blob: 45f4286970351ae8ebf22599c1bfc68fcc1556c3 [file] [log] [blame]
Pascal Brand6044eb52016-02-23 15:48:31 +01001################################################################################
2# Following variables defines how the NS_USER (Non Secure User - Client
3# Application), NS_KERNEL (Non Secure Kernel), S_KERNEL (Secure Kernel) and
4# S_USER (Secure User - TA) are compiled
5################################################################################
Pascal Brandefe56592016-03-03 10:46:52 +01006COMPILE_NS_USER ?= 64
7override COMPILE_NS_KERNEL := 64
Pascal Brand6044eb52016-02-23 15:48:31 +01008COMPILE_S_USER ?= 64
9COMPILE_S_KERNEL ?= 64
10
Etienne Carriere3768a2b2019-05-14 17:13:19 +020011OPTEE_OS_PLATFORM = vexpress-fvp
12
Victor Chong7a716512017-09-11 15:18:44 +010013include common.mk
Pascal Brandd6536da2015-09-01 10:38:43 +020014
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000015################################################################################
16# Variables used for TPM configuration.
17################################################################################
18BR2_ROOTFS_OVERLAY = $(ROOT)/build/br-ext/board/fvp/overlay
19BR2_PACKAGE_FTPM_OPTEE_EXT_SITE ?= $(CURDIR)/br-ext/package/ftpm_optee_ext
20BR2_PACKAGE_FTPM_OPTEE_PACKAGE_SITE ?= $(ROOT)/ms-tpm-20-ref
21
22# The fTPM implementation is based on ARM32 architecture whereas the rest of the
23# system is built to run on 64-bit mode (COMPILE_S_USER = 64). Therefore set
24# BR2_PACKAGE_FTPM_OPTEE_EXT_SDK manually to the arm32 OPTEE toolkit rather than
25# relying on OPTEE_OS_TA_DEV_KIT_DIR variable.
26BR2_PACKAGE_FTPM_OPTEE_EXT_SDK ?= $(OPTEE_OS_PATH)/out/arm/export-ta_arm32
27
28BR2_PACKAGE_LINUX_FTPM_MOD_EXT_SITE ?= $(CURDIR)/br-ext/package/linux_ftpm_mod_ext
29BR2_PACKAGE_LINUX_FTPM_MOD_EXT_PATH ?= $(LINUX_PATH)
Joakim Bech427dd632015-05-04 15:52:33 +020030
31################################################################################
32# Paths to git projects and various binaries
33################################################################################
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000034MEASURED_BOOT ?= n
Victor Chongdf54b112019-08-11 15:58:12 +010035TF_A_PATH ?= $(ROOT)/trusted-firmware-a
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000036ifeq ($(MEASURED_BOOT),y)
37# Prefer release mode for TF-A if using Measured Boot, debug may exhaust memory.
38TF_A_BUILD ?= release
39endif
Sudeep Holla48a071b2024-05-19 19:27:00 +010040TF_A_DEBUG ?= $(DEBUG)
41ifeq ($(TF_A_DEBUG),1)
42TF_A_LOGLVL ?= 40
Victor Chongeca7cfd2019-11-08 09:18:05 +000043TF_A_BUILD ?= debug
44else
Sudeep Holla48a071b2024-05-19 19:27:00 +010045TF_A_LOGLVL ?= 20
Victor Chongeca7cfd2019-11-08 09:18:05 +000046TF_A_BUILD ?= release
47endif
Balint Dobszayc394dcd2022-05-23 18:32:57 +020048FVP_PATH ?= $(ROOT)/Base_RevC_AEMvA_pkg/models/Linux64_GCC-9.3
49FVP_BIN ?= FVP_Base_RevC-2xAEMvA
50FVP_LINUX_DTB ?= $(LINUX_PATH)/arch/arm64/boot/dts/arm/fvp-base-revc.dtb
Joakim Bech277ddad2017-11-15 09:33:21 +010051OUT_PATH ?= $(ROOT)/out
Balint Dobszayb80d8cb2024-04-24 14:09:18 +020052BINARIES_PATH ?= $(ROOT)/out/bin
53UBOOT_PATH ?= $(ROOT)/u-boot
