Skip to content

Share the isolation level 3 layer across AArch64 ports instead of per board #66

Description

@aidangarske

Context

The Armv8-M level 3 layer is moving to port/common/armv8m so a new Cortex-M port gets level 3 without rewriting it. AArch64 needs the same: the band layout, SPMC linker placement, S-EL0 partition bands and level 3 platform hooks must live once in port/common/aarch64, not per board in port/qemuvirt and port/versal.

Origin

#46, #29, the shared Armv8-M level 3 layer

What is needed

  • A shared AArch64 level 3 layout header, platform file and linker fragment in port/common/aarch64; each board supplies only base addresses and its attribution backend
  • The Split the AArch64 keystore band so vault, crypto and attestation meet isolation level 3 #43 keystore band split built on the shared layer rather than per board
  • A level 3 required-scenario set for the QEMU runner that fails a port missing one
  • An AArch64 section in the docs/Porting.md isolation level 3 guide

Blockers and dependencies

#29 merges first. #43 should land on this layer.

Acceptance criteria

  • qemuvirt and versal-virt build level 3 from the shared layer with no per-board duplication of bands, hooks or linker sections
  • QEMU level 3 negatives pass on both engines
  • confboot 85/4/0 and positive on virt with both engines

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1High: blocks a claim, release, or port milestone; next uptodoDeferred work tracked for later

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions