Realm Management Monitor
Unknown
Home
About
1. Readme for TF-RMM
1.1. License
1.1.1. Third Party Projects
1.2. Contributing
1.3. Feedback and support
2. Project Maintenance
2.1. Maintainers
3. Change-log and Release notes
3.1. v0.9.0
3.1.1. New features in this release
3.1.2. Bug fixes/improvements in this release
3.1.3. Build/Testing/Tooling improvements
3.1.4. Platforms
3.1.5. Documentation
3.1.6. Drivers
3.1.7. Known issues and limitations
3.1.8. Upcoming features
3.2. v0.8.0
3.2.1. New features in this release
3.2.2. Bug fixes/improvements in this release
3.2.3. Build/Testing/Tooling improvements
3.2.4. Platforms
3.2.5. Known issues and limitations
3.2.6. Upcoming features
3.3. v0.7.0
3.3.1. New features in this release
3.3.2. Bug fixes/improvements in this release
3.3.3. Build/Testing/Tooling improvements
3.3.4. Platforms
3.3.5. Known issues and limitations
3.3.6. Upcoming features
3.4. v0.6.0
3.4.1. New features in this release
3.4.2. Bug fixes/improvements in this release
3.4.3. Build/Testing/Tooling improvements
3.4.4. Platforms
3.4.5. Known issues and limitations
3.4.6. Upcoming features
3.5. v0.5.0
3.5.1. New features in this release
3.5.2. Bug fixes/improvements in this release
3.5.3. Build/Testing/Tooling improvements
3.5.4. Platforms
3.5.5. Known issues and limitations
3.5.6. Upcoming features
3.6. v0.4.0
3.6.1. New features in this release
3.6.2. Build/Testing/Tooling improvements
3.6.3. Platforms
3.6.4. Bug fixes/improvements in this release
3.6.5. Known issues and limitations
3.6.6. Upcoming features
3.7. v0.3.0
3.7.1. New features in this release
3.7.2. Build/Testing improvements
3.7.3. Bug fixes in this release
3.7.4. Upcoming features
3.7.5. Known issues and limitations
3.8. v0.2.0
3.9. v0.1.0
3.9.1. Upcoming features
3.9.2. Known issues and limitations
4. Developer Certificate of Origin
5. License
Getting Started Guides
1. Prerequisite
2. Build Host
3. Tool & Dependency overview
4. Setup Toolchain
5. Package Installation (Ubuntu-20.04 x64)
6. Install python dependencies
7. Install python dependencies for Documentation
8. Install coverage tools analysis dependencies
9. Getting the RMM Source
9.1. Additional steps for Contributors
10. Install Cppcheck and dependencies
11. Install CBMC
12. Install Clang-tidy
13. Performing an Initial Build
14. Running the RMM
15. RMM Build Examples
16. RMM Build Options
17. RMM LLVM Build
18. RMM Fake Host Build
19. Building with Shrinkwrap
19.1. Introduction
19.2. Setup local RMM with Shrinkwrap
19.3. 3-World testing
19.4. 3-World testing with CCA DA
19.5. Testing RMM with TFTF
19.6. Overlays
19.6.1. Example of use
Process
1. Coding Standard
1.1. General
1.2. File Encoding
1.3. Language
1.4. C Language Standard
1.5. Length
1.6. Headers/Footers
1.7. Naming conventions
1.8. Indentation
1.9. Spacing
1.10. Braces
1.11. Commenting
1.12. Error return values and Exception handling
1.13. Use of asserts and panic
1.14. Using COMPILER_ASSERT to check for compile time data errors
1.15. Data types, structures and typedefs
1.16. Macros and Enums
1.17. Switch statements
1.18. Inline assembly
1.19. Libc functions that are banned or to be used with caution
2. Security Handling
3. Commit Style
3.1. Mandated Trailers
4. Contributor’s Guide
4.1. Getting Started
4.2. Making Changes
4.3. Submitting Changes
4.4. License and Copyright for Contributions
Design
1. RMM Locking Guidelines
1.1. Introduction
1.2. Requirements
1.2.1. Critical Section
1.2.2. Mutual Exclusion
1.2.3. Deadlock Avoidance
1.2.4. Starvation Avoidance
1.2.5. Nested Critical Sections
1.3. Implementation
1.3.1. Locking
1.3.2. Reference Counting
1.4. Guidelines
1.4.1. Mutual Exclusion
1.4.2. Deadlock Avoidance
1.4.3. Starvation Avoidance
1.4.4. Nested Critical Sections
1.4.5. Object-map Epoch Counter
1.4.6. Tracking-region representation locking
1.5. References
2. MMU setup and memory management design in RMM
2.1. Physical Address Space
2.2. Granule state tracking
2.3. RMM stage 1 translation regime
2.3.1. Stage 1 Low VA range
2.3.2. Stage 1 High VA range
2.4. Stage 1 translation library (xlat library)
2.5. RMM executable bootstrap
3. Dynamic Granule object management
3.1. Tracking model
3.1.1. Terminology
3.1.2. Tracking metadata layout
3.1.3.
struct
tracking_region
3.2. Initialization and memory
3.2.1. Boot-time setup
3.2.2. Activation modes
3.2.3. SRO donation and reclaim
3.2.4. Tracking transitions
3.3. Runtime management
3.3.1. Lookup and locking
3.3.2. SRO context reservation
3.3.3. Single and range operations
3.3.4. Tracking RMI commands
3.4. RTT map and unmap interaction
3.4.1. Tracking size and S2TT level
3.4.2. Map
3.4.3. Unmap
3.5. Current implementation limits
4. RTT map/unmap flows
4.1. Shared model
4.1.1. Address ranges
4.1.2. Progress model
4.1.3. Locking and lifetime
4.1.4. Drain-pending markers
4.2. Map flow
4.2.1. Common validation
4.2.2. Common execution
4.2.3.
RMI_RTT_DATA_MAP_INIT
4.3. Unmap flow
4.3.1. Sweep phase
4.3.2. Deferred phase
4.3.3. Result formatting
4.4. Flavour-specific detail
4.4.1. DATA map
4.4.2. DATA unmap
4.4.3. UNPROT map
4.4.4. UNPROT unmap
4.4.5. DEV map
4.4.6. DEV unmap
5. RMM Folder and Component organization
5.1. Root Level Folders and Components
5.2. Component File and Cmake Structure
6. PDEV auxiliary granules
6.1. Overview
6.2. Granule layout and role
6.3. PDEV stream interactions
6.4. PDEV communication workflow
7. RMM Fake host architecture
7.1. Fake host architecture design
7.2. Fake host architecture employment scenarios implemented or ongoing
8. RMM Cold and Warm boot design
9. RMM-EL3 communication specification
10. EL0 apps in RMM
10.1. Goal
10.2. Building app binaries
10.3. Building final RMM image
10.4. RMM App Instance
10.5. RMM App VA space
10.6. Initialising RMM app pages
10.7. RMM App Service Calls
10.8. Debugging RMM on FVP
10.9. RMM Fake Host Build
10.10. RMM Apps currently in RMM
10.11. Directory layout of apps
10.12. Proposed Enhancements to the RMM App Framework
11. ASID Management and TLB Maintenance for EL0 Apps
11.1. Introduction
11.2. Translation Regime Overview
11.2.1. High VA Usage by RMM Core (Slot Buffer)
11.2.2. TTBR1 Time-Multiplexing
11.3. ASID Allocation
11.3.1. Instance Model
11.4. TLB Maintenance on TTBR1 Switching
11.4.1. Entry to EL0 App (run_app)
11.4.2. Return from EL0 App (back_from_el0)
11.5. TCR_EL2.E0PD0 — Static Configuration
11.6. Scope of Invalidation
11.7. DSB Scope Selection
11.8. Summary of Rules
Security
1. Threat Model
1.1. Introduction
1.2. Data Flow Diagram
1.2.1. Target of Evaluation
1.2.2. Data Flow Diagram
1.3. Threat Analysis components
1.3.1. Assets
1.3.2. Threat Agents
1.3.3. Threat Types
1.3.4. Threat Risk Ratings
1.4. Threat Assessment
Resources
1. Application Notes
1.1. CBMC
1.1.1. CBMC in RMM
1.1.2. cbmc-viewer
1.1.3. CBMC proof debugger
1.2. Cppcheck Application Note
1.2.1. Installing Cppcheck
1.2.2. Invoking Cppcheck rule within TF-RMM build system
1.2.3. Generating the Cppcheck HTML report
1.2.4. Cppcheck Error Suppression
1.3. RMM Fuzzing
1.3.1. Configuration
1.3.2. Quick start
1.3.3. More
1.4. Generate corpus
1.4.1. Command Support Matrix
1.4.2. Command order in corpora
Glossary
Realm Management Monitor
Security
View page source
Previous
Next
Security
Contents
1. Threat Model