<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2-platforms.git/Platform/StandaloneMm, branch CodeCleanup</title>
<subtitle>EDK II sample platform branches and tags (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2-platforms.git/atom?h=CodeCleanup</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2-platforms.git/atom?h=CodeCleanup'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2-platforms.git/'/>
<updated>2022-05-19T03:46:19+00:00</updated>
<entry>
<title>PlatformStandaloneMmPkg: Add VariableFlashInfoLib</title>
<updated>2022-05-19T03:46:19+00:00</updated>
<author>
<name>Michael Kubacki</name>
<email>michael.kubacki@microsoft.com</email>
</author>
<published>2022-04-20T20:35:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2-platforms.git/commit/?id=5b9002e5f9119a832918c479071d18796349f3f1'/>
<id>urn:sha1:5b9002e5f9119a832918c479071d18796349f3f1</id>
<content type='text'>
REF:https://bugzilla.tianocore.org/show_bug.cgi?id=3479

Adds an instance for the library class VariableFlashInfoLib that
was recently introduced in MdeModulePkg. This change is made to
allow the new variable driver to build that has a dependency on
this library class and does not require any further platform
changes.

Cc: Sami Mujawar &lt;sami.mujawar@arm.com&gt;
Cc: Ilias Apalodimas &lt;ilias.apalodimas@linaro.org&gt;
Signed-off-by: Michael Kubacki &lt;michael.kubacki@microsoft.com&gt;
Reviewed-by: Michael D Kinney &lt;michael.d.kinney@intel.com&gt;
Reviewed-by: Sami Mujawar &lt;sami.mujawar@arm.com&gt;
Reviewed-by: Ilias Apalodimas &lt;ilias.apalodimas@linaro.org&gt;
Acked-by: Ard Biesheuvel &lt;ardb@kernel.org&gt;
</content>
</entry>
<entry>
<title>Platform/StandaloneMm: build StandaloneMmRpmb for 32bit architectures</title>
<updated>2021-08-11T11:44:10+00:00</updated>
<author>
<name>Etienne Carriere</name>
<email>etienne.carriere@linaro.org</email>
</author>
<published>2021-08-10T16:40:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2-platforms.git/commit/?id=70b67dc9ab89689f26ad5e68a5efeac509a12115'/>
<id>urn:sha1:70b67dc9ab89689f26ad5e68a5efeac509a12115</id>
<content type='text'>
Build PlatformStandaloneMmRpmb for ARM architecture (32bit arm machine).
The generated image targets an execution environment similar to AArch64
StMM secure partition in OP-TEE but in 32bit mode.

GCC flag -fno-stack-protector
added. The stack protection code bring
GOT dependencies we prefer avoid when StMM runs in OP-TEE.

Cc: Ard Biesheuvel &lt;ardb+tianocore@kernel.org&gt;
Cc: Ilias Apalodimas &lt;ilias.apalodimas@linaro.org&gt;
Cc: Leif Lindholm &lt;leif@nuviainc.com&gt;
Cc: Sami Mujawar &lt;sami.mujawar@arm.com&gt;
Signed-off-by: Etienne Carriere &lt;etienne.carriere@linaro.org&gt;
</content>
</entry>
<entry>
<title>Platform/StandaloneMm: sync with edk2 StandaloneMmCpu path change</title>
<updated>2021-08-11T11:44:10+00:00</updated>
<author>
<name>Etienne Carriere</name>
<email>etienne.carriere@linaro.org</email>
</author>
<published>2021-08-10T16:40:33+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2-platforms.git/commit/?id=646c444efe168ef998bd1e8c6dec0e6e806de064'/>
<id>urn:sha1:646c444efe168ef998bd1e8c6dec0e6e806de064</id>
<content type='text'>
Synchronize with edk2 package where StandaloneMmCpu component has moved
from StandaloneMmPkg/Drivers/StandaloneMmCpu/AArch64/StandaloneMmCpu.inf
to StandaloneMmPkg/Drivers/StandaloneMmCpu/StandaloneMmCpu.inf

Cc: Ard Biesheuvel &lt;ardb+tianocore@kernel.org&gt;
Cc: Ilias Apalodimas &lt;ilias.apalodimas@linaro.org&gt;
Cc: Leif Lindholm &lt;leif@nuviainc.com&gt;
Cc: Sami Mujawar &lt;sami.mujawar@arm.com&gt;
Cc: Sughosh Ganu &lt;sughosh.ganu@linaro.org&gt;
Cc: Thomas Abraham &lt;thomas.abraham@arm.com&gt;
Signed-off-by: Etienne Carriere &lt;etienne.carriere@linaro.org&gt;
</content>
</entry>
<entry>
<title>StMMRpmb: Add support for building StandaloneMm image for OP-TEE</title>
<updated>2021-03-28T09:46:35+00:00</updated>
<author>
<name>Ilias Apalodimas</name>
<email>ilias.apalodimas@linaro.org</email>
</author>
<published>2021-03-13T18:31:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2-platforms.git/commit/?id=bd5071cfbde01dbf6f8e23f72e594b8f7f90abd6'/>
<id>urn:sha1:bd5071cfbde01dbf6f8e23f72e594b8f7f90abd6</id>
<content type='text'>
With some recent changes in OP-TEE [1] and U-Boot [2] we can compile StMM
and launch it from an OP-TEE secure partition which is mimicking SPM.

There's a number of advantages in this approach. In Arm world SPM,
currently used for dispatching StMM, and SPD used for OP-TEE, are
mutually exclusive. Since there's no application in OP-TEE for managing
EFI variables, this means that one can have a secure OS or secure
variable storage.

By re-using StMM we have EDK2s approved application controlling
variable storage and the ability to run a secure world OS. This also
allows various firmware implementations to adopt EDK2 way of storing
variables (including the FTW implementation), as long as OP-TEE is
available on that given platform (or any other secure OS that can launch
StMM and has a supplicant for handling the RPMB partition).
Another advantage is that OP-TEE has the ability to access an eMMC RPMB
partition to store those variables. This requires a normal world
supplicant, which is implemented in U-Boot currently. The supplicant
picks up the encrypted buffer from OP-TEE and wires it to the eMMC
driver(s). Similar functionality can be added in EDK2 by porting the
supplicant and adapt it to using the native eMMC drivers.

There's is one drawback in using OP-TEE. The current SPM calls need to run
to completion. This contradicts the current OP-TEE RPC call requirements,
used to access the RPMB storage. Thats leads to two different SMC calls for
entering secure world to access StMM.

So let's add support for a platform that compiles StMM and an RPMB
driver that communicates with OP-TEE to read/write the variables.
For anyone interested in testing this there's repo that builds all the
sources and works on QEMU [3].

[1] https://github.com/OP-TEE/optee_os/pull/3973
[2] http://u-boot.10912.n7.nabble.com/PATCH-0-7-v4-EFI-variable-support-via-OP-TEE-td412499.html
[3] https://git.linaro.org/people/ilias.apalodimas/efi_optee_variables.git/

Reviewed-by: Sami Mujawar &lt;sami.mujawar@arm.com&gt;
Signed-off-by: Ilias Apalodimas &lt;ilias.apalodimas@linaro.org&gt;
</content>
</entry>
</feed>
