This shows you the differences between two versions of the page.
|
ass:labs-2025:05:tasks:02 [2025/08/07 22:18] florin.stancu created |
ass:labs-2025:05:tasks:02 [2026/07/17 10:11] (current) florin.stancu |
||
|---|---|---|---|
| Line 21: | Line 21: | ||
| make ARCH=... dtbs | make ARCH=... dtbs | ||
| </code> | </code> | ||
| - | |||
| - | Afterwards, you need to copy the new ''.dtb'' into your ''staging/'' directory and [[:ass:labs-2025:02:tasks:01#task_d_-_fit_image|re-build the Linux FIT]] (e.g., ''linux.itb''). And upload it to your emmc (check out the ''ums'' trick described below!). | ||
| </note> | </note> | ||
| + | |||
| + | Afterwards, you need to copy the new ''.dtb'' into your ''staging/'' directory and re-build the Linux uImage (using the previously provided ''staging/Makefile''). | ||
| + | |||
| + | As for the userspace (rootfs), there are two choices: either **Debian** or **Buildroot** (disable RAUC nevertheless and use the first version of ''mk-disk-image.sh'' to upload the rootfs when ready to test, towards the end of the task). | ||
| + | |||
| + | For Buildroot, you must use ''menuconfig'' and enable ''PACKAGE_OPTEE_CLIENT''! Built it & unpack it to the secondary ext4 disk partition (just edit the mk-disk-image script). | ||
| + | |||
| + | For Debian, you can either cross compile the OP-TEE client or try out the ''optee-client'' package from APT (use a ''chroot'' to install from host). | ||
| == Step 6. Building a TA == | == Step 6. Building a TA == | ||
| Line 31: | Line 37: | ||
| Read the [[https://optee.readthedocs.io/en/latest/building/gits/optee_examples/optee_examples.html|official instructions here]]. | Read the [[https://optee.readthedocs.io/en/latest/building/gits/optee_examples/optee_examples.html|official instructions here]]. | ||
| - | <note> | + | Build both the host app and the Trusted Application need to be compiled TOGETHER with the TEE Client Library, and the OPTEE OS exported SDK, respectively. |
| - | Note that you must build [[https://optee.readthedocs.io/en/latest/building/gits/optee_client.html#build-instructions|the optee_client first]]. Note that CMake needs to receive the path to CROSS_COMPILEr's gcc via specific define (argument). | + | |
| - | Also set the ''-DCMAKE_INSTALL_PREFIX=...'' cmake flag to some dir in your project's working root directory and run ''make install'' at the end to copy the final product there. It will be required to specify its path (see below). | + | Make sure to read the examples documentation to see the make variables to set! |
| - | </note> | + | |
| - | <note> | + | <spoiler Special Instructions for Buildroot> |
| - | Build both the host app and the TA need to be compiled TOGETHER with the TEE Client Library, and the OPTEE OS exported SDK, respectively. | + | Note that, usually, you must build optee-client from source on the host machine [[https://optee.readthedocs.io/en/latest/building/gits/optee_client.html#build-instructions|the optee_client first]]. . |
| - | Make sure to read the examples documentation to see the make variables to set! | + | Since you're using Buildroot, you can find it already compiled for the target system at ''<buildroot-dir>/output/build/optee-client-<version>''. |
| + | |||
| + | Touugh we need to give a ''TEEC_EXPORT'' install path when invoking the TA makefile... Use find for ''tee_client_api.h'' and see where it's found (hint: ''sysroot'')! | ||
| + | |||
| + | Also note that for building Buildroot-targeted applications, your classic ''aarch64-none-gnu-'' toolchain **won't work** since Buildroot uses a custom LibC by default. But, fortunately, you may find the cross compilation prefix at ''<buildroot-dir>/output/host/bin/aarch64-buildroot-linux-gnu-'' (see the difference?)! | ||
| + | </spoiler> | ||
| + | |||
| + | <note> | ||
| + | As for ''TA_DEV_KIT_DIR'' of a Trusted Application, it must point to an SDK generated inside BL32 (optee_os) source directory (something like ''export-ta...'''. | ||
| </note> | </note> | ||
| Line 66: | Line 78: | ||
| </code> | </code> | ||
| - | Do not Ctrl+C yet, leave it running and mount the newly appeared USB device in your PC/VM! | + | Use ''lsblk'' to find out which is the second (ext4) partition, mount it and copy the TA files: |
| + | <code bash> | ||
| + | mount /dev/sda2 /mnt | ||
| + | ls -l /mnt | ||
| + | # copy them inside your home | ||
| + | cp $OPTEE_FILES /mnt/root/ | ||
| + | </code> | ||
| - | After copying the files, boot the Linux package (you can use the Lab02 boot commands, see Readme.md). | + | After copying the files, boot Linux. |
| + | |||
| + | On buildroot, check if ''tee-supplicant'' is running... or start it: | ||
| + | <code bash> | ||
| + | ps aux | grep tee-supplicant | ||
| + | tee-supplicant -d | ||
| + | </code> | ||
| - | Mount the boot partition and run the TA (you might need to copy it somewhere else and ''chmod +x'')! | + | Then execute the trusted application ;) |
| - | Then execute the program ;) | + | |
| <note info> | <note info> | ||
| Observe the error: OP-TEE cannot find the ''.ta'' file inside a trusted memory or REE. | Observe the error: OP-TEE cannot find the ''.ta'' file inside a trusted memory or REE. | ||
| - | For this, you will need to copy the signed ''<UUID>.ta'' file to ''/lib/optee_armtz/'', as (very badly) documented. | + | For this, you will need to copy the signed ''<UUID>.ta'' file to ''/lib/optee_armtz/'' (create it if it doesn't exist), as (very badly) documented. |
| </note> | </note> | ||