
    

    <?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://ocw.cs.pub.ro/courses/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="http://ocw.cs.pub.ro/courses/feed.php">
        <title>CS Open CourseWare</title>
        <description></description>
        <link>http://ocw.cs.pub.ro/courses/</link>
        <image rdf:resource="http://ocw.cs.pub.ro/courses/lib/tpl/arctic/images/favicon.ico" />
       <dc:date>2026-08-03T22:31:08+03:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/ep/teme/01?rev=1785241206&amp;do=diff"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/rasb/lab/hackathon?rev=1784330124&amp;do=diff"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/ass/labs-2025/05/tasks/01?rev=1784294183&amp;do=diff"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/ass/research/01?rev=1784284148&amp;do=diff"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/ass/labs-2025/05/tasks/02?rev=1784272263&amp;do=diff"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/ass/labs-2025/04/tasks/03?rev=1784205268&amp;do=diff"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=ass%3Alabs-2025%3Adeb-rauc-lab-skel-2026.tar.gz&amp;ns=ass%3Alabs-2025&amp;rev=1784204746&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/ass/labs-2025/04/tasks/02?rev=1784203699&amp;do=diff"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=ass%3Alabs-2025%3A04%3Adeb-rauc-lab-skel-2026.tar.gz&amp;ns=ass%3Alabs-2025%3A04&amp;rev=1784202057&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Apupper_viz.tar.gz&amp;ns=rasb%3Alab&amp;rev=1783110861&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Abase_back_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782916568&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al3_ee_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al2_l3_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al1_l2_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Abase_l1_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Ap_control.png&amp;ns=rasb%3Alab&amp;rev=1782625962&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Apid_eqn.png&amp;ns=rasb%3Alab&amp;rev=1782625907&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Anxpcar-lab.zip&amp;ns=rasb%3Alab&amp;rev=1782478029&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Alab1_skel.zip&amp;ns=rasb%3Alab&amp;rev=1782139694&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
                <rdf:li rdf:resource="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Allm_lab.zip&amp;ns=rasb%3Alab&amp;rev=1781871010&amp;tab_details=history&amp;mediado=diff&amp;do=media"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="http://ocw.cs.pub.ro/courses/lib/tpl/arctic/images/favicon.ico">
        <title>CS Open CourseWare</title>
        <link>http://ocw.cs.pub.ro/courses/</link>
        <url>http://ocw.cs.pub.ro/courses/lib/tpl/arctic/images/favicon.ico</url>
    </image>
    <item rdf:about="http://ocw.cs.pub.ro/courses/ep/teme/01?rev=1785241206&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-28T15:20:06+03:00</dc:date>
        <dc:creator>radu.mantu</dc:creator>
        <title>Assignment</title>
        <link>http://ocw.cs.pub.ro/courses/ep/teme/01?rev=1785241206&amp;do=diff</link>
        <description>&lt;pre&gt;
@@ -1,7 +1,5 @@
  ====== Assignment ======
- 
- &amp;lt;hidden&amp;gt;
  
  ===== 01. Overview =====
  
  The goal of this assignment is to implement a tool based on [[https://man.archlinux.org/man/perf_event_open.2.en|Linux Perf Events]] that is able to monitor main memory accesses performed by another process.
@@ -75,6 +73,4 @@
  
  ===== FAQ =====
  
  :?:
- 
- &amp;lt;/hidden&amp;gt;

&lt;/pre&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/rasb/lab/hackathon?rev=1784330124&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-18T02:15:24+03:00</dc:date>
        <dc:creator>cezar.zlatea</dc:creator>
        <title>GhostTag Apocalypse</title>
        <link>http://ocw.cs.pub.ro/courses/rasb/lab/hackathon?rev=1784330124&amp;do=diff</link>
        <description>&lt;pre&gt;
@@ -1,320 +1,233 @@
- ====== Hackathon: GhostTag Apocalypse ======
+ ====== GhostTag Apocalypse ======
  
- ===== Scope =====
+ ===== Challenge overview =====
  
- GhostTag Apocalypse is a firmware, security, and BLE simulation challenge.
- Students implement the protocol of an nRF52840 tag that must be found by
- authorized gateways without transmitting a stable identifier.
+ The Internet is unavailable, GPS is jammed, and only a sparse network of BLE
+ gateways remains operational. Your task is to complete the firmware protocol
+ for battery-powered rescue tags that must remain discoverable without
+ broadcasting a permanent identity.
  
- The challenge combines:
+ The protocol must survive unstable power, reject forged and replayed packets,
+ limit flash wear, and remain within a strict energy budget. The final system is
+ tested as a multi-device nRF52840 swarm in Renode.
  
-   * C code for the protocol;
-   * SipHash-2-4 for ephemeral identity and authentication;
-   * Zephyr firmware for &amp;#039;&amp;#039;nrf52840dk/nrf52840&amp;#039;&amp;#039;;
-   * Renode simulation with multiple boards and a positional BLE environment;
-   * Automated validation, HTML report, and execution in Kubernetes.
+ This is an approximately 8-hour firmware challenge. You will work only in:
  
- This is a hackathon challenge, not a complete protocol for a real product.
- It does not fully cover secure provisioning, key protection, replay attacks,
- radio certification, or a complete privacy evaluation.
+ &amp;lt;code text&amp;gt;
+ firmware/ghost_protocol.c
+ &amp;lt;/code&amp;gt;
  
- ===== Challenge Status =====
+ The public API, application code, gateway firmware, simulation scenario, and
+ validation rules are fixed contracts.
  
- ^ Component ^ Status ^ Remarks ^
- | Challenge code | Ready | Local commit &amp;#039;&amp;#039;29a2b3d&amp;#039;&amp;#039; on branch &amp;#039;&amp;#039;nrf52840-swarm/ghosttag-apocalypse&amp;#039;&amp;#039; |
- | Student starter | Ready | Contains exactly 3 TODOs in &amp;#039;&amp;#039;firmware/ghost_protocol.c&amp;#039;&amp;#039; |
- | Native tests | Ready | SipHash vectors, rotation, tamper, wrong seed, and leakage check |
- | Zephyr build | Ready | Tag and gateway for &amp;#039;&amp;#039;nrf52840dk/nrf52840&amp;#039;&amp;#039; |
- | Renode simulation | Ready | Tags, gateways, clones, deterministic positions and BLE range |
- | Validator and report | Ready | Produces &amp;#039;&amp;#039;validation.json&amp;#039;&amp;#039; and &amp;#039;&amp;#039;output/report.html&amp;#039;&amp;#039; |
- | Platform integration | Ready in repository | Manifest exists for the scenario and the Showcase Job |
- | Local reference validation | Passed | Last local evidence: 6/6 tags, 6/6 rotated, 75 rogue packets rejected |
- | Kubernetes cluster | Healthy | All 3 nodes are &amp;#039;&amp;#039;Ready&amp;#039;&amp;#039;, no failed pods, public health 200 |
- | Active student scenario | No | Platform still uses &amp;#039;&amp;#039;rp2040-sensor-filter-tinyml&amp;#039;&amp;#039; |
- | GhostTag image in registry | Unconfirmed | Image must be rebuilt, pushed, and verified before activation |
- | GhostTag showcase | Not running | Job &amp;#039;&amp;#039;ghosttag-apocalypse&amp;#039;&amp;#039; is absent |
+ ===== Read this documentation thoroughly =====
  
- ===== What Is Already Implemented =====
+ &amp;lt;note important&amp;gt;
+ Do not start coding before reading every file in this section, in order. The
+ fixed C header and the complete problem statement are authoritative.
+ &amp;lt;/note&amp;gt;
  
- ==== Radio Contract ====
+   - &amp;#039;&amp;#039;problem/problem.md&amp;#039;&amp;#039; -- the complete protocol, journal, recovery, energy,
+     and acceptance contract.
+   - &amp;#039;&amp;#039;firmware/include/ghost_protocol.h&amp;#039;&amp;#039; -- all public types, constants,
+     callbacks, and function signatures.
+   - &amp;#039;&amp;#039;firmware/ghost_protocol.c&amp;#039;&amp;#039; -- the starter implementation and the six
+     TODOs you must complete.
+   - &amp;#039;&amp;#039;firmware/tests/test_protocol.c&amp;#039;&amp;#039; -- the fast public tests and the expected
+     storage behavior.
+   - &amp;#039;&amp;#039;renode/README.md&amp;#039;&amp;#039; -- the files exposed for the simulation and the
+     reset/attacker sequence.
+   - &amp;#039;&amp;#039;renode/generate_swarm_resc.py&amp;#039;&amp;#039; and &amp;#039;&amp;#039;renode/run_test.sh&amp;#039;&amp;#039; -- how the swarm
+     is generated, executed, and passed to validation.
+   - &amp;#039;&amp;#039;docs/renode_primer.md&amp;#039;&amp;#039; -- the nRF52840 machines, BLE medium, provisioning
+     region, persistent journal region, and UART evidence.
+   - &amp;#039;&amp;#039;docs/exercise_guide.md&amp;#039;&amp;#039; -- the recommended solution order and the three
+     feedback layers.
  
- The BLE payload is exactly 28 bytes:
+ The values and byte layouts below are a summary. If this page and the fixed C
+ header differ, follow the header and &amp;#039;&amp;#039;problem/problem.md&amp;#039;&amp;#039;.
  
- ^ Bytes ^ Content ^
- | &amp;#039;&amp;#039;0..1&amp;#039;&amp;#039; | Company ID &amp;#039;&amp;#039;0xF00D&amp;#039;&amp;#039; |
- | &amp;#039;&amp;#039;2&amp;#039;&amp;#039; | Protocol version &amp;#039;&amp;#039;2&amp;#039;&amp;#039; |
- | &amp;#039;&amp;#039;3&amp;#039;&amp;#039; | Flags |
- | &amp;#039;&amp;#039;4..7&amp;#039;&amp;#039; | Rotation epoch, little-endian |
- | &amp;#039;&amp;#039;8..11&amp;#039;&amp;#039; | Public sector, little-endian |
- | &amp;#039;&amp;#039;12..19&amp;#039;&amp;#039; | Authenticated ephemeral identifier |
- | &amp;#039;&amp;#039;20..27&amp;#039;&amp;#039; | Authentication tag for bytes &amp;#039;&amp;#039;0..19&amp;#039;&amp;#039; |
+ ===== What you must implement =====
  
- The packet does not contain the stable ID of the device. The radio identity
- changes at every epoch, and the gateway verifies the packet using the small
- authorized key space of the sector.
+ Complete the six TODOs in &amp;#039;&amp;#039;firmware/ghost_protocol.c&amp;#039;&amp;#039;:
  
- ==== Student Environment ====
+   - canonical SipHash-2-4, including partial final message blocks;
+   - the two-lane persistent key-ratchet step;
+   - construction of the protocol-v3 packet, EID, and domain-separated MAC;
+   - strict packet verification with constant-time EID and MAC comparison;
+   - boot-time journal scan, validation, recovery, and lease reservation;
+   - payload emission with reservation before lease exhaustion and exactly one
+     in-memory epoch advance.
  
- The student receives in the browser:
+ Keep the existing function signatures. Do not change the packet size,
+ constants, storage callbacks, or public structures to work around the
+ contract.
  
-   * &amp;#039;&amp;#039;firmware/&amp;#039;&amp;#039; - Editable source;
-   * &amp;#039;&amp;#039;problem/&amp;#039;&amp;#039; - Challenge statement;
-   * &amp;#039;&amp;#039;output/&amp;#039;&amp;#039; - Logs, results, and HTML report;
-   * Run button - Starts the validation pipeline;
-   * Results panel - Displays &amp;#039;&amp;#039;output/report.html&amp;#039;&amp;#039;.
+ ===== Packet contract =====
  
- Data is kept on the user&amp;#039;s PVC. A scenario change archives the previous
- workspace. PVCs must not be deleted during the challenge or at rollback.
+ Every BLE manufacturer payload is exactly 28 bytes:
  
- ==== Automated Pipeline ====
+ ^ Bytes ^ Field ^
+ | &amp;#039;&amp;#039;0..1&amp;#039;&amp;#039; | company ID &amp;#039;&amp;#039;0xF00D&amp;#039;&amp;#039;, little-endian |
+ | &amp;#039;&amp;#039;2&amp;#039;&amp;#039; | protocol version &amp;#039;&amp;#039;3&amp;#039;&amp;#039; |
+ | &amp;#039;&amp;#039;3&amp;#039;&amp;#039; | flags |
+ | &amp;#039;&amp;#039;4..7&amp;#039;&amp;#039; | persistent ratchet epoch, little-endian |
+ | &amp;#039;&amp;#039;8..11&amp;#039;&amp;#039; | public city sector, little-endian |
+ | &amp;#039;&amp;#039;12..19&amp;#039;&amp;#039; | keyed ephemeral identifier |
+ | &amp;#039;&amp;#039;20..27&amp;#039;&amp;#039; | keyed MAC over bytes &amp;#039;&amp;#039;0..19&amp;#039;&amp;#039; |
  
- Every Run executes, in order:
+ A stable tag identifier must never appear on air in either byte order.
  
-   - Native C17 compilation with &amp;#039;&amp;#039;-Wall -Wextra -Werror&amp;#039;&amp;#039;;
-   - Known SipHash vectors and tamper tests;
-   - Zephyr build for the tag firmware;
-   - Zephyr build for the trusted gateway;
-   - Renode sector generation;
-   - Starting the nRF52840 machines in the BLE environment;
-   - Collecting UART logs from gateways;
-   - Fleet validation and HTML report generation.
+ ==== Key ratchet ====
  
- The validator uses only the traffic observed by gateways. It does not read
- the student&amp;#039;s C variables and does not inspect the tags&amp;#039; memory.
+ The provided &amp;#039;&amp;#039;seed_to_key&amp;#039;&amp;#039; function derives the epoch-0 key. To derive the
+ key for &amp;#039;&amp;#039;next_epoch&amp;#039;&amp;#039;, compute two SipHash outputs using the current 16-byte
+ key:
  
- ==== Scenario Scale ====
- 
- ^ Mode ^ Tags ^ Gateways ^ Rogue Clones ^ Total Boards ^
- | Local smoke | 6 | 3 | 2 | 11 |
- | Normal student run | 12 | 3 | 2 | 17 |
- | One showcase sector | 16 | 3 | 2 | 21 |
- | Complete showcase | 192 | 36 | 24 | 252 |
- 
- The showcase uses 12 independent sectors and runs a maximum of 4 in parallel.
- Each sector has a limit of &amp;#039;&amp;#039;3 CPU&amp;#039;&amp;#039; and &amp;#039;&amp;#039;2560 MiB&amp;#039;&amp;#039; RAM. These values were
- chosen after real testing; they must not be increased without a new capacity test.
- 
- ==== Live Infrastructure ====
- 
- The platform was recovered and hardened after the power incident:
- 
-   * CoreDNS is functioning and resolving internal and external names;
-   * Cloudflare tunnel uses token from mounted file, not token in arguments;
-   * Tunnel credential was rotated;
-   * Platform frontend is healthy;
-   * Provisioner selects only &amp;#039;&amp;#039;Ready=True&amp;#039;&amp;#039; and schedulable workers;
-   * All 3 nodes have systemd in &amp;#039;&amp;#039;running&amp;#039;&amp;#039; state;
-   * The infinite block in &amp;#039;&amp;#039;plymouth-quit-wait.service&amp;#039;&amp;#039; was removed;
-   * systemd journals are persistent on all nodes.
- 
- &amp;lt;hidden&amp;gt;
- Platform changes are in commit &amp;#039;&amp;#039;f5081ea&amp;#039;&amp;#039; from
- &amp;#039;&amp;#039;/home/pwd/eg106-platform&amp;#039;&amp;#039; on &amp;#039;&amp;#039;cloud_s1&amp;#039;&amp;#039;.
- 
- &amp;lt;/hidden&amp;gt;
- ===== What Students Need To Do =====
- 
- ==== Workspace ====
- 
- Students only modify:
- 
- &amp;lt;code&amp;gt;
- firmware/ghost_protocol.c
+ &amp;lt;code text&amp;gt;
+ 0x52 || next_epoch_le32 || lane
  &amp;lt;/code&amp;gt;
  
- &amp;lt;note warning&amp;gt;
- The header, packet size, CMake, gateway, UART format, epoch duration, or
- testing harness must not be changed.&amp;lt;/note&amp;gt;
+ Use lane &amp;#039;&amp;#039;0&amp;#039;&amp;#039; for new key bytes &amp;#039;&amp;#039;0..7&amp;#039;&amp;#039; and lane &amp;#039;&amp;#039;1&amp;#039;&amp;#039; for bytes &amp;#039;&amp;#039;8..15&amp;#039;&amp;#039;.
+ Compute both outputs before replacing the current key.
  
