29#ifndef TESAIOT_HSM_API_H
30#define TESAIOT_HSM_API_H
39#include "optiga_util.h"
40#include "common/optiga_lib_types.h"
103int publish_csr(uint8_t *csr,
size_t csr_length, uint16_t target_oid,
104 uint16_t trust_anchor_oid, uint32_t payload_version);
110 const char *trust_anchor_oid,
111 uint32_t payload_version,
bool optiga_manager_init(callback_handler_t callback, void *context)
Bring up the OPTIGA stack (idempotent); task context only — false if the chip did not answer.
void optiga_chip_exit(void)
One exit per successful enter; never call it after a failed enter.
void optiga_manager_unlock(void)
One unlock per successful lock, every early exit included; release a touch hold first.
optiga_util_t * optiga_manager_acquire(void)
The shared optiga_util instance; NULL until optiga_manager_init() has run.
bool optiga_chip_enter(void)
Open a chip session (re-entrant per task); false is fatal for this call — and NOT an init check.
bool optiga_manager_lock(void)
Take the manager mutex; false when never initialised — the real "is the manager up?...
void optiga_manager_release(void)
Release the acquired instance — exactly one per non-NULL acquire, on every exit.
void tesaiot_run_protected_update_isolated_test(void)
Interactive end-to-end Protected Update against the isolated test slot; blocks on scanf().
int publish_csr(uint8_t *csr, size_t csr_length, uint16_t target_oid, uint16_t trust_anchor_oid, uint32_t payload_version)
Publish an already-built CSR for the platform to sign; weak — NULL-check first. Arms the ingest.
int tesaiot_publish_protected_update(const char *target_oid, const char *trust_anchor_oid, uint32_t payload_version, bool with_csr)
Ask the platform for a Protected Update (OIDs as hex strings); weak — NULL-check first.
void trustm_update_state(trustm_state_t new_state, const char *status_code, const char *detail)
A setter with a timestamp, not a dispatcher; set WAITING_* before the transport starts.
void trustm_reset_state(void)
Back to IDLE, correlation id zeroed — this is what ends a run; call it at every exit.
uint16_t trustm_requested_target_oid(void)
The target OID the last request named; weak — NULL-check and fall back to 0xE0E1.
const char * trustm_current_correlation_id(void)
The in-flight run's id, or NULL; NULL means discard the inbound bundle — the replay defence.
uint16_t trustm_requested_anchor_oid(void)
The trust anchor the last request named; weak — same pattern, default 0xE0E8.
void optiga_manager_touch_release(void)
Decrement the hold counter — strict 1:1 with every hold, on every early return.
void optiga_manager_touch_hold_reason(const char *reason)
The same counted hold, plus the busy-modal string CM55 shows while touch is off.
void optiga_manager_touch_hold(void)
Counted hold for the whole chip conversation; the first hold sleeps 50 ms.
trustm_state_t
Definition tesaiot_hsm_api.h:83
@ TRUSTM_STATE_IDLE
Definition tesaiot_hsm_api.h:84
@ TRUSTM_STATE_COMPLETE
Definition tesaiot_hsm_api.h:89
@ TRUSTM_STATE_APPLYING_UPDATE
Definition tesaiot_hsm_api.h:87
@ TRUSTM_STATE_WAITING_FOR_MANIFEST
Definition tesaiot_hsm_api.h:86
@ TRUSTM_STATE_PUBLISHING_CSR
Definition tesaiot_hsm_api.h:85
@ TRUSTM_STATE_VERIFYING_MANIFEST
Definition tesaiot_hsm_api.h:94
@ TRUSTM_STATE_PROTECTED_UPDATE_SUCCESS
Definition tesaiot_hsm_api.h:96
@ TRUSTM_STATE_WAITING_FOR_CERTIFICATE
Definition tesaiot_hsm_api.h:88
@ TRUSTM_STATE_ERROR
Definition tesaiot_hsm_api.h:90
@ TRUSTM_STATE_WRITING_TRUST_ANCHOR
Definition tesaiot_hsm_api.h:93
@ TRUSTM_STATE_WAITING_FOR_JSON_BUNDLE
Definition tesaiot_hsm_api.h:91
@ TRUSTM_STATE_PROCESSING_JSON_BUNDLE
Definition tesaiot_hsm_api.h:92
@ TRUSTM_STATE_PROTECTED_UPDATE_FAILED
Definition tesaiot_hsm_api.h:97
@ TRUSTM_STATE_APPLYING_FRAGMENTS
Definition tesaiot_hsm_api.h:95