Skip to content

[v3.4-branch] manifest: tf-m: update to v2.3.1 - #30846

Merged
anangl merged 2 commits into
nrfconnect:v3.4-branchfrom
tomi-font:v3.4-tf-m_update_v2.3.1
Aug 27, 2026
Merged

anangl merged 2 commits into
nrfconnect:v3.4-branchfrom
tomi-font:v3.4-tf-m_update_v2.3.1

Conversation

@tomi-font

Copy link
Copy Markdown
Contributor

From v2.3.0.

v3.4 equivalent of #30727.

@tomi-font
tomi-font requested a review from a team August 21, 2026 12:12
@tomi-font
tomi-font requested review from a team as code owners August 21, 2026 12:12
@NordicBuilder NordicBuilder added doc-required PR must not be merged without tech writer approval. manifest changelog labels Aug 21, 2026
@tomi-font tomi-font added the backwards-compatible PR doesnt break code, Kconfig, or DTS. I.e no changes needed for customers to port their application label Aug 21, 2026
@NordicBuilder

NordicBuilder commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

The following west manifest projects have changed revision in this Pull Request:

Name Old Revision New Revision Diff
trusted-firmware-m nrfconnect/sdk-trusted-firmware-m@30161e6 (ncs-v3.4.99-snapshot1) nrfconnect/sdk-trusted-firmware-m@b0d724b (ncs-v3.4-branch) nrfconnect/sdk-trusted-firmware-m@30161e6c..b0d724bc

Additional metadata changed:

Name URL Submodules West cmds module.yml Blobs
trusted-firmware-m

DNM label due to: 1 project with metadata changes

Note: This message is automatically posted and updated by the Manifest GitHub Action.

@NordicBuilder

NordicBuilder commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

CI Information

To view the history of this post, click the 'edited' button above
Build number: 4

Inputs:

Sources:

trusted-firmware-m: PR head: b0d724bc0f2f46a396d59280476ec06fad1d4ecd
sdk-nrf: PR head: e266b6c8a0afbd9b36a28229c5cd66d6767886a2

more details

trusted-firmware-m:

PR head: b0d724bc0f2f46a396d59280476ec06fad1d4ecd
merge base: 5d906d29d7b6d1a7f7134960d228f9e75f6a8a07
Diff

sdk-nrf:

PR head: e266b6c8a0afbd9b36a28229c5cd66d6767886a2
merge base: 2e2729ab9bc4eafe7b295431e89c986f4b2fef12
target head (v3.4-branch): 2e2729ab9bc4eafe7b295431e89c986f4b2fef12
Diff

