This shows you the differences between two versions of the page.
|
ass:labs-2025:05:tasks:02 [2025/08/08 10:01] florin.stancu |
ass:labs-2025:05:tasks:02 [2026/07/17 10:11] (current) florin.stancu |
||
|---|---|---|---|
| Line 23: | Line 23: | ||
| </note> | </note> | ||
| - | Oh, and re-enable **Buildroot** if disabled for the previous lab (you backed up your ITS file, hopefully). | + | Afterwards, you need to copy the new ''.dtb'' into your ''staging/'' directory and re-build the Linux uImage (using the previously provided ''staging/Makefile''). |
| - | Then enter its ''menuconfig'' and search for ''PACKAGE_OPTEE_CLIENT''. Enable it and rebuild your rootfs! | + | |
| - | Afterwards, you need to copy the new ''.dtb'' into your ''staging/'' directory and [[:ass:labs-2025:02:tasks:01#task_d_-_fit_image|re-build the Linux FIT]] (e.g., ''linux.itb''). And upload it to your emmc (use u-boot's ''ums'' and simply copy the file on the FAT32 boot partition). | + | As for the userspace (rootfs), there are two choices: either **Debian** or **Buildroot** (disable RAUC nevertheless and use the first version of ''mk-disk-image.sh'' to upload the rootfs when ready to test, towards the end of the task). |
| + | |||
| + | For Buildroot, you must use ''menuconfig'' and enable ''PACKAGE_OPTEE_CLIENT''! Built it & unpack it to the secondary ext4 disk partition (just edit the mk-disk-image script). | ||
| + | |||
| + | For Debian, you can either cross compile the OP-TEE client or try out the ''optee-client'' package from APT (use a ''chroot'' to install from host). | ||
| == Step 6. Building a TA == | == Step 6. Building a TA == | ||
| Line 38: | Line 41: | ||
| Make sure to read the examples documentation to see the make variables to set! | Make sure to read the examples documentation to see the make variables to set! | ||
| - | <note> | + | <spoiler Special Instructions for Buildroot> |
| Note that, usually, you must build optee-client from source on the host machine [[https://optee.readthedocs.io/en/latest/building/gits/optee_client.html#build-instructions|the optee_client first]]. . | Note that, usually, you must build optee-client from source on the host machine [[https://optee.readthedocs.io/en/latest/building/gits/optee_client.html#build-instructions|the optee_client first]]. . | ||
| - | But, since we're using Buildroot and have enabled it, you can find it already compiled for the target system at ''<buildroot-dir>/output/build/optee-client-<version>''. | + | Since you're using Buildroot, you can find it already compiled for the target system at ''<buildroot-dir>/output/build/optee-client-<version>''. |
| Touugh we need to give a ''TEEC_EXPORT'' install path when invoking the TA makefile... Use find for ''tee_client_api.h'' and see where it's found (hint: ''sysroot'')! | Touugh we need to give a ''TEEC_EXPORT'' install path when invoking the TA makefile... Use find for ''tee_client_api.h'' and see where it's found (hint: ''sysroot'')! | ||
| - | </note> | + | |
| + | Also note that for building Buildroot-targeted applications, your classic ''aarch64-none-gnu-'' toolchain **won't work** since Buildroot uses a custom LibC by default. But, fortunately, you may find the cross compilation prefix at ''<buildroot-dir>/output/host/bin/aarch64-buildroot-linux-gnu-'' (see the difference?)! | ||
| + | </spoiler> | ||
| <note> | <note> | ||
| - | As for ''TA_DEV_KIT_DIR'' of a Trusted Application, it must point to your BL32 (optee_os) source directory (you may optionally export it as portable SDK by invoking a special ''make'' target and store it somewhere else, but it is laborious). | + | As for ''TA_DEV_KIT_DIR'' of a Trusted Application, it must point to an SDK generated inside BL32 (optee_os) source directory (something like ''export-ta...'''. |
| </note> | </note> | ||
| - | |||
| - | Also note that for building Buildroot-targeted applications, your classic ''aarch64-none-gnu-'' toolchain **won't work** since Buildroot uses custom [[https://www.uclibc.org/|ucLibC]] by default. But, fortunately, you may find the cross compilation prefix at ''<buildroot-dir>/output/host/bin/aarch64-buildroot-linux-gnu-'' (see the difference?)! | ||
| == Step 7. Signing the TA == | == Step 7. Signing the TA == | ||
| Line 75: | Line 78: | ||
| </code> | </code> | ||
| - | Do not Ctrl+C yet, leave it running and mount the newly appeared USB device in your PC/VM! | + | Use ''lsblk'' to find out which is the second (ext4) partition, mount it and copy the TA files: |
| + | <code bash> | ||
| + | mount /dev/sda2 /mnt | ||
| + | ls -l /mnt | ||
| + | # copy them inside your home | ||
| + | cp $OPTEE_FILES /mnt/root/ | ||
| + | </code> | ||
| - | After copying the files, boot the Linux package (you can use the Lab02 boot commands, see Readme.md). | + | After copying the files, boot Linux. |
| + | |||
| + | On buildroot, check if ''tee-supplicant'' is running... or start it: | ||
| + | <code bash> | ||
| + | ps aux | grep tee-supplicant | ||
| + | tee-supplicant -d | ||
| + | </code> | ||
| - | Mount the boot partition and run the TA (you might need to copy it somewhere else and ''chmod +x'')! | + | Then execute the trusted application ;) |
| - | Then execute the program ;) | + | |
| <note info> | <note info> | ||
| Observe the error: OP-TEE cannot find the ''.ta'' file inside a trusted memory or REE. | Observe the error: OP-TEE cannot find the ''.ta'' file inside a trusted memory or REE. | ||
| - | For this, you will need to copy the signed ''<UUID>.ta'' file to ''/lib/optee_armtz/'', as (very badly) documented. | + | For this, you will need to copy the signed ''<UUID>.ta'' file to ''/lib/optee_armtz/'' (create it if it doesn't exist), as (very badly) documented. |
| </note> | </note> | ||