Revise readme to clearly state that this is only a test tool

Signed-off-by: Gilles Peskine <[email protected]>
This commit is contained in:
Gilles Peskine
2024-04-16 12:10:44 +02:00
parent 001c09ded9
commit 8ef1e0b2a5
+22 -22
View File
@@ -1,11 +1,18 @@
# psasim # psasim
This is a library that simulates a PSA Firmware Framework compliant implementation. This tool simulates a PSA Firmware Framework implementation.
It allows you to develop secure partitions and their clients on a desktop computer. It allows you to develop secure partitions and their clients on a desktop computer.
It should be able to run on all systems that support POSIX and System V IPC: It should be able to run on all systems that support POSIX and System V IPC:
e.g. macOS, Linux, FreeBSD, and perhaps Windows 10 WSL2. e.g. macOS, Linux, FreeBSD, and perhaps Windows 10 WSL2.
To build and run the test program make sure you have `make`, `python` and a Please note that the code in this directory is maintained by the Mbed TLS / PSA Crypto project solely for the purpose of testing the use of Mbed TLS with client/service separation. We do not recommend using this code for any other purpose. In particular:
* This simulator is not intended to pass or demonstrate compliance.
* This code is only intended for simulation and does not have any security goals. It does not isolate services from clients.
## Building
To build and run the test program make sure you have `make`, `python` and a
C compiler installed and then enter the following commands: C compiler installed and then enter the following commands:
```sh ```sh
@@ -15,33 +22,26 @@ make run
On Linux you may need to run `ldconfig` to ensure the library is properly installed. On Linux you may need to run `ldconfig` to ensure the library is properly installed.
An example pair of programs is included in the **test** directory. An example pair of programs is included in the `test` directory.
The implemented API is compliant with PSA-FF 1.0.0 with the exception of ## Features
a couple of things that are a work in progress:
The implemented API is intended to be compliant with PSA-FF 1.0.0 with the exception of a couple of things that are a work in progress:
* `psa_notify` support * `psa_notify` support
* "strict" policy in manifest * "strict" policy in manifest
The only supported "interrupts" are POSIX signals, which act The only supported "interrupts" are POSIX signals, which act
as a "virtual interrupt" :-) as a "virtual interrupt".
The standard PSA RoT APIs are not included (e.g. cryptography, attestation, lifecycle etc). The standard PSA RoT APIs are not included (e.g. cryptography, attestation, lifecycle etc).
## Design ## Design
The code is designed to be readable rather than fast. The code is designed to be readable rather than fast or secure.
In this implementation only one message is delivered to a In this implementation only one message is delivered to a
RoT service at a time. RoT service at a time.
Things that need to be done to improve this implementation: The code is not thread-safe.
* run against the official test suite
* make thread safe
* make code more readable
* improve quality of code
* man pages
* use sockets for message passing (WSL doesn't support System V message queues)
* general robustness and hardening
To debug the simulator enable the debug flag: To debug the simulator enable the debug flag:
@@ -55,6 +55,6 @@ Because this is a simulator there are a few things that
can't be reasonably emulated: can't be reasonably emulated:
* Manifest MMIO regions are unsupported * Manifest MMIO regions are unsupported
* Manifest priority field is ignored * Manifest priority field is ignored
* Partition IDs are in fact POSIX `pid_t`, which are only assigned at runtime, * Partition IDs are in fact POSIX `pid_t`, which are only assigned at runtime,
making it infeasible to populate pid.h with correct values. making it infeasible to populate pid.h with correct values.