- ==== TODO 1 - SipHash-2-4 ====
+ ==== EID and MAC ====
  
- The student implements &amp;#039;&amp;#039;ghost_siphash24&amp;#039;&amp;#039;:
+ For a packet at epoch &amp;#039;&amp;#039;e&amp;#039;&amp;#039;:
  
-   * 128-bit key;
-   * 64-bit result;
-   * Canonical SipHash-2-4 construction;
-   * Little-endian read;
-   * Correct support for lengths that are not a multiple of 8;
-   * Result identical to the known vectors included in tests.
+   * ratchet from epoch 0 through &amp;#039;&amp;#039;e&amp;#039;&amp;#039; to obtain the epoch key;
+   * compute the EID with SipHash over
+     &amp;#039;&amp;#039;0x45 || epoch_le32 || sector_le32&amp;#039;&amp;#039;;
+   * copy the epoch key and XOR bytes &amp;#039;&amp;#039;0&amp;#039;&amp;#039;, &amp;#039;&amp;#039;7&amp;#039;&amp;#039;, &amp;#039;&amp;#039;8&amp;#039;&amp;#039;, and &amp;#039;&amp;#039;15&amp;#039;&amp;#039; with
+     &amp;#039;&amp;#039;0x4d&amp;#039;&amp;#039;, &amp;#039;&amp;#039;0x41&amp;#039;&amp;#039;, &amp;#039;&amp;#039;0x43&amp;#039;&amp;#039;, and &amp;#039;&amp;#039;0xa7&amp;#039;&amp;#039; to obtain the MAC key;
+   * authenticate packet bytes &amp;#039;&amp;#039;0..19&amp;#039;&amp;#039; with the MAC key;
+   * reject an incorrect company ID, version, EID, MAC, or an epoch above
+     &amp;#039;&amp;#039;1,000,000&amp;#039;&amp;#039;;
+   * compare all EID and MAC bytes without returning on the first mismatch.
  
- An approximate implementation or with wrong byte order will not pass.
+ ===== Crash-safe persistent state =====
  
- ==== TODO 2 - Building The Payload ====
+ The tag has two 4096-byte journal pages. Erased bytes are &amp;#039;&amp;#039;0xff&amp;#039;&amp;#039;; a write may
+ only change bits from 1 to 0; an erase operates on one complete page.
  
- The student completes &amp;#039;&amp;#039;ghost_build_payload&amp;#039;&amp;#039;:
+ Each journal slot is a 40-byte record:
  
-   * Keeps the existing header and layout;
-   * Derives the ephemeral identity using domain &amp;#039;&amp;#039;0x45&amp;#039;&amp;#039;, the epoch, and the sector;
-   * Writes the ephemeral identity in bytes &amp;#039;&amp;#039;12..19&amp;#039;&amp;#039;;
-   * Derives the MAC with a different key domain than the one used for EID;
-   * Authenticates bytes &amp;#039;&amp;#039;0..19&amp;#039;&amp;#039;;
-   * Writes the MAC in bytes &amp;#039;&amp;#039;20..27&amp;#039;&amp;#039;;
-   * Does not copy &amp;#039;&amp;#039;device_seed&amp;#039;&amp;#039; into the packet.
+ ^ Bytes ^ Field ^
+ | &amp;#039;&amp;#039;0..3&amp;#039;&amp;#039; | magic &amp;#039;&amp;#039;0x47535452&amp;#039;&amp;#039; |
+ | &amp;#039;&amp;#039;4..7&amp;#039;&amp;#039; | generation |
+ | &amp;#039;&amp;#039;8..11&amp;#039;&amp;#039; | future resume epoch |
+ | &amp;#039;&amp;#039;12..15&amp;#039;&amp;#039; | cumulative page-erase count |
+ | &amp;#039;&amp;#039;16..31&amp;#039;&amp;#039; | ratcheted key for the resume epoch |
+ | &amp;#039;&amp;#039;32..35&amp;#039;&amp;#039; | IEEE CRC32 over bytes &amp;#039;&amp;#039;0..31&amp;#039;&amp;#039; |
+ | &amp;#039;&amp;#039;36..39&amp;#039;&amp;#039; | commit word &amp;#039;&amp;#039;0xC01117ED&amp;#039;&amp;#039; |
  
- The same raw key must not be reused directly for both roles.
+ Write the 36-byte body first. Write the commit word in a separate final storage
+ operation. A missing commit, bad CRC, bad magic, or partially written body is
+ not a valid record.
  
- ==== TODO 3 - Verifying The Payload ====
+ The journal reserves leases of 16 epochs:
  
- The student completes &amp;#039;&amp;#039;ghost_verify_payload&amp;#039;&amp;#039; so that it rejects:
+   * before the first advertisement, durably reserve epochs &amp;#039;&amp;#039;0..15&amp;#039;&amp;#039; by storing
+     the resume state for epoch &amp;#039;&amp;#039;16&amp;#039;&amp;#039;;
+   * after a clean reboot, resume at the stored future epoch and reserve the next
+     lease before transmitting;
+   * if a non-erased invalid slot follows the newest valid record, skip two full
+     leases conservatively before reserving again;
+   * append after the newest record;
+   * when one page is full, erase the other page and write its first record;
+   * never erase the page holding the newest valid state before its successor is
+     committed.
  
-   * Wrong company ID;
-   * Wrong version;
-   * Wrong ephemeral identity;
-   * Wrong MAC;
-   * Flags modified after signing;
-   * Any modification to authenticated bytes;
-   * Verification with an unauthorized seed;
-   * Clone packets that only respect the protocol format.
+ These rules must prevent epoch reuse after a torn body write, torn commit,
+ corrupted CRC, page rollover, or power loss at any storage operation.
  
- The verification must reconstruct the expected values, don`t accept a packet
- just because it has the correct size and header.
+ ===== Energy and endurance limits =====
  
- ==== Recommended Student Workflow ====
+ Runtime energy is calculated as:
  
-   - Read &amp;#039;&amp;#039;problem/problem.md&amp;#039;&amp;#039; and the comments for the 3 TODOs;
-   - Implement and verify SipHash first;
-   - Implement EID and MAC;
-   - Implement verification;
-   - Run the challenge using the Run button;
-   - Fix native errors first, then Zephyr errors;
-   - Analyze Renode logs only after builds pass;
-   - Open or refresh the Results panel after the run finishes.
+ &amp;lt;code text&amp;gt;
+ energy = flash_writes * 8 + page_erases * 40 + advertisements
+ &amp;lt;/code&amp;gt;
  
- ==== Success Criteria For Students ====
+ One committed record requires two writes: body, then commit. The power-cut
+ simulation must use no more than 80 energy units.
  
- A solution is accepted only if:
+ The endurance tests generate 2000 sequential payloads. A passing solution uses
+ at most 252 flash writes and exactly one page erase. Persisting every packet
+ cannot pass these limits; lease reservation is required.
  
-   * All SipHash tests pass;
-   * All 3 gateways start;
-   * All authorized tags are observed;
-   * Each tag changes its radio identity;
-   * Clone traffic is rejected;
-   * There are no fatal errors in the firmware;
-   * The validator displays &amp;#039;&amp;#039;GHOST_VALIDATION passed=1&amp;#039;&amp;#039;;
-   * The run finishes with &amp;#039;&amp;#039;GHOSTTAG FLEET SURVIVED THE APOCALYPSE&amp;#039;&amp;#039;.
+ ===== Simulation =====
  
- Compiling without errors is not enough.
+ The complete run starts:
  
- &amp;lt;hidden&amp;gt;
- ===== What We Need To Do As Organizers =====
+   * 6 authorized nRF52840 tags;
+   * 3 trusted observer gateways;
+   * 1 unregistered clone;
+   * 1 attacker replaying a captured, correctly authenticated packet.
  
- ==== Before The Challenge ====
+ At virtual second 3, Renode resets tag 1 while preserving its nonvolatile
+ journal. The replay attacker then transmits an old epoch-0 packet from a
+ different BLE address.
  
-   - Check the cluster, frontend, registry, and workers;
-   - Rebuild the GhostTag image from the correct branch;
-   - Run the smoke test with the reference implementation and 6 tags;
-   - Do not continue if the final success marker is missing;
-   - Explicitly push the tag
-     &amp;#039;&amp;#039;nrf52840-swarm-ghosttag-apocalypse&amp;#039;&amp;#039; to the registry;
-   - Verify the image manifest directly in the registry or by pulling on a node;
-   - Run server-side dry-run for both Kubernetes manifests;
-   - Save the active scenario ConfigMap for rollback;
-   - Activate &amp;#039;&amp;#039;k8s/platform/active-scenario.yaml&amp;#039;&amp;#039;;
-   - Test with a disposable user.
+ A correct system must:
  
- The disposable test must demonstrate both directions:
+   * discover all six authorized tags;
+   * observe identity rotation for every tag;
+   * reject the unregistered clone;
+   * reject the captured replay;
+   * recover tag 1 without reusing an epoch;
+   * remain within the runtime energy budget;
+   * finish without firmware fatal errors.
  
-   * The starter is properly seeded and fails cleanly;
-   * The reference implementation passes completely;
-   * The report appears in Results;
-   * Old files are archived upon scenario change.
+ ===== Recommended workflow =====
  
- Complete operational commands are in &amp;#039;&amp;#039;docs/HACKATHON_RUNBOOK.md&amp;#039;&amp;#039;.
+ ^ Goal ^
+ | Read every contract and pass all SipHash vectors. |
+ | Implement ratchet, packet generation, EID, MAC, and verification. |
+ | Implement record encoding, CRC32, scanning, append, and leases. |
+ | Handle torn writes, corruption, reboot, and page rollover. |
+ | Verify flash-wear and energy bounds. |
+ | Run Zephyr and Renode; diagnose the complete swarm. |
  
- ==== At The Beginning Of The Session ====
+ Use the fastest feedback first. Do not repeatedly run the full swarm while the
+ native protocol suite still fails.
  
- We must clearly explain:
+ ===== Understanding the Run result =====
  
-   * The privacy problem: a stable ID allows tracking the person;
-   * Why epoch, EID, and MAC exist;
-   * Why the trusted gateway searches within the authorized fleet;
-   * What the student controls and what the harness controls;
-   * Why rogue clones exist;
-   * Which is the only editable file;
-   * How to read the three feedback levels.
+ The Run action has three gates:
  
- We do not provide the reference implementation and do not expose fleet seeds.
- &amp;lt;/hidden&amp;gt;
+   - native C17 tests for cryptography, packet integrity, persistence, recovery,
+     corruption handling, and endurance;
+   - Zephyr builds for the nRF52840 tag and trusted gateway;
+   - an 8-second Renode swarm followed by validation and report generation.
  
- ==== During The Challenge ====
+ The complete success output includes lines equivalent to:
  
- We monitor:
- 
-   * Node and pod health;
-   * The Job queue for student runs;
-   * Image pull errors;
-   * CPU, RAM, and ephemeral storage usage;
-   * Frontend and ingress availability;
-   * Participants&amp;#039; PVCs;
-   * Renode execution times.
- 
- We help students with compilation errors, platform usage, and interpreting
- the report. We do not implement TODOs for them.
- 
- ==== Final Showcase ====
- 
- The showcase is optional and separate from student runs.
- 
- Before launching:
- 
-   * Check requested resources on both workers;
-   * Confirm there is at least one healthy worker and enough space for the
-     approx. 3.76 GB image;
-   * Keep &amp;#039;&amp;#039;parallelism: 4&amp;#039;&amp;#039;;
-   * Do not delete pods or student PVCs to make room.
- 
- Launch &amp;#039;&amp;#039;k8s/showcase/indexed-job.yaml&amp;#039;&amp;#039; and monitor all 12 completions.
- The showcase is successful only if all 12 sectors finish successfully and
- each log contains &amp;#039;&amp;#039;GHOST_VALIDATION passed=1&amp;#039;&amp;#039;.
- 
- ==== After The Challenge Or At Rollback ====
- 
-   * Only delete the Showcase Job if it needs to be stopped;
-   * Restore the saved ConfigMap if reverting to the previous scenario;
-   * Do not delete student PVCs;
-   * Keep reports and logs useful for evaluation;
-   * Check the public health endpoint again;
-   * Document any cluster incident or observed capacity limit.
- 
- ===== Definition Of Done For Organizers =====
- 
- The challenge can be opened to students when all points are true:
+ &amp;lt;code text&amp;gt;
+ PROTOCOL_CONTRACT_TESTS failures=0
+ Renode exit status: 0
+ GHOST_VALIDATION passed=1 ... tags=6/6 rotated=6/6 ... recovered=1 energy=.../80
+ &amp;gt;&amp;gt;&amp;gt; GHOSTTAG FLEET SURVIVED THE APOCALYPSE &amp;lt;&amp;lt;&amp;lt;
+ &amp;lt;/code&amp;gt;
  
-   * [ ] GhostTag image is built from the desired commit;
-   * [ ] Reference smoke test passes;
-   * [ ] Image tag is confirmed in the registry;
-   * [ ] All required nodes are &amp;#039;&amp;#039;Ready&amp;#039;&amp;#039;;
-   * [ ] Frontend and DNS are healthy;
-   * [ ] Manifest dry-run passes;
-   * [ ] Previous scenario state is saved;
-   * [ ] GhostTag scenario is active;
-   * [ ] Starter fails in a controlled manner for the disposable user;
-   * [ ] Reference passes for the disposable user;
-   * [ ] HTML report loads in Results;
-   * [ ] Rollback is prepared;
-   * [ ] Reference solution is not accessible to participants.
+ After the run, refresh the Results panel and inspect &amp;#039;&amp;#039;output/report.html&amp;#039;&amp;#039;.
+ When a check fails, read the first failing gate and its log before changing
+ code.
  
- At the time of writing, the first two remaining operational actions are build/push
- for the image and controlled activation of the scenario. The showcase must not
- be launched before the disposable test.
+ ===== Completion checklist =====
  
- ===== Important Files =====
+ Before considering the challenge complete, confirm that:
  
- ^ File ^ Role ^
- | &amp;#039;&amp;#039;firmware/ghost_protocol.c&amp;#039;&amp;#039; | The only file edited by the student |
- | &amp;#039;&amp;#039;firmware/include/ghost_protocol.h&amp;#039;&amp;#039; | Wire contract and API |
- | &amp;#039;&amp;#039;firmware/tests/test_protocol.c&amp;#039;&amp;#039; | Public native tests |
- | &amp;#039;&amp;#039;ide/problem/problem.md&amp;#039;&amp;#039; | Full statement displayed in the browser |
- | &amp;#039;&amp;#039;support/gateway/&amp;#039;&amp;#039; | Trusted gateway |
- | &amp;#039;&amp;#039;docker/scripts/build_firmware.sh&amp;#039;&amp;#039; | Native tests and Zephyr builds |
- | &amp;#039;&amp;#039;docker/scripts/generate_swarm_resc.py&amp;#039;&amp;#039; | Renode topology generation |
- | &amp;#039;&amp;#039;docker/scripts/validate_swarm.py&amp;#039;&amp;#039; | Automated acceptance criteria |
- | &amp;#039;&amp;#039;docker/scripts/generate_report.py&amp;#039;&amp;#039; | HTML report |
- | &amp;#039;&amp;#039;k8s/platform/active-scenario.yaml&amp;#039;&amp;#039; | Scenario activation for students |
- | &amp;#039;&amp;#039;k8s/showcase/indexed-job.yaml&amp;#039;&amp;#039; | 252-board showcase |
- | &amp;#039;&amp;#039;docs/HACKATHON_RUNBOOK.md&amp;#039;&amp;#039; | Operational procedure and rollback |
- | &amp;#039;&amp;#039;docs/instructor_notes.md&amp;#039;&amp;#039; | Recommended structure for the 3-hour session |
+   * all six TODOs have real implementations;
+   * all 64 SipHash vectors pass;
+   * the exact ratchet and 28-byte packet vectors pass;
+   * malformed, tampered, forged, and unreasonable packets are rejected;
+   * fresh boot reserves a lease before any packet is emitted;
+   * every recovery path avoids epoch reuse;
+   * torn and corrupted records remain invalid;
+   * 2000 payloads stay within the write and erase limits;
+   * both Zephyr applications build;
+   * the Renode validator reports all six tags seen and rotated;
+   * clone rejection, replay rejection, recovery, energy, and fatal-error checks
+     all pass.
  
- &amp;lt;hidden&amp;gt;
- | &amp;#039;&amp;#039;reference/firmware/&amp;#039;&amp;#039; | Organizers&amp;#039; solution |
- &amp;lt;/hidden&amp;gt;

&lt;/pre&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/ass/labs-2025/05/tasks/01?rev=1784294183&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-17T16:16:23+03:00</dc:date>
        <dc:creator>florin.stancu</dc:creator>
        <title>01. [Re]Configuring &amp; building OP-TEE + ATF</title>
        <link>http://ocw.cs.pub.ro/courses/ass/labs-2025/05/tasks/01?rev=1784294183&amp;do=diff</link>
        <description>&lt;pre&gt;
@@ -51,9 +51,9 @@
  
  &amp;lt;note warning&amp;gt;
  There is currently a bug inside OP-TEE that makes it unable to boot: it uses the NXP EdgeLock Enclave for TRNG generation, whose firmware does not start (and we weren&amp;#039;t able to figure it out since its documentation is &amp;quot;secret&amp;quot; / available using NDA-only).
  
- As workaround, we can disable the ELE RNG driver and enable a software one using the following additional make configuration options: &amp;#039;&amp;#039;CFG_WITH_SOFTWARE_PRNG=y CFG_IMX_ELE=n&amp;#039;&amp;#039;. So make sure to also set them!
+ As workaround, we can disable the ELE RNG driver and enable a software one using the following additional make configuration options: &amp;#039;&amp;#039;CFG_WITH_SOFTWARE_PRNG=y CFG_IMX_ELE=n CFG_IMX_TRUSTED_ARM_CE=n&amp;#039;&amp;#039;. So make sure to also set them!
  &amp;lt;/note&amp;gt;
  
  After a successful build, check the output (&amp;#039;&amp;#039;O&amp;#039;&amp;#039;) directory&amp;#039;s &amp;#039;&amp;#039;core&amp;#039;&amp;#039; subdirectory for the &amp;#039;&amp;#039;tee.bin&amp;#039;&amp;#039;, &amp;#039;&amp;#039;tee-raw.bin&amp;#039;&amp;#039; and many other files!
  We will keep the raw one for later inclusion into the firmware package using &amp;#039;&amp;#039;mkimage&amp;#039;&amp;#039; ;)
@@ -72,23 +72,35 @@
  You need to set the following additional configuration variables to its make invocation:
    * &amp;#039;&amp;#039;SPD=opteed&amp;#039;&amp;#039; -- this is the [[https://trustedfirmware-a.readthedocs.io/en/latest/components/spd/index.html|Secure Payload Dispatcher]] module, aka: who does ATF&amp;#039;s Secure Monitor need to talk with? Our OP-TEE, of course!
    * ATF also has to know the memory region where we&amp;#039;ve put OP-TEE (set the &amp;#039;&amp;#039;BL32_BASE&amp;#039;&amp;#039; variable to lower limit, in hexadecimal); we also need to specify its total size: &amp;#039;&amp;#039;BL32_SIZE&amp;#039;&amp;#039; (remember: we allocated &amp;#039;&amp;#039;36MB&amp;#039;&amp;#039;, but give it in bytes, either in base 10 or 16 using C integer notation);
    * We want ATF to print some debug messages over the first serial peripheral so, finally, set the &amp;#039;&amp;#039;LOG_LEVEL=40&amp;#039;&amp;#039; and &amp;#039;&amp;#039;%%IMX_BOOT_UART_BASE=0x44380000%%&amp;#039;&amp;#039; (if you look in iMX93&amp;#039;s Memory Map (the Reference Manual), this is the physical address of our LPUART1 - i.e. our serial communication module!).
+ 
  
  == Step 4. Rebuild the firmware image package ==
  
  Before we can take a look at the fruits of our effort so far, we need to re-build the firmware package with these last two components.
  
- This is easy if you saved your mkimage script (in your Makefile). You will need JUST one additional file copied: &amp;#039;&amp;#039;tee-raw.bin&amp;#039;&amp;#039; from &amp;#039;&amp;#039;optee&amp;#039;&amp;#039; build output directory, &amp;#039;&amp;#039;core&amp;#039;&amp;#039; subdirectory (as mentioned in the subtask above!) inside &amp;#039;&amp;#039;mkimage&amp;#039;&amp;#039;&amp;#039;s build directory, but rename it as &amp;#039;&amp;#039;tee.bin&amp;#039;&amp;#039;.
- The bundled scripts will [[https://github.com/nxp-imx/imx-mkimage/blob/lf-6.12.20_2.0.0/iMX93/soc.mak#L43|see that this file exists]] and add it to the image automatically!
+ Since we&amp;#039;re using mainline [[https://docs.u-boot-project.org/en/latest/develop/package/binman.html|u-boot&amp;#039;s binman]] to generate our &amp;#039;&amp;#039;flash.bin&amp;#039;&amp;#039;, we must reconfigure its descriptor to embed our new &amp;#039;&amp;#039;BL32&amp;#039;&amp;#039; component.
  
- &amp;lt;note warning&amp;gt;
- One more thing: when calling the imx-mkimage&amp;#039;s script, set &amp;#039;&amp;#039;TEE_LOAD_ADDR=&amp;lt;TrustZone DRAM start address&amp;gt;&amp;#039;&amp;#039;.
- 
- The default value is wrong for our SoC.
- &amp;lt;/note&amp;gt;
+ Fortunately, [[https://lists.denx.de/pipermail/u-boot/2026-June/621618.html|it&amp;#039;s quite easy]], so manually apply this patch (minus the &amp;#039;&amp;#039;if def&amp;#039;&amp;#039;):
+ &amp;lt;code patch&amp;gt;
+ diff --git i/arch/arm/dts/imx93-u-boot.dtsi w/arch/arm/dts/imx93-u-boot.dtsi
+ index dc86746ac90..06fe228d568 100644
+ --- i/arch/arm/dts/imx93-u-boot.dtsi
+ +++ w/arch/arm/dts/imx93-u-boot.dtsi
+ @@ -69,6 +69,7 @@
+  				container;
+  				image0 = &amp;quot;a55&amp;quot;, &amp;quot;bl31.bin&amp;quot;, &amp;quot;0x204E0000&amp;quot;;
+  				image1 = &amp;quot;a55&amp;quot;, &amp;quot;u-boot.bin&amp;quot;, &amp;quot;0x80200000&amp;quot;;
+ +				image2 = &amp;quot;a55&amp;quot;, &amp;quot;tee-raw.bin&amp;quot;, &amp;quot;0xfdc00000&amp;quot;; // replace with your OP-TEE TZDRAM addr
+  			};
+  		};
+  	};
+ &amp;lt;/code&amp;gt;
  
+ Then simply copy &amp;#039;&amp;#039;tee-raw.bin&amp;#039;&amp;#039; from op-tee&amp;#039;s &amp;#039;&amp;#039;build/core&amp;#039;&amp;#039; directory to u-boot&amp;#039;s source and run your make script again.
  Also make sure to replace &amp;#039;&amp;#039;bl31.bin&amp;#039;&amp;#039; with the newly recompiled one from ARM Trusted Firmware-A!
+ To verify, the newly obtained &amp;#039;&amp;#039;flash.bin&amp;#039;&amp;#039; should be &amp;#039;&amp;#039;&amp;gt;=2MB&amp;#039;&amp;#039; in size.
  
  Proceed to load this image over the serial boot protocol using the IMX &amp;#039;&amp;#039;uuu&amp;#039;&amp;#039; utility.
  Check the serial console (the one provided by the board&amp;#039;s DEBUG USB port) for confirmation!
  

&lt;/pre&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/ass/research/01?rev=1784284148&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-17T13:29:08+03:00</dc:date>
        <dc:creator>radu.mantu</dc:creator>
        <title>Research projects</title>
        <link>http://ocw.cs.pub.ro/courses/ass/research/01?rev=1784284148&amp;do=diff</link>
        <description>&lt;pre&gt;
@@ -2,6 +2,7 @@
  
  ===== Research projects  =====
  
  &amp;lt;html&amp;gt;
- &amp;lt;iframe src=&amp;quot;https://docs.google.com/presentation/d/e/2PACX-1vQ7QFyYtR3yZU0yRlgX1Vrk245McK9iTw42L8WQAHvt5pRAJWw4Oks3EJnH8JNnXzxw44YLJbQtiFXG/pubembed?start=false&amp;amp;loop=false&amp;quot; frameborder=&amp;quot;0&amp;quot; width=&amp;quot;800&amp;quot; height=&amp;quot;486&amp;quot; allowfullscreen=&amp;quot;true&amp;quot; mozallowfullscreen=&amp;quot;true&amp;quot; webkitallowfullscreen=&amp;quot;true&amp;quot;&amp;gt;&amp;lt;/iframe&amp;gt;
+ &amp;lt;iframe src=&amp;quot;https://docs.google.com/presentation/d/e/2PACX-1vSdlaU-Cvatr7LIMGgpOca1HW16qpVids9FwICEzdyV7JPCsR8zwIlf0tJqPEOdor3yTH_ytUy5-TM3/pubembed?start=false&amp;amp;loop=false&amp;quot; frameborder=&amp;quot;0&amp;quot; width=&amp;quot;800&amp;quot; height=&amp;quot;486&amp;quot; allowfullscreen=&amp;quot;true&amp;quot; mozallowfullscreen=&amp;quot;true&amp;quot; webkitallowfullscreen=&amp;quot;true&amp;quot;&amp;gt;&amp;lt;/iframe&amp;gt;
  &amp;lt;/html&amp;gt;
+ 

&lt;/pre&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/ass/labs-2025/05/tasks/02?rev=1784272263&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-17T10:11:03+03:00</dc:date>
        <dc:creator>florin.stancu</dc:creator>
        <title>02. Writing Trusted Applications</title>
        <link>http://ocw.cs.pub.ro/courses/ass/labs-2025/05/tasks/02?rev=1784272263&amp;do=diff</link>
        <description>&lt;pre&gt;
@@ -21,12 +21,15 @@
  make ARCH=... dtbs
  &amp;lt;/code&amp;gt;
  &amp;lt;/note&amp;gt;
  
- Oh, and re-enable **Buildroot** if disabled for the previous lab (you backed up your ITS file, hopefully).
- Then enter its &amp;#039;&amp;#039;menuconfig&amp;#039;&amp;#039; and search for &amp;#039;&amp;#039;PACKAGE_OPTEE_CLIENT&amp;#039;&amp;#039;. Enable it and rebuild your rootfs!
+ Afterwards, you need to copy the new &amp;#039;&amp;#039;.dtb&amp;#039;&amp;#039; into your &amp;#039;&amp;#039;staging/&amp;#039;&amp;#039; directory and re-build the Linux uImage (using the previously provided &amp;#039;&amp;#039;staging/Makefile&amp;#039;&amp;#039;).
  
- Afterwards, you need to copy the new &amp;#039;&amp;#039;.dtb&amp;#039;&amp;#039; into your &amp;#039;&amp;#039;staging/&amp;#039;&amp;#039; directory and [[:ass:labs-2025:02:tasks:01#task_d_-_fit_image|re-build the Linux FIT]] (e.g., &amp;#039;&amp;#039;linux.itb&amp;#039;&amp;#039;). And upload it to your emmc (use u-boot&amp;#039;s &amp;#039;&amp;#039;ums&amp;#039;&amp;#039; and simply copy the file on the FAT32 boot partition).
+ As for the userspace (rootfs), there are two choices: either **Debian** or **Buildroot** (disable RAUC nevertheless and use the first version of &amp;#039;&amp;#039;mk-disk-image.sh&amp;#039;&amp;#039; to upload the rootfs when ready to test, towards the end of the task).
+ 
+ For Buildroot, you must use &amp;#039;&amp;#039;menuconfig&amp;#039;&amp;#039; and enable &amp;#039;&amp;#039;PACKAGE_OPTEE_CLIENT&amp;#039;&amp;#039;! Built it &amp;amp; unpack it to the secondary ext4 disk partition (just edit the mk-disk-image script).
+ 
+ For Debian, you can either cross compile the OP-TEE client or try out the &amp;#039;&amp;#039;optee-client&amp;#039;&amp;#039; package from APT (use a &amp;#039;&amp;#039;chroot&amp;#039;&amp;#039; to install from host).
  
  == Step 6. Building a TA ==
  
  We can use our workstation / laptop to cross-compile a trusted application!
@@ -36,21 +39,21 @@
  Build both the host app and the Trusted Application need to be compiled TOGETHER with the TEE Client Library, and the OPTEE OS exported SDK, respectively.
  
  Make sure to read the examples documentation to see the make variables to set!
  
- &amp;lt;note&amp;gt;
+ &amp;lt;spoiler Special Instructions for Buildroot&amp;gt;
  Note that, usually, you must build optee-client from source on the host machine [[https://optee.readthedocs.io/en/latest/building/gits/optee_client.html#build-instructions|the optee_client first]]. .
  
- But, since we&amp;#039;re using Buildroot and have enabled it, you can find it already compiled for the target system at &amp;#039;&amp;#039;&amp;lt;buildroot-dir&amp;gt;/output/build/optee-client-&amp;lt;version&amp;gt;&amp;#039;&amp;#039;.
+ Since you&amp;#039;re using Buildroot, you can find it already compiled for the target system at &amp;#039;&amp;#039;&amp;lt;buildroot-dir&amp;gt;/output/build/optee-client-&amp;lt;version&amp;gt;&amp;#039;&amp;#039;.
  
  Touugh we need to give a &amp;#039;&amp;#039;TEEC_EXPORT&amp;#039;&amp;#039; install path when invoking the TA makefile... Use find for &amp;#039;&amp;#039;tee_client_api.h&amp;#039;&amp;#039; and see where it&amp;#039;s found (hint: &amp;#039;&amp;#039;sysroot&amp;#039;&amp;#039;)!
- &amp;lt;/note&amp;gt;
+ 
+ Also note that for building Buildroot-targeted applications, your classic &amp;#039;&amp;#039;aarch64-none-gnu-&amp;#039;&amp;#039; toolchain **won&amp;#039;t work** since Buildroot uses a custom LibC by default. But, fortunately, you may find the cross compilation prefix at &amp;#039;&amp;#039;&amp;lt;buildroot-dir&amp;gt;/output/host/bin/aarch64-buildroot-linux-gnu-&amp;#039;&amp;#039; (see the difference?)!
+ &amp;lt;/spoiler&amp;gt;
  
  &amp;lt;note&amp;gt;
  As for &amp;#039;&amp;#039;TA_DEV_KIT_DIR&amp;#039;&amp;#039; of a Trusted Application, it must point to an SDK generated inside BL32 (optee_os) source directory (something like &amp;#039;&amp;#039;export-ta...&amp;#039;&amp;#039;&amp;#039;.
  &amp;lt;/note&amp;gt;
- 
- Also note that for building Buildroot-targeted applications, your classic &amp;#039;&amp;#039;aarch64-none-gnu-&amp;#039;&amp;#039; toolchain **won&amp;#039;t work** since Buildroot uses custom [[https://www.uclibc.org/|ucLibC]] by default. But, fortunately, you may find the cross compilation prefix at &amp;#039;&amp;#039;&amp;lt;buildroot-dir&amp;gt;/output/host/bin/aarch64-buildroot-linux-gnu-&amp;#039;&amp;#039; (see the difference?)!
  
  == Step 7. Signing the TA ==
  
  Remember the secure boot process?
@@ -73,73 +76,29 @@
  &amp;lt;code&amp;gt;
  u-boot=&amp;gt; ums mmc 0
  &amp;lt;/code&amp;gt;
  
- Do not Ctrl+C yet, leave it running and mount the newly appeared USB device in your PC/VM!
+ Use &amp;#039;&amp;#039;lsblk&amp;#039;&amp;#039; to find out which is the second (ext4) partition, mount it and copy the TA files:
+ &amp;lt;code bash&amp;gt;
+ mount /dev/sda2 /mnt
+ ls -l /mnt
+ # copy them inside your home
+ cp $OPTEE_FILES /mnt/root/
+ &amp;lt;/code&amp;gt;
  
  After copying the files, boot Linux.
  
- Now check if &amp;#039;&amp;#039;tee-supplicant&amp;#039;&amp;#039; is running... let&amp;#039;s mount devtmpfs then start it:
+ On buildroot, check if &amp;#039;&amp;#039;tee-supplicant&amp;#039;&amp;#039; is running... or start it:
  &amp;lt;code bash&amp;gt;
- mount -t devtmpfs devtmpfs /dev
+ ps aux | grep tee-supplicant
  tee-supplicant -d
  &amp;lt;/code&amp;gt;
  
- Mount the boot partition and run the TA (you might need to copy it somewhere else and &amp;#039;&amp;#039;chmod +x&amp;#039;&amp;#039;)!
- Then execute the program ;) 
+ Then execute the trusted application ;) 
  
  &amp;lt;note info&amp;gt;
  Observe the error: OP-TEE cannot find the &amp;#039;&amp;#039;.ta&amp;#039;&amp;#039; file inside a trusted memory or REE.
  
