Differences

This shows you the differences between two versions of the page.

Link to this comparison view

ass:labs-2025:05:tasks:02 [2025/08/08 09:55]
florin.stancu
ass:labs-2025:05:tasks:02 [2026/07/17 10:11] (current)
florin.stancu
Line 23: Line 23:
 </​note>​ </​note>​
  
-Ohand re-enable **Buildroot** if disabled for the previous lab (you backed up your ITS file, hopefully). +Afterwards, you need to copy the new ''​.dtb'' ​into your ''​staging/''​ directory ​and re-build the Linux uImage (using the previously provided ​''​staging/​Makefile''​).
-Then enter its ''​menuconfig''​ and search for ''​PACKAGE_OPTEE_CLIENT''​. ​Enable it and rebuild your rootfs!+
  
-Afterwardsyou need to copy the new ''​.dtb'' ​into your ''​staging/'' ​directory ​and [[:​ass:​labs-2025:​02:​tasks:​01#​task_d_-_fit_image|re-build ​the Linux FIT]] (e.g., ''​linux.itb''​). And upload it to your emmc (use u-boot'''​ums'' and simply copy the file on the FAT32 boot partition).+As for the userspace (rootfs)there are two choices: either **Debian** or **Buildroot** (disable RAUC nevertheless and use the first version of ''​mk-disk-image.sh'' ​to upload the rootfs when ready to test, towards the end of the task). 
 + 
 +For Buildroot, you must use ''​menuconfig''​ and enable ''​PACKAGE_OPTEE_CLIENT''​! Built it & unpack it to the secondary ext4 disk partition ​(just edit the mk-disk-image script). 
 + 
 +For Debianyou can either cross compile the OP-TEE client or try out the ''​optee-client'' ​package from APT (use ''​chroot'' ​to install from host).
  
 == Step 6. Building a TA == == Step 6. Building a TA ==
Line 34: Line 37:
 Read the [[https://​optee.readthedocs.io/​en/​latest/​building/​gits/​optee_examples/​optee_examples.html|official instructions here]]. Read the [[https://​optee.readthedocs.io/​en/​latest/​building/​gits/​optee_examples/​optee_examples.html|official instructions here]].
  
-Build both the host app and the TA need to be compiled TOGETHER with the TEE Client Library, and the OPTEE OS exported SDK, respectively.+Build both the host app and the Trusted Application ​need to be compiled TOGETHER with the TEE Client Library, and the OPTEE OS exported SDK, respectively.
  
 Make sure to read the examples documentation to see the make variables to set! Make sure to read the examples documentation to see the make variables to set!
  
-<note+<spoiler Special Instructions for Buildroot
-Note that, usually, you must must optee-client from source on the host machine [[https://​optee.readthedocs.io/​en/​latest/​building/​gits/​optee_client.html#​build-instructions|the optee_client first]]. .+Note that, usually, you must build optee-client from source on the host machine [[https://​optee.readthedocs.io/​en/​latest/​building/​gits/​optee_client.html#​build-instructions|the optee_client first]]. .
  
-But, since we're using Buildroot ​and have enabled it, you can find it already compiled for the target system at ''<​buildroot-dir>/​output/​build/​optee-client-<​version>''​.+Since you're using Buildroot, you can find it already compiled for the target system at ''<​buildroot-dir>/​output/​build/​optee-client-<​version>''​.
  
-Touugh we need to give a ''​TEEC_EXPORT''​ path when invoking the TA makefile... Use find for ''​tee_client_api.h''​ and see where it's found (hint: ''​sysroot''​)+Touugh we need to give a ''​TEEC_EXPORT'' ​install ​path when invoking the TA makefile... Use find for ''​tee_client_api.h''​ and see where it's found (hint: ''​sysroot''​)!
-</​note>​+
  
-Also note that for building Buildroot-targeted applications,​ your classic ''​aarch64-none-gnu-''​ toolchain **won'​t work** since Buildroot uses custom ​[[https://​www.uclibc.org/​|ucLibC]] ​by default. But, fortunately,​ you may find the cross compilation prefix at ''<​buildroot-dir>/​output/​host/​bin/​aarch64-buildroot-linux-gnu-''​ (see the difference?​)!+Also note that for building Buildroot-targeted applications,​ your classic ''​aarch64-none-gnu-''​ toolchain **won'​t work** since Buildroot uses custom ​LibC by default. But, fortunately,​ you may find the cross compilation prefix at ''<​buildroot-dir>/​output/​host/​bin/​aarch64-buildroot-linux-gnu-''​ (see the difference?​)! 
 +</​spoiler>​ 
 + 
 +<​note>​ 
 +As for ''​TA_DEV_KIT_DIR''​ of a Trusted Application,​ it must point to an SDK generated inside BL32 (optee_os) source directory (something like ''​export-ta...'''​. 
 +</​note>​
  
 == Step 7. Signing the TA == == Step 7. Signing the TA ==
Line 71: Line 78:
 </​code>​ </​code>​
  
-Do not Ctrl+C yetleave it running ​and mount the newly appeared USB device in your PC/VM!+Use ''​lsblk''​ to find out which is the second (ext4) partitionmount it and copy the TA files: 
 +<code bash> 
 +mount /dev/sda2 /mnt 
 +ls -l /mnt 
 +# copy them inside ​your home 
 +cp $OPTEE_FILES /​mnt/​root/​ 
 +</code>
  
-After copying the files, boot the Linux package (you can use the Lab02 boot commandssee Readme.md).+After copying the files, boot Linux
 + 
 +On buildrootcheck if ''​tee-supplicant''​ is running... or start it: 
 +<code bash> 
 +ps aux | grep tee-supplicant 
 +tee-supplicant -d 
 +</​code>​
  
-Mount the boot partition and run the TA (you might need to copy it somewhere else and ''​chmod +x''​)! +Then execute the trusted application ​;) 
-Then execute the program ​;) +
  
 <note info> <note info>
 Observe the error: OP-TEE cannot find the ''​.ta''​ file inside a trusted memory or REE. Observe the error: OP-TEE cannot find the ''​.ta''​ file inside a trusted memory or REE.
  
-For this, you will need to copy the signed ''<​UUID>​.ta''​ file to ''/​lib/​optee_armtz/'',​ as (very badly) documented.+For this, you will need to copy the signed ''<​UUID>​.ta''​ file to ''/​lib/​optee_armtz/'' ​(create it if it doesn'​t exist), as (very badly) documented.
 </​note>​ </​note>​
  
  
ass/labs-2025/05/tasks/02.1754636155.txt.gz · Last modified: 2025/08/08 09:55 by florin.stancu
CC Attribution-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0