|
SDK for TESAIoT Dev Kit
API reference & tutorials (ModusToolbox)
|
Topics | |
| Chip gate & manager | |
| Touch holds | |
| Enrolment & Protected Update publish | |
| State & correlation | |
| Isolated test | |
| Usage notes | |
The archive exports exactly 18 functions (dist/tesaiot_hsm/api.txt), all declared in the hand-written tesaiot_hsm_api.h — the editable declaration home, checked against api.txt on every package run. They are defined in three archived files (tesaiot_optiga_manager.c, tesaiot_optiga_trust_m.c, tesaiot_protected_update_isolated.c — dist/tesaiot_hsm/PROVENANCE.txt), none of which ships as source. The ~52 other functions the older tesaiot_optiga*.h headers declare are the enrolment and Protected Update machinery; they are renamed inside the archive precisely so a consumer cannot reach them.
Unchanged between variants: variants/mtb-only.mk:14 — "OPTIGA CSR and Protected Update. libbento_hsm.a needs zero MPY symbols."
dist/tesaiot_hsm/overridable.txt is empty: nothing in this archive is weak-overridable — no symbol here is a hook a consumer implements. But six of the 18 are consumed as weak symbols by the shipped callers, because they link only under ENABLE_OPTIGA_CLM=1 (default 1). A caller that must build with CLM off declares them __attribute__((weak)) and NULL-checks the function pointer before every call:
| Function | Shipped weak-consumption site |
|---|---|
| publish_csr() | proj_cm33_ns/ipc_hsm_handler.c:1691-1693 (decl), :2174 (check) |
| tesaiot_publish_protected_update() | ipc_hsm_handler.c:2192 |
| trustm_reset_state() | ipc_hsm_handler.c:1966-1968 |
| trustm_current_correlation_id() | ipc_hsm_handler.c:1792-1794 — two NULL checks: the pointer, then the returned string |
| trustm_requested_target_oid() | tesaiot_pu_ingest.c:139-144, fallback 0xE0E1 |
| trustm_requested_anchor_oid() | tesaiot_pu_ingest.c:133-137, fallback 0xE0E8 |
The other twelve are strong everywhere and need no such guard.