  For this, you will need to copy the signed &amp;#039;&amp;#039;&amp;lt;UUID&amp;gt;.ta&amp;#039;&amp;#039; file to &amp;#039;&amp;#039;/lib/optee_armtz/&amp;#039;&amp;#039; (create it if it doesn&amp;#039;t exist), as (very badly) documented.
  &amp;lt;/note&amp;gt;
  
- 
- == TODO: format me ==
- 
- &amp;lt;code bash&amp;gt;
- # mount the relevant partitions
- [user@host]$ sudo mount /dev/nbd0p1 /mnt
- [user@host]$ sudo mkdir -p /mnt/{root,var,boot}
- [user@host]$ sudo mount /dev/nbd0p5 /mnt/root
- [user@host]$ sudo mount /dev/nbd0p6 /mnt/var
- [user@host]$ sudo mount /dev/nbd0p7 /mnt/boot
- 
- # delete the lost+found/ directories (because I don&amp;#039;t like them)
- [user@host]$ sudo find /mnt -type d -name lost+found -delete
- 
- # bootstrap the rootfs and install qemu-user-static for chroot
- # NOTE: mainline debootstrap is broken on CachyOS; that&amp;#039;s why we use a submodule
- [user@host]$ sudo ./third-party/debootstrap/debootstrap \
-                 --include=neovim,locales,iproute2       \
-                 --arch=arm64 --foreign                  \
-                 trixie /mnt
- [user@host]$ sudo cp $(which qemu-aarch64-static) /mnt/usr/bin
- 
- # finish up debootstrap process inside chroot
- # NOTE: arch-chroot automatically mounted /proc /sys /dev inside jail
- #       you can install it via the arch-install-scripts on non-ArchLinux distros
- [user@host]$ sudo arch-chroot /mnt
- 
- [root@jail]$ export PATH=/usr/sbin:${PATH}
- [root@jail]$ /debootstrap/debootstrap --second-stage
- 
- [root@jail]$ passwd
- 
- [root@jail]$ echo &amp;quot;en_US.UTF-8 UTF-8&amp;quot; &amp;gt;&amp;gt; /etc/locale.gen
- [root@jail]$ locale-gen
- [root@jail]$ update-locale LANG=en_US.UTF-8 LC_ALL=en_US.UTF-8
- 
- [root@jail]$ exit
- 
- # before unmounting, create the fstab so that /root, /var and /boot are mounted
- # after the rootfs is verified; these three are unprotected but also unimportant
- [user@host]$ cat &amp;lt;&amp;lt;EOF | sudo tee /mnt/etc/fstab
- /dev/vda5   /root             ext4  rw,relatime                    0  2
- /dev/vda6   /var              ext4  rw,relatime                    0  2
- /dev/vda7   /boot             vfat  rw,relatime                    0  2
- EOF
- 
- # finally, do a recursive unmount of all three partitions
- [user@host]$ sudo umount -R /mnt
- &amp;lt;/code&amp;gt;
  

&lt;/pre&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/ass/labs-2025/04/tasks/03?rev=1784205268&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-16T15:34:28+03:00</dc:date>
        <dc:creator>florin.stancu</dc:creator>
        <title>03. RAUC</title>
        <link>http://ocw.cs.pub.ro/courses/ass/labs-2025/04/tasks/03?rev=1784205268&amp;do=diff</link>
        <description>&lt;pre&gt;
@@ -15,11 +15,19 @@
    - Sets up &amp;#039;&amp;#039;/etc/fw_env.config&amp;#039;&amp;#039;, &amp;#039;&amp;#039;fstab&amp;#039;&amp;#039;, and enables systemd services
  
  But in order to run it, recursively copy the entire RAUC utils directory from host to somewhere inside the debian rootfs (e.g., &amp;#039;&amp;#039;/root/rauc-utils/&amp;#039;&amp;#039;) and run it using &amp;#039;&amp;#039;chroot-enter.sh&amp;#039;&amp;#039; (as you&amp;#039;ve done in the prev. task).
  
- === Generate the disk image ===
+ === [Re]Generate the disk image ===
  
  We can now run &amp;#039;&amp;#039;mk-disk-image2.sh&amp;#039;&amp;#039;. The &amp;#039;&amp;#039;disk.img&amp;#039;&amp;#039; will be updated with 4 partitions (boot, A, B + data), Debian will be copied to the first 2 EXT4 partitions and the bootloader will be installed at 32KB offset (the SoC&amp;#039;s BL1/BOOTROM wants it there).
+ 
+ === Custom u-boot script ===
+ 
+ 📄 In order to have the A-B partitioning scheme, we&amp;#039;ll need to add this script: &amp;#039;&amp;#039;rauc-utils/boot.cmd.in&amp;#039;&amp;#039; to our u-boot default environment. Feel free to study it (highly recommended)!
+ 
+ Use the &amp;#039;&amp;#039;rauc-utils/uboot-modify-bootcmd.sh&amp;#039;&amp;#039; script to just to this!
+ 
+ Then rebuild uboot (you must delete &amp;#039;&amp;#039;u-boot/.config&amp;#039;&amp;#039; and &amp;#039;&amp;#039;u-boot/flash.bin&amp;#039;&amp;#039; for our Makefile to trigger the recompilation of UBoot).
  
  === Flashing the board ===
  
  Power up the board and go into u-boot. Let &amp;#039;&amp;#039;fastboot&amp;#039;&amp;#039; start and use &amp;#039;&amp;#039;fastboot flash 0:0 disk.img&amp;#039;&amp;#039;.

&lt;/pre&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=ass%3Alabs-2025%3Adeb-rauc-lab-skel-2026.tar.gz&amp;ns=ass%3Alabs-2025&amp;rev=1784204746&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-16T15:25:46+03:00</dc:date>
        <dc:creator>florin.stancu</dc:creator>
        <title>ass:labs-2025:deb-rauc-lab-skel-2026.tar.gz</title>
        <link>http://ocw.cs.pub.ro/courses/?image=ass%3Alabs-2025%3Adeb-rauc-lab-skel-2026.tar.gz&amp;ns=ass%3Alabs-2025&amp;rev=1784204746&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description></description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/ass/labs-2025/04/tasks/02?rev=1784203699&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-16T15:08:19+03:00</dc:date>
        <dc:creator>florin.stancu</dc:creator>
        <title>02. Bootstrapping Debian</title>
        <link>http://ocw.cs.pub.ro/courses/ass/labs-2025/04/tasks/02?rev=1784203699&amp;do=diff</link>
        <description>&lt;pre&gt;
@@ -9,13 +9,12 @@
  📄 Edit the &amp;#039;&amp;#039;mk-debian-rootfs.sh&amp;#039;&amp;#039; script, read the code and fill the TODOs.
  
  Since we need to install the Debian binaries executable on a 64-bit ARM architecture, we will need to split the installation into two stages: first, the .deb (Debian install packages) are downloaded from a Debian mirror server and unpacked into the target rootfs directory. Afterwards, since Debian will need to run some scripts to setup its distro system, we must **emulate** the target architecture. Enter [[https://www.qemu.org/|qemu]] which will help us to just that!
  
- Finally, we need to obtain the &amp;#039;&amp;#039;debian-rootfs.tar.gz&amp;#039;&amp;#039; archive with the contents of our newly-created Aarch64 Debian. Use &amp;#039;&amp;#039;tar&amp;#039;&amp;#039; to &amp;#039;&amp;#039;c&amp;#039;&amp;#039;reate a g&amp;#039;&amp;#039;z&amp;#039;&amp;#039;ipped archive, and be sure to &amp;#039;&amp;#039;p&amp;#039;&amp;#039;reserve permissions!
+ Finally, we need to obtain the &amp;#039;&amp;#039;debian-rootfs.tar.gz&amp;#039;&amp;#039; archive with the contents of our newly-created Aarch64 Debian. Use &amp;#039;&amp;#039;tar&amp;#039;&amp;#039; to &amp;#039;&amp;#039;c&amp;#039;&amp;#039;reate a g&amp;#039;&amp;#039;z&amp;#039;&amp;#039;ipped archive, and be sure to &amp;#039;&amp;#039;p&amp;#039;&amp;#039;reserve permissions:
  
- The final results should be something like:
- &amp;lt;code&amp;gt;
- -rw-r--r--  1 root  root  213M 2026-07-26 14:23 debian-rootfs.tar.gz
+ &amp;lt;code bash&amp;gt;
+ sudo tar czpf debian-rootfs.tar.gz -C debian-rootfs/ .
  &amp;lt;/code&amp;gt;
  
  Note: each time you chroot and install / modify your rootfs on your local machine, make sure to rebuild the &amp;#039;&amp;#039;tar.gz&amp;#039;&amp;#039; archive!
  

&lt;/pre&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=ass%3Alabs-2025%3A04%3Adeb-rauc-lab-skel-2026.tar.gz&amp;ns=ass%3Alabs-2025%3A04&amp;rev=1784202057&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-16T14:40:57+03:00</dc:date>
        <dc:creator>florin.stancu</dc:creator>
        <title>ass:labs-2025:04:deb-rauc-lab-skel-2026.tar.gz - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=ass%3Alabs-2025%3A04%3Adeb-rauc-lab-skel-2026.tar.gz&amp;ns=ass%3Alabs-2025%3A04&amp;rev=1784202057&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description></description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Apupper_viz.tar.gz&amp;ns=rasb%3Alab&amp;rev=1783110861&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-03T23:34:21+03:00</dc:date>
        <dc:creator>andrei.batasev</dc:creator>
        <title>rasb:lab:pupper_viz.tar.gz - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Apupper_viz.tar.gz&amp;ns=rasb%3Alab&amp;rev=1783110861&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description></description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Abase_back_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782916568&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-01T17:36:08+03:00</dc:date>
        <dc:creator>andrei.batasev</dc:creator>
        <title>rasb:lab:base_back_kinematics.png - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Abase_back_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782916568&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;table&gt;&lt;tr&gt;&lt;th width=&quot;50%&quot;&gt;&lt;/th&gt;&lt;th width=&quot;50%&quot;&gt;current&lt;/th&gt;&lt;/tr&gt;&lt;tr align=&quot;center&quot;&gt;&lt;td&gt;&lt;img src=&quot;&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;td&gt;&lt;img src=&quot;/courses/_media/rasb/lab/base_back_kinematics.png?w=300&amp;h=221t=1782916568&amp;amp;tok=194ec7&quot; alt=&quot;rasb:lab:base_back_kinematics.png&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al3_ee_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-01T17:25:21+03:00</dc:date>
        <dc:creator>andrei.batasev</dc:creator>
        <title>rasb:lab:l3_ee_kinematics.png - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al3_ee_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;table&gt;&lt;tr&gt;&lt;th width=&quot;50%&quot;&gt;&lt;/th&gt;&lt;th width=&quot;50%&quot;&gt;current&lt;/th&gt;&lt;/tr&gt;&lt;tr align=&quot;center&quot;&gt;&lt;td&gt;&lt;img src=&quot;&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;td&gt;&lt;img src=&quot;/courses/_media/rasb/lab/l3_ee_kinematics.png?w=300&amp;h=236t=1782915921&amp;amp;tok=081190&quot; alt=&quot;rasb:lab:l3_ee_kinematics.png&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al2_l3_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-01T17:25:21+03:00</dc:date>
        <dc:creator>andrei.batasev</dc:creator>
        <title>rasb:lab:l2_l3_kinematics.png - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al2_l3_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;table&gt;&lt;tr&gt;&lt;th width=&quot;50%&quot;&gt;&lt;/th&gt;&lt;th width=&quot;50%&quot;&gt;current&lt;/th&gt;&lt;/tr&gt;&lt;tr align=&quot;center&quot;&gt;&lt;td&gt;&lt;img src=&quot;&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;td&gt;&lt;img src=&quot;/courses/_media/rasb/lab/l2_l3_kinematics.png?w=300&amp;h=235t=1782915921&amp;amp;tok=5e9221&quot; alt=&quot;rasb:lab:l2_l3_kinematics.png&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al1_l2_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-01T17:25:21+03:00</dc:date>
        <dc:creator>andrei.batasev</dc:creator>
        <title>rasb:lab:l1_l2_kinematics.png - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Al1_l2_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;table&gt;&lt;tr&gt;&lt;th width=&quot;50%&quot;&gt;&lt;/th&gt;&lt;th width=&quot;50%&quot;&gt;current&lt;/th&gt;&lt;/tr&gt;&lt;tr align=&quot;center&quot;&gt;&lt;td&gt;&lt;img src=&quot;&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;td&gt;&lt;img src=&quot;/courses/_media/rasb/lab/l1_l2_kinematics.png?w=300&amp;h=237t=1782915921&amp;amp;tok=1b4541&quot; alt=&quot;rasb:lab:l1_l2_kinematics.png&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Abase_l1_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-07-01T17:25:21+03:00</dc:date>
        <dc:creator>andrei.batasev</dc:creator>
        <title>rasb:lab:base_l1_kinematics.png - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Abase_l1_kinematics.png&amp;ns=rasb%3Alab&amp;rev=1782915921&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;table&gt;&lt;tr&gt;&lt;th width=&quot;50%&quot;&gt;&lt;/th&gt;&lt;th width=&quot;50%&quot;&gt;current&lt;/th&gt;&lt;/tr&gt;&lt;tr align=&quot;center&quot;&gt;&lt;td&gt;&lt;img src=&quot;&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;td&gt;&lt;img src=&quot;/courses/_media/rasb/lab/base_l1_kinematics.png?w=300&amp;h=238t=1782915921&amp;amp;tok=178327&quot; alt=&quot;rasb:lab:base_l1_kinematics.png&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Ap_control.png&amp;ns=rasb%3Alab&amp;rev=1782625962&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-28T08:52:42+03:00</dc:date>
        <dc:creator>jan.vaduva</dc:creator>
        <title>rasb:lab:p_control.png - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Ap_control.png&amp;ns=rasb%3Alab&amp;rev=1782625962&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;table&gt;&lt;tr&gt;&lt;th width=&quot;50%&quot;&gt;&lt;/th&gt;&lt;th width=&quot;50%&quot;&gt;current&lt;/th&gt;&lt;/tr&gt;&lt;tr align=&quot;center&quot;&gt;&lt;td&gt;&lt;img src=&quot;&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;td&gt;&lt;img src=&quot;/courses/_media/rasb/lab/p_control.png?w=300&amp;h=51t=1782625962&amp;amp;tok=41ebee&quot; alt=&quot;rasb:lab:p_control.png&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Apid_eqn.png&amp;ns=rasb%3Alab&amp;rev=1782625907&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-28T08:51:47+03:00</dc:date>
        <dc:creator>jan.vaduva</dc:creator>
        <title>rasb:lab:pid_eqn.png - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Apid_eqn.png&amp;ns=rasb%3Alab&amp;rev=1782625907&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description>&lt;table&gt;&lt;tr&gt;&lt;th width=&quot;50%&quot;&gt;&lt;/th&gt;&lt;th width=&quot;50%&quot;&gt;current&lt;/th&gt;&lt;/tr&gt;&lt;tr align=&quot;center&quot;&gt;&lt;td&gt;&lt;img src=&quot;&quot; alt=&quot;&quot; /&gt;&lt;/td&gt;&lt;td&gt;&lt;img src=&quot;/courses/_media/rasb/lab/pid_eqn.png?w=300&amp;h=24t=1782625907&amp;amp;tok=99009b&quot; alt=&quot;rasb:lab:pid_eqn.png&quot; /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Anxpcar-lab.zip&amp;ns=rasb%3Alab&amp;rev=1782478029&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-26T15:47:09+03:00</dc:date>
        <dc:creator>rares.sarmasag</dc:creator>
        <title>rasb:lab:nxpcar-lab.zip - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Anxpcar-lab.zip&amp;ns=rasb%3Alab&amp;rev=1782478029&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description></description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Alab1_skel.zip&amp;ns=rasb%3Alab&amp;rev=1782139694&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-22T17:48:14+03:00</dc:date>
        <dc:creator>ciprian.popescu0411</dc:creator>
        <title>rasb:lab:lab1_skel.zip - created</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Alab1_skel.zip&amp;ns=rasb%3Alab&amp;rev=1782139694&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description></description>
    </item>
    <item rdf:about="http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Allm_lab.zip&amp;ns=rasb%3Alab&amp;rev=1781871010&amp;tab_details=history&amp;mediado=diff&amp;do=media">
        <dc:format>text/html</dc:format>
        <dc:date>2026-06-19T15:10:10+03:00</dc:date>
        <dc:creator>vlad.radulescu2901</dc:creator>
        <title>rasb:lab:llm_lab.zip</title>
        <link>http://ocw.cs.pub.ro/courses/?image=rasb%3Alab%3Allm_lab.zip&amp;ns=rasb%3Alab&amp;rev=1781871010&amp;tab_details=history&amp;mediado=diff&amp;do=media</link>
        <description></description>
    </item>
</rdf:RDF>
