-
Overview
-
redpesk OS releases
-
Security updates
- Security CVE / errata
- CVE quick look
-
Redpesk OS Tips and Tricks
-
Application Framework Manager
-
Application Framework Binder
-
APIs & Services
-
Security manager
-
OP-TEE within redpesk
-
Trusted Boot
-
Recovery features
-
redpak
-
Minimal image
- Reduce image size
- Optimizing boot time
-
Kernel fragments description
- Introduction to Linux Kernel Configuration
- 01 Disable IPC, Timers and Audit
- 02 Disable Kconfig, Scheduler and Initrd
- 03 Disable Perf, Profiling and Errata
- 04 Disable EFI, Power Management Debug and Energy Model
- 05 Disable Schedutil, CPUFreq Governors and Virtualization
- 06 Disable Kprobes and Jump Labels
- 07 Disable GCC Plugins and Function Alignment
- 08 Disable Partition Parsers
- 09 Enable Inline Spinlocks and Kernel Operations
- 10 Disable Swap, Memory Hotplug and KSM
- 11 Disable Networking IPv4, IPv6, Netfilter
- 12 Disable SCTP, VLAN, TIPC, BATMAN
- 13 Disable Wireless, Bluetooth, CAN and RFKILL
- 14 Disable PCI and Firmware
- 15 Disable GNSS and ProcEvents
- 16 Disable Block Storage NBD and AoE
- 17 Disable EEPROM and Misc Drivers
- 18 Disable Network Device Drivers
- 19 Disable PHY Drivers
- 20 Disable PPP, WLAN Coexistence, and Failover
- 21 Disable Input Devices
- 22 Disable Serial, TTY and TPM
- 23 Disable I2C, Power and Sensor Drivers
- 24 Disable MFD, Display and Media Drivers
- 25 Disable USB, Sound, RTC and VirtIO
- 26 Disable Filesystem Encodings and Compatibility
- 27 Enable Minimal Cryptographic Core with SHA3 and XTS
- 28 Disable Hardware Cryptography, Keep DRBG and Jitter Entropy
- 29 Disable Kernel Debugging Features
- 30 Disable Filesystem Verity and SecurityFS
-
Zephyr in Redpesk
-
PERM-CHECK extension
-
Mender redpesk (OTA)
-
Hardware support
- Download images
- Image metrics
- Trusted Boot
- Boards - ARM64
- Boards - x86_64
- Boards - Virtual
- Miscs
-
Building microservices natively within SDK container
-
Building microservices and framework from sources
The websocket protocol x-afb-ws-json1
The WebSocket protocol x-afb-ws-json1 is used to communicate between an application and a binder. It allows access to all registered apis of the binder.
This protocol is inspired from the protocol OCPP - SRPC as described for example here: OCPP transport specification - SRPC over WebSocket.
The registration to the IANA is still to be done, see: WebSocket Protocol Registries
This document gives a short description of the protocol x-afb-ws-json1. A more formal description has to be done.
Architecture
The protocol is intended to be symmetric. It allows:
- to CALL a remote procedure that returns a result
- to push and receive EVENT
Messages
Valid messages are made of text frames that are all valid JSON.
Valid messages are:
Calls:
[ 2, ID, PROCN, ARGS ]
[ 2, ID, PROCN, ARGS, TOKEN ]
Replies (3: OK, 4: ERROR):
[ 3, ID, RESP ]
[ 4, ID, RESP ]
Events:
[ 5, EVTN, OBJ ]
Where:
| Field | Type | Description |
|---|---|---|
| ID | string | A string that identifies the call. A reply to that call use the ID of the CALL. |
| PROCN | string | The procedure name to call of the form “api/verb” |
| ARGS | any | Any argument to pass to the call (see afb_req_json that returns it) |
| RESP | any | The response to the call |
| TOKEN | string | The authorisation token |
| EVTN | string | Name of the event in the form “api/event” |
| OBJ | any | The companion object of the event |
Below, an example of exchange:
C->S: [2,"156","hello/ping",null]
S->C: [3,"156",{"response":"Some String","jtype":"afb-reply","request":{"status":"success","info":"Ping Binder Daemon tag=pingSample count=1 query=\"null\""}}]
History
14 November 2019
Removal of token returning. The replies
[ 3, ID, RESP, TOKEN ]
[ 4, ID, RESP, TOKEN ]
are removed from the specification.
Future
Here are the planned extensions:
- add binary messages with cbor data
- add calls with unstructured replies
This could be implemented by extending the current protocol or by allowing the binder to accept either protocol including the new ones.
Javascript implementation
The file AFB.js is a javascript implementation of the protocol.
It can be downloaded here