xref: /aosp_15_r20/system/core/trusty/trusty-base.mk (revision 00c7fec1bb09f3284aad6a6f96d2f63dfc3650ad)
1*00c7fec1SAndroid Build Coastguard Worker#
2*00c7fec1SAndroid Build Coastguard Worker# Copyright (C) 2016 The Android Open-Source Project
3*00c7fec1SAndroid Build Coastguard Worker#
4*00c7fec1SAndroid Build Coastguard Worker# Licensed under the Apache License, Version 2.0 (the "License");
5*00c7fec1SAndroid Build Coastguard Worker# you may not use this file except in compliance with the License.
6*00c7fec1SAndroid Build Coastguard Worker# You may obtain a copy of the License at
7*00c7fec1SAndroid Build Coastguard Worker#
8*00c7fec1SAndroid Build Coastguard Worker#      http://www.apache.org/licenses/LICENSE-2.0
9*00c7fec1SAndroid Build Coastguard Worker#
10*00c7fec1SAndroid Build Coastguard Worker# Unless required by applicable law or agreed to in writing, software
11*00c7fec1SAndroid Build Coastguard Worker# distributed under the License is distributed on an "AS IS" BASIS,
12*00c7fec1SAndroid Build Coastguard Worker# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13*00c7fec1SAndroid Build Coastguard Worker# See the License for the specific language governing permissions and
14*00c7fec1SAndroid Build Coastguard Worker# limitations under the License.
15*00c7fec1SAndroid Build Coastguard Worker#
16*00c7fec1SAndroid Build Coastguard Worker
17*00c7fec1SAndroid Build Coastguard Worker#
18*00c7fec1SAndroid Build Coastguard Worker# This makefile should be included by devices that use Trusty TEE
19*00c7fec1SAndroid Build Coastguard Worker# to pull in the baseline set of Trusty specific modules.
20*00c7fec1SAndroid Build Coastguard Worker#
21*00c7fec1SAndroid Build Coastguard Worker
22*00c7fec1SAndroid Build Coastguard Worker# For gatekeeper, we include the generic -service and -impl to use legacy
23*00c7fec1SAndroid Build Coastguard Worker# HAL loading of gatekeeper.trusty.
24*00c7fec1SAndroid Build Coastguard Worker
25*00c7fec1SAndroid Build Coastguard Worker$(call inherit-product, system/core/trusty/keymint/trusty-keymint.mk)
26*00c7fec1SAndroid Build Coastguard Worker
27*00c7fec1SAndroid Build Coastguard Workerifeq ($(SECRETKEEPER_ENABLED),true)
28*00c7fec1SAndroid Build Coastguard Worker    LOCAL_SECRETKEEPER_PRODUCT_PACKAGE := android.hardware.security.secretkeeper.trusty
29*00c7fec1SAndroid Build Coastguard Workerelse
30*00c7fec1SAndroid Build Coastguard Worker    LOCAL_SECRETKEEPER_PRODUCT_PACKAGE :=
31*00c7fec1SAndroid Build Coastguard Workerendif
32*00c7fec1SAndroid Build Coastguard Worker
33*00c7fec1SAndroid Build Coastguard WorkerPRODUCT_PACKAGES += \
34*00c7fec1SAndroid Build Coastguard Worker	$(LOCAL_SECRETKEEPER_PRODUCT_PACKAGE) \
35*00c7fec1SAndroid Build Coastguard Worker	android.hardware.gatekeeper-service.trusty \
36*00c7fec1SAndroid Build Coastguard Worker	trusty_apploader \
37*00c7fec1SAndroid Build Coastguard Worker
38*00c7fec1SAndroid Build Coastguard WorkerPRODUCT_PROPERTY_OVERRIDES += \
39*00c7fec1SAndroid Build Coastguard Worker	ro.hardware.keystore_desede=true \
40*00c7fec1SAndroid Build Coastguard Worker	ro.hardware.keystore=trusty \
41*00c7fec1SAndroid Build Coastguard Worker	ro.hardware.gatekeeper=trusty
42*00c7fec1SAndroid Build Coastguard Worker
43*00c7fec1SAndroid Build Coastguard WorkerPRODUCT_COPY_FILES += \
44*00c7fec1SAndroid Build Coastguard Worker	frameworks/native/data/etc/android.hardware.keystore.app_attest_key.xml:$(TARGET_COPY_OUT_VENDOR)/etc/permissions/android.hardware.keystore.app_attest_key.xml
45