Context
xlnx-versal-virt in QEMU (checked on 11.0.2) models no XMPU or XPPU, so the Versal port declares isolation_profile 0 and the Arm FF-M suite shows the 7 Normal-world fence tests failing there. A real fence needs silicon.
Origin
PR #29; docs/Porting.md and docs/FF-A-Compatibility.md (versal-virt has no Normal-world fence model)
What is needed
- Bring wolfTrust up on a Versal board (VMK180 or VCK190) booted by wolfBoot
- Program and lock XMPU regions over DDR and OCM for the SPMC and partition bands, and XPPU for Secure peripherals, before the Normal world starts
- Set WT_PORT_NS_MEMORY_FENCE and a real isolation_profile only once the fence is active and locked
- Normal-world probes that read and write Secure memory and must fault
- A hardware runner in tests/target beside the existing runners
Blockers and dependencies
A Versal board attached to the test host.
Acceptance criteria
- Normal-world probes fault on silicon for every Secure band
- Arm FF-M IPC suite 85/4/0 on the board
- positive and confboot pass on silicon with both engines
Context
xlnx-versal-virt in QEMU (checked on 11.0.2) models no XMPU or XPPU, so the Versal port declares isolation_profile 0 and the Arm FF-M suite shows the 7 Normal-world fence tests failing there. A real fence needs silicon.
Origin
PR #29; docs/Porting.md and docs/FF-A-Compatibility.md (versal-virt has no Normal-world fence model)
What is needed
Blockers and dependencies
A Versal board attached to the test host.
Acceptance criteria