Github labels

Enabled Name Description
ci-disabled Disable the ci execution
ci-all-test Run all of ci, no test spec filtering will be done
ci-force-downstream Force execution of downstream even if twister fails
ci-run-twister Force run twister
ci-run-zephyr-twister Force run zephyr twister
List of changed files detected by CI (224)
doc
│  ├── nrf
│  │  ├── links.txt
│  │  ├── releases_and_maturity
│  │  │  ├── releases
│  │  │  │  │ release-notes-changelog.rst
modules
│  ├── tee
│  │  ├── tf-m
│  │  │  ├── trusted-firmware-m
│  │  │  │  ├── .github
│  │  │  │  │  ├── workflows
│  │  │  │  │  │  │ manifest-PR.yml
│  │  │  │  ├── .readthedocs.yaml
│  │  │  │  ├── README.md
│  │  │  │  ├── bl2
│  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  ├── ext
│  │  │  │  │  │  ├── mcuboot
│  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  ├── Kconfig
│  │  │  │  │  │  │  ├── config
│  │  │  │  │  │  │  │  │ mcuboot_crypto_config.h
│  │  │  │  │  │  │  ├── include
│  │  │  │  │  │  │  │  ├── mcuboot_config
│  │  │  │  │  │  │  │  │  │ mcuboot_config.h.in
│  │  │  │  │  │  │  ├── keys.c
│  │  │  │  │  │  │  ├── mcuboot_default_config.cmake
│  │  │  │  │  │  │  ├── scripts
│  │  │  │  │  │  │  │  │ wrapper.py
│  │  │  │  ├── cmake
│  │  │  │  │  ├── hex_generator.cmake
│  │  │  │  │  ├── install.cmake
│  │  │  │  │  ├── remote_library.cmake
│  │  │  │  │  │ version.cmake
│  │  │  │  ├── config
│  │  │  │  │  ├── check_config.cmake
│  │  │  │  │  │ config_base.cmake
│  │  │  │  ├── docs
│  │  │  │  │  ├── doxygen
│  │  │  │  │  │  ├── Doxyfile.in
│  │  │  │  │  │  │ api_reference.rst
│  │  │  │  │  ├── index.rst
│  │  │  │  │  ├── releases
│  │  │  │  │  │  ├── 2.3.1.rst
│  │  │  │  │  │  │ index.rst
│  │  │  │  │  ├── security
│  │  │  │  │  │  ├── security_advisories
│  │  │  │  │  │  │  ├── fwu_partial_fmp_header.rst
│  │  │  │  │  │  │  ├── index.rst
│  │  │  │  │  │  │  │ missing_ns_pointer_validation_mailbox_init.rst
│  │  │  │  ├── interface
│  │  │  │  │  ├── include
│  │  │  │  │  │  ├── psa
│  │  │  │  │  │  │  ├── crypto.h
│  │  │  │  │  │  │  ├── crypto_compat.h
│  │  │  │  │  │  │  ├── crypto_driver_common.h
│  │  │  │  │  │  │  ├── crypto_driver_contexts_composites.h
│  │  │  │  │  │  │  ├── crypto_driver_contexts_key_derivation.h
│  │  │  │  │  │  │  ├── crypto_driver_contexts_primitives.h
│  │  │  │  │  │  │  ├── crypto_driver_random.h
│  │  │  │  │  │  │  ├── crypto_extra.h
│  │  │  │  │  │  │  ├── crypto_platform.h
│  │  │  │  │  │  │  ├── crypto_sizes.h
│  │  │  │  │  │  │  ├── crypto_struct.h
│  │  │  │  │  │  │  ├── crypto_types.h
│  │  │  │  │  │  │  │ crypto_values.h
│  │  │  │  │  │  ├── tf-psa-crypto
│  │  │  │  │  │  │  ├── build_info.h
│  │  │  │  │  │  │  │ version.h
│  │  │  │  │  │  ├── tfm_crypto_defs.h
│  │  │  │  │  │  │ tfm_platform_api.h
│  │  │  │  │  ├── src
│  │  │  │  │  │  ├── tfm_crypto_api.c
│  │  │  │  │  │  │ tfm_platform_api.c
│  │  │  │  ├── lib
│  │  │  │  │  ├── ext
│  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  ├── qcbor
│  │  │  │  │  │  │  │ CMakeLists.txt
│  │  │  │  │  │  ├── tf-m-tests
│  │  │  │  │  │  │  │ version.txt
│  │  │  │  │  │  ├── tf-psa-crypto
│  │  │  │  │  │  │  ├── 0001-Add-generated-files-to-the-source-tree.patch
│  │  │  │  │  │  │  ├── 0002-Add-TF-M-Builtin-Key-Loader-driver-entry-points.patch
│  │  │  │  │  │  │  ├── 0003-Enable-crypto-code-sharing-between-independent-binar.patch
│  │  │  │  │  │  │  ├── 0004-Initialise-driver-wrappers-as-first-step-in-psa_cryp.patch
│  │  │  │  │  │  │  ├── 0005-Hardcode-CC3XX-entry-points.patch
│  │  │  │  │  │  │  ├── 0006-P256M-Add-option-to-force-not-use-of-asm.patch
│  │  │  │  │  │  │  ├── 0007-psa-mac-only-call-memset-if-key_length-is-less-than-.patch
│  │  │  │  │  │  │  ├── 0008-Add-CC3XX-Opaque-Key-entry-points.patch
│  │  │  │  │  │  │  ├── 0009-Define-base-attributes-and-structure-for-SP800-108-C.patch
│  │  │  │  │  │  │  ├── 0010-Add-experimental-LMS-support-as-a-vendor-extension.patch
│  │  │  │  │  │  │  ├── 0011-Exclude-built-in-definitions-for-PSA-Crypto-client.patch
│  │  │  │  │  │  │  ├── 0012-Re-add-psa_can_do_cipher-to-public-interface.patch
│  │  │  │  │  │  │  ├── 0013-Implement-SP800-108-Counter-CMAC-key-derivation-in-P.patch
│  │  │  │  │  │  │  ├── 0014-Support-use-of-cc3xx-opaque-keys-in-PSA-Crypto-core.patch
│  │  │  │  │  │  │  ├── 0015-Re-add-support-for-AES-Keywrap-for-TF-M.patch
│  │  │  │  │  │  │  ├── 0016-Do-not-define-__STDC_WANT_LIB_EXT1__-with-ATfE.patch
│  │  │  │  │  │  │  │ 0017-include-tf_psa_crypto_platform_requirements.h-in-tf_.patch
│  │  │  │  │  │  ├── thin-psa-crypto-core
│  │  │  │  │  │  │  │ thin_psa_crypto_core.c
│  │  │  │  │  ├── fih
│  │  │  │  │  │  ├── inc
│  │  │  │  │  │  │  │ fih.h
│  │  │  │  ├── platform
│  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  ├── ext
│  │  │  │  │  │  ├── accelerator
│  │  │  │  │  │  │  │ CMakeLists.txt
│  │  │  │  │  │  ├── common
│  │  │  │  │  │  │  ├── atfe
│  │  │  │  │  │  │  │  ├── tfm_common_ns.ldc
│  │  │  │  │  │  │  │  │ tfm_isolation_s.ld.template
│  │  │  │  │  │  │  ├── exception_info.c
│  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  ├── tfm_common_bl2.ld
│  │  │  │  │  │  │  │  ├── tfm_common_ns.ld
│  │  │  │  │  │  │  │  ├── tfm_common_s.ld.template
│  │  │  │  │  │  │  │  │ tfm_isolation_s.ld.template
│  │  │  │  │  │  ├── target
│  │  │  │  │  │  │  ├── adi
│  │  │  │  │  │  │  │  ├── max32657
│  │  │  │  │  │  │  │  │  ├── device
│  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │ max32657_sla.ld
│  │  │  │  │  │  │  ├── arm
│  │  │  │  │  │  │  │  ├── corstone1000
│  │  │  │  │  │  │  │  │  ├── Device
│  │  │  │  │  │  │  │  │  │  ├── Source
│  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  ├── corstone1000_bl1_1.ld
│  │  │  │  │  │  │  │  │  │  │  │  │ corstone1000_bl1_2.ld
│  │  │  │  │  │  │  │  │  ├── bootloader
│  │  │  │  │  │  │  │  │  │  ├── mcuboot
│  │  │  │  │  │  │  │  │  │  │  │ tfm_mcuboot_fwu.c
│  │  │  │  │  │  │  │  ├── mps4
│  │  │  │  │  │  │  │  │  ├── common
│  │  │  │  │  │  │  │  │  │  ├── device
│  │  │  │  │  │  │  │  │  │  │  ├── source
│  │  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  │  ├── mps4_corstone3xx_bl1_1.ld
│  │  │  │  │  │  │  │  │  │  │  │  │  │ mps4_corstone3xx_bl1_2.ld
│  │  │  │  │  │  │  │  ├── musca_b1
│  │  │  │  │  │  │  │  │  ├── Device
│  │  │  │  │  │  │  │  │  │  ├── Source
│  │  │  │  │  │  │  │  │  │  │  ├── atfe
│  │  │  │  │  │  │  │  │  │  │  │  ├── musca_bl2.ld
│  │  │  │  │  │  │  │  │  │  │  │  │ musca_ns.ldc
│  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  ├── musca_bl2.ld
│  │  │  │  │  │  │  │  │  │  │  │  │ musca_ns.ld
│  │  │  │  │  │  │  │  ├── rse
│  │  │  │  │  │  │  │  │  ├── common
│  │  │  │  │  │  │  │  │  │  ├── config.cmake
│  │  │  │  │  │  │  │  │  │  ├── device
│  │  │  │  │  │  │  │  │  │  │  ├── source
│  │  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  │  ├── rse_bl1_1.ld
│  │  │  │  │  │  │  │  │  │  │  │  │  │ rse_bl1_2.ld
│  │  │  │  │  │  │  │  │  │  ├── native_drivers
│  │  │  │  │  │  │  │  │  │  │  ├── atu_rse_drv.h
│  │  │  │  │  │  │  │  │  │  │  │ atu_rse_lib.c
│  │  │  │  │  │  │  │  │  │  ├── sfcp
│  │  │  │  │  │  │  │  │  │  │  ├── sfcp_core
│  │  │  │  │  │  │  │  │  │  │  │  ├── sfcp.c
│  │  │  │  │  │  │  │  │  │  │  │  ├── sfcp_encryption_handshake.c
│  │  │  │  │  │  │  │  │  │  │  │  ├── sfcp_encryption_stub.c
│  │  │  │  │  │  │  │  │  │  │  │  ├── sfcp_helpers.c
│  │  │  │  │  │  │  │  │  │  │  │  ├── sfcp_helpers.h
│  │  │  │  │  │  │  │  │  │  │  │  ├── sfcp_interrupt_handler.c
│  │  │  │  │  │  │  │  │  │  │  │  │ sfcp_trusted_subnets.c
│  │  │  │  │  │  │  │  │  │  ├── tests
│  │  │  │  │  │  │  │  │  │  │  ├── rse_test_executable
│  │  │  │  │  │  │  │  │  │  │  │  │ rse_tests.ld
│  │  │  │  │  │  │  ├── cypress
│  │  │  │  │  │  │  │  ├── psoc64
│  │  │  │  │  │  │  │  │  ├── Device
│  │  │  │  │  │  │  │  │  │  ├── Source
│  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  │ psoc6_ns.ld
│  │  │  │  │  │  │  │  │  ├── mailbox
│  │  │  │  │  │  │  │  │  │  │ platform_spe_mailbox.c
│  │  │  │  │  │  │  ├── infineon
│  │  │  │  │  │  │  │  ├── common
│  │  │  │  │  │  │  │  │  ├── interface
│  │  │  │  │  │  │  │  │  │  ├── src
│  │  │  │  │  │  │  │  │  │  │  │ ifx_mtb_srf.c
│  │  │  │  │  │  │  │  │  ├── libs
│  │  │  │  │  │  │  │  │  │  │ CMakeLists.txt
│  │  │  │  │  │  │  │  │  ├── spe
│  │  │  │  │  │  │  │  │  │  ├── services
│  │  │  │  │  │  │  │  │  │  │  ├── mailbox
│  │  │  │  │  │  │  │  │  │  │  │  │ platform_spe_mailbox.c
│  │  │  │  │  │  │  ├── nordic_nrf
│  │  │  │  │  │  │  │  ├── common
│  │  │  │  │  │  │  │  │  ├── core
│  │  │  │  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  │  │  │  ├── config.cmake
│  │  │  │  │  │  │  │  │  │  ├── native_drivers
│  │  │  │  │  │  │  │  │  │  │  │ spu.c
│  │  │  │  │  │  │  │  │  │  ├── ns
│  │  │  │  │  │  │  │  │  │  │  │ CMakeLists.txt
│  │  │  │  │  │  │  │  │  │  ├── services
│  │  │  │  │  │  │  │  │  │  │  ├── include
│  │  │  │  │  │  │  │  │  │  │  │  ├── tfm_ioctl_core_api.h
│  │  │  │  │  │  │  │  │  │  │  │  │ tfm_platform_hal_ioctl.h
│  │  │  │  │  │  │  │  │  │  │  ├── src
│  │  │  │  │  │  │  │  │  │  │  │  ├── tfm_ioctl_core_ns_api.c
│  │  │  │  │  │  │  │  │  │  │  │  │ tfm_platform_hal_ioctl.c
│  │  │  │  │  │  │  │  │  │  ├── startup_nrf54lvc.c
│  │  │  │  │  │  │  │  │  │  ├── target_cfg_54l.c
│  │  │  │  │  │  │  │  │  │  │ target_cfg_71.c
│  │  │  │  │  │  │  │  │  ├── nrf54lc10a
│  │  │  │  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  │  │  │  ├── config.cmake
│  │  │  │  │  │  │  │  │  │  ├── cpuarch.cmake
│  │  │  │  │  │  │  │  │  │  ├── memory_service_ranges
│  │  │  │  │  │  │  │  │  │  │  │ tfm_platform_user_memory_ranges.h
│  │  │  │  │  │  │  │  │  │  ├── ns
│  │  │  │  │  │  │  │  │  │  │  │ CMakeLists.txt
│  │  │  │  │  │  │  │  │  │  ├── partition
│  │  │  │  │  │  │  │  │  │  │  ├── flash_layout.h
│  │  │  │  │  │  │  │  │  │  │  │ region_defs.h
│  │  │  │  │  │  │  │  │  │  ├── tests
│  │  │  │  │  │  │  │  │  │  │  │ psa_arch_tests_config.cmake
│  │  │  │  │  │  │  │  │  ├── nrf54lm20a
│  │  │  │  │  │  │  │  │  │  │ cpuarch.cmake
│  │  │  │  │  │  │  │  │  ├── nrf54lv10a
│  │  │  │  │  │  │  │  │  │  │ cpuarch.cmake
│  │  │  │  │  │  │  │  ├── nrf54lc10dk_nrf54lc10a_cpuapp
│  │  │  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  │  │  ├── RTE_Device.h
│  │  │  │  │  │  │  │  │  ├── config.cmake
│  │  │  │  │  │  │  │  │  ├── cpuarch.cmake
│  │  │  │  │  │  │  │  │  ├── device_cfg.h
│  │  │  │  │  │  │  │  │  ├── ns
│  │  │  │  │  │  │  │  │  │  │ cpuarch_ns.cmake
│  │  │  │  │  │  │  │  │  ├── services
│  │  │  │  │  │  │  │  │  │  ├── src
│  │  │  │  │  │  │  │  │  │  │  │ tfm_platform_system.c
│  │  │  │  │  │  │  │  │  ├── tests
│  │  │  │  │  │  │  │  │  │  ├── psa_arch_tests_config.cmake
│  │  │  │  │  │  │  │  │  │  │ tfm_tests_config.cmake
│  │  │  │  │  │  │  │  │  ├── tfm_hal_platform.c
│  │  │  │  │  │  │  │  │  │ tfm_peripherals_config.h
│  │  │  │  │  │  │  ├── nuvoton
│  │  │  │  │  │  │  │  ├── m2351
│  │  │  │  │  │  │  │  │  ├── device
│  │  │  │  │  │  │  │  │  │  ├── source
│  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  ├── m2351_bl2.ld
│  │  │  │  │  │  │  │  │  │  │  │  │ m2351_ns.ld
│  │  │  │  │  │  │  │  ├── m2354
│  │  │  │  │  │  │  │  │  ├── device
│  │  │  │  │  │  │  │  │  │  ├── source
│  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  ├── m2354_bl2.ld
│  │  │  │  │  │  │  │  │  │  │  │  │ m2354_ns.ld
│  │  │  │  │  │  │  ├── rpi
│  │  │  │  │  │  │  │  ├── rp2350
│  │  │  │  │  │  │  │  │  ├── linker_bl2.ld
│  │  │  │  │  │  │  │  │  ├── linker_ns.ld
│  │  │  │  │  │  │  │  │  ├── linker_s.ld
│  │  │  │  │  │  │  │  │  │ tfm_hal_mailbox.c
│  │  │  │  │  │  │  ├── stm
│  │  │  │  │  │  │  │  ├── b_u585i_iot02a
│  │  │  │  │  │  │  │  │  │ config.cmake
│  │  │  │  │  │  │  │  ├── common
│  │  │  │  │  │  │  │  │  ├── hal
│  │  │  │  │  │  │  │  │  │  ├── CMSIS_Driver
│  │  │  │  │  │  │  │  │  │  │  │ low_level_flash.c
│  │  │  │  │  │  │  │  │  │  ├── provision
│  │  │  │  │  │  │  │  │  │  │  │ otp_provision.c
│  │  │  │  │  │  │  │  │  │  ├── template
│  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  ├── appli_ns.ld
│  │  │  │  │  │  │  │  │  │  │  │  │ bl2.ld
│  │  │  │  │  │  │  │  │  ├── stm32h5xx
│  │  │  │  │  │  │  │  │  │  ├── Device
│  │  │  │  │  │  │  │  │  │  │  ├── Source
│  │  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  │  │ tfm_common_s.ld
│  │  │  │  │  │  │  │  │  │  ├── template
│  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  │ bl2.ld
│  │  │  │  │  │  │  │  │  ├── stm32l5xx
│  │  │  │  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  │  │  │  ├── bl2
│  │  │  │  │  │  │  │  │  │  │  │ boot_hal_bl2.c
│  │  │  │  │  │  │  │  │  ├── stm32u3xx
│  │  │  │  │  │  │  │  │  │  ├── Device
│  │  │  │  │  │  │  │  │  │  │  ├── Source
│  │  │  │  │  │  │  │  │  │  │  │  ├── startup_stm32u3xx_ns.c
│  │  │  │  │  │  │  │  │  │  │  │  ├── startup_stm32u3xx_s.c
│  │  │  │  │  │  │  │  │  │  │  │  │ system_stm32u3xx.c
│  │  │  │  │  │  │  │  │  │  ├── scripts
│  │  │  │  │  │  │  │  │  │  │  ├── TFM_UPDATE.sh
│  │  │  │  │  │  │  │  │  │  │  │ regression.sh
│  │  │  │  │  │  │  │  │  │  ├── secure
│  │  │  │  │  │  │  │  │  │  │  ├── low_level_device.c
│  │  │  │  │  │  │  │  │  │  │  │ target_cfg.c
│  │  │  │  │  │  │  │  │  ├── stm32u5xx
│  │  │  │  │  │  │  │  │  │  ├── Device
│  │  │  │  │  │  │  │  │  │  │  ├── Source
│  │  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  │  │ tfm_common_s.ld
│  │  │  │  │  │  │  │  │  ├── stm32wbaxx
│  │  │  │  │  │  │  │  │  │  ├── Device
│  │  │  │  │  │  │  │  │  │  │  ├── Source
│  │  │  │  │  │  │  │  │  │  │  │  ├── gcc
│  │  │  │  │  │  │  │  │  │  │  │  │  │ tfm_common_s.ld
│  │  │  │  │  │  │  │  │  │  │  │  ├── startup_stm32wbaxx_ns.c
│  │  │  │  │  │  │  │  │  │  │  │  │ startup_stm32wbaxx_s.c
│  │  │  │  │  │  │  │  │  │  ├── scripts
│  │  │  │  │  │  │  │  │  │  │  │ regression.sh
│  │  │  │  │  │  │  │  │  │  ├── secure
│  │  │  │  │  │  │  │  │  │  │  ├── low_level_device.c
│  │  │  │  │  │  │  │  │  │  │  ├── target_cfg.c
│  │  │  │  │  │  │  │  │  │  │  │ tfm_hal_isolation.c
│  │  │  │  │  │  │  │  ├── nucleo_l552ze_q
│  │  │  │  │  │  │  │  │  ├── accelerator
│  │  │  │  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  │  │  │  ├── crypto_accelerator_config.h
│  │  │  │  │  │  │  │  │  │  ├── include
│  │  │  │  │  │  │  │  │  │  │  │ tf_psa_crypto_accelerator_config.h
│  │  │  │  │  │  │  │  │  │  │ mbedtls_accelerator_config.h
│  │  │  │  │  │  │  │  │  ├── config.cmake
│  │  │  │  │  │  │  │  │  ├── partition