54UBOOT_BIN ?= $(UBOOT_PATH)/u-boot.bin
55MKIMAGE_PATH ?= $(UBOOT_PATH)/tools
56UBOOT_BOOT_SCRIPT ?= $(OUT_PATH)/boot.scr
Joakim Bechab622612017-11-15 10:45:28 +010057BOOT_IMG ?= $(OUT_PATH)/boot-fat.uefi.img
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000058FTPM_PATH ?= $(ROOT)/ms-tpm-20-ref/Samples/ARM32-FirmwareTPM/optee_ta
59
Sudeep Holla6bab50e2024-05-19 19:41:48 +010060# Option to configure FF-A and SPM:
61# n: disabled
62# 3: not supported, SPMC and SPMD at EL3 (in TF-A)
63# 2: not supported, SPMC at S-EL2 (in Hafnium), SPMD at EL3 (in TF-A)
64# 1: SPMC at S-EL1 (in OP-TEE), SPMD at EL3 (in TF-A)
65SPMC_AT_EL ?= n
66ifneq ($(filter-out n 1,$(SPMC_AT_EL)),)
67$(error Unsupported SPMC_AT_EL value $(SPMC_AT_EL))
68endif
69
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000070ifeq ($(MEASURED_BOOT),y)
Balint Dobszay35e60992022-06-10 16:19:10 +020071# By default enable FTPM for backwards compatibility.
72MEASURED_BOOT_FTPM ?= y
73else
74$(call force,MEASURED_BOOT_FTPM,n,requires MEASURED_BOOT enabled)
75endif
76
77# Build ancillary components to access fTPM if Measured Boot is enabled.
78ifeq ($(MEASURED_BOOT_FTPM),y)
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000079DEFCONFIG_FTPM ?= --br-defconfig build/br-ext/configs/ftpm_optee
80DEFCONFIG_TPM_MODULE ?= --br-defconfig build/br-ext/configs/linux_ftpm
81DEFCONFIG_TSS ?= --br-defconfig build/br-ext/configs/tss
82endif
Joakim Bech427dd632015-05-04 15:52:33 +020083
84################################################################################
Joakim Bech427dd632015-05-04 15:52:33 +020085# Targets
86################################################################################
Balint Dobszayb80d8cb2024-04-24 14:09:18 +020087all: arm-tf optee-os ftpm boot-img linux u-boot
88clean: arm-tf-clean boot-img-clean buildroot-clean ftpm-clean optee-os-clean u-boot-clean
Joakim Bech427dd632015-05-04 15:52:33 +020089
Victor Chong7a716512017-09-11 15:18:44 +010090include toolchain.mk
Joakim Bech427dd632015-05-04 15:52:33 +020091
92################################################################################
Joakim Bech277ddad2017-11-15 09:33:21 +010093# Folders
94################################################################################
95$(OUT_PATH):
96 mkdir -p $@
97
98################################################################################
Balint Dobszay276212d2022-05-24 18:45:34 +020099# Shared folder
100################################################################################
101# Enable accessing the host directory FVP_VIRTFS_HOST_DIR from the FVP.
102# The shared folder can be mounted in the following ways:
103# - Run 'mount -t 9p -o trans=virtio,version=9p2000.L FM <mount point>' or,
104# - enable FVP_VIRTFS_AUTOMOUNT.
105# The latter will use the Buildroot post-build script to add an entry to the
106# target's /etc/fstab, mounting the shared directory to FVP_VIRTFS_MOUNTPOINT
107# on the FVP.
108# Note: the post-build script can only append to fstab. If FVP_VIRTFS_AUTOMOUNT
109# is changed from "y" to "n", run 'rm -r ../out-br/build/skeleton-init-sysv' so
110# the target's fstab will be replaced with the unmodified original again.
