build(amd-h): vendor GlobalPlatform exports for j3r452 builds
Drops gpapi-globalplatform 1.7 and gpapi-upgrade 1.1 (AMD-H Amendment H v1.1) under applet/build-tools/gp-amdh/, sourced from OpenJavaCard/globalplatform-exports (master snapshot 2020-09-30). - dt-mvn.sh mounts exports/org/ into the converter's api_export_files/. - pom.xml adds the .jar files as system-scope deps under the j3r452 profile so javac on j3r452 builds resolves org.globalplatform.upgrade symbols (j3r180 builds don't see them on classpath). - .gitignore: narrow build-tools/ exclusion to top-level only so the new applet/build-tools/gp-amdh/ tree is trackable while the top-level build-tools/jcardsim/ vendor fork stays out of the repo. This commit alone produces zero CAP bytecode change because no current source imports org.globalplatform.*. The infra is provably inert until the Task 3.1+ source on feat/amd-h-epic-3-wip is merged. Verified by diffing CAP zip components for both profiles: only the embedded Java-Card-CAP-Creation-Time timestamp in META-INF/MANIFEST.MF differs. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
7
.gitignore
vendored
7
.gitignore
vendored
@@ -1,6 +1,9 @@
|
||||
# --- pre-existing ---
|
||||
# Local build/test tooling, not committed (jcardsim fork etc.)
|
||||
build-tools/
|
||||
# Local build/test tooling, not committed (jcardsim fork etc.). Matches the
|
||||
# top-level build-tools/ dir only — applet/build-tools/ is a different beast
|
||||
# (vendored AMD-H exports etc.) and IS committed; see negation below.
|
||||
/build-tools/
|
||||
!applet/build-tools/
|
||||
|
||||
# --- secrets / private keys ---
|
||||
# aliro-trustgen emits aliro_trust.h with the reader's PRIVATE scalar.
|
||||
|
||||
65
applet/build-tools/gp-amdh/README.md
Normal file
65
applet/build-tools/gp-amdh/README.md
Normal file
@@ -0,0 +1,65 @@
|
||||
# GlobalPlatform Amendment H exports (vendored)
|
||||
|
||||
This directory ships GlobalPlatform API exports and stub JARs needed to compile
|
||||
Aliro applet source against `org.globalplatform.*` and
|
||||
`org.globalplatform.upgrade.*` (Amendment H — ELF Upgrade).
|
||||
|
||||
The `vivokey/smartcard-ci` Docker image does not include these exports, so we
|
||||
vendor them here and bind-mount / classpath them in at build time.
|
||||
|
||||
## Files
|
||||
|
||||
| Path | Source artifact | Notes |
|
||||
|------|-----------------|-------|
|
||||
| `exports/org/globalplatform/javacard/globalplatform.exp` | `org.globalplatform-1.7/exports/...` | Converter export file, GP base API v1.7 |
|
||||
| `exports/org/globalplatform/upgrade/javacard/upgrade.exp` | `org.globalplatform.upgrade-1.1/exports/...` | Converter export file, AMD-H Upgrade API v1.1 |
|
||||
| `lib/gpapi-globalplatform.jar` | `org.globalplatform-1.7/gpapi-globalplatform.jar` | Stub classes for javac classpath |
|
||||
| `lib/gpapi-upgrade.jar` | `org.globalplatform.upgrade-1.1/gpapi-upgrade.jar` | Stub classes for javac classpath |
|
||||
|
||||
## Version selection
|
||||
|
||||
AMD-H v1.1 targets **GlobalPlatform Card Specification v2.3.1**, which exposes
|
||||
the v1.7 base API. Pairing **base 1.7 + upgrade 1.1** is the canonical combo;
|
||||
see `GPC_2.3_H_ELF_Upgrade_v1.1_PublicRelease.pdf` in the project root for the
|
||||
specification text.
|
||||
|
||||
## Provenance
|
||||
|
||||
All four files were extracted verbatim from the `master` snapshot of the
|
||||
public repository:
|
||||
|
||||
https://github.com/OpenJavaCard/globalplatform-exports
|
||||
|
||||
specifically from these subdirectories:
|
||||
|
||||
* `org.globalplatform-1.7/`
|
||||
* `org.globalplatform.upgrade-1.1/`
|
||||
|
||||
The local zip used to extract them (`globalplatform-exports-master.zip`) was
|
||||
fetched on 2020-09-30 (mtime of the archive entries). File sizes match the
|
||||
upstream manifest:
|
||||
|
||||
43749 gpapi-globalplatform.jar
|
||||
12638 gpapi-upgrade.jar
|
||||
6641 globalplatform.exp
|
||||
1705 upgrade.exp
|
||||
|
||||
## License
|
||||
|
||||
These artifacts are GlobalPlatform-published API descriptors / stubs and are
|
||||
governed by the GlobalPlatform Specification license under which AMD-H v1.1
|
||||
was released. The corresponding specification PDF
|
||||
(`GPC_2.3_H_ELF_Upgrade_v1.1_PublicRelease.pdf`) lives at the project root and
|
||||
documents the licensing terms.
|
||||
|
||||
## How the build consumes these files
|
||||
|
||||
* `applet/scripts/dt-mvn.sh` bind-mounts `exports/org/` into the Docker
|
||||
image at `/app/sdks/jc305u3_kit/api_export_files/org` so the ant-javacard
|
||||
converter can resolve `org.globalplatform.*` package imports during CAP
|
||||
conversion.
|
||||
* `applet/pom.xml` declares the two `.jar` files as `system`-scope
|
||||
dependencies under the `j3r452` Maven profile only, so javac on j3r452
|
||||
builds resolves the symbols. The `j3r180` profile never adds the JARs to
|
||||
its classpath — its CAP cannot depend on AMD-H because the J3R180 OS does
|
||||
not implement the Upgrade API.
|
||||
Binary file not shown.
Binary file not shown.
BIN
applet/build-tools/gp-amdh/lib/gpapi-globalplatform.jar
Normal file
BIN
applet/build-tools/gp-amdh/lib/gpapi-globalplatform.jar
Normal file
Binary file not shown.
BIN
applet/build-tools/gp-amdh/lib/gpapi-upgrade.jar
Normal file
BIN
applet/build-tools/gp-amdh/lib/gpapi-upgrade.jar
Normal file
Binary file not shown.
@@ -164,6 +164,33 @@
|
||||
<cap.elf.aid>A0000009094454414C49524F02</cap.elf.aid>
|
||||
<cap.output.name>aliro-applet-j3r452.cap</cap.output.name>
|
||||
</properties>
|
||||
<dependencies>
|
||||
<!--
|
||||
GlobalPlatform AMD-H export JARs (system-scope, vendored
|
||||
under build-tools/gp-amdh/lib/). Scoped to this profile only
|
||||
so they never leak onto the j3r180 classpath. See
|
||||
build-tools/gp-amdh/README.md for provenance.
|
||||
|
||||
system scope is deprecated in modern Maven but remains
|
||||
functional in 3.x and is the canonical pattern for
|
||||
locally-vendored JARs that we don't want to push through
|
||||
`mvn install:install-file` as a CI ordering step.
|
||||
-->
|
||||
<dependency>
|
||||
<groupId>org.globalplatform</groupId>
|
||||
<artifactId>gpapi-globalplatform</artifactId>
|
||||
<version>1.7</version>
|
||||
<scope>system</scope>
|
||||
<systemPath>${project.basedir}/build-tools/gp-amdh/lib/gpapi-globalplatform.jar</systemPath>
|
||||
</dependency>
|
||||
<dependency>
|
||||
<groupId>org.globalplatform</groupId>
|
||||
<artifactId>gpapi-upgrade</artifactId>
|
||||
<version>1.1</version>
|
||||
<scope>system</scope>
|
||||
<systemPath>${project.basedir}/build-tools/gp-amdh/lib/gpapi-upgrade.jar</systemPath>
|
||||
</dependency>
|
||||
</dependencies>
|
||||
<build>
|
||||
<plugins>
|
||||
<!--
|
||||
|
||||
@@ -21,8 +21,16 @@ if ! docker volume inspect "$VOLUME" >/dev/null 2>&1; then
|
||||
-c 'cp -a /root/.m2/. /dst/ && chmod -R a+rwX /dst'
|
||||
fi
|
||||
|
||||
# GlobalPlatform Amendment H export files (vendored under build-tools/gp-amdh/).
|
||||
# Mounted into the SDK's api_export_files tree so the JC 3.0.5 converter can
|
||||
# resolve org.globalplatform.* imports during CAP conversion. The mount is
|
||||
# unconditional: when the j3r180 profile builds, no source imports those
|
||||
# packages, so the converter never opens these exports.
|
||||
GP_AMDH_EXPORTS="$project_root/build-tools/gp-amdh/exports/org"
|
||||
|
||||
exec docker run --rm -t \
|
||||
-v "$project_root:/work" -w /work \
|
||||
-v "$VOLUME:/root/.m2" \
|
||||
-v "$GP_AMDH_EXPORTS:/app/sdks/jc305u3_kit/api_export_files/org:ro" \
|
||||
-e JC_CLASSIC_HOME=/app/sdks/jc305u3_kit \
|
||||
"$IMAGE" "mvn $*"
|
||||
|
||||
Reference in New Issue
Block a user