│  │  │  │  │  │  │  │  │  │  │ flash_layout.h
│  │  │  │  │  │  │  │  ├── nucleo_u3c5zi_q
│  │  │  │  │  │  │  │  │  ├── partition
│  │  │  │  │  │  │  │  │  │  ├── flash_layout.h
│  │  │  │  │  │  │  │  │  │  │ region_defs.h
│  │  │  │  │  │  │  │  ├── stm32h573i_dk
│  │  │  │  │  │  │  │  │  │ config.cmake
│  │  │  │  │  │  │  │  ├── stm32l562e_dk
│  │  │  │  │  │  │  │  │  ├── accelerator
│  │  │  │  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  │  │  │  ├── crypto_accelerator_config.h
│  │  │  │  │  │  │  │  │  │  ├── include
│  │  │  │  │  │  │  │  │  │  │  │ tf_psa_crypto_accelerator_config.h
│  │  │  │  │  │  │  │  │  │  │ mbedtls_accelerator_config.h
│  │  │  │  │  │  │  │  │  ├── config.cmake
│  │  │  │  │  │  │  │  │  ├── partition
│  │  │  │  │  │  │  │  │  │  │ flash_layout.h
│  │  │  │  │  │  │  │  ├── stm32wba65i_dk
│  │  │  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  │  │  ├── partition
│  │  │  │  │  │  │  │  │  │  ├── flash_layout.h
│  │  │  │  │  │  │  │  │  │  │ region_defs.h
│  │  │  │  │  ├── include
│  │  │  │  │  │  ├── tfm_hal_mailbox.h
│  │  │  │  │  │  │ tfm_platform_system.h
│  │  │  │  │  ├── ns
│  │  │  │  │  │  │ toolchain_ns_GNUARM.cmake
│  │  │  │  ├── pyproject.toml
│  │  │  │  ├── readme.rst
│  │  │  │  ├── secure_fw
│  │  │  │  │  ├── partitions
│  │  │  │  │  │  ├── crypto
│  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  ├── Kconfig.comp
│  │  │  │  │  │  │  ├── config_crypto_check.h
│  │  │  │  │  │  │  ├── crypto_aead.c
│  │  │  │  │  │  │  ├── crypto_check_config.h
│  │  │  │  │  │  │  ├── crypto_init.c
│  │  │  │  │  │  │  ├── crypto_key_wrapping.c
│  │  │  │  │  │  │  ├── crypto_library.c
│  │  │  │  │  │  │  ├── crypto_pake.c
│  │  │  │  │  │  │  ├── crypto_spe.h
│  │  │  │  │  │  │  ├── tfm_crypto.yaml
│  │  │  │  │  │  │  │ tfm_crypto_api.h
│  │  │  │  │  │  ├── internal_trusted_storage
│  │  │  │  │  │  │  ├── CMakeLists.txt
│  │  │  │  │  │  │  ├── tfm_internal_trusted_storage.c
│  │  │  │  │  │  │  │ tfm_its_req_mngr.c
│  │  │  │  │  │  ├── lib
│  │  │  │  │  │  │  ├── runtime
│  │  │  │  │  │  │  │  ├── assert.c
│  │  │  │  │  │  │  │  │ crt_start.c
│  │  │  │  │  │  ├── ns_agent_mailbox
│  │  │  │  │  │  │  │ tfm_spe_mailbox.c
│  │  │  │  │  │  ├── platform
│  │  │  │  │  │  │  │ platform_sp.c
│  │  │  │  │  │  ├── protected_storage
│  │  │  │  │  │  │  ├── crypto
│  │  │  │  │  │  │  │  │ ps_crypto_interface.c
│  │  │  │  │  ├── spm
│  │  │  │  │  │  ├── core
│  │  │  │  │  │  │  ├── arch
│  │  │  │  │  │  │  │  │ tfm_arch_v8m_main.c
│  │  │  │  │  │  │  ├── spm_ipc.c
│  │  │  │  │  │  │  │ tfm_svcalls.c
│  │  │  │  ├── toolchain_ARMCLANG.cmake
│  │  │  │  ├── toolchain_ATFE.cmake
│  │  │  │  ├── toolchain_GNUARM.cmake
│  │  │  │  ├── toolchain_IARARM.cmake
│  │  │  │  ├── tools
│  │  │  │  │  ├── requirements.txt
│  │  │  │  │  │ tfm_manifest_list.yaml
│  │  │  │  ├── uv.lock
│  │  │  │  ├── zephyr
│  │  │  │  │  │ module.yml
west.yml

Outputs:

Toolchain

Version: 8285d8ad56
Build docker image: docker-dtr.nordicsemi.no/sw-production/ncs-build:8285d8ad56_015a0ddcc9

Test Spec & Results: ✅ Success; ❌ Failure; 🟠 Queued; 🟡 Progress; ◻️ Skipped; ⚠️ Quarantine

  • ◻️ Toolchain - Skipped: existing toolchain is used
  • ✅ Build twister
    • sdk-nrf test count: 9
  • ✅ Integration tests
    • ✅ test-fw-nrfconnect-tfm
Disabled integration tests
    • test-fw-nrfconnect-nrf_lrcs_mosh
    • test-fw-nrfconnect-nrf_lrcs_positioning
    • desktop52_verification
    • test_ble_nrf_config
    • test-fw-nrfconnect-apps
    • test-fw-nrfconnect-apps_nrfdesktop
    • test-fw-nrfconnect-ble_mesh
    • test-fw-nrfconnect-ble_samples
    • test-fw-nrfconnect-chip
    • test-fw-nrfconnect-fem
    • test-fw-nrfconnect-nfc
    • test-fw-nrfconnect-nrf-iot_libmodem-nrf
    • test-fw-nrfconnect-nrf-iot_lwm2m
    • test-fw-nrfconnect-nrf-iot_samples
    • test-fw-nrfconnect-nrf-iot_zephyr_lwm2m
    • test-fw-nrfconnect-nrf_crypto
    • test-fw-nrfconnect-ps-main
    • test-fw-nrfconnect-rpc
    • test-fw-nrfconnect-rs
    • test-fw-nrfconnect-thread-main
    • test-low-level
    • test-sdk-audio
    • test-sdk-dfu
    • test-sdk-find-my
    • test-sdk-mcuboot
    • test-sdk-wifi
    • test-secdom-samples-public

Note: This message is automatically posted and updated by the CI

@github-actions

github-actions Bot commented Aug 21, 2026

Copy link
Copy Markdown

You can find the documentation preview for this PR here.

@frkv frkv left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM (pending correct SHA)

@tomi-font
tomi-font force-pushed the v3.4-tf-m_update_v2.3.1 branch from 0e52f66 to baf8beb Compare August 25, 2026 10:20
@tomi-font tomi-font removed the upmerge label Aug 25, 2026
From v2.3.0.

Signed-off-by: Tomi Fontanilles <tomi.fontanilles@nordicsemi.no>
Document TF-M update.

Signed-off-by: Tomi Fontanilles <tomi.fontanilles@nordicsemi.no>
@tomi-font
tomi-font force-pushed the v3.4-tf-m_update_v2.3.1 branch from baf8beb to e266b6c Compare August 26, 2026 08:45
@Vge0rge
Vge0rge self-requested a review August 26, 2026 08:53
@tomi-font tomi-font removed the DNM label Aug 27, 2026
@anangl
anangl merged commit 3ce0b69 into nrfconnect:v3.4-branch Aug 27, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backwards-compatible PR doesnt break code, Kconfig, or DTS. I.e no changes needed for customers to port their application changelog doc-required PR must not be merged without tech writer approval. manifest manifest-trusted-firmware-m

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants