diff mbox series

[1/3] arm/trusted-firmware-m: add TF-M 2.3 signing support

Message ID 20260923095314.382668-2-ahmed.gomaa@arm.com
State New
Headers show
Series corstone1000: bump Trusted Firmware-M to 2.3.0 | expand

Commit Message

Ahmed Gomaa Sept. 23, 2026, 9:53 a.m. UTC
TF-M 2.3 packages its image-signing wrapper as the
mcuboot_imagesign_wrapper console command. Add the required native
Python runtime dependencies and install the bundled MCUboot PEM
signing keys in the native sysroot.

Install TF-M's patched MCUboot imgtool package, including its
imgtool.keys Python modules for loading and handling cryptographic
keys. These modules are part of the signing tool implementation,
separate from the PEM signing-key files installed above.

Prefer this patched package through PYTHONPATH because it supports
PSA key IDs and writes them into signed image metadata.

Update tfm_sign_image.bbclass to invoke the console command when
available, retaining wrapper.py as a fallback for older TF-M versions.
Add optional PSA key ID arguments so platforms can provide the
identifier expected by BL2 during image verification.

Signed-off-by: Ahmed Gomaa <ahmed.gomaa@arm.com>
---
 meta-arm/classes/tfm_sign_image.bbclass       | 18 +++++++++++++++-
 ...trusted-firmware-m-scripts-native_2.3.0.bb | 21 +++++++++++++++++++
 2 files changed, 38 insertions(+), 1 deletion(-)
diff mbox series

Patch

diff --git a/meta-arm/classes/tfm_sign_image.bbclass b/meta-arm/classes/tfm_sign_image.bbclass
index f7900bb0..adc919a1 100644
--- a/meta-arm/classes/tfm_sign_image.bbclass
+++ b/meta-arm/classes/tfm_sign_image.bbclass
@@ -17,6 +17,11 @@  TFM_IMAGE_SIGN_DEPLOY_DIR = "${WORKDIR}/deploy-tfm-signed-images"
 # version by default
 RE_WRAPPER_SECURITY_COUNTER ?= "auto"
 
+# Optional PSA key IDs to add to the signed image. Multiple IDs may be
+# provided as a space-separated list.
+TFM_IMAGE_SIGN_PSA_KEY_IDS ?= ""
+TFM_IMAGE_SIGN_PSA_KEY_ID_ARGS = "${@' '.join(['--psa-key-ids %s' % key_id for key_id in d.getVar('TFM_IMAGE_SIGN_PSA_KEY_IDS').split()])}"
+
 SSTATETASKS += "do_sign_images"
 do_sign_images[sstate-inputdirs] = "${TFM_IMAGE_SIGN_DEPLOY_DIR}"
 do_sign_images[sstate-outputdirs] = "${DEPLOY_DIR_IMAGE}"
@@ -47,6 +52,7 @@  TFM_IMAGE_SIGN_ARGS ?= "\
     -s ${RE_WRAPPER_SECURITY_COUNTER} \
     --layout "${TFM_IMAGE_SIGN_DIR}/${host_binary_layout}" \
     --public-key-format full \
+    ${TFM_IMAGE_SIGN_PSA_KEY_ID_ARGS} \
     --align 1 \
     --pad \
     --pad-header \
@@ -86,7 +92,17 @@  EOF
 
     host_binary_signed="${TFM_IMAGE_SIGN_DEPLOY_DIR}/signed_$(basename "${1}")"
 
-    ${PYTHON} "${STAGING_LIBDIR_NATIVE}/tfm-scripts/wrapper/wrapper.py" \
+    # TF-M 2.3 installs the wrapper as a console script. Older releases use
+    # the Python script under tfm-scripts, so retain that as a fallback.
+    if [ -x "${STAGING_BINDIR_NATIVE}/mcuboot_imagesign_wrapper" ]; then
+        tfm_sign_wrapper="${STAGING_BINDIR_NATIVE}/mcuboot_imagesign_wrapper"
+    else
+        tfm_sign_wrapper="${PYTHON} ${STAGING_LIBDIR_NATIVE}/tfm-scripts/wrapper/wrapper.py"
+    fi
+
+    # TF-M's patched imgtool contains IMAGE_TLV_KEYID support required to add
+    # PSA key IDs to image metadata; prefer it over python3-imgtool-native.
+    PYTHONPATH="${STAGING_LIBDIR_NATIVE}/tfm-scripts" ${tfm_sign_wrapper} \
             ${TFM_IMAGE_SIGN_ARGS} \
             -k  "${signing_key_path}" \
             "${1}" \
diff --git a/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m-scripts-native_2.3.0.bb b/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m-scripts-native_2.3.0.bb
index b5220934..d1fa266f 100644
--- a/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m-scripts-native_2.3.0.bb
+++ b/meta-arm/recipes-bsp/trusted-firmware-m/trusted-firmware-m-scripts-native_2.3.0.bb
@@ -3,7 +3,28 @@  require recipes-bsp/trusted-firmware-m/trusted-firmware-m-${PV}-src.inc
 inherit native python_setuptools_build_meta
 
 RDEPENDS:${PN} = "\
+    python3-cryptography-native \
+    python3-pyasn1-native \
+    python3-pyyaml-native \
+    python3-cbor2-native \
+    python3-imgtool-native \
+    python3-click-native \
     python3-pyelftools-native \
     python3-rich-native \
     clang-native \
 "
+
+do_install:append() {
+    install -d ${D}${libdir}/tfm-scripts
+    install -m 0644 ${S}/bl2/ext/mcuboot/*.pem ${D}${libdir}/tfm-scripts/
+
+    # TF-M applies additional patches to its bundled MCUboot imgtool. Install
+    # that copy privately so the signing wrapper can emit TF-M-specific TLVs.
+    install -d ${D}${libdir}/tfm-scripts/imgtool/keys
+    install -m 0644 ${S}/external/mcuboot/scripts/imgtool/*.py \
+        ${D}${libdir}/tfm-scripts/imgtool/
+    install -m 0644 ${S}/external/mcuboot/scripts/imgtool/keys/*.py \
+        ${D}${libdir}/tfm-scripts/imgtool/keys/
+}
+
+FILES:${PN} += "${libdir}/tfm-scripts"