⚠️ The code is based on: https://gitlab.com/riseproject/riscv-optee/optee_os/-/tree/dev-optee-mpxy
Commit ID:
75df9ba41a404aec897399ead0ff0aebcbff48ca
ldelf_hex.cis generated byscripts/gen_ldelf_hex.pyfrom the input file:ldelf.elfand is included by OP-TEE, i.e.ldelf_data[],ldelf_code_size,ldelf_data_size, andldelf_entry.ldelfsources:<optee-src>/ldelf/ldelfis running in U-mode.
| |
| |
scall_handle_ldelf()- Handle syscall according to
ldelf_syscall_table:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21// core/kernel/syscall.c /* * The ldelf return, log, panic syscalls have the same functionality and syscall * number as the user TAs'. To avoid unnecessary code duplication, the ldelf SVC * handler doesn't implement separate functions for these. */ static const struct syscall_entry ldelf_syscall_table[] = { SYSCALL_ENTRY(syscall_sys_return), SYSCALL_ENTRY(syscall_log), SYSCALL_ENTRY(syscall_panic), SYSCALL_ENTRY(ldelf_syscall_map_zi), SYSCALL_ENTRY(ldelf_syscall_unmap), SYSCALL_ENTRY(ldelf_syscall_open_bin), SYSCALL_ENTRY(ldelf_syscall_close_bin), SYSCALL_ENTRY(ldelf_syscall_map_bin), SYSCALL_ENTRY(ldelf_syscall_copy_from_bin), SYSCALL_ENTRY(ldelf_syscall_set_prot), SYSCALL_ENTRY(ldelf_syscall_remap), SYSCALL_ENTRY(ldelf_syscall_gen_rnd_num), };- Handle syscall according to
_ldelf_start()ldelf()ta_elf_load_main()load_main()init_elf()sys_open_ta_bin()_ldelf_open_bin()- Issue
LDELF_OPEN_BINsyscall, which will eventually callldelf_syscall_open_bin()
- Issue
_ldelf_return()- Issue
LDELF_RETURNsyscall, which will eventually callsyscall_sys_return()
- Issue
-
ldelf_syscall_open_bin()If the session is for user TAs, look up user TA ELF by UUID. Currently, there are three ways (TA storages) to load user TA in OP-TEE:
- Early TA
- REE filesystem TA
- REE-FS TA rollback protection
- Each TA storage is registered by
REGISTER_TA_STORE()and is stored intota_storesscattered array in the priority order, e.g.Early TA:
Secure Storage TA:
Iterates each TA storage, call their
op->open()callback, e.g.ree_fs_ta_open().- Each TA storage’s
op->open()is responsible for comparing UUID (either by itself or through thread RPC) to determine whether user TA for UUID can be found or not.- Returns
TEE_ERROR_ITEM_NOT_FOUNDif user TA for UUID cannot be found.
- Returns
- Each TA storage’s