login terminal serial port settings
|
# login terminal serial port settings
|
||||||
SERIAL_CONSOLES ?= "115200;ttyAMA0"
|
SERIAL_CONSOLES ?= "115200;ttyAMA0"
|
||||||
|
|
||||||
|
IMAGE_FSTYPES += "wic"
|
||||||
|
# Need to clear the suffix so TESTIMAGE_AUTO works
|
||||||
|
IMAGE_NAME_SUFFIX = ""
|
||||||
|
WKS_FILE ?= "efi-disk-no-swap.wks.in"
|
||||||
|
WKS_FILE:firmware ?= "corstone1000-flash-firmware.wks.in"
|
||||||
|
|
||||||
# making sure EXTRA_IMAGEDEPENDS will be used while creating the image
|
# making sure EXTRA_IMAGEDEPENDS will be used while creating the image
|
||||||
WKS_FILE_DEPENDS:append = " ${EXTRA_IMAGEDEPENDS}"
|
WKS_FILE_DEPENDS:append = " ${EXTRA_IMAGEDEPENDS}"
|
||||||
|
|
||||||
WKS_FILE ?= "corstone1000-image.corstone1000.wks"
|
# If not building under the firmware multiconf we need to build the actual firmware
|
||||||
|
FIRMWARE_DEPLOYMENT ?= "firmware-deploy-image"
|
||||||
|
FIRMWARE_DEPLOYMENT:firmware ?= ""
|
||||||
|
EXTRA_IMAGEDEPENDS += "${FIRMWARE_DEPLOYMENT}"
|
||||||
|
|
||||||
# Disable openssl in kmod to shink the initramfs size
|
ARM_SYSTEMREADY_FIRMWARE = "${FIRMWARE_DEPLOYMENT}:do_deploy \
|
||||||
PACKAGECONFIG:remove:pn-kmod = "openssl"
|
corstone1000-esp-image:do_image_complete \
|
||||||
|
"
|
||||||
|
ARM_SYSTEMREADY_ACS_CONSOLE ?= "default"
|
||||||
|
|||||||
@@ -1,36 +0,0 @@
|
|||||||
TUNE_FEATURES = "aarch64"
|
|
||||||
|
|
||||||
require conf/machine/include/arm/arch-armv8a.inc
|
|
||||||
|
|
||||||
MACHINEOVERRIDES =. "tc:"
|
|
||||||
|
|
||||||
# Das U-boot
|
|
||||||
UBOOT_MACHINE ?= "total_compute_defconfig"
|
|
||||||
UBOOT_RD_LOADADDRESS = "0x88000000"
|
|
||||||
UBOOT_RD_ENTRYPOINT = "0x88000000"
|
|
||||||
UBOOT_LOADADDRESS = "0x80080000"
|
|
||||||
UBOOT_ENTRYPOINT = "0x80080000"
|
|
||||||
|
|
||||||
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
|
||||||
|
|
||||||
# OP-TEE
|
|
||||||
PREFERRED_VERSION_optee-os ?= "3.20%"
|
|
||||||
PREFERRED_VERSION_optee-client ?= "3.20%"
|
|
||||||
PREFERRED_VERSION_optee-test ?= "3.20%"
|
|
||||||
|
|
||||||
# Cannot use the default zImage on arm64
|
|
||||||
KERNEL_IMAGETYPE = "Image"
|
|
||||||
KERNEL_IMAGETYPES += "fitImage"
|
|
||||||
KERNEL_CLASSES = " kernel-fitimage "
|
|
||||||
|
|
||||||
IMAGE_FSTYPES += "cpio.gz"
|
|
||||||
INITRAMFS_IMAGE ?= "core-image-minimal"
|
|
||||||
IMAGE_NAME_SUFFIX = ""
|
|
||||||
|
|
||||||
SERIAL_CONSOLES = "115200;ttyAMA0"
|
|
||||||
|
|
||||||
EXTRA_IMAGEDEPENDS += "trusted-firmware-a optee-os"
|
|
||||||
PREFERRED_VERSION_trusted-firmware-a ?= "2.8.%"
|
|
||||||
# FIXME - there is signed image dependency/race with testimage.
|
|
||||||
# This should be fixed in oe-core
|
|
||||||
TESTIMAGEDEPENDS:append = " virtual/kernel:do_deploy"
|
|
||||||
@@ -19,7 +19,7 @@ WKS_FILE_DEPENDS:append = " ${EXTRA_IMAGEDEPENDS}"
|
|||||||
|
|
||||||
# Use kernel provided by yocto
|
# Use kernel provided by yocto
|
||||||
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
||||||
PREFERRED_VERSION_linux-yocto ?= "6.5%"
|
PREFERRED_VERSION_linux-yocto ?= "6.6%"
|
||||||
|
|
||||||
# RTL8168E Gigabit Ethernet Controller is attached to the PCIe interface
|
# RTL8168E Gigabit Ethernet Controller is attached to the PCIe interface
|
||||||
MACHINE_ESSENTIAL_EXTRA_RDEPENDS += "linux-firmware-rtl8168"
|
MACHINE_ESSENTIAL_EXTRA_RDEPENDS += "linux-firmware-rtl8168"
|
||||||
@@ -27,16 +27,21 @@ MACHINE_ESSENTIAL_EXTRA_RDEPENDS += "linux-firmware-rtl8168"
|
|||||||
# TF-A
|
# TF-A
|
||||||
EXTRA_IMAGEDEPENDS += "trusted-firmware-a"
|
EXTRA_IMAGEDEPENDS += "trusted-firmware-a"
|
||||||
TFA_PLATFORM = "n1sdp"
|
TFA_PLATFORM = "n1sdp"
|
||||||
|
PREFERRED_VERSION_trusted-firmware-a ?= "2.10.%"
|
||||||
|
PREFERRED_VERSION_tf-a-tests ?= "2.10.%"
|
||||||
|
|
||||||
# SCP
|
# SCP
|
||||||
EXTRA_IMAGEDEPENDS += "virtual/control-processor-firmware"
|
EXTRA_IMAGEDEPENDS += "virtual/control-processor-firmware"
|
||||||
|
|
||||||
#UEFI EDK2 firmware
|
#UEFI EDK2 firmware
|
||||||
EXTRA_IMAGEDEPENDS += "edk2-firmware"
|
EXTRA_IMAGEDEPENDS += "edk2-firmware"
|
||||||
PREFERRED_VERSION_edk2-firmware ?= "202305"
|
PREFERRED_VERSION_edk2-firmware ?= "202311"
|
||||||
|
|
||||||
#optee
|
#optee
|
||||||
PREFERRED_VERSION_optee-os ?= "3.22.%"
|
PREFERRED_VERSION_optee-os ?= "4.1.%"
|
||||||
|
PREFERRED_VERSION_optee-os-tadevkit ?= "4.1.%"
|
||||||
|
PREFERRED_VERSION_optee-test ?= "4.1.%"
|
||||||
|
PREFERRED_VERSION_optee-client ?= "4.1.%"
|
||||||
|
|
||||||
#grub-efi
|
#grub-efi
|
||||||
EFI_PROVIDER ?= "grub-efi"
|
EFI_PROVIDER ?= "grub-efi"
|
||||||
|
|||||||
+18
-9
@@ -1,14 +1,17 @@
|
|||||||
#@TYPE: Machine
|
#@TYPE: Machine
|
||||||
#@NAME: qemu-generic-arm64
|
#@NAME: sbsa-ref
|
||||||
#@DESCRIPTION: Generic Arm64 machine for typical SystemReady platforms, which
|
#@DESCRIPTION: Reference SBSA machine in qemu-system-aarch64 on Neoverse N2
|
||||||
#have working firmware and boot via EFI.
|
|
||||||
|
|
||||||
MACHINEOVERRIDES =. "generic-arm64:"
|
require conf/machine/include/arm/armv9a/tune-neoversen2.inc
|
||||||
|
|
||||||
require conf/machine/generic-arm64.conf
|
|
||||||
require conf/machine/include/qemu.inc
|
require conf/machine/include/qemu.inc
|
||||||
|
|
||||||
EXTRA_IMAGEDEPENDS += "edk2-firmware"
|
PREFERRED_PROVIDER_virtual/kernel ?= "linux-yocto"
|
||||||
|
KERNEL_IMAGETYPE = "Image"
|
||||||
|
MACHINE_EXTRA_RRECOMMENDS += "kernel-modules"
|
||||||
|
|
||||||
|
MACHINE_FEATURES = " alsa bluetooth efi qemu-usermode rtc screen usbhost vfat wifi"
|
||||||
|
|
||||||
|
IMAGE_FSTYPES += "wic.qcow2"
|
||||||
|
|
||||||
# This unique WIC file is necessary because kernel boot args cannot be passed
|
# This unique WIC file is necessary because kernel boot args cannot be passed
|
||||||
# because there is no default kernel (see below). There is no default kernel
|
# because there is no default kernel (see below). There is no default kernel
|
||||||
@@ -17,17 +20,23 @@ EXTRA_IMAGEDEPENDS += "edk2-firmware"
|
|||||||
# boot arg (which we need for testimage), we have to have a WIC file unique to
|
# boot arg (which we need for testimage), we have to have a WIC file unique to
|
||||||
# this platform.
|
# this platform.
|
||||||
WKS_FILE = "qemu-efi-disk.wks.in"
|
WKS_FILE = "qemu-efi-disk.wks.in"
|
||||||
IMAGE_FSTYPES += "wic.qcow2"
|
|
||||||
|
EFI_PROVIDER ?= "${@bb.utils.contains("DISTRO_FEATURES", "systemd", "systemd-boot", "grub-efi", d)}"
|
||||||
|
|
||||||
|
SERIAL_CONSOLES ?= "115200;ttyAMA0 115200;hvc0"
|
||||||
|
|
||||||
|
EXTRA_IMAGEDEPENDS += "edk2-firmware"
|
||||||
|
|
||||||
QB_SYSTEM_NAME = "qemu-system-aarch64"
|
QB_SYSTEM_NAME = "qemu-system-aarch64"
|
||||||
QB_MACHINE = "-machine sbsa-ref"
|
QB_MACHINE = "-machine sbsa-ref"
|
||||||
|
QB_CPU = "-cpu neoverse-n2"
|
||||||
QB_MEM = "-m 1024"
|
QB_MEM = "-m 1024"
|
||||||
QB_DEFAULT_FSTYPE = "wic.qcow2"
|
QB_DEFAULT_FSTYPE = "wic.qcow2"
|
||||||
QB_NETWORK_DEVICE = "-device virtio-net-pci,netdev=net0,mac=@MAC@"
|
QB_NETWORK_DEVICE = "-device virtio-net-pci,netdev=net0,mac=@MAC@"
|
||||||
QB_DRIVE_TYPE = "/dev/hd"
|
QB_DRIVE_TYPE = "/dev/hd"
|
||||||
QB_ROOTFS_OPT = "-drive file=@ROOTFS@,if=ide,format=qcow2"
|
QB_ROOTFS_OPT = "-drive file=@ROOTFS@,if=ide,format=qcow2"
|
||||||
QB_DEFAULT_KERNEL = "none"
|
QB_DEFAULT_KERNEL = "none"
|
||||||
QB_OPT_APPEND = "-device qemu-xhci -device usb-tablet -device usb-kbd -pflash @DEPLOY_DIR_IMAGE@/SBSA_FLASH0.fd -pflash @DEPLOY_DIR_IMAGE@/SBSA_FLASH1.fd"
|
QB_OPT_APPEND = "-device usb-tablet -device usb-kbd -pflash @DEPLOY_DIR_IMAGE@/SBSA_FLASH0.fd -pflash @DEPLOY_DIR_IMAGE@/SBSA_FLASH1.fd"
|
||||||
QB_SERIAL_OPT = "-device virtio-serial-pci -chardev null,id=virtcon -device virtconsole,chardev=virtcon"
|
QB_SERIAL_OPT = "-device virtio-serial-pci -chardev null,id=virtcon -device virtconsole,chardev=virtcon"
|
||||||
QB_TCPSERIAL_OPT = "-device virtio-serial-pci -chardev socket,id=virtcon,port=@PORT@,host=127.0.0.1 -device virtconsole,chardev=virtcon"
|
QB_TCPSERIAL_OPT = "-device virtio-serial-pci -chardev socket,id=virtcon,port=@PORT@,host=127.0.0.1 -device virtconsole,chardev=virtcon"
|
||||||
# sbsa-ref is a true virtual machine so can't use KVM
|
# sbsa-ref is a true virtual machine so can't use KVM
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
# Configuration for TC1
|
|
||||||
|
|
||||||
#@TYPE: Machine
|
|
||||||
#@NAME: TC1
|
|
||||||
#@DESCRIPTION: Machine configuration for TC1
|
|
||||||
|
|
||||||
require conf/machine/include/tc.inc
|
|
||||||
|
|
||||||
TEST_TARGET = "OEFVPTarget"
|
|
||||||
TEST_SUITES = "fvp_boot"
|
|
||||||
|
|
||||||
# FVP Config
|
|
||||||
FVP_PROVIDER ?= "fvp-tc1-native"
|
|
||||||
FVP_EXE ?= "FVP_TC1"
|
|
||||||
|
|
||||||
# FVP Parameters
|
|
||||||
FVP_CONFIG[css.scp.ROMloader.fname] ?= "scp_romfw.bin"
|
|
||||||
FVP_CONFIG[css.trustedBootROMloader.fname] ?= "bl1-tc.bin"
|
|
||||||
FVP_CONFIG[board.flashloader0.fname] ?= "fip_gpt-tc.bin"
|
|
||||||
|
|
||||||
#FVP_CONFIG[board.hostbridge.userNetworking] ?= "true"
|
|
||||||
#FVP_CONFIG[board.hostbridge.userNetPorts] ?= "2222=22"
|
|
||||||
#smsc ethernet takes a very long time to come up. disable now to prevent testimage timeout
|
|
||||||
#FVP_CONFIG[board.smsc_91c111.enabled] ?= "1"
|
|
||||||
|
|
||||||
FVP_CONSOLE = "terminal_s1"
|
|
||||||
FVP_TERMINALS[soc.terminal_s0] ?= "Secure Console"
|
|
||||||
FVP_TERMINALS[soc.terminal_s1] ?= "Console"
|
|
||||||
|
|
||||||
# Boot image
|
|
||||||
FVP_DATA ?= "board.dram=fitImage-core-image-minimal-tc1-tc1@0x20000000"
|
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
version: 2
|
||||||
|
build:
|
||||||
|
os: "ubuntu-22.04"
|
||||||
|
tools:
|
||||||
|
python: "3.9"
|
||||||
|
sphinx:
|
||||||
|
configuration: meta-arm-bsp/documentation/corstone1000/conf.py
|
||||||
|
formats:
|
||||||
|
- pdf
|
||||||
|
python:
|
||||||
|
install:
|
||||||
|
- requirements: meta-arm-bsp/documentation/requirements.txt
|
||||||
@@ -10,6 +10,77 @@ Change Log
|
|||||||
This document contains a summary of the new features, changes and
|
This document contains a summary of the new features, changes and
|
||||||
fixes in each release of Corstone-1000 software stack.
|
fixes in each release of Corstone-1000 software stack.
|
||||||
|
|
||||||
|
***************
|
||||||
|
Version 2023.11
|
||||||
|
***************
|
||||||
|
|
||||||
|
Changes
|
||||||
|
=======
|
||||||
|
|
||||||
|
- Making Corstone-1000 SystemReady IR 2.0 certifiable
|
||||||
|
- Allow booting Debian & OpenSUSE on FVP
|
||||||
|
- Add support for two MMC cards for the FVP
|
||||||
|
- Add signed capsule update support
|
||||||
|
- Enable on-disk capsule update
|
||||||
|
- Add the feature of purging specific DT nodes in U-Boot before Linux
|
||||||
|
- Add Ethernet over VirtIO support in U-Boot
|
||||||
|
- Add support for unaligned MMC card images
|
||||||
|
- Reducing the out-of-tree patches by upstreaming them to the corresponding open-source projects
|
||||||
|
- SW components upgrades
|
||||||
|
- Bug fixes
|
||||||
|
|
||||||
|
Corstone-1000 components versions
|
||||||
|
=================================
|
||||||
|
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| arm-ffa-tee | 1.1.2-r0 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| linux-yocto | 6.5.7 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| u-boot | 2023.07 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| external-system | 0.1.0+gitAUTOINC+8c9dca74b1-r0 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| optee-client | 3.22.0 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| optee-os | 3.22.0 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| trusted-firmware-a | 2.9.0 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| trusted-firmware-m | 1.8.1 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| libts | 08b3d39471 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| ts-newlib | 4.1.0 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| ts-psa-{crypto, iat, its. ps}-api-test | 38cb53a4d9 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
| ts-sp-{se-proxy, smm-gateway} | 08b3d39471 |
|
||||||
|
+-------------------------------------------+-----------------------------------------------------+
|
||||||
|
|
||||||
|
Yocto distribution components versions
|
||||||
|
======================================
|
||||||
|
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| meta-arm | nanbield |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| poky | nanbield |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| meta-openembedded | nanbield |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| meta-secure-core | nanbield |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| busybox | 1.36.1 |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| musl | 1.2.4 |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| gcc-arm-none-eabi | 11.2-2022.02 |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| gcc-cross-aarch64 | 13.2.0 |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
| openssl | 3.1.3 |
|
||||||
|
+-------------------------------------------+------------------------------+
|
||||||
|
|
||||||
***************
|
***************
|
||||||
Version 2023.06
|
Version 2023.06
|
||||||
***************
|
***************
|
||||||
|
|||||||
Binary file not shown.
|
Before Width: | Height: | Size: 40 KiB After Width: | Height: | Size: 54 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 57 KiB After Width: | Height: | Size: 108 KiB |
@@ -1,11 +1,21 @@
|
|||||||
..
|
..
|
||||||
# Copyright (c) 2022, Arm Limited.
|
# Copyright (c) 2022, 2024, Arm Limited.
|
||||||
#
|
#
|
||||||
# SPDX-License-Identifier: MIT
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
################
|
#################
|
||||||
ARM Corstone1000
|
Arm Corstone-1000
|
||||||
################
|
#################
|
||||||
|
|
||||||
|
*************************
|
||||||
|
Disclaimer
|
||||||
|
*************************
|
||||||
|
|
||||||
|
Arm reference solutions are Arm public example software projects that track and
|
||||||
|
pull upstream components, incorporating their respective security fixes
|
||||||
|
published over time. Arm partners are responsible for ensuring that the
|
||||||
|
components they use contain all the required security fixes, if and when they
|
||||||
|
deploy a product derived from Arm reference solutions.
|
||||||
|
|
||||||
.. toctree::
|
.. toctree::
|
||||||
:maxdepth: 1
|
:maxdepth: 1
|
||||||
|
|||||||
@@ -19,6 +19,27 @@ intended for safety-critical applications. Should Your Software or Your Hardware
|
|||||||
prove defective, you assume the entire cost of all necessary servicing, repair
|
prove defective, you assume the entire cost of all necessary servicing, repair
|
||||||
or correction.
|
or correction.
|
||||||
|
|
||||||
|
***********************
|
||||||
|
Release notes - 2023.11
|
||||||
|
***********************
|
||||||
|
|
||||||
|
Known Issues or Limitations
|
||||||
|
---------------------------
|
||||||
|
|
||||||
|
- Use Ethernet over VirtIO due to lan91c111 Ethernet driver support dropped from U-Boot.
|
||||||
|
- Temporally removing the External system support in Linux due to it using multiple custom devicetree bindings that caused problems with SystemReady IR 2.0 certification. For External system support please refer to the version 2023.06. We are aiming to restore it in a more standardised manner in our next release.
|
||||||
|
- Due to the performance uplimit of MPS3 FPGA and FVP, some Linux distros like Fedora Rawhide can not boot on Corstone-1000 (i.e. user may experience timeouts or boot hang).
|
||||||
|
- PSA Crypto tests (psa-crypto-api-test command) approximately take 30 minutes to complete for FVP and MPS3.
|
||||||
|
- Corstone-1000 SoC on FVP doesn't have a secure debug peripheral. It does on the MPS3.
|
||||||
|
- See previous release notes for the known limitations regarding ACS tests.
|
||||||
|
|
||||||
|
Platform Support
|
||||||
|
-----------------
|
||||||
|
- This software release is tested on Corstone-1000 FPGA version AN550_v2
|
||||||
|
https://developer.arm.com/downloads/-/download-fpga-images
|
||||||
|
- This software release is tested on Corstone-1000 Fast Model platform (FVP) version 11.23_25
|
||||||
|
https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
|
|
||||||
***********************
|
***********************
|
||||||
Release notes - 2023.06
|
Release notes - 2023.06
|
||||||
***********************
|
***********************
|
||||||
|
|||||||
@@ -72,8 +72,10 @@ non-secure and the secure world is performed via FF-A messages.
|
|||||||
|
|
||||||
An external system is intended to implement use-case specific
|
An external system is intended to implement use-case specific
|
||||||
functionality. The system is based on Cortex-M3 and run RTX RTOS.
|
functionality. The system is based on Cortex-M3 and run RTX RTOS.
|
||||||
Communictaion between external system and Host(cortex-A35) is performed
|
Communication between the external system and Host (Cortex-A35) is performed
|
||||||
using MHU as transport mechanism and rpmsg messaging system.
|
using MHU as transport mechanism and rpmsg messaging system (the external system
|
||||||
|
support in Linux is disabled in this release. More info about this change can be found in the
|
||||||
|
release-notes).
|
||||||
|
|
||||||
Overall, the Corstone-1000 architecture is designed to cover a range
|
Overall, the Corstone-1000 architecture is designed to cover a range
|
||||||
of Power, Performance, and Area (PPA) applications, and enable extension
|
of Power, Performance, and Area (PPA) applications, and enable extension
|
||||||
@@ -138,10 +140,13 @@ flow path for such calls.
|
|||||||
|
|
||||||
The SE Proxy SP (Secure Enclave Proxy Secure Partition) is a proxy partition
|
The SE Proxy SP (Secure Enclave Proxy Secure Partition) is a proxy partition
|
||||||
managed by OPTEE which forwards such calls to the secure enclave. The
|
managed by OPTEE which forwards such calls to the secure enclave. The
|
||||||
solution relies on OpenAMP which uses shared memory and MHU interrupts as
|
solution relies on the `RSE communication protocol
|
||||||
a doorbell for communication between two cores. Corstone-1000 implements
|
<https://tf-m-user-guide.trustedfirmware.org/platform/arm/rse/rse_comms.html>`_
|
||||||
isolation level 2. Cortex-M0+ MPU (Memory Protection Unit) is used to implement
|
which is a lightweight serialization of the psa_call() API. It can use shared
|
||||||
isolation level 2.
|
memory and MHU interrupts as a doorbell for communication between two cores
|
||||||
|
but currently the whole message is forwarded through the MHU channels in Corstone-1000.
|
||||||
|
Corstone-1000 implements isolation level 2. Cortex-M0+ MPU (Memory Protection
|
||||||
|
Unit) is used to implement isolation level 2.
|
||||||
|
|
||||||
For a user to define its own secure service, both the options of the host
|
For a user to define its own secure service, both the options of the host
|
||||||
secure world or secure encalve are available. It's a trade-off between
|
secure world or secure encalve are available. It's a trade-off between
|
||||||
@@ -157,9 +162,9 @@ Secure Firmware Update
|
|||||||
**********************
|
**********************
|
||||||
|
|
||||||
Apart from always booting the authorized images, it is also essential that
|
Apart from always booting the authorized images, it is also essential that
|
||||||
the device only accepts the authorized images in the firmware update
|
the device only accepts the authorized (signed) images in the firmware update
|
||||||
process. Corstone-1000 supports OTA (Over the Air) firmware updates and
|
process. Corstone-1000 supports OTA (Over the Air) firmware updates and
|
||||||
follows Platform Security Firmware Update sepcification (`FWU`_).
|
follows Platform Security Firmware Update specification (`FWU`_).
|
||||||
|
|
||||||
As standardized into `FWU`_, the external flash is divided into two
|
As standardized into `FWU`_, the external flash is divided into two
|
||||||
banks of which one bank has currently running images and the other bank is
|
banks of which one bank has currently running images and the other bank is
|
||||||
@@ -172,7 +177,10 @@ Image (the initramfs bundle). The new images are accepted in the form of a UEFI
|
|||||||
:width: 690
|
:width: 690
|
||||||
:alt: ExternalFlash
|
:alt: ExternalFlash
|
||||||
|
|
||||||
|
When Firmware update is triggered, u-boot verifies the capsule by checking the
|
||||||
|
capsule signature, version number and size. Then it signals the Secure Enclave
|
||||||
|
that can start writing UEFI capsule into the flash. Once this operation finishes
|
||||||
|
,Secure Enclave resets the entire system.
|
||||||
The Metadata Block in the flash has the below firmware update state machine.
|
The Metadata Block in the flash has the below firmware update state machine.
|
||||||
TF-M runs an OTA service that is responsible for accepting and updating the
|
TF-M runs an OTA service that is responsible for accepting and updating the
|
||||||
images in the flash. The communication between the UEFI Capsule update
|
images in the flash. The communication between the UEFI Capsule update
|
||||||
@@ -230,7 +238,7 @@ References
|
|||||||
.. _Arm security features: https://www.arm.com/architecture/security-features/platform-security
|
.. _Arm security features: https://www.arm.com/architecture/security-features/platform-security
|
||||||
.. _linux repo: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
|
.. _linux repo: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/
|
||||||
.. _FF-A: https://developer.arm.com/documentation/den0077/latest
|
.. _FF-A: https://developer.arm.com/documentation/den0077/latest
|
||||||
.. _FF-M: https://developer.arm.com/-/media/Files/pdf/PlatformSecurityArchitecture/Architect/DEN0063-PSA_Firmware_Framework-1.0.0-2.pdf?revision=2d1429fa-4b5b-461a-a60e-4ef3d8f7f4b4&hash=3BFD6F3E687F324672F18E5BE9F08EDC48087C93
|
.. _FF-M: https://developer.arm.com/architectures/Firmware%20Framework%20for%20M-Profile
|
||||||
.. _FWU: https://developer.arm.com/documentation/den0118/a/
|
.. _FWU: https://developer.arm.com/documentation/den0118/a/
|
||||||
.. _OPTEE-OS: https://github.com/OP-TEE/optee_os
|
.. _OPTEE-OS: https://github.com/OP-TEE/optee_os
|
||||||
.. _PSA: https://www.psacertified.org/
|
.. _PSA: https://www.psacertified.org/
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
..
|
..
|
||||||
# Copyright (c) 2022-2023, Arm Limited.
|
# Copyright (c) 2022-2024, Arm Limited.
|
||||||
#
|
#
|
||||||
# SPDX-License-Identifier: MIT
|
# SPDX-License-Identifier: MIT
|
||||||
|
|
||||||
@@ -18,7 +18,7 @@ for more information.
|
|||||||
Prerequisites
|
Prerequisites
|
||||||
-------------
|
-------------
|
||||||
|
|
||||||
This guide assumes that your host PC is running Ubuntu 20.04 LTS, with at least
|
This guide assumes that your host machine is running Ubuntu 20.04 LTS, with at least
|
||||||
32GB of free disk space and 16GB of RAM as minimum requirement.
|
32GB of free disk space and 16GB of RAM as minimum requirement.
|
||||||
|
|
||||||
The following prerequisites must be available on the host system:
|
The following prerequisites must be available on the host system:
|
||||||
@@ -68,33 +68,33 @@ Trusted Firmware-A
|
|||||||
==================
|
==================
|
||||||
Based on `Trusted Firmware-A <https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git>`__
|
Based on `Trusted Firmware-A <https://git.trustedfirmware.org/TF-A/trusted-firmware-a.git>`__
|
||||||
|
|
||||||
+----------+-----------------------------------------------------------------------------------------------------+
|
+----------+-------------------------------------------------------------------------------------------------+
|
||||||
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a_2.8.%.bbappend |
|
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-bsp/trusted-firmware-a/trusted-firmware-a_%.bbappend |
|
||||||
+----------+-----------------------------------------------------------------------------------------------------+
|
+----------+-------------------------------------------------------------------------------------------------+
|
||||||
| Recipe | <_workspace>/meta-arm/meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a_2.8.0.bb |
|
| Recipe | <_workspace>/meta-arm/meta-arm/recipes-bsp/trusted-firmware-a/trusted-firmware-a_2.9.0.bb |
|
||||||
+----------+-----------------------------------------------------------------------------------------------------+
|
+----------+-------------------------------------------------------------------------------------------------+
|
||||||
|
|
||||||
OP-TEE
|
OP-TEE
|
||||||
======
|
======
|
||||||
Based on `OP-TEE <https://git.trustedfirmware.org/OP-TEE/optee_os.git>`__
|
Based on `OP-TEE <https://git.trustedfirmware.org/OP-TEE/optee_os.git>`__
|
||||||
|
|
||||||
+----------+------------------------------------------------------------------------------------+
|
+----------+----------------------------------------------------------------------------------------+
|
||||||
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-security/optee/optee-os_3.20.0.bbappend |
|
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-security/optee/optee-os_3.22.0.bbappend |
|
||||||
+----------+------------------------------------------------------------------------------------+
|
+----------+----------------------------------------------------------------------------------------+
|
||||||
| Recipe | <_workspace>/meta-arm/meta-arm/recipes-security/optee/optee-os_3.20.0.bb |
|
| Recipe | <_workspace>/meta-arm/meta-arm-bsp/recipes-security/optee/optee-os_3.22.0.bb |
|
||||||
+----------+------------------------------------------------------------------------------------+
|
+----------+----------------------------------------------------------------------------------------+
|
||||||
|
|
||||||
U-Boot
|
U-Boot
|
||||||
======
|
======
|
||||||
Based on `U-Boot repo`_
|
Based on `U-Boot repo`_
|
||||||
|
|
||||||
+----------+-------------------------------------------------------------------------+
|
+----------+----------------------------------------------------------------------------+
|
||||||
| bbappend | <_workspace>/meta-arm/meta-arm/recipes-bsp/u-boot/u-boot_%.bbappend |
|
| bbappend | <_workspace>/meta-arm/meta-arm/recipes-bsp/u-boot/u-boot_%.bbappend |
|
||||||
+----------+-------------------------------------------------------------------------+
|
+----------+----------------------------------------------------------------------------+
|
||||||
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-bsp/u-boot/u-boot_%.bbappend |
|
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-bsp/u-boot/u-boot_%.bbappend |
|
||||||
+----------+-------------------------------------------------------------------------+
|
+----------+----------------------------------------------------------------------------+
|
||||||
| Recipe | <_workspace>/poky/meta/recipes-bsp/u-boot/u-boot_2023.01.bb |
|
| Recipe | <_workspace>/meta-arm/meta-arm-bsp/recipes-bsp/u-boot/u-boot_2023.07.02.bb |
|
||||||
+----------+-------------------------------------------------------------------------+
|
+----------+----------------------------------------------------------------------------+
|
||||||
|
|
||||||
Linux
|
Linux
|
||||||
=====
|
=====
|
||||||
@@ -107,30 +107,20 @@ recipe responsible for building a tiny version of Linux is listed below.
|
|||||||
+-----------+----------------------------------------------------------------------------------------------+
|
+-----------+----------------------------------------------------------------------------------------------+
|
||||||
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-kernel/linux/linux-yocto_%.bbappend |
|
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-kernel/linux/linux-yocto_%.bbappend |
|
||||||
+-----------+----------------------------------------------------------------------------------------------+
|
+-----------+----------------------------------------------------------------------------------------------+
|
||||||
| Recipe | <_workspace>/poky/meta/recipes-kernel/linux/linux-yocto_6.1.bb |
|
| Recipe | <_workspace>/poky/meta/recipes-kernel/linux/linux-yocto_6.5.bb |
|
||||||
+-----------+----------------------------------------------------------------------------------------------+
|
+-----------+----------------------------------------------------------------------------------------------+
|
||||||
| defconfig | <_workspace>/meta-arm/meta-arm-bsp/recipes-kernel/linux/files/corstone1000/defconfig |
|
| defconfig | <_workspace>/meta-arm/meta-arm-bsp/recipes-kernel/linux/files/corstone1000/defconfig |
|
||||||
+-----------+----------------------------------------------------------------------------------------------+
|
+-----------+----------------------------------------------------------------------------------------------+
|
||||||
|
|
||||||
External System Tests
|
|
||||||
=====================
|
|
||||||
Based on `Corstone-1000/applications <https://git.gitlab.arm.com/arm-reference-solutions/corstone1000/applications>`__
|
|
||||||
|
|
||||||
+------------+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+
|
|
||||||
| Recipe | <_workspace>/meta-arm/meta-arm-bsp/recipes-test/corstone1000-external-sys-tests/corstone1000-external-sys-tests_1.0.bb |
|
|
||||||
+------------+-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+
|
|
||||||
|
|
||||||
The recipe provides the systems-comms-tests command run in Linux and used for testing the External System.
|
|
||||||
|
|
||||||
**************************************************
|
**************************************************
|
||||||
Software for Boot Processor (a.k.a Secure Enclave)
|
Software for Boot Processor (a.k.a Secure Enclave)
|
||||||
**************************************************
|
**************************************************
|
||||||
Based on `Trusted Firmware-M <https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git>`__
|
Based on `Trusted Firmware-M <https://git.trustedfirmware.org/TF-M/trusted-firmware-m.git>`__
|
||||||
|
|
||||||
+----------+-----------------------------------------------------------------------------------------------------+
|
+----------+-----------------------------------------------------------------------------------------------------+
|
||||||
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-bsp/trusted-firmware-m/trusted-firmware-m_1.7.%.bbappend |
|
| bbappend | <_workspace>/meta-arm/meta-arm-bsp/recipes-bsp/trusted-firmware-m/trusted-firmware-m_%.bbappend |
|
||||||
+----------+-----------------------------------------------------------------------------------------------------+
|
+----------+-----------------------------------------------------------------------------------------------------+
|
||||||
| Recipe | <_workspace>/meta-arm/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m_1.7.0.bb |
|
| Recipe | <_workspace>/meta-arm/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m_1.8.1.bb |
|
||||||
+----------+-----------------------------------------------------------------------------------------------------+
|
+----------+-----------------------------------------------------------------------------------------------------+
|
||||||
|
|
||||||
********************************
|
********************************
|
||||||
@@ -156,7 +146,7 @@ to as ``<_workspace>`` in these instructions. To create the folder, run:
|
|||||||
cd <_workspace>
|
cd <_workspace>
|
||||||
|
|
||||||
Corstone-1000 software is based on the Yocto Project which uses kas and bitbake
|
Corstone-1000 software is based on the Yocto Project which uses kas and bitbake
|
||||||
commands to build the stack. To install kas tool, run:
|
commands to build the stack. kas version 4 is required. To install kas, run:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
@@ -168,7 +158,7 @@ In the top directory of the workspace ``<_workspace>``, run:
|
|||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
git clone https://git.yoctoproject.org/git/meta-arm -b CORSTONE1000-2023.06
|
git clone https://git.yoctoproject.org/git/meta-arm -b CORSTONE1000-2023.11
|
||||||
|
|
||||||
To build a Corstone-1000 image for MPS3 FPGA, run:
|
To build a Corstone-1000 image for MPS3 FPGA, run:
|
||||||
|
|
||||||
@@ -199,12 +189,12 @@ Once the build is successful, all output binaries will be placed in the followin
|
|||||||
- ``<_workspace>/build/tmp/deploy/images/corstone1000-mps3/`` folder for FPGA build.
|
- ``<_workspace>/build/tmp/deploy/images/corstone1000-mps3/`` folder for FPGA build.
|
||||||
|
|
||||||
Everything apart from the Secure Enclave ROM firmware and External System firmware, is bundled into a single binary, the
|
Everything apart from the Secure Enclave ROM firmware and External System firmware, is bundled into a single binary, the
|
||||||
``corstone1000-image-corstone1000-{mps3,fvp}.wic`` file.
|
``corstone1000-flash-firmware-image-corstone1000-{mps3,fvp}.wic`` file.
|
||||||
|
|
||||||
The output binaries run in the Corstone-1000 platform are the following:
|
The output binaries run in the Corstone-1000 platform are the following:
|
||||||
- The Secure Enclave ROM firmware: ``<_workspace>/build/tmp/deploy/images/corstone1000-{mps3,fvp}/bl1.bin``
|
- The Secure Enclave ROM firmware: ``<_workspace>/build/tmp/deploy/images/corstone1000-{mps3,fvp}/bl1.bin``
|
||||||
- The External System firmware: ``<_workspace>/build/tmp/deploy/images/corstone1000-{mps3,fvp}/es_flashfw.bin``
|
- The External System firmware: ``<_workspace>/build/tmp/deploy/images/corstone1000-{mps3,fvp}/es_flashfw.bin``
|
||||||
- The flash image: ``<_workspace>/build/tmp/deploy/images/corstone1000-{mps3,fvp}/corstone1000-image-corstone1000-{mps3,fvp}.wic``
|
- The flash image: ``<_workspace>/build/tmp/deploy/images/corstone1000-{mps3,fvp}/corstone1000-flash-firmware-image-corstone1000-{mps3,fvp}.wic``
|
||||||
|
|
||||||
Flash the firmware image on FPGA
|
Flash the firmware image on FPGA
|
||||||
--------------------------------
|
--------------------------------
|
||||||
@@ -283,7 +273,7 @@ OUTPUT_DIR = ``<_workspace>/build/tmp/deploy/images/corstone1000-mps3``
|
|||||||
1. Copy ``bl1.bin`` from OUTPUT_DIR directory to SOFTWARE directory of the FPGA bundle.
|
1. Copy ``bl1.bin`` from OUTPUT_DIR directory to SOFTWARE directory of the FPGA bundle.
|
||||||
2. Copy ``es_flashfw.bin`` from OUTPUT_DIR directory to SOFTWARE directory of the FPGA bundle
|
2. Copy ``es_flashfw.bin`` from OUTPUT_DIR directory to SOFTWARE directory of the FPGA bundle
|
||||||
and rename the binary to ``es0.bin``.
|
and rename the binary to ``es0.bin``.
|
||||||
3. Copy ``corstone1000-image-corstone1000-mps3.wic`` from OUTPUT_DIR directory to SOFTWARE
|
3. Copy ``corstone1000-flash-firmware-image-corstone1000-mps3.wic`` from OUTPUT_DIR directory to SOFTWARE
|
||||||
directory of the FPGA bundle and rename the wic image to ``cs1000.bin``.
|
directory of the FPGA bundle and rename the wic image to ``cs1000.bin``.
|
||||||
|
|
||||||
**NOTE:** Renaming of the images are required because MCC firmware has
|
**NOTE:** Renaming of the images are required because MCC firmware has
|
||||||
@@ -343,11 +333,11 @@ A Yocto recipe is provided and allows to download the latest supported FVP versi
|
|||||||
|
|
||||||
The recipe is located at <_workspace>/meta-arm/meta-arm/recipes-devtools/fvp/fvp-corstone1000.bb
|
The recipe is located at <_workspace>/meta-arm/meta-arm/recipes-devtools/fvp/fvp-corstone1000.bb
|
||||||
|
|
||||||
The latest supported Fixed Virtual Platform (FVP) version is 11.19_21 and is automatically downloaded and installed when using the runfvp command as detailed below. The FVP version can be checked by running the following command:
|
The latest supported Fixed Virtual Platform (FVP) version is 11_23.25 and is automatically downloaded and installed when using the runfvp command as detailed below. The FVP version can be checked by running the following command:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
<_workspace>/meta-arm/scripts/runfvp <_workspace>/build/tmp/deploy/images/corstone1000-fvp/corstone1000-image-corstone1000-fvp.fvpconf -- --version
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c "../meta-arm/scripts/runfvp -- --version"
|
||||||
|
|
||||||
The FVP can also be manually downloaded from the `Arm Ecosystem FVPs`_ page. On this page, navigate
|
The FVP can also be manually downloaded from the `Arm Ecosystem FVPs`_ page. On this page, navigate
|
||||||
to "Corstone IoT FVPs" section to download the Corstone-1000 platform FVP installer. Follow the
|
to "Corstone IoT FVPs" section to download the Corstone-1000 platform FVP installer. Follow the
|
||||||
@@ -357,7 +347,7 @@ To run the FVP using the runfvp command, please run the following command:
|
|||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
<_workspace>/meta-arm/scripts/runfvp --terminals=xterm <_workspace>/build/tmp/deploy/images/corstone1000-fvp/corstone1000-image-corstone1000-fvp.fvpconf
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c "../meta-arm/scripts/runfvp --terminals=xterm"
|
||||||
|
|
||||||
When the script is executed, three terminal instances will be launched, one for the boot processor
|
When the script is executed, three terminal instances will be launched, one for the boot processor
|
||||||
(aka Secure Enclave) processing element and two for the Host processing element. Once the FVP is
|
(aka Secure Enclave) processing element and two for the Host processing element. Once the FVP is
|
||||||
@@ -374,8 +364,6 @@ The host will boot trusted-firmware-a, OP-TEE, U-Boot and then Linux, and presen
|
|||||||
|
|
||||||
Login using the username root.
|
Login using the username root.
|
||||||
|
|
||||||
The External System can be released out of reset on demand using the systems-comms-tests command.
|
|
||||||
|
|
||||||
SystemReady-IR tests
|
SystemReady-IR tests
|
||||||
--------------------
|
--------------------
|
||||||
|
|
||||||
@@ -398,6 +386,42 @@ steps described in following section "Clean Secure Flash Before Testing" to
|
|||||||
erase the SecureEnclave flash cleanly and prepare a clean board environment for
|
erase the SecureEnclave flash cleanly and prepare a clean board environment for
|
||||||
the testing.
|
the testing.
|
||||||
|
|
||||||
|
Prepare EFI System Partition
|
||||||
|
===========================================================
|
||||||
|
Corstone-1000 FVP and FPGA do not have enough on-chip nonvolatile memory to host
|
||||||
|
an EFI System Partition (ESP). Thus, Corstone-1000 uses mass storage device for
|
||||||
|
ESP. The instructions below should be followed for both FVP and FPGA before
|
||||||
|
running the ACS tests.
|
||||||
|
|
||||||
|
**Common to FVP and FPGA:**
|
||||||
|
|
||||||
|
::
|
||||||
|
kas build meta-arm/kas/corstone1000-{mps3,fvp}.yml:meta-arm/ci/debug.yml --target corstone1000-esp-image
|
||||||
|
|
||||||
|
Once the build is successful ``corstone1000-esp-image-corstone1000-{mps3,fvp}.wic`` will be available in either:
|
||||||
|
- ``<_workspace>/build/tmp/deploy/images/corstone1000-fvp/`` folder for FVP build;
|
||||||
|
- ``<_workspace>/build/tmp/deploy/images/corstone1000-mps3/`` folder for FPGA build.
|
||||||
|
|
||||||
|
**Using ESP in FPGA:**
|
||||||
|
|
||||||
|
Once the ESP is created, it needs to be flashed to a second USB drive different than ACS image.
|
||||||
|
This can be done with the development machine. In the given example here
|
||||||
|
we assume the USB device is ``/dev/sdb`` (the user should use ``lsblk`` command to
|
||||||
|
confirm). Be cautious here and don't confuse your host machine own hard drive with the
|
||||||
|
USB drive. Run the following commands to prepare the ACS image in USB stick:
|
||||||
|
|
||||||
|
::
|
||||||
|
sudo dd if=corstone1000-esp-image-corstone1000-mps3.wic of=/dev/sdb iflag=direct oflag=direct status=progress bs=512; sync;
|
||||||
|
|
||||||
|
Now you can plug this USB stick to the board together with ACS test USB stick.
|
||||||
|
|
||||||
|
**Using ESP in FVP:**
|
||||||
|
|
||||||
|
The ESP disk image once created will be used automatically in the Corstone-1000 FVP as the 2nd MMC card image.
|
||||||
|
|
||||||
|
::
|
||||||
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c "../meta-arm/scripts/runfvp -- -C board.msd_mmc.p_mmc_file="${<path-to-img>/ir_acs_live_image.img}"
|
||||||
|
|
||||||
Clean Secure Flash Before Testing (applicable to FPGA only)
|
Clean Secure Flash Before Testing (applicable to FPGA only)
|
||||||
===========================================================
|
===========================================================
|
||||||
|
|
||||||
@@ -408,8 +432,8 @@ boot. Run following commands to build such image.
|
|||||||
::
|
::
|
||||||
|
|
||||||
cd <_workspace>
|
cd <_workspace>
|
||||||
git clone https://git.yoctoproject.org/git/meta-arm -b CORSTONE1000-2023.06
|
git clone https://git.yoctoproject.org/git/meta-arm -b CORSTONE1000-2023.11
|
||||||
git clone https://git.gitlab.arm.com/arm-reference-solutions/systemready-patch.git -b CORSTONE1000-2023.06
|
git clone https://git.gitlab.arm.com/arm-reference-solutions/systemready-patch.git -b CORSTONE1000-2023.11
|
||||||
cp -f systemready-patch/embedded-a/corstone1000/erase_flash/0001-embedded-a-corstone1000-clean-secure-flash.patch meta-arm
|
cp -f systemready-patch/embedded-a/corstone1000/erase_flash/0001-embedded-a-corstone1000-clean-secure-flash.patch meta-arm
|
||||||
cd meta-arm
|
cd meta-arm
|
||||||
git apply 0001-embedded-a-corstone1000-clean-secure-flash.patch
|
git apply 0001-embedded-a-corstone1000-clean-secure-flash.patch
|
||||||
@@ -418,7 +442,7 @@ boot. Run following commands to build such image.
|
|||||||
|
|
||||||
Replace the bl1.bin and cs1000.bin files on the SD card with following files:
|
Replace the bl1.bin and cs1000.bin files on the SD card with following files:
|
||||||
- The ROM firmware: <_workspace>/build/tmp/deploy/images/corstone1000-mps3/bl1.bin
|
- The ROM firmware: <_workspace>/build/tmp/deploy/images/corstone1000-mps3/bl1.bin
|
||||||
- The flash image: <_workspace>/build/tmp/deploy/images/corstone1000-mps3/corstone1000-image-corstone1000-mps3.wic
|
- The flash image: <_workspace>/build/tmp/deploy/images/corstone1000-mps3/corstone1000-flash-firmware-image-corstone1000-mps3.wic
|
||||||
|
|
||||||
Now reboot the board. This step erases the Corstone-1000 SecureEnclave flash
|
Now reboot the board. This step erases the Corstone-1000 SecureEnclave flash
|
||||||
completely, the user should expect following message from TF-M log (can be seen
|
completely, the user should expect following message from TF-M log (can be seen
|
||||||
@@ -471,7 +495,7 @@ BOOT partition contains the following:
|
|||||||
└── ramdisk-busybox.img
|
└── ramdisk-busybox.img
|
||||||
|
|
||||||
RESULT partition is used to store the test results.
|
RESULT partition is used to store the test results.
|
||||||
**NOTE**: PLEASE MAKE SURE THAT THE RESULT PARTITION IS EMPTY BEFORE YOU START THE TESTING. OTHERWISE THE TEST RESULTS
|
**NOTE**: PLEASE MAKE SURE THAT "acs_results" FOLDER UNDER THE RESULT PARTITION IS EMPTY BEFORE YOU START THE TESTING. OTHERWISE THE TEST RESULTS
|
||||||
WILL NOT BE CONSISTENT
|
WILL NOT BE CONSISTENT
|
||||||
|
|
||||||
FPGA instructions for ACS image
|
FPGA instructions for ACS image
|
||||||
@@ -500,7 +524,7 @@ SystemReady release in this repository.
|
|||||||
|
|
||||||
Then, the user should prepare a USB stick with ACS image. In the given example here,
|
Then, the user should prepare a USB stick with ACS image. In the given example here,
|
||||||
we assume the USB device is ``/dev/sdb`` (the user should use ``lsblk`` command to
|
we assume the USB device is ``/dev/sdb`` (the user should use ``lsblk`` command to
|
||||||
confirm). Be cautious here and don't confuse your host PC's own hard drive with the
|
confirm). Be cautious here and don't confuse your host machine own hard drive with the
|
||||||
USB drive. Run the following commands to prepare the ACS image in USB stick:
|
USB drive. Run the following commands to prepare the ACS image in USB stick:
|
||||||
|
|
||||||
::
|
::
|
||||||
@@ -510,45 +534,44 @@ USB drive. Run the following commands to prepare the ACS image in USB stick:
|
|||||||
sudo dd if=ir-acs-live-image-generic-arm64.wic of=/dev/sdb iflag=direct oflag=direct bs=1M status=progress; sync
|
sudo dd if=ir-acs-live-image-generic-arm64.wic of=/dev/sdb iflag=direct oflag=direct bs=1M status=progress; sync
|
||||||
|
|
||||||
Once the USB stick with ACS image is prepared, the user should make sure that
|
Once the USB stick with ACS image is prepared, the user should make sure that
|
||||||
ensure that only the USB stick with the ACS image is connected to the board,
|
ensure that both USB sticks (ESP and ACS image) are connected to the board,
|
||||||
and then boot the board.
|
and then boot the board.
|
||||||
|
|
||||||
The FPGA will reset multiple times during the test, and it might take approx. 24-36 hours to finish the test.
|
The FPGA will reset multiple times during the test, and it might take approx. 24-36 hours to finish the test.
|
||||||
|
|
||||||
|
**NOTE**: The USB stick which contains the ESP partition might cause grub to
|
||||||
|
unable to find the bootable partition (only in the FPGA). If that's the case, please
|
||||||
|
remove the USB stick and run the ACS tests. ESP partition can be mounted after
|
||||||
|
the platform is booted to linux at the end of the ACS tests.
|
||||||
|
|
||||||
|
|
||||||
FVP instructions for ACS image and run
|
FVP instructions for ACS image and run
|
||||||
======================================
|
======================================
|
||||||
|
|
||||||
Download ACS image from:
|
The FVP has been integrated in the meta-arm-systemready layer so the running of the ACS tests can be handled automatically as follows
|
||||||
- ``https://gitlab.arm.com/systemready/acs/arm-systemready/-/tree/main/IR/prebuilt_images/v23.03_2.0.0``
|
::
|
||||||
|
|
||||||
Use the below command to run the FVP with ACS image support in the
|
kas build meta-arm/ci/corstone1000-fvp.yml:meta-arm/ci/debug.yml:kas/arm-systemready-ir-acs.yml
|
||||||
SD card.
|
|
||||||
|
The details of how this layer works can be found in : ``<_workspace>/meta-arm-systemready/README.md``
|
||||||
|
|
||||||
|
**NOTE:** You can't use the standard meta-arm/kas/corstone1000-fvp.yml kas file as it sets the build up for only building firmware
|
||||||
|
|
||||||
|
**NOTE:** These test might take up to 1 day to finish
|
||||||
|
|
||||||
|
**NOTE:** A rare issue has been noticed (5-6% occurence) during which the FVP hangs during booting the system while running ACS tests.
|
||||||
|
If this happens, please apply the following patch, rebuild the software stack for FVP and re-run the ACS tests.
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
unxz ${<path-to-img>/ir-acs-live-image-generic-arm64.wic.xz}
|
cd <_workspace>
|
||||||
|
git clone https://git.gitlab.arm.com/arm-reference-solutions/systemready-patch.git -b CORSTONE1000-2023.11
|
||||||
|
cp -f systemready-patch/embedded-a/corstone1000/sr_ir_workaround/0001-embedded-a-corstone1000-sr-ir-workaround.patch meta-arm
|
||||||
|
cd meta-arm
|
||||||
|
git am 0001-embedded-a-corstone1000-sr-ir-workaround.patch
|
||||||
|
cd ..
|
||||||
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c "bitbake u-boot -c cleanall; bitbake trusted-firmware-a -c cleanall; bitbake corstone1000-flash-firmware-image -c cleanall; bitbake corstone1000-flash-firmware-image"
|
||||||
|
|
||||||
<_workspace>/meta-arm/scripts/runfvp --terminals=xterm <_workspace>/build/tmp/deploy/images/corstone1000-fvp/corstone1000-image-corstone1000-fvp.fvpconf -- -C board.msd_mmc.p_mmc_file=<path-to-img>/ir-acs-live-image-generic-arm64.wic
|
|
||||||
|
|
||||||
The test results can be fetched using following commands:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
sudo mkdir /mnt/test
|
|
||||||
sudo mount -o rw,offset=<offset_3rd_partition> <path-to-img>/ir-acs-live-image-generic-arm64.wic /mnt/test/
|
|
||||||
fdisk -lu <path-to-img>/ir-acs-live-image-generic-arm64.wic
|
|
||||||
-> Device Start End Sectors Size Type
|
|
||||||
<path-to-img>/ir-acs-live-image-generic-arm64.wic1 2048 206847 204800 100M Microsoft basic data
|
|
||||||
<path-to-img>/ir-acs-live-image-generic-arm64.wic2 206848 1024239 817392 399.1M Linux filesystem
|
|
||||||
<path-to-img>/ir-acs-live-image-generic-arm64.wic3 1026048 1128447 102400 50M Microsoft basic data
|
|
||||||
|
|
||||||
-> <offset_3rd_partition> = 1026048 * 512 (sector size) = 525336576
|
|
||||||
|
|
||||||
The FVP will reset multiple times during the test, and it might take up to 1 day to finish
|
|
||||||
the test. At the end of test, the FVP host terminal will halt showing a shell prompt.
|
|
||||||
Once test is finished, the FVP can be stoped, and result can be copied following above
|
|
||||||
instructions.
|
|
||||||
|
|
||||||
Common to FVP and FPGA
|
Common to FVP and FPGA
|
||||||
======================
|
======================
|
||||||
@@ -568,7 +591,7 @@ The results can be fetched from the ``acs_results`` folder in the RESULT partiti
|
|||||||
Manual capsule update and ESRT checks
|
Manual capsule update and ESRT checks
|
||||||
-------------------------------------
|
-------------------------------------
|
||||||
|
|
||||||
The following section describes running manual capsule update with the ``direct`` method.
|
The following section describes running manual capsule update.
|
||||||
|
|
||||||
The steps described in this section perform manual capsule update and show how to use the ESRT feature
|
The steps described in this section perform manual capsule update and show how to use the ESRT feature
|
||||||
to retrieve the installed capsule details.
|
to retrieve the installed capsule details.
|
||||||
@@ -581,71 +604,57 @@ incorrect capsule (corrupted or outdated) which fails to boot to the host softwa
|
|||||||
Check the "Run SystemReady-IR ACS tests" section above to download and unpack the ACS image file
|
Check the "Run SystemReady-IR ACS tests" section above to download and unpack the ACS image file
|
||||||
- ``ir-acs-live-image-generic-arm64.wic.xz``
|
- ``ir-acs-live-image-generic-arm64.wic.xz``
|
||||||
|
|
||||||
|
|
||||||
Download u-boot under <_workspace> and install tools:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
git clone https://github.com/u-boot/u-boot.git
|
|
||||||
cd u-boot
|
|
||||||
git checkout 83aa0ed1e93e1ffac24888d98d37a5b04ed3fb07
|
|
||||||
make tools-only_defconfig
|
|
||||||
make tools-only
|
|
||||||
|
|
||||||
Download systemready-patch repo under <_workspace>:
|
Download systemready-patch repo under <_workspace>:
|
||||||
::
|
::
|
||||||
|
|
||||||
git clone https://git.gitlab.arm.com/arm-reference-solutions/systemready-patch.git -b CORSTONE1000-2023.06
|
git clone https://git.gitlab.arm.com/arm-reference-solutions/systemready-patch.git -b CORSTONE1000-2023.11
|
||||||
|
|
||||||
*******************
|
*******************
|
||||||
Generating Capsules
|
Generating Capsules
|
||||||
*******************
|
*******************
|
||||||
|
|
||||||
Generating FPGA Capsules
|
A no-partition image is created during the Yocto build. An update capsule is generated using this ``.nopt`` image.
|
||||||
========================
|
This can be found in ``build/tmp_corstone1000-<fvp/mps3>/deploy/images/corstone1000-<fvp/mps3>/corstone1000-<fvp/mps3>_image.nopt``.
|
||||||
|
The capsule's default metadata (name, version, etc.) can be found in ``meta-arm/meta-arm-bsp/recipes-bsp/images/corstone1000-flash-firmware-image.bb``
|
||||||
|
and ``meta-arm/kas/corstone1000-image-configuration.yml``.
|
||||||
|
|
||||||
::
|
FPGA Capsules
|
||||||
|
=============
|
||||||
|
|
||||||
cd <_workspace>/build/tmp/deploy/images/corstone1000-mps3/
|
The generated capsule can be found in ``build/tmp_corstone1000-mps3/deploy/images/corstone1000-mps3/corstone1000-mps3-v6.uefi.capsule``.
|
||||||
sh <_workspace>/systemready-patch/embedded-a/corstone1000/capsule_gen/capsule_gen.sh -d mps3
|
If a new capsule has to be generated with different metadata, then it can be done by using the ``u-boot-tools`` and the previously
|
||||||
|
created ``.nopt`` image.
|
||||||
This will generate a file called "corstone1000_image.nopt" which will be used to
|
|
||||||
generate a UEFI capsule.
|
|
||||||
|
|
||||||
|
For example a capsule for the negative update test scenario, if the host's architecture is x86_64:
|
||||||
::
|
::
|
||||||
|
|
||||||
cd <_workspace>
|
cd <_workspace>
|
||||||
|
|
||||||
./u-boot/tools/mkeficapsule --monotonic-count 1 --private-key build/tmp/deploy/images/corstone1000-mps3/corstone1000_capsule_key.key \
|
./build/tmp/sysroots-components/x86_64/u-boot-tools-native/usr/bin/mkeficapsule --monotonic-count 1 \
|
||||||
--certificate build/tmp/deploy/images/corstone1000-mps3/corstone1000_capsule_cert.crt --index 1 --guid 989f3a4e-46e0-4cd0-9877-a25c70c01329 \
|
--private-key build/tmp/deploy/images/corstone1000-mps3/corstone1000_capsule_key.key \
|
||||||
--fw-version 6 build/tmp/deploy/images/corstone1000-mps3/corstone1000_image.nopt cs1k_cap_mps3_v6
|
--certificate build/tmp/deploy/images/corstone1000-mps3/corstone1000_capsule_cert.crt --index 1 --guid df1865d1-90fb-4d59-9c38-c9f2c1bba8cc \
|
||||||
|
--fw-version 5 build/tmp_corstone1000-mps3/deploy/images/corstone1000-mps3/corstone1000-mps3_image.nopt corstone1000-mps3-v5.uefi.capsule
|
||||||
|
|
||||||
./u-boot/tools/mkeficapsule --monotonic-count 1 --private-key build/tmp/deploy/images/corstone1000-mps3/corstone1000_capsule_key.key \
|
This command will put the newly generated capsule to the ``<_workspace>`` directory.
|
||||||
--certificate build/tmp/deploy/images/corstone1000-mps3/corstone1000_capsule_cert.crt --index 1 --guid 989f3a4e-46e0-4cd0-9877-a25c70c01329 \
|
|
||||||
--fw-version 5 build/tmp/deploy/images/corstone1000-mps3/corstone1000_image.nopt cs1k_cap_mps3_v5
|
|
||||||
|
|
||||||
Generating FVP Capsules
|
Generating FVP Capsules
|
||||||
=======================
|
=======================
|
||||||
|
|
||||||
::
|
The generated capsule can be found in ``build/tmp_corstone1000-fvp/deploy/images/corstone1000-fvp/corstone1000-fvp-v6.uefi.capsule``.
|
||||||
|
If a new capsule has to be generated with different metadata, then it can be done by using the ``u-boot-tools`` and the previously
|
||||||
cd <_workspace>/build/tmp/deploy/images/corstone1000-fvp/
|
created ``.nopt`` image.
|
||||||
sh <_workspace>/systemready-patch/embedded-a/corstone1000/capsule_gen/capsule_gen.sh -d fvp
|
|
||||||
|
|
||||||
This will generate a file called "corstone1000_image.nopt" which will be used to
|
|
||||||
generate a UEFI capsule.
|
|
||||||
|
|
||||||
|
For example a capsule for the negative update test scenario, if the host's architecture is x86_64:
|
||||||
::
|
::
|
||||||
|
|
||||||
cd <_workspace>
|
cd <_workspace>
|
||||||
./u-boot/tools/mkeficapsule --monotonic-count 1 --private-key build/tmp/deploy/images/corstone1000-fvp/corstone1000_capsule_key.key \
|
|
||||||
--certificate build/tmp/deploy/images/corstone1000-fvp/corstone1000_capsule_cert.crt --index 1 --guid 989f3a4e-46e0-4cd0-9877-a25c70c01329 \
|
|
||||||
--fw-version 6 build/tmp/deploy/images/corstone1000-fvp/corstone1000_image.nopt cs1k_cap_fvp_v6
|
|
||||||
|
|
||||||
./u-boot/tools/mkeficapsule --monotonic-count 1 --private-key build/tmp/deploy/images/corstone1000-fvp/corstone1000_capsule_key.key \
|
./build/tmp/sysroots-components/x86_64/u-boot-tools-native/usr/bin/mkeficapsule --monotonic-count 1 \
|
||||||
|
--private-key build/tmp/deploy/images/corstone1000-fvp/corstone1000_capsule_key.key \
|
||||||
--certificate build/tmp/deploy/images/corstone1000-fvp/corstone1000_capsule_cert.crt --index 1 --guid 989f3a4e-46e0-4cd0-9877-a25c70c01329 \
|
--certificate build/tmp/deploy/images/corstone1000-fvp/corstone1000_capsule_cert.crt --index 1 --guid 989f3a4e-46e0-4cd0-9877-a25c70c01329 \
|
||||||
--fw-version 5 build/tmp/deploy/images/corstone1000-fvp/corstone1000_image.nopt cs1k_cap_fvp_v5
|
--fw-version 5 build/tmp_corstone1000-fvp/deploy/images/corstone1000-fvp/corstone1000-fvp_image.nopt corstone1000-fvp-v5.uefi.capsule
|
||||||
|
|
||||||
|
This command will put the newly generated capsule to the ``<_workspace>`` directory.
|
||||||
|
|
||||||
Common Notes for FVP and FPGA
|
Common Notes for FVP and FPGA
|
||||||
=============================
|
=============================
|
||||||
@@ -664,33 +673,45 @@ Copying the FPGA capsules
|
|||||||
=========================
|
=========================
|
||||||
|
|
||||||
The user should prepare a USB stick as explained in ACS image section `FPGA instructions for ACS image`_.
|
The user should prepare a USB stick as explained in ACS image section `FPGA instructions for ACS image`_.
|
||||||
Place the generated ``cs1k_cap`` files in the root directory of the boot partition
|
Place the generated ``corstone1000-mps3-v<5/6>.uefi.capsule`` files in the root directory of the boot partition
|
||||||
in the USB stick. Note: As we are running the direct method, the ``cs1k_cap`` file
|
in the USB stick. Note: As we are running the direct method, the ``corstone1000-mps3-v<5/6>.uefi.capsule`` files
|
||||||
should not be under the EFI/UpdateCapsule directory as this may or may not trigger
|
should not be under the EFI/UpdateCapsule directory as this may or may not trigger
|
||||||
the on disk method.
|
the on disk method.
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
sudo cp cs1k_cap_mps3_v6 <mounting path>/BOOT/
|
sudo cp <capsule path>/corstone1000-mps3-v6.uefi.capsule <mounting path>/BOOT/
|
||||||
sudo cp cs1k_cap_mps3_v5 <mounting path>/BOOT/
|
sudo cp <capsule path>/corstone1000-mps3-v5.uefi.capsule <mounting path>/BOOT/
|
||||||
sync
|
sync
|
||||||
|
|
||||||
Copying the FVP capsules
|
Copying the FVP capsules
|
||||||
========================
|
========================
|
||||||
|
|
||||||
First, mount the IR image:
|
First, Find the 1st partition offset:
|
||||||
|
|
||||||
|
::
|
||||||
|
|
||||||
|
fdisk -lu <path-to-img>/ir-acs-live-image-generic-arm64.wic
|
||||||
|
-> Device Start End Sectors Size Type
|
||||||
|
<path-to-img>/ir-acs-live-image-generic-arm64.wic1 2048 206847 204800 100M Microsoft basic data
|
||||||
|
<path-to-img>/ir-acs-live-image-generic-arm64.wic2 206848 1024239 817392 399.1M Linux filesystem
|
||||||
|
<path-to-img>/ir-acs-live-image-generic-arm64.wic3 1026048 1128447 102400 50M Microsoft basic data
|
||||||
|
|
||||||
|
-> <offset_3rd_partition> = 2048 * 512 (sector size) = 1048576
|
||||||
|
|
||||||
|
Next, mount the IR image:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
sudo mkdir /mnt/test
|
sudo mkdir /mnt/test
|
||||||
sudo mount -o rw,offset=1048576 <path-to-img>/ir-acs-live-image-generic-arm64.wic /mnt/test
|
sudo mount -o rw,offset=<first_partition_offset> <path-to-img>/ir-acs-live-image-generic-arm64.wic /mnt/test
|
||||||
|
|
||||||
Then, copy the capsules:
|
Then, copy the capsules:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
sudo cp cs1k_cap_fvp_v6 /mnt/test/
|
sudo cp <capsule path>/corstone1000-fvp-v6.uefi.capsule /mnt/test/
|
||||||
sudo cp cs1k_cap_fvp_v5 /mnt/test/
|
sudo cp <capsule path>/corstone1000-fvp-v5.uefi.capsule /mnt/test/
|
||||||
sync
|
sync
|
||||||
|
|
||||||
Then, unmount the IR image:
|
Then, unmount the IR image:
|
||||||
@@ -699,27 +720,17 @@ Then, unmount the IR image:
|
|||||||
|
|
||||||
sudo umount /mnt/test
|
sudo umount /mnt/test
|
||||||
|
|
||||||
**NOTE:**
|
|
||||||
|
|
||||||
The size of first partition in the image file is calculated in the following way. The data is
|
|
||||||
just an example and might vary with different ir-acs-live-image-generic-arm64.wic files.
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
fdisk -lu <path-to-img>/ir-acs-live-image-generic-arm64.wic
|
|
||||||
-> Device Start End Sectors Size Type
|
|
||||||
<path-to-img>/ir-acs-live-image-generic-arm64.wic1 2048 206847 204800 100M Microsoft basic data
|
|
||||||
<path-to-img>/ir-acs-live-image-generic-arm64.wic2 206848 1024239 817392 399.1M Linux filesystem
|
|
||||||
<path-to-img>/ir-acs-live-image-generic-arm64.wic3 1026048 1128447 102400 50M Microsoft basic data
|
|
||||||
|
|
||||||
-> <offset_1st_partition> = 2048 * 512 (sector size) = 1048576
|
|
||||||
|
|
||||||
******************************
|
******************************
|
||||||
Performing the capsule update
|
Performing the capsule update
|
||||||
******************************
|
******************************
|
||||||
|
|
||||||
During this section we will be using the capsule with the higher version (cs1k_cap_<fvp/mps3>_v6) for the positive scenario
|
During this section we will be using the capsule with the higher version (``corstone1000-<fvp/mps3>-v6.uefi.capsule``) for the positive scenario
|
||||||
and the capsule with the lower version (cs1k_cap_<fvp/mps3>_v5) for the negative scenario.
|
and the capsule with the lower version (``corstone1000-<fvp/mps3>-v5.uefi.capsule``) for the negative scenario.
|
||||||
|
|
||||||
|
Running the FPGA with the IR prebuilt image
|
||||||
|
===========================================
|
||||||
|
|
||||||
|
Insert the prepared USB stick then Power cycle the MPS3 board.
|
||||||
|
|
||||||
Running the FVP with the IR prebuilt image
|
Running the FVP with the IR prebuilt image
|
||||||
==========================================
|
==========================================
|
||||||
@@ -728,17 +739,9 @@ Run the FVP with the IR prebuilt image:
|
|||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
<_workspace>/meta-arm/scripts/runfvp --terminals=xterm <_workspace>/build/tmp/deploy/images/corstone1000-fvp/corstone1000-image-corstone1000-fvp.fvpconf -- -C board.msd_mmc.p_mmc_file=<path-to-img>/ir-acs-live-image-generic-arm64.wic
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c "../meta-arm/scripts/runfvp --terminals=xterm -- -C board.msd_mmc.p_mmc_file=<path-to-img>/ir-acs-live-image-generic-arm64.wic"
|
||||||
|
|
||||||
**NOTE:**
|
**NOTE:** <path-to-img> must start from the root directory. make sure there are no spaces before or after of "=". board.msd_mmc.p_mmc_file=<path-to-img>/ir-acs-live-image-generic-arm64.wic.
|
||||||
|
|
||||||
<path-to-img> must start from the root directory.
|
|
||||||
make sure there are no spaces before or after of "=". board.msd_mmc.p_mmc_file=<path-to-img>/ir-acs-live-image-generic-arm64.wic.
|
|
||||||
|
|
||||||
Running the FPGA with the IR prebuilt image
|
|
||||||
===========================================
|
|
||||||
|
|
||||||
Insert the prepared USB stick then Power cycle the MPS3 board.
|
|
||||||
|
|
||||||
Executing capsule update for FVP and FPGA
|
Executing capsule update for FVP and FPGA
|
||||||
=========================================
|
=========================================
|
||||||
@@ -759,7 +762,7 @@ In case of the positive scenario run the update with the higher version capsule
|
|||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
EFI/BOOT/app/CapsuleApp.efi cs1k_cap_<fvp/mps3>_v6
|
EFI/BOOT/app/CapsuleApp.efi corstone1000-<fvp/mps3>-v6.uefi.capsule
|
||||||
|
|
||||||
After successfully updating the capsule the system will reset.
|
After successfully updating the capsule the system will reset.
|
||||||
|
|
||||||
@@ -767,7 +770,7 @@ In case of the negative scenario run the update with the lower version capsule a
|
|||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
EFI/BOOT/app/CapsuleApp.efi cs1k_cap_<fvp/mps3>_v5
|
EFI/BOOT/app/CapsuleApp.efi corstone1000-<fvp/mps3>-v5.uefi.capsule
|
||||||
|
|
||||||
The command above should fail and in the TF-M logs the following message should appear:
|
The command above should fail and in the TF-M logs the following message should appear:
|
||||||
|
|
||||||
@@ -859,8 +862,8 @@ In the Linux command-line run the following:
|
|||||||
lowest_supported_fw_ver: 0
|
lowest_supported_fw_ver: 0
|
||||||
|
|
||||||
|
|
||||||
Negative scenario
|
Negative scenario (Applicable to FPGA only)
|
||||||
=================
|
===========================================
|
||||||
|
|
||||||
In the negative case scenario (rollback the capsule version), the user should
|
In the negative case scenario (rollback the capsule version), the user should
|
||||||
see appropriate logs in the secure enclave terminal.
|
see appropriate logs in the secure enclave terminal.
|
||||||
@@ -923,19 +926,25 @@ In the Linux command-line run the following:
|
|||||||
last_attempt_version: 5
|
last_attempt_version: 5
|
||||||
lowest_supported_fw_ver: 0
|
lowest_supported_fw_ver: 0
|
||||||
|
|
||||||
|
**Note**: This test is currently not working properly in Corstone-1000 FVP.
|
||||||
|
However, it is not part of the System-Ready IR tests, and it won't affect the
|
||||||
|
SR-IR certification. All the compulsory `capsule update tests for SR-IR
|
||||||
|
<https://developer.arm.com/documentation/DUI1101/2-1/Test-SystemReady-IR/Test-UpdateCapsule>`__
|
||||||
|
works on both Corstone-1000 FVP and FPGA.
|
||||||
|
|
||||||
Linux distros tests
|
Linux distros tests
|
||||||
-------------------
|
-------------------
|
||||||
|
|
||||||
*************************************************************
|
*************************************************************
|
||||||
Debian install and boot preparation (applicable to FPGA only)
|
Debian install and boot preparation
|
||||||
*************************************************************
|
*************************************************************
|
||||||
|
|
||||||
There is a known issue in the `Shim 15.7 <https://salsa.debian.org/efi-team/shim/-/tree/upstream/15.7?ref_type=tags>`__
|
There is a known issue in the `Shim 15.7 <https://salsa.debian.org/efi-team/shim/-/tree/upstream/15.7?ref_type=tags>`__
|
||||||
provided with the Debian installer image (see below). This bug causes a fatal
|
provided with the Debian installer image (see below). This bug causes a fatal
|
||||||
error when attempting to boot media installer for Debian, and it resets the MPS3 before installation starts.
|
error when attempting to boot media installer for Debian, and it resets the platform before installation starts.
|
||||||
A patch to be applied to the Corstone-1000 stack (only applicable when
|
A patch to be applied to the Corstone-1000 stack (only applicable when
|
||||||
installing Debian) is provided to
|
installing Debian) is provided to
|
||||||
`Skip the Shim <https://gitlab.arm.com/arm-reference-solutions/systemready-patch/-/blob/CORSTONE1000-2023.06/embedded-a/corstone1000/shim/0001-arm-bsp-u-boot-corstone1000-Skip-the-shim-by-booting.patch>`__.
|
`Skip the Shim <https://gitlab.arm.com/arm-reference-solutions/systemready-patch/-/blob/CORSTONE1000-2023.11/embedded-a/corstone1000/shim/0001-arm-bsp-u-boot-corstone1000-Skip-the-shim-by-booting.patch>`__.
|
||||||
This patch makes U-Boot automatically bypass the Shim and run grub and allows
|
This patch makes U-Boot automatically bypass the Shim and run grub and allows
|
||||||
the user to proceed with a normal installation. If at the moment of reading this
|
the user to proceed with a normal installation. If at the moment of reading this
|
||||||
document the problem is solved in the Shim, the user is encouraged to try the
|
document the problem is solved in the Shim, the user is encouraged to try the
|
||||||
@@ -947,36 +956,58 @@ documentation.
|
|||||||
::
|
::
|
||||||
|
|
||||||
cd <_workspace>
|
cd <_workspace>
|
||||||
git clone https://git.gitlab.arm.com/arm-reference-solutions/systemready-patch.git -b CORSTONE1000-2023.06
|
git clone https://git.gitlab.arm.com/arm-reference-solutions/systemready-patch.git -b CORSTONE1000-2023.11
|
||||||
cp -f systemready-patch/embedded-a/corstone1000/shim/0001-arm-bsp-u-boot-corstone1000-Skip-the-shim-by-booting.patch meta-arm
|
cp -f systemready-patch/embedded-a/corstone1000/shim/0001-arm-bsp-u-boot-corstone1000-Skip-the-shim-by-booting.patch meta-arm
|
||||||
cd meta-arm
|
cd meta-arm
|
||||||
git am 0001-arm-bsp-u-boot-corstone1000-Skip-the-shim-by-booting.patch
|
git am 0001-arm-bsp-u-boot-corstone1000-Skip-the-shim-by-booting.patch
|
||||||
cd ..
|
cd ..
|
||||||
kas shell meta-arm/kas/corstone1000-mps3.yml:meta-arm/ci/debug.yml -c="bitbake u-boot trusted-firmware-a corstone1000-image -c cleansstate; bitbake corstone1000-image"
|
|
||||||
|
|
||||||
Please update the cs1000.bin on the SD card with the newly generated wic file.
|
**On FPGA**
|
||||||
|
::
|
||||||
|
|
||||||
|
kas shell meta-arm/kas/corstone1000-mps3.yml:meta-arm/ci/debug.yml -c="bitbake u-boot trusted-firmware-a corstone1000-flash-firmware-image -c cleansstate; bitbake corstone1000-flash-firmware-image"
|
||||||
|
|
||||||
|
**On FVP**
|
||||||
|
::
|
||||||
|
|
||||||
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c="bitbake u-boot trusted-firmware-a corstone1000-flash-firmware-image -c cleansstate; bitbake corstone1000-flash-firmware-image"
|
||||||
|
|
||||||
|
On FPGA, please update the cs1000.bin on the SD card with the newly generated wic file.
|
||||||
|
|
||||||
|
**NOTE:** Skip the shim patch only applies to Debian installation. The user should remove the patch from meta-arm before running the software to boot OpenSUSE or executing any other tests in this user guide. You can make sure of removing the skip the shim patch by executing the steps below.
|
||||||
|
|
||||||
|
::
|
||||||
|
|
||||||
|
cd <_workspace>/meta-arm
|
||||||
|
git reset --hard HEAD~1
|
||||||
|
cd ..
|
||||||
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c="bitbake u-boot -c cleanall; bitbake trusted-firmware-a -c cleanall; bitbake corstone1000-flash-firmware-image -c cleanall; bitbake corstone1000-flash-firmware-image"
|
||||||
|
|
||||||
*************************************************
|
*************************************************
|
||||||
Debian/openSUSE install (applicable to FPGA only)
|
Preparing the Installation Media
|
||||||
*************************************************
|
*************************************************
|
||||||
|
|
||||||
To test Linux distro install and boot, the user should prepare two empty USB
|
|
||||||
sticks (minimum size should be 4GB and formatted with FAT32).
|
|
||||||
|
|
||||||
Download one of following Linux distro images:
|
Download one of following Linux distro images:
|
||||||
- `Debian 12.0.0 installer image <https://cdimage.debian.org/debian-cd/current/arm64/iso-dvd/debian-12.0.0-arm64-DVD-1.iso>`__
|
- `Debian installer image <https://cdimage.debian.org/debian-cd/current/arm64/iso-dvd/>`__ (Tested on: debian-12.2.0-arm64-DVD-1.iso)
|
||||||
- `OpenSUSE Tumbleweed installer image <http://download.opensuse.org/ports/aarch64/tumbleweed/iso/>`__
|
- `OpenSUSE Tumbleweed installer image <http://download.opensuse.org/ports/aarch64/tumbleweed/iso/>`__ (Tested on: openSUSE-Tumbleweed-DVD-aarch64-Snapshot20231120-Media.iso)
|
||||||
|
|
||||||
**NOTE:** For OpenSUSE Tumbleweed, the user should look for a DVD Snapshot like
|
**NOTE:** For OpenSUSE Tumbleweed, the user should look for a DVD Snapshot like
|
||||||
openSUSE-Tumbleweed-DVD-aarch64-Snapshot<date>-Media.iso
|
openSUSE-Tumbleweed-DVD-aarch64-Snapshot<date>-Media.iso
|
||||||
|
|
||||||
Once the iso file is downloaded, the iso file needs to be flashed to your USB
|
|
||||||
drive. This can be done with your development machine.
|
FPGA
|
||||||
|
==================================================
|
||||||
|
|
||||||
|
To test Linux distro install and boot on FPGA, the user should prepare two empty USB
|
||||||
|
sticks (minimum size should be 4GB and formatted with FAT32).
|
||||||
|
|
||||||
|
The downloaded iso file needs to be flashed to your USB drive.
|
||||||
|
This can be done with your development machine.
|
||||||
|
|
||||||
In the example given below, we assume the USB device is ``/dev/sdb`` (the user
|
In the example given below, we assume the USB device is ``/dev/sdb`` (the user
|
||||||
should use the `lsblk` command to confirm).
|
should use the `lsblk` command to confirm).
|
||||||
|
|
||||||
**NOTE:** Please don't confuse your host PC's own hard drive with the USB drive.
|
**NOTE:** Please don't confuse your host machine own hard drive with the USB drive.
|
||||||
Then, copy the contents of the iso file into the first USB stick by running the
|
Then, copy the contents of the iso file into the first USB stick by running the
|
||||||
following command in the development machine:
|
following command in the development machine:
|
||||||
|
|
||||||
@@ -984,6 +1015,27 @@ following command in the development machine:
|
|||||||
|
|
||||||
sudo dd if=<path-to-iso_file> of=/dev/sdb iflag=direct oflag=direct status=progress bs=1M; sync;
|
sudo dd if=<path-to-iso_file> of=/dev/sdb iflag=direct oflag=direct status=progress bs=1M; sync;
|
||||||
|
|
||||||
|
|
||||||
|
FVP
|
||||||
|
==================================================
|
||||||
|
|
||||||
|
To test Linux distro install and boot on FVP, the user should prepare an mmc image.
|
||||||
|
With a minimum size of 8GB formatted with gpt.
|
||||||
|
|
||||||
|
::
|
||||||
|
|
||||||
|
#Generating mmc2
|
||||||
|
dd if=/dev/zero of=<_workspace>/mmc2_file.img bs=1 count=0 seek=8G; sync;
|
||||||
|
parted -s mmc2_file.img mklabel gpt
|
||||||
|
|
||||||
|
|
||||||
|
*************************************************
|
||||||
|
Debian/openSUSE install
|
||||||
|
*************************************************
|
||||||
|
|
||||||
|
FPGA
|
||||||
|
==================================================
|
||||||
|
|
||||||
Unplug the first USB stick from the development machine and connect it to the
|
Unplug the first USB stick from the development machine and connect it to the
|
||||||
MSP3 board. At this moment, only the first USB stick should be connected. Open
|
MSP3 board. At this moment, only the first USB stick should be connected. Open
|
||||||
the following picocom sessions in your development machine:
|
the following picocom sessions in your development machine:
|
||||||
@@ -1001,15 +1053,25 @@ the process.
|
|||||||
**NOTE:** Due to the performance limitation of Corstone-1000 MPS3 FPGA, the
|
**NOTE:** Due to the performance limitation of Corstone-1000 MPS3 FPGA, the
|
||||||
distro installation process can take up to 24 hours to complete.
|
distro installation process can take up to 24 hours to complete.
|
||||||
|
|
||||||
|
FVP
|
||||||
|
==================================================
|
||||||
|
|
||||||
|
::
|
||||||
|
|
||||||
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c "../meta-arm/scripts/runfvp --terminals=xterm -- -C board.msd_mmc.p_mmc_file="<path-to-iso_file>" -C board.msd_mmc_2.p_mmc_file="<_workspace>/mmc2_file.img"
|
||||||
|
|
||||||
|
The installer should now start.
|
||||||
|
The os will be installed on the second mmc 'mmc2_file.img'.
|
||||||
|
|
||||||
*******************************************************
|
*******************************************************
|
||||||
Debian install clarifications (applicable to FPGA only)
|
Debian install clarifications
|
||||||
*******************************************************
|
*******************************************************
|
||||||
|
|
||||||
As the installation process for Debian is different than the one for openSUSE,
|
As the installation process for Debian is different than the one for openSUSE,
|
||||||
Debian may need some extra steps, that are indicated below:
|
Debian may need some extra steps, that are indicated below:
|
||||||
|
|
||||||
During Debian installation, please answer the following question:
|
During Debian installation, please answer the following question:
|
||||||
- "Force GRUB installation to the EFI removable media path?" Yes
|
- "Force grub installation to the EFI removable media path?" Yes
|
||||||
- "Update NVRAM variables to automatically boot into Debian?" No
|
- "Update NVRAM variables to automatically boot into Debian?" No
|
||||||
|
|
||||||
If the grub installation fails, these are the steps to follow on the subsequent
|
If the grub installation fails, these are the steps to follow on the subsequent
|
||||||
@@ -1040,21 +1102,55 @@ popups:
|
|||||||
8. At this stage, the installation should proceed as normal.
|
8. At this stage, the installation should proceed as normal.
|
||||||
|
|
||||||
*****************************************************************
|
*****************************************************************
|
||||||
Debian/openSUSE boot after installation (applicable to FPGA only)
|
Debian/openSUSE boot after installation
|
||||||
*****************************************************************
|
*****************************************************************
|
||||||
|
|
||||||
|
FPGA
|
||||||
|
===============
|
||||||
Once the installation is complete, unplug the first USB stick and reboot the
|
Once the installation is complete, unplug the first USB stick and reboot the
|
||||||
board.
|
board.
|
||||||
The board will then enter recovery mode, from which the user can access a shell
|
The board will then enter recovery mode, from which the user can access a shell
|
||||||
after entering the password for the root user. Proceed to edit the following
|
after entering the password for the root user.
|
||||||
files accordingly:
|
|
||||||
|
FVP
|
||||||
|
==============
|
||||||
|
Once the installation is complete, you will need to exit the shell instance
|
||||||
|
and run this command to boot into the installed OS:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
|
kas shell meta-arm/kas/corstone1000-fvp.yml:meta-arm/ci/debug.yml -c "../meta-arm/scripts/runfvp --terminals=xterm -- -C board.msd_mmc.p_mmc_file="<path-to-iso_file>" -C board.msd_mmc.p_mmc_file="<_workspace>/mmc2_file.img"
|
||||||
|
|
||||||
|
Once the FVP begins booting, you will need to quickly change the boot option in grub,
|
||||||
|
to boot into recovery mode.
|
||||||
|
|
||||||
|
**NOTE:** This option will disappear quickly, so it's best to preempt it.
|
||||||
|
|
||||||
|
Select 'Advanced Options for '<OS>' and then '<OS> (recovery mode)'.
|
||||||
|
|
||||||
|
Common
|
||||||
|
==============
|
||||||
|
|
||||||
|
Proceed to edit the following files accordingly:
|
||||||
|
|
||||||
|
::
|
||||||
|
|
||||||
|
#Only applicable to Debian
|
||||||
vi /etc/systemd/system.conf
|
vi /etc/systemd/system.conf
|
||||||
DefaultDeviceTimeoutSec=infinity
|
DefaultDeviceTimeoutSec=infinity
|
||||||
|
|
||||||
The file to be editted next is different depending on the installed distro:
|
::
|
||||||
|
|
||||||
|
#Only applicable to openSUSE
|
||||||
|
vi /usr/lib/systemd/system.conf
|
||||||
|
DefaultDeviceTimeoutSec=infinity
|
||||||
|
|
||||||
|
The system.conf has been moved from /etc/systemd/ to /usr/lib/systemd/ and directly modifying
|
||||||
|
the /usr/lib/systemd/system.conf is not working and it is getting overridden. We have to create
|
||||||
|
drop ins system configurations in /etc/systemd/system.conf.d/ directory. So, copy the
|
||||||
|
/usr/lib/systemd/system.conf to /etc/systemd/system.conf.d/ directory after the mentioned modifications.
|
||||||
|
|
||||||
|
The file to be edited next is different depending on the installed distro:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
@@ -1068,8 +1164,9 @@ To make sure the changes are applied, please run:
|
|||||||
|
|
||||||
systemctl daemon-reload
|
systemctl daemon-reload
|
||||||
|
|
||||||
After applying the previous commands, please reboot the board. The user should
|
After applying the previous commands, please reboot the board or restart the runfvp command.
|
||||||
see a login prompt after booting, for example, for debian:
|
|
||||||
|
The user should see a login prompt after booting, for example, for debian:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
@@ -1078,37 +1175,7 @@ see a login prompt after booting, for example, for debian:
|
|||||||
Login with the username root and its corresponding password (already set at
|
Login with the username root and its corresponding password (already set at
|
||||||
installation time).
|
installation time).
|
||||||
|
|
||||||
************************************************************
|
**NOTE:** Debian/OpenSUSE Timeouts are not applicable for all systems. Some systems are faster than the others (especially when running the FVP) and works well with default timeouts. If the system boots to Debian or OpenSUSE unmodified, the user can skip this section.
|
||||||
OpenSUSE Raw image install and boot (applicable to FVP only)
|
|
||||||
************************************************************
|
|
||||||
|
|
||||||
Steps to download OpenSUSE Tumbleweed raw image:
|
|
||||||
- Under `OpenSUSE Tumbleweed appliances <http://download.opensuse.org/ports/aarch64/tumbleweed/appliances/>`__
|
|
||||||
- The user should look for a Tumbleweed-ARM-JeOS-efi.aarch64-* Snapshot, for example,
|
|
||||||
``openSUSE-Tumbleweed-ARM-JeOS-efi.aarch64-<date>-Snapshot<date>.raw.xz``
|
|
||||||
|
|
||||||
Once the .raw.xz file is downloaded, the raw image file needs to be extracted:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
unxz <file-name.raw.xz>
|
|
||||||
|
|
||||||
|
|
||||||
The above command will generate a file ending with extension .raw image. Now, use the following command
|
|
||||||
to run FVP with raw image installation process.
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
<_workspace>/meta-arm/scripts/runfvp --terminals=xterm <_workspace>/build/tmp/deploy/images/corstone1000-fvp/corstone1000-image-corstone1000-fvp.fvpconf -- -C board.msd_mmc.p_mmc_file="${openSUSE raw image file path}"
|
|
||||||
|
|
||||||
After successfully installing and booting the Linux distro, the user should see
|
|
||||||
a openSUSE login prompt.
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
localhost login:
|
|
||||||
|
|
||||||
Login with the username 'root' and password 'linux'.
|
|
||||||
|
|
||||||
PSA API tests
|
PSA API tests
|
||||||
-------------
|
-------------
|
||||||
@@ -1129,19 +1196,19 @@ First, load FF-A TEE kernel module:
|
|||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
insmod /lib/modules/6.1.32-yocto-standard/extra/arm-ffa-tee.ko
|
insmod /lib/modules/6.1.32-yocto-standard/extra/arm-tstee.ko
|
||||||
|
|
||||||
Then, check whether the FF-A TEE driver is loaded correctly by using the following command:
|
Then, check whether the FF-A TEE driver is loaded correctly by using the following command:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
cat /proc/modules | grep arm_ffa_tee
|
cat /proc/modules | grep arm_tstee
|
||||||
|
|
||||||
The output should be:
|
The output should be:
|
||||||
|
|
||||||
::
|
::
|
||||||
|
|
||||||
arm_ffa_tee 16384 - - Live 0xffffffc000510000 (O)
|
arm_tstee 16384 - - Live 0xffffffc000510000 (O)
|
||||||
|
|
||||||
Now, run the PSA API tests in the following order:
|
Now, run the PSA API tests in the following order:
|
||||||
|
|
||||||
@@ -1154,105 +1221,16 @@ Now, run the PSA API tests in the following order:
|
|||||||
|
|
||||||
**NOTE:** The psa-crypto-api-test takes between 30 minutes to 1 hour to run.
|
**NOTE:** The psa-crypto-api-test takes between 30 minutes to 1 hour to run.
|
||||||
|
|
||||||
External System tests
|
|
||||||
---------------------
|
|
||||||
|
|
||||||
**************************************************************
|
|
||||||
Running the External System test command (systems-comms-tests)
|
|
||||||
**************************************************************
|
|
||||||
|
|
||||||
Test 1: Releasing the External System out of reset
|
|
||||||
==================================================
|
|
||||||
|
|
||||||
Run this command in the Linux command-line:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
systems-comms-tests 1
|
|
||||||
|
|
||||||
The output on the External System terminal should be:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
___ ___
|
|
||||||
| / __|
|
|
||||||
|=== \___
|
|
||||||
|___ |___/
|
|
||||||
External System Cortex-M3 Processor
|
|
||||||
Running RTX RTOS
|
|
||||||
v0.1.0_2022-10-19_16-41-32-8c9dca7
|
|
||||||
MHUv2 module 'MHU0_H' started
|
|
||||||
MHUv2 module 'MHU1_H' started
|
|
||||||
MHUv2 module 'MHU0_SE' started
|
|
||||||
MHUv2 module 'MHU1_SE' started
|
|
||||||
|
|
||||||
Test 2: Communication
|
|
||||||
=====================
|
|
||||||
|
|
||||||
Test 2 releases the External System out of reset if not already done. Then, it performs communication between host and External System.
|
|
||||||
|
|
||||||
After running Test 1, run this command in the Linux command-line:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
systems-comms-tests 2
|
|
||||||
|
|
||||||
Additional output on the External System terminal will be printed:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
MHUv2: Message from 'MHU0_H': 0xabcdef1
|
|
||||||
Received 'abcdef1' From Host MHU0
|
|
||||||
CMD: Increment and return to sender...
|
|
||||||
MHUv2: Message from 'MHU1_H': 0xabcdef1
|
|
||||||
Received 'abcdef1' From Host MHU1
|
|
||||||
CMD: Increment and return to sender...
|
|
||||||
|
|
||||||
When running Test 2 the first, Test 1 will be run in the background.
|
|
||||||
|
|
||||||
The output on the External System terminal should be:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
___ ___
|
|
||||||
| / __|
|
|
||||||
|=== \___
|
|
||||||
|___ |___/
|
|
||||||
External System Cortex-M3 Processor
|
|
||||||
Running RTX RTOS
|
|
||||||
v0.1.0_2022-10-19_16-41-32-8c9dca7
|
|
||||||
MHUv2 module 'MHU0_H' started
|
|
||||||
MHUv2 module 'MHU1_H' started
|
|
||||||
MHUv2 module 'MHU0_SE' started
|
|
||||||
MHUv2 module 'MHU1_SE' started
|
|
||||||
MHUv2: Message from 'MHU0_H': 0xabcdef1
|
|
||||||
Received 'abcdef1' From Host MHU0
|
|
||||||
CMD: Increment and return to sender...
|
|
||||||
MHUv2: Message from 'MHU1_H': 0xabcdef1
|
|
||||||
Received 'abcdef1' From Host MHU1
|
|
||||||
CMD: Increment and return to sender...
|
|
||||||
|
|
||||||
The output on the Host terminal should be:
|
|
||||||
|
|
||||||
::
|
|
||||||
|
|
||||||
Received abcdf00 from es0mhu0
|
|
||||||
Received abcdf00 from es0mhu1
|
|
||||||
|
|
||||||
|
|
||||||
Tests results
|
Tests results
|
||||||
-------------
|
-------------
|
||||||
|
|
||||||
As a reference for the end user, reports for various tests for `Corstone-1000 software (CORSTONE1000-2023.06) <https://git.yoctoproject.org/meta-arm/tag/?h=CORSTONE1000-2023.06>`__
|
As a reference for the end user, reports for various tests for `Corstone-1000 software (CORSTONE1000-2023.11) <https://git.yoctoproject.org/meta-arm/tag/?h=CORSTONE1000-2023.11>`__
|
||||||
can be found `here <https://gitlab.arm.com/arm-reference-solutions/arm-reference-solutions-test-report/-/tree/master/embedded-a/corstone1000>`__.
|
can be found `here <https://gitlab.arm.com/arm-reference-solutions/arm-reference-solutions-test-report/-/tree/master/embedded-a/corstone1000>`__.
|
||||||
|
|
||||||
Running the software on FVP on Windows
|
Running the software on FVP on Windows or AArch64 Linux
|
||||||
--------------------------------------
|
------------------------------------------------------------
|
||||||
|
|
||||||
If the user needs to run the Corstone-1000 software on FVP on Windows. The user
|
The user should follow the build instructions in this document to build on a Linux host machine. Then, copy the output binaries to the Windows or Aarch64 Linux machine where the FVP is located. Then, launch the FVP binary.
|
||||||
should follow the build instructions in this document to build on Linux host
|
|
||||||
PC, and copy the output binaries to the Windows PC where the FVP is located,
|
|
||||||
and launch the FVP binary.
|
|
||||||
|
|
||||||
Security Issue Reporting
|
Security Issue Reporting
|
||||||
------------------------
|
------------------------
|
||||||
@@ -1260,7 +1238,7 @@ To report any security issues identified with Corstone-1000, please send an emai
|
|||||||
|
|
||||||
--------------
|
--------------
|
||||||
|
|
||||||
*Copyright (c) 2022-2023, Arm Limited. All rights reserved.*
|
*Copyright (c) 2022-2024, Arm Limited. All rights reserved.*
|
||||||
|
|
||||||
.. _Arm Ecosystem FVPs: https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
.. _Arm Ecosystem FVPs: https://developer.arm.com/tools-and-software/open-source-software/arm-platforms-software/arm-ecosystem-fvps
|
||||||
.. _U-Boot repo: https://github.com/u-boot/u-boot.git
|
.. _U-Boot repo: https://github.com/u-boot/u-boot.git
|
||||||
|
|||||||
@@ -6,7 +6,6 @@
|
|||||||
jinja2==3.1.1
|
jinja2==3.1.1
|
||||||
|
|
||||||
# Required to build the documentation
|
# Required to build the documentation
|
||||||
sphinx==4.5.0
|
sphinx~=5.0
|
||||||
sphinx_rtd_theme==1.0.0
|
sphinx_rtd_theme~=2.0.0
|
||||||
sphinx-copybutton==0.5.0
|
|
||||||
docutils==0.17.1
|
docutils==0.17.1
|
||||||
|
|||||||
@@ -1,32 +0,0 @@
|
|||||||
# TC1 Platform Support in meta-arm-bsp
|
|
||||||
|
|
||||||
## Overview
|
|
||||||
The Total Compute platform provides an envelope for all of Arm's latest IP and
|
|
||||||
software solutions, optimised to work together. Further information can be
|
|
||||||
found on the Total Compute community page:
|
|
||||||
https://community.arm.com/developer/tools-software/oss-platforms/w/docs/606/total-compute
|
|
||||||
|
|
||||||
The user guide for TC1 platform with detailed instructions for
|
|
||||||
syncing and building the source code and running on TC1 Fixed Virtual Platform
|
|
||||||
for poky and android distributions is available at:
|
|
||||||
https://git.linaro.org/landing-teams/working/arm/arm-reference-platforms.git/tree/docs/tc1/user-guide.rst
|
|
||||||
|
|
||||||
## Building
|
|
||||||
In the local.conf file, MACHINE should be set as follows:
|
|
||||||
MACHINE = "tc1"
|
|
||||||
|
|
||||||
To build the required binaries for tc1, run the commmand:
|
|
||||||
```bash$ bitbake tc-artifacts-image```
|
|
||||||
|
|
||||||
Trusted-firmware-a is the final component to be built with the rest of the
|
|
||||||
components dependent of it, therefore building tc-artifacts-image which depends
|
|
||||||
on trusted-firmware-a will build all the required binaries.
|
|
||||||
|
|
||||||
## Running
|
|
||||||
To run the produced binaries in a TC1 Fixed Virtual Platform please get
|
|
||||||
the run scripts at:
|
|
||||||
https://git.linaro.org/landing-teams/working/arm/model-scripts.git/
|
|
||||||
|
|
||||||
and follow the instructions in the user-guide.rst available in:
|
|
||||||
https://git.linaro.org/landing-teams/working/arm/arm-reference-platforms.git/tree/docs/tc1/user-guide.rst
|
|
||||||
|
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
# The release of EDK2 after 202402 should fix this
|
||||||
|
NUMA: Failed to initialise from firmware
|
||||||
|
|
||||||
|
# TODO: we should be using bochsdrm over efifb?
|
||||||
|
efifb: cannot reserve video memory at 0x80000000
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
COMPATIBLE_MACHINE:fvp-base = "fvp-base"
|
||||||
@@ -38,15 +38,20 @@ do_compile() {
|
|||||||
do_compile[cleandirs] = "${B}"
|
do_compile[cleandirs] = "${B}"
|
||||||
|
|
||||||
do_install() {
|
do_install() {
|
||||||
install -D -p -m 0644 ${B}/product/${PRODUCT}/firmware/release/bin/firmware.bin ${D}/firmware/es_flashfw.bin
|
install -D -p -m 0644 ${B}/product/${PRODUCT}/firmware/release/bin/firmware.bin ${D}${nonarch_base_libdir}/firmware/es_flashfw.bin
|
||||||
|
install -D -p -m 0644 ${B}/product/${PRODUCT}/firmware/release/bin/firmware.elf ${D}${nonarch_base_libdir}/firmware/es_flashfw.elf
|
||||||
}
|
}
|
||||||
|
|
||||||
FILES:${PN} = "/firmware"
|
FILES:${PN} = "${nonarch_base_libdir}/firmware/es_flashfw.bin"
|
||||||
SYSROOT_DIRS += "/firmware"
|
FILES:${PN}-elf = "${nonarch_base_libdir}/firmware/es_flashfw.elf"
|
||||||
|
PACKAGES += "${PN}-elf"
|
||||||
|
INSANE_SKIP:${PN}-elf += "arch"
|
||||||
|
|
||||||
|
SYSROOT_DIRS += "${nonarch_base_libdir}/firmware"
|
||||||
|
|
||||||
inherit deploy
|
inherit deploy
|
||||||
|
|
||||||
do_deploy() {
|
do_deploy() {
|
||||||
cp -rf ${D}/firmware/* ${DEPLOYDIR}/
|
cp -rf ${D}${nonarch_base_libdir}/firmware/* ${DEPLOYDIR}/
|
||||||
}
|
}
|
||||||
addtask deploy after do_install
|
addtask deploy after do_install
|
||||||
|
|||||||
@@ -1,8 +0,0 @@
|
|||||||
# TC specific configuration
|
|
||||||
|
|
||||||
COMPATIBLE_MACHINE = "(tc?)"
|
|
||||||
HAFNIUM_PLATFORM = "secure_tc"
|
|
||||||
|
|
||||||
do_compile() {
|
|
||||||
PATH="${S}/prebuilts/linux-x64/clang/bin:$PATH" oe_runmake -C ${S}
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
SUMMARY = "Corstone1000 platform esp Image"
|
||||||
|
DESCRIPTION = "This builds a simple image file that only contains an esp \
|
||||||
|
partition for use when running the SystemReady IR ACS tests."
|
||||||
|
LICENSE = "MIT"
|
||||||
|
|
||||||
|
COMPATIBLE_MACHINE = "corstone1000"
|
||||||
|
|
||||||
|
# IMAGE_FSTYPES must be set before 'inherit image'
|
||||||
|
# https://docs.yoctoproject.org/ref-manual/variables.html#term-IMAGE_FSTYPES
|
||||||
|
IMAGE_FSTYPES = "wic"
|
||||||
|
|
||||||
|
inherit image
|
||||||
|
|
||||||
|
IMAGE_FEATURES = ""
|
||||||
|
IMAGE_LINGUAS = ""
|
||||||
|
|
||||||
|
PACKAGE_INSTALL = ""
|
||||||
|
|
||||||
|
# This builds a very specific image so we can ignore any customization
|
||||||
|
WKS_FILE = "efi-disk-esp-only.wks.in"
|
||||||
|
WKS_FILE:firmware = "efi-disk-esp-only.wks.in"
|
||||||
|
|
||||||
|
EXTRA_IMAGEDEPENDS = ""
|
||||||
|
# Don't write an fvp configuration file for this image as it can't run
|
||||||
|
IMAGE_POSTPROCESS_COMMAND:remove = "do_write_fvpboot_conf;"
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
COMPATIBLE_MACHINE = "corstone1000"
|
||||||
|
|
||||||
|
FIRMWARE_BINARIES = "corstone1000-flash-firmware-image-${MACHINE}.wic \
|
||||||
|
bl1.bin \
|
||||||
|
es_flashfw.bin \
|
||||||
|
${CAPSULE_NAME}.${CAPSULE_EXTENSION} \
|
||||||
|
corstone1000_capsule_cert.crt \
|
||||||
|
corstone1000_capsule_key.key \
|
||||||
|
"
|
||||||
|
|
||||||
|
do_deploy[mcdepends] = "mc::firmware:corstone1000-flash-firmware-image:do_image_complete"
|
||||||
@@ -0,0 +1,96 @@
|
|||||||
|
SUMMARY = "Corstone1000 platform Image"
|
||||||
|
DESCRIPTION = "This is the main image which is the container of all the binaries \
|
||||||
|
generated for the Corstone1000 platform."
|
||||||
|
LICENSE = "MIT"
|
||||||
|
|
||||||
|
COMPATIBLE_MACHINE = "corstone1000"
|
||||||
|
|
||||||
|
# IMAGE_FSTYPES must be set before 'inherit image'
|
||||||
|
# https://docs.yoctoproject.org/ref-manual/variables.html#term-IMAGE_FSTYPES
|
||||||
|
IMAGE_FSTYPES = "wic uefi_capsule"
|
||||||
|
|
||||||
|
inherit image
|
||||||
|
inherit tfm_sign_image
|
||||||
|
inherit uefi_capsule
|
||||||
|
inherit deploy
|
||||||
|
|
||||||
|
DEPENDS += "external-system \
|
||||||
|
trusted-firmware-a \
|
||||||
|
trusted-firmware-m \
|
||||||
|
u-boot \
|
||||||
|
"
|
||||||
|
|
||||||
|
IMAGE_FEATURES = ""
|
||||||
|
IMAGE_LINGUAS = ""
|
||||||
|
|
||||||
|
PACKAGE_INSTALL = ""
|
||||||
|
|
||||||
|
# The generated ${MACHINE}_image.nopt is used instead of the default wic image
|
||||||
|
# for the capsule generation. The uefi.capsule image type doesn't have to
|
||||||
|
# depend on the wic because of this.
|
||||||
|
#
|
||||||
|
# The corstone1000_capsule_cert.crt and corstone1000_capsule_key.key are installed
|
||||||
|
# by the U-Boot recipe so this recipe has to depend on that.
|
||||||
|
CAPSULE_IMGTYPE = ""
|
||||||
|
CAPSULE_CERTIFICATE_PATH = "${DEPLOY_DIR_IMAGE}/corstone1000_capsule_cert.crt"
|
||||||
|
CAPSULE_GUID:corstone1000-fvp ?= "989f3a4e-46e0-4cd0-9877-a25c70c01329"
|
||||||
|
CAPSULE_GUID:corstone1000-mps3 ?= "df1865d1-90fb-4d59-9c38-c9f2c1bba8cc"
|
||||||
|
CAPSULE_IMGLOCATION = "${DEPLOY_DIR_IMAGE}"
|
||||||
|
CAPSULE_INDEX = "1"
|
||||||
|
CAPSULE_MONOTONIC_COUNT = "1"
|
||||||
|
CAPSULE_PRIVATE_KEY_PATH = "${DEPLOY_DIR_IMAGE}/corstone1000_capsule_key.key"
|
||||||
|
UEFI_FIRMWARE_BINARY = "${B}/${MACHINE}_image.nopt"
|
||||||
|
|
||||||
|
# TF-A settings for signing host images
|
||||||
|
TFA_BL2_BINARY = "bl2-corstone1000.bin"
|
||||||
|
TFA_FIP_BINARY = "fip-corstone1000.bin"
|
||||||
|
TFA_BL2_RE_IMAGE_LOAD_ADDRESS = "0x62353000"
|
||||||
|
TFA_BL2_RE_SIGN_BIN_SIZE = "0x2d000"
|
||||||
|
TFA_FIP_RE_IMAGE_LOAD_ADDRESS = "0x68130000"
|
||||||
|
TFA_FIP_RE_SIGN_BIN_SIZE = "0x00200000"
|
||||||
|
RE_LAYOUT_WRAPPER_VERSION = "0.0.7"
|
||||||
|
TFM_SIGN_PRIVATE_KEY = "${libdir}/tfm-scripts/root-RSA-3072_1.pem"
|
||||||
|
RE_IMAGE_OFFSET = "0x1000"
|
||||||
|
|
||||||
|
# Offsets for the .nopt image generation
|
||||||
|
TFM_OFFSET = "102400"
|
||||||
|
FIP_OFFSET = "479232"
|
||||||
|
KERNEL_OFFSET = "2576384"
|
||||||
|
|
||||||
|
do_sign_images() {
|
||||||
|
# Sign TF-A BL2
|
||||||
|
sign_host_image ${RECIPE_SYSROOT}/firmware/${TFA_BL2_BINARY} \
|
||||||
|
${TFA_BL2_RE_IMAGE_LOAD_ADDRESS} ${TFA_BL2_RE_SIGN_BIN_SIZE}
|
||||||
|
|
||||||
|
# Update BL2 in the FIP image
|
||||||
|
cp ${RECIPE_SYSROOT}/firmware/${TFA_FIP_BINARY} .
|
||||||
|
fiptool update --tb-fw \
|
||||||
|
${TFM_IMAGE_SIGN_DEPLOY_DIR}/signed_${TFA_BL2_BINARY} \
|
||||||
|
${TFM_IMAGE_SIGN_DIR}/${TFA_FIP_BINARY}
|
||||||
|
|
||||||
|
# Sign the FIP image
|
||||||
|
sign_host_image ${TFM_IMAGE_SIGN_DIR}/${TFA_FIP_BINARY} \
|
||||||
|
${TFA_FIP_RE_IMAGE_LOAD_ADDRESS} ${TFA_FIP_RE_SIGN_BIN_SIZE}
|
||||||
|
}
|
||||||
|
do_sign_images[depends] = "\
|
||||||
|
fiptool-native:do_populate_sysroot \
|
||||||
|
"
|
||||||
|
|
||||||
|
# This .nopt image is not the same as the one which is generated by meta-arm/meta-arm/classes/wic_nopt.bbclass.
|
||||||
|
# The meta-arm/meta-arm/classes/wic_nopt.bbclass removes the partition table from the wic image, but keeps the
|
||||||
|
# second bank. This function creates a no-partition image with only the first bank.
|
||||||
|
create_nopt_image() {
|
||||||
|
dd conv=notrunc bs=1 if=${DEPLOY_DIR_IMAGE}/bl2_signed.bin of=${B}/${MACHINE}_image.nopt
|
||||||
|
dd conv=notrunc bs=1 if=${DEPLOY_DIR_IMAGE}/tfm_s_signed.bin of=${B}/${MACHINE}_image.nopt seek=${TFM_OFFSET}
|
||||||
|
dd conv=notrunc bs=1 if=${DEPLOY_DIR_IMAGE}/signed_fip-corstone1000.bin of=${B}/${MACHINE}_image.nopt seek=${FIP_OFFSET}
|
||||||
|
dd conv=notrunc bs=1 if=${DEPLOY_DIR_IMAGE}/Image.gz-initramfs-${MACHINE}.bin of=${B}/${MACHINE}_image.nopt seek=${KERNEL_OFFSET}
|
||||||
|
}
|
||||||
|
do_image_uefi_capsule[depends] += " linux-yocto:do_deploy"
|
||||||
|
do_image_uefi_capsule[mcdepends] += " ${@bb.utils.contains('BBMULTICONFIG', 'firmware', 'mc::firmware:linux-yocto:do_deploy', '', d)}"
|
||||||
|
do_image_uefi_capsule[prefuncs] += "create_nopt_image"
|
||||||
|
|
||||||
|
do_deploy() {
|
||||||
|
install -m 0755 ${B}/${MACHINE}_image.nopt ${DEPLOYDIR}
|
||||||
|
}
|
||||||
|
|
||||||
|
addtask deploy after do_image_uefi_capsule
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
SUMARY = "Corstone1000 platform Image"
|
|
||||||
DESCRIPTION = "This is the main image which is the container of all the binaries \
|
|
||||||
generated for the Corstone1000 platform."
|
|
||||||
LICENSE = "MIT"
|
|
||||||
|
|
||||||
COMPATIBLE_MACHINE = "corstone1000"
|
|
||||||
|
|
||||||
inherit image
|
|
||||||
inherit tfm_sign_image
|
|
||||||
inherit uefi_capsule
|
|
||||||
|
|
||||||
PACKAGE_INSTALL = ""
|
|
||||||
|
|
||||||
IMAGE_FSTYPES += "wic uefi_capsule"
|
|
||||||
|
|
||||||
UEFI_FIRMWARE_BINARY = "${PN}-${MACHINE}.${CAPSULE_IMGTYPE}"
|
|
||||||
UEFI_CAPSULE_CONFIG = "${THISDIR}/files/${PN}-capsule-update-image.json"
|
|
||||||
CAPSULE_IMGTYPE = "wic"
|
|
||||||
|
|
||||||
do_sign_images() {
|
|
||||||
# Sign TF-A BL2
|
|
||||||
sign_host_image ${RECIPE_SYSROOT}/firmware/${TFA_BL2_BINARY} \
|
|
||||||
${TFA_BL2_RE_IMAGE_LOAD_ADDRESS} ${TFA_BL2_RE_SIGN_BIN_SIZE}
|
|
||||||
|
|
||||||
# Update BL2 in the FIP image
|
|
||||||
cp ${RECIPE_SYSROOT}/firmware/${TFA_FIP_BINARY} .
|
|
||||||
fiptool update --tb-fw \
|
|
||||||
${TFM_IMAGE_SIGN_DEPLOY_DIR}/signed_${TFA_BL2_BINARY} \
|
|
||||||
${TFM_IMAGE_SIGN_DIR}/${TFA_FIP_BINARY}
|
|
||||||
|
|
||||||
# Sign the FIP image
|
|
||||||
sign_host_image ${TFM_IMAGE_SIGN_DIR}/${TFA_FIP_BINARY} \
|
|
||||||
${TFA_FIP_RE_IMAGE_LOAD_ADDRESS} ${TFA_FIP_RE_SIGN_BIN_SIZE}
|
|
||||||
}
|
|
||||||
do_sign_images[depends] = "\
|
|
||||||
trusted-firmware-a:do_populate_sysroot \
|
|
||||||
fiptool-native:do_populate_sysroot \
|
|
||||||
"
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
SUMARY = "Corstone1000 platform Initramfs Image"
|
|
||||||
DESCRIPTION = "This is the main Linux image which includes an initramfs kernel/rootfs bundle."
|
|
||||||
|
|
||||||
LICENSE = "MIT"
|
|
||||||
|
|
||||||
COMPATIBLE_MACHINE = "corstone1000"
|
|
||||||
|
|
||||||
IMAGE_FSTYPES = "${INITRAMFS_FSTYPES}"
|
|
||||||
|
|
||||||
inherit core-image
|
|
||||||
|
|
||||||
# By default all basic packages required for a bootable system are installed
|
|
||||||
# by core-image . These packages are: packagegroup-core-boot and
|
|
||||||
# packagegroup-base-extended
|
|
||||||
|
|
||||||
inherit image-buildinfo
|
|
||||||
|
|
||||||
#package management is not supported in corstone1000
|
|
||||||
IMAGE_FEATURES:remove = "package-management"
|
|
||||||
|
|
||||||
# all optee packages
|
|
||||||
IMAGE_INSTALL += "optee-client"
|
|
||||||
|
|
||||||
# TS PSA API tests commands for crypto, its, ps and iat
|
|
||||||
IMAGE_INSTALL += "packagegroup-ts-tests-psa"
|
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
require recipes-core/images/core-image-minimal.bb
|
||||||
|
|
||||||
|
# The core-image-minimal is used for the initramfs bundle for the
|
||||||
|
# Corstone1000 but the testimage task caused hanging errors. This is
|
||||||
|
# why the core-image-minimal is forked here so the testimage task can
|
||||||
|
# be disabled as it is not relevant for the Corstone1000.
|
||||||
|
IMAGE_CLASSES:remove = "testimage"
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
{
|
|
||||||
"Payloads": [
|
|
||||||
{
|
|
||||||
"FwVersion": "5",
|
|
||||||
"Guid": "e2bb9c06-70e9-4b14-97a3-5a7913176e3f",
|
|
||||||
"LowestSupportedVersion": "1",
|
|
||||||
"Payload": "$UEFI_FIRMWARE_BINARY",
|
|
||||||
"UpdateImageIndex": "0"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
MACHINE_DEPLOY_FIRMWARE_REQUIRE ?= ""
|
||||||
|
MACHINE_DEPLOY_FIRMWARE_REQUIRE:corstone1000 = "corstone1000-firmware-deploy-image.inc"
|
||||||
|
|
||||||
|
require ${MACHINE_DEPLOY_FIRMWARE_REQUIRE}
|
||||||
@@ -13,9 +13,6 @@ DEPENDS += "n1sdp-board-firmware"
|
|||||||
EXTRA_OECMAKE:append = " \
|
EXTRA_OECMAKE:append = " \
|
||||||
-DSCP_N1SDP_SENSOR_LIB_PATH=${RECIPE_SYSROOT}/n1sdp-board-firmware_source/LIB/sensor.a \
|
-DSCP_N1SDP_SENSOR_LIB_PATH=${RECIPE_SYSROOT}/n1sdp-board-firmware_source/LIB/sensor.a \
|
||||||
"
|
"
|
||||||
# scp-firmware version aligning to Arm Reference Solutions N1SDP-2023.06.22 Release
|
|
||||||
SRCREV = "543ae8ca3c9e38da3058311118fa3ceef1da47f7"
|
|
||||||
PV .= "+git"
|
|
||||||
|
|
||||||
do_install:append() {
|
do_install:append() {
|
||||||
fiptool \
|
fiptool \
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
# SGI575 specific SCP configurations and build instructions
|
# SGI575 specific SCP configurations and build instructions
|
||||||
|
|
||||||
COMPATIBLE_MACHINE:sgi575 = "sgi575"
|
COMPATIBLE_MACHINE:sgi575 = "sgi575"
|
||||||
|
SCP_PRODUCT_GROUP = "neoverse-rd"
|
||||||
|
|
||||||
SCP_LOG_LEVEL = "INFO"
|
SCP_LOG_LEVEL = "INFO"
|
||||||
|
|||||||
@@ -1,5 +0,0 @@
|
|||||||
# TC specific SCP configuration
|
|
||||||
|
|
||||||
COMPATIBLE_MACHINE = "(tc1)"
|
|
||||||
|
|
||||||
FW_TARGETS = "scp"
|
|
||||||
-162
@@ -1,162 +0,0 @@
|
|||||||
From fa7ab9b40babee29d2aadb267dfce7a96f8989d4 Mon Sep 17 00:00:00 2001
|
|
||||||
From: Mohamed Omar Asaker <mohamed.omarasaker@arm.com>
|
|
||||||
Date: Mon, 9 Jan 2023 13:59:06 +0000
|
|
||||||
Subject: [PATCH] feat(corstone1000): bl2 loads fip based on metadata
|
|
||||||
|
|
||||||
Previously bl2 was reading the boot_index directly with a hard coded
|
|
||||||
address and then set the fip image spec with fip offsets base based on
|
|
||||||
the boot_index value.
|
|
||||||
This commit removes this logic and rely on PSA_FWU_SUPPORT
|
|
||||||
which reads the fip partition based on the active firmware bank written in
|
|
||||||
metadata.
|
|
||||||
|
|
||||||
Note: fip partition contains signature area at the begining. Hence, the fip
|
|
||||||
image starts at fip partition + fip signature area size.
|
|
||||||
|
|
||||||
Upstream-Status: Pending
|
|
||||||
Signed-off-by: Mohamed Omar Asaker <mohamed.omarasaker@arm.com>
|
|
||||||
---
|
|
||||||
bl2/bl2_main.c | 4 +++
|
|
||||||
.../corstone1000/common/corstone1000_plat.c | 32 ++++++-------------
|
|
||||||
.../common/include/platform_def.h | 12 +++----
|
|
||||||
tools/cert_create/Makefile | 4 +--
|
|
||||||
tools/fiptool/Makefile | 4 +--
|
|
||||||
5 files changed, 24 insertions(+), 32 deletions(-)
|
|
||||||
|
|
||||||
diff --git a/bl2/bl2_main.c b/bl2/bl2_main.c
|
|
||||||
index ce83692e0ebc..1a9febc007b2 100644
|
|
||||||
--- a/bl2/bl2_main.c
|
|
||||||
+++ b/bl2/bl2_main.c
|
|
||||||
@@ -87,6 +87,10 @@ void bl2_main(void)
|
|
||||||
/* Perform remaining generic architectural setup in S-EL1 */
|
|
||||||
bl2_arch_setup();
|
|
||||||
|
|
||||||
+#if ARM_GPT_SUPPORT
|
|
||||||
+ partition_init(GPT_IMAGE_ID);
|
|
||||||
+#endif
|
|
||||||
+
|
|
||||||
#if PSA_FWU_SUPPORT
|
|
||||||
fwu_init();
|
|
||||||
#endif /* PSA_FWU_SUPPORT */
|
|
||||||
diff --git a/plat/arm/board/corstone1000/common/corstone1000_plat.c b/plat/arm/board/corstone1000/common/corstone1000_plat.c
|
|
||||||
index 0235f8b8474c..7f9708a82489 100644
|
|
||||||
--- a/plat/arm/board/corstone1000/common/corstone1000_plat.c
|
|
||||||
+++ b/plat/arm/board/corstone1000/common/corstone1000_plat.c
|
|
||||||
@@ -33,36 +33,17 @@ const mmap_region_t plat_arm_mmap[] = {
|
|
||||||
static void set_fip_image_source(void)
|
|
||||||
{
|
|
||||||
const struct plat_io_policy *policy;
|
|
||||||
- /*
|
|
||||||
- * metadata for firmware update is written at 0x0000 offset of the flash.
|
|
||||||
- * PLAT_ARM_BOOT_BANK_FLAG contains the boot bank that TF-M is booted.
|
|
||||||
- * As per firmware update spec, at a given point of time, only one bank
|
|
||||||
- * is active. This means, TF-A should boot from the same bank as TF-M.
|
|
||||||
- */
|
|
||||||
- volatile uint32_t *boot_bank_flag = (uint32_t *)(PLAT_ARM_BOOT_BANK_FLAG);
|
|
||||||
-
|
|
||||||
- if (*boot_bank_flag > 1) {
|
|
||||||
- VERBOSE("Boot_bank is set higher than possible values");
|
|
||||||
- }
|
|
||||||
-
|
|
||||||
- VERBOSE("Boot bank flag = %u.\n\r", *boot_bank_flag);
|
|
||||||
|
|
||||||
policy = FCONF_GET_PROPERTY(arm, io_policies, FIP_IMAGE_ID);
|
|
||||||
|
|
||||||
assert(policy != NULL);
|
|
||||||
assert(policy->image_spec != 0UL);
|
|
||||||
|
|
||||||
+ /* FIP Partition contains Signature area at the begining which TF-A doesn't expect */
|
|
||||||
io_block_spec_t *spec = (io_block_spec_t *)policy->image_spec;
|
|
||||||
+ spec->offset += FIP_SIGNATURE_AREA_SIZE;
|
|
||||||
+ spec->length -= FIP_SIGNATURE_AREA_SIZE;
|
|
||||||
|
|
||||||
- if ((*boot_bank_flag) == 0) {
|
|
||||||
- VERBOSE("Booting from bank 0: fip offset = 0x%lx\n\r",
|
|
||||||
- PLAT_ARM_FIP_BASE_BANK0);
|
|
||||||
- spec->offset = PLAT_ARM_FIP_BASE_BANK0;
|
|
||||||
- } else {
|
|
||||||
- VERBOSE("Booting from bank 1: fip offset = 0x%lx\n\r",
|
|
||||||
- PLAT_ARM_FIP_BASE_BANK1);
|
|
||||||
- spec->offset = PLAT_ARM_FIP_BASE_BANK1;
|
|
||||||
- }
|
|
||||||
}
|
|
||||||
|
|
||||||
void bl2_platform_setup(void)
|
|
||||||
@@ -75,6 +56,13 @@ void bl2_platform_setup(void)
|
|
||||||
set_fip_image_source();
|
|
||||||
}
|
|
||||||
|
|
||||||
+void bl2_early_platform_setup2(u_register_t arg0, u_register_t arg1,
|
|
||||||
+ u_register_t arg2, u_register_t arg3)
|
|
||||||
+{
|
|
||||||
+ arm_bl2_early_platform_setup((uintptr_t)arg0, (meminfo_t *)arg1);
|
|
||||||
+ NOTICE("CS1k: early at bl2_platform_setup\n");
|
|
||||||
+}
|
|
||||||
+
|
|
||||||
/* corstone1000 only has one always-on power domain and there
|
|
||||||
* is no power control present
|
|
||||||
*/
|
|
||||||
diff --git a/plat/arm/board/corstone1000/common/include/platform_def.h b/plat/arm/board/corstone1000/common/include/platform_def.h
|
|
||||||
index 584d485f3ea7..0bfab05a482b 100644
|
|
||||||
--- a/plat/arm/board/corstone1000/common/include/platform_def.h
|
|
||||||
+++ b/plat/arm/board/corstone1000/common/include/platform_def.h
|
|
||||||
@@ -173,16 +173,16 @@
|
|
||||||
|
|
||||||
/* NOR Flash */
|
|
||||||
|
|
||||||
-#define PLAT_ARM_BOOT_BANK_FLAG UL(0x08002000)
|
|
||||||
-#define PLAT_ARM_FIP_BASE_BANK0 UL(0x081EF000)
|
|
||||||
-#define PLAT_ARM_FIP_BASE_BANK1 UL(0x0916F000)
|
|
||||||
-#define PLAT_ARM_FIP_MAX_SIZE UL(0x1ff000) /* 1.996 MB */
|
|
||||||
-
|
|
||||||
#define PLAT_ARM_NVM_BASE V2M_FLASH0_BASE
|
|
||||||
#define PLAT_ARM_NVM_SIZE (SZ_32M) /* 32 MB */
|
|
||||||
+#define PLAT_ARM_FIP_MAX_SIZE UL(0x1ff000) /* 1.996 MB */
|
|
||||||
|
|
||||||
-#define PLAT_ARM_FLASH_IMAGE_BASE PLAT_ARM_FIP_BASE_BANK0
|
|
||||||
+#define PLAT_ARM_FLASH_IMAGE_BASE UL(0x08000000)
|
|
||||||
#define PLAT_ARM_FLASH_IMAGE_MAX_SIZE PLAT_ARM_FIP_MAX_SIZE
|
|
||||||
+#define PLAT_ARM_FIP_OFFSET_IN_GPT (0x86000)
|
|
||||||
+
|
|
||||||
+/* FIP Information */
|
|
||||||
+#define FIP_SIGNATURE_AREA_SIZE (0x1000) /* 4 KB */
|
|
||||||
|
|
||||||
/*
|
|
||||||
* Some data must be aligned on the biggest cache line size in the platform.
|
|
||||||
diff --git a/tools/cert_create/Makefile b/tools/cert_create/Makefile
|
|
||||||
index 042e844626bd..45b76a022f91 100644
|
|
||||||
--- a/tools/cert_create/Makefile
|
|
||||||
+++ b/tools/cert_create/Makefile
|
|
||||||
@@ -78,8 +78,8 @@ INC_DIR += -I ./include -I ${PLAT_INCLUDE} -I ${OPENSSL_DIR}/include
|
|
||||||
# directory. However, for a local build of OpenSSL, the built binaries are
|
|
||||||
# located under the main project directory (i.e.: ${OPENSSL_DIR}, not
|
|
||||||
# ${OPENSSL_DIR}/lib/).
|
|
||||||
-LIB_DIR := -L ${OPENSSL_DIR}/lib -L ${OPENSSL_DIR}
|
|
||||||
-LIB := -lssl -lcrypto
|
|
||||||
+LIB_DIR := -L ${OPENSSL_DIR}/lib -L ${OPENSSL_DIR} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS}
|
|
||||||
+LIB := -lssl -lcrypto ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS}
|
|
||||||
|
|
||||||
HOSTCC ?= gcc
|
|
||||||
|
|
||||||
diff --git a/tools/fiptool/Makefile b/tools/fiptool/Makefile
|
|
||||||
index 2ebee33931ba..dcfd314bee89 100644
|
|
||||||
--- a/tools/fiptool/Makefile
|
|
||||||
+++ b/tools/fiptool/Makefile
|
|
||||||
@@ -39,7 +39,7 @@ HOSTCCFLAGS += -DUSING_OPENSSL3=$(USING_OPENSSL3)
|
|
||||||
# directory. However, for a local build of OpenSSL, the built binaries are
|
|
||||||
# located under the main project directory (i.e.: ${OPENSSL_DIR}, not
|
|
||||||
# ${OPENSSL_DIR}/lib/).
|
|
||||||
-LDLIBS := -L${OPENSSL_DIR}/lib -L${OPENSSL_DIR} -lcrypto
|
|
||||||
+LDLIBS := -L${OPENSSL_DIR}/lib -L${OPENSSL_DIR} -lcrypto ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS} ${BUILD_LDFLAGS}
|
|
||||||
|
|
||||||
ifeq (${V},0)
|
|
||||||
Q := @
|
|
||||||
@@ -47,7 +47,7 @@ else
|
|
||||||
Q :=
|
|
||||||
endif
|
|
||||||
|
|
||||||
-INCLUDE_PATHS := -I../../include/tools_share -I${OPENSSL_DIR}/include
|
|
||||||
+INCLUDE_PATHS := -I../../include/tools_share -I${OPENSSL_DIR}/include ${BUILD_CFLAGS} ${BUILD_CFLAGS} ${BUILD_CFLAGS} ${BUILD_CFLAGS} ${BUILD_CFLAGS} ${BUILD_CFLAGS}
|
|
||||||
|
|
||||||
HOSTCC ?= gcc
|
|
||||||
|
|
||||||
+32
@@ -0,0 +1,32 @@
|
|||||||
|
From d70a07562d3b0a7b4441922fd3ce136565927d04 Mon Sep 17 00:00:00 2001
|
||||||
|
From: Emekcan Aras <Emekcan.Aras@arm.com>
|
||||||
|
Date: Wed, 21 Feb 2024 07:57:36 +0000
|
||||||
|
Subject: [PATCH] fix(corstone1000): pass spsr value explicitly
|
||||||
|
|
||||||
|
Passes spsr value for BL32 (OPTEE) explicitly between different boot
|
||||||
|
stages.
|
||||||
|
|
||||||
|
Upstream-Status: Pending
|
||||||
|
Signed-off-by: Emekcan Aras <Emekcan.Aras@arm.com>
|
||||||
|
---
|
||||||
|
.../corstone1000/common/corstone1000_bl2_mem_params_desc.c | 3 ++-
|
||||||
|
1 file changed, 2 insertions(+), 1 deletion(-)
|
||||||
|
|
||||||
|
diff --git a/plat/arm/board/corstone1000/common/corstone1000_bl2_mem_params_desc.c b/plat/arm/board/corstone1000/common/corstone1000_bl2_mem_params_desc.c
|
||||||
|
index fe521a9fa..2cc096f38 100644
|
||||||
|
--- a/plat/arm/board/corstone1000/common/corstone1000_bl2_mem_params_desc.c
|
||||||
|
+++ b/plat/arm/board/corstone1000/common/corstone1000_bl2_mem_params_desc.c
|
||||||
|
@@ -72,7 +72,8 @@ static bl_mem_params_node_t bl2_mem_params_descs[] = {
|
||||||
|
SET_STATIC_PARAM_HEAD(ep_info, PARAM_EP,
|
||||||
|
VERSION_2, entry_point_info_t, NON_SECURE | EXECUTABLE),
|
||||||
|
.ep_info.pc = BL33_BASE,
|
||||||
|
-
|
||||||
|
+ .ep_info.spsr = SPSR_64(MODE_EL2, MODE_SP_ELX,
|
||||||
|
+ DISABLE_ALL_EXCEPTIONS),
|
||||||
|
SET_STATIC_PARAM_HEAD(image_info, PARAM_EP,
|
||||||
|
VERSION_2, image_info_t, 0),
|
||||||
|
.image_info.image_base = BL33_BASE,
|
||||||
|
--
|
||||||
|
2.25.1
|
||||||
|
|
||||||
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user