111FVP_VIRTFS_ENABLE ?= n
112FVP_VIRTFS_HOST_DIR ?= $(ROOT)
113FVP_VIRTFS_AUTOMOUNT ?= n
114FVP_VIRTFS_MOUNTPOINT ?= /mnt/host
115
116ifeq ($(FVP_VIRTFS_AUTOMOUNT),y)
117$(call force,FVP_VIRTFS_ENABLE,y,required by FVP_VIRTFS_AUTOMOUNT)
118endif
119
Balint Dobszay276212d2022-05-24 18:45:34 +0200120BR2_ROOTFS_POST_BUILD_SCRIPT = $(ROOT)/build/br-ext/board/fvp/post-build.sh
121BR2_ROOTFS_POST_SCRIPT_ARGS = "$(FVP_VIRTFS_AUTOMOUNT) $(FVP_VIRTFS_MOUNTPOINT)"
122
123################################################################################
Joakim Bech427dd632015-05-04 15:52:33 +0200124# ARM Trusted Firmware
125################################################################################
Victor Chong371d7c22019-08-08 17:17:14 +0100126TF_A_EXPORTS ?= \
Joakim Bech69a8a372016-04-26 11:05:04 +0200127 CROSS_COMPILE="$(CCACHE)$(AARCH64_CROSS_COMPILE)"
Pascal Brandb130ea22015-10-13 13:18:36 +0200128
Victor Chong371d7c22019-08-08 17:17:14 +0100129TF_A_FLAGS ?= \
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200130 BL33=$(UBOOT_BIN) \
Jerome Forissier0c761952018-11-09 11:09:26 +0100131 FVP_USE_GIC_DRIVER=FVP_GICV3 \
Pascal Brandb130ea22015-10-13 13:18:36 +0200132 PLAT=fvp \
Sudeep Holla48a071b2024-05-19 19:27:00 +0100133 DEBUG=$(TF_A_DEBUG) \
134 LOG_LEVEL=$(TF_A_LOGLVL)
Pascal Brandb130ea22015-10-13 13:18:36 +0200135
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000136ifneq ($(MEASURED_BOOT),y)
Sudeep Holla48a071b2024-05-19 19:27:00 +0100137 TF_A_FLAGS += MEASURED_BOOT=0
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000138else
Sudeep Holla48a071b2024-05-19 19:27:00 +0100139 TF_A_FLAGS += MBEDTLS_DIR=$(ROOT)/mbedtls \
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000140 ARM_ROTPK_LOCATION=devel_rsa \
141 GENERATE_COT=1 \
142 MEASURED_BOOT=1 \
143 ROT_KEY=plat/arm/board/common/rotpk/arm_rotprivk_rsa.pem \
144 TPM_HASH_ALG=sha256 \
145 TRUSTED_BOARD_BOOT=1 \
146 EVENT_LOG_LEVEL=20
147endif
148
Sudeep Holla6bab50e2024-05-19 19:41:48 +0100149TF_A_FLAGS_BL32_OPTEE = BL32=$(OPTEE_OS_HEADER_V2_BIN)
150TF_A_FLAGS_BL32_OPTEE += BL32_EXTRA1=$(OPTEE_OS_PAGER_V2_BIN)
151TF_A_FLAGS_BL32_OPTEE += BL32_EXTRA2=$(OPTEE_OS_PAGEABLE_V2_BIN)
152TF_A_FLAGS_BL32_OPTEE += ARM_TSP_RAM_LOCATION=tdram
153
154TF_A_FLAGS_SPMC_AT_EL_n = $(TF_A_FLAGS_BL32_OPTEE) SPD=opteed
155TF_A_FLAGS_SPMC_AT_EL_1 = BL32=$(OPTEE_OS_PAGER_V2_BIN) SPD=spmd
156TF_A_FLAGS_SPMC_AT_EL_1 += CTX_INCLUDE_EL2_REGS=0 SPMD_SPM_AT_SEL2=0
157TF_A_FLAGS_SPMC_AT_EL_1 += SPMC_OPTEE=1
158
159TF_A_FLAGS += $(TF_A_FLAGS_SPMC_AT_EL_$(SPMC_AT_EL))
160
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200161arm-tf: optee-os u-boot
Victor Chong371d7c22019-08-08 17:17:14 +0100162 $(TF_A_EXPORTS) $(MAKE) -C $(TF_A_PATH) $(TF_A_FLAGS) all fip
Joakim Bech427dd632015-05-04 15:52:33 +0200163
164arm-tf-clean:
Victor Chong371d7c22019-08-08 17:17:14 +0100165 $(TF_A_EXPORTS) $(MAKE) -C $(TF_A_PATH) $(TF_A_FLAGS) clean
Joakim Bech427dd632015-05-04 15:52:33 +0200166
167################################################################################
Joakim Bech427dd632015-05-04 15:52:33 +0200168# Linux kernel
169################################################################################
Jerome Forissiere1002382015-11-26 11:36:00 +0100170LINUX_DEFCONFIG_COMMON_ARCH := arm64
Balint Dobszay3730e012023-06-02 11:40:41 +0200171LINUX_DEFCONFIG_COMMON_FILES ?= \
Jerome Forissiere1002382015-11-26 11:36:00 +0100172 $(LINUX_PATH)/arch/arm64/configs/defconfig \
173 $(CURDIR)/kconfigs/fvp.conf
Joakim Bech427dd632015-05-04 15:52:33 +0200174
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000175.PHONY: linux-ftpm-module
176linux-ftpm-module: linux
Balint Dobszay35e60992022-06-10 16:19:10 +0200177ifeq ($(MEASURED_BOOT_FTPM),y)
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000178linux-ftpm-module:
179 $(MAKE) -C $(LINUX_PATH) $(LINUX_COMMON_FLAGS) M=drivers/char/tpm \
180 modules_install INSTALL_MOD_PATH=$(LINUX_PATH)
181endif
182
Joakim Bech427dd632015-05-04 15:52:33 +0200183linux-defconfig: $(LINUX_PATH)/.config
184
Pascal Brande3d85982015-09-10 17:20:42 +0200185LINUX_COMMON_FLAGS += ARCH=arm64
186
187linux: linux-common
188
189linux-defconfig-clean: linux-defconfig-clean-common
190
191LINUX_CLEAN_COMMON_FLAGS += ARCH=arm64
192
193linux-clean: linux-clean-common
194
195LINUX_CLEANER_COMMON_FLAGS += ARCH=arm64
196
197linux-cleaner: linux-cleaner-common
Joakim Bech427dd632015-05-04 15:52:33 +0200198
199################################################################################
200# OP-TEE
201################################################################################
Etienne Carriere3768a2b2019-05-14 17:13:19 +0200202OPTEE_OS_COMMON_FLAGS += CFG_ARM_GICV3=y
Sudeep Holla6bab50e2024-05-19 19:41:48 +0100203OPTEE_OS_COMMON_FLAGS_SPMC_AT_EL_1 = CFG_CORE_SEL1_SPMC=y
204
205OPTEE_OS_COMMON_FLAGS += $(OPTEE_OS_COMMON_FLAGS_SPMC_AT_EL_$(SPMC_AT_EL))
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000206
207ifeq ($(MEASURED_BOOT),y)
208 OPTEE_OS_COMMON_FLAGS += CFG_DT=y CFG_CORE_TPM_EVENT_LOG=y
209endif
210
Jerome Forissierae45fbf2015-09-04 09:40:17 +0200211optee-os: optee-os-common
Joakim Bech427dd632015-05-04 15:52:33 +0200212
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000213optee-os-clean: ftpm-clean optee-os-clean-common
214
215################################################################################
216# Buildroot
217################################################################################
218
219buildroot: linux-ftpm-module
Joakim Bech427dd632015-05-04 15:52:33 +0200220
Joakim Bech427dd632015-05-04 15:52:33 +0200221################################################################################
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200222# U-Boot
Joakim Bech277ddad2017-11-15 09:33:21 +0100223################################################################################
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200224UBOOT_DEFCONFIG_FILES := $(ROOT)/build/kconfigs/u-boot_fvp.conf
Joakim Bech277ddad2017-11-15 09:33:21 +0100225
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200226UBOOT_COMMON_FLAGS ?= CROSS_COMPILE=$(CROSS_COMPILE_NS_KERNEL)
Joakim Bech277ddad2017-11-15 09:33:21 +0100227
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200228$(UBOOT_PATH)/.config: $(UBOOT_DEFCONFIG_FILES)
229 cd $(UBOOT_PATH) && scripts/kconfig/merge_config.sh $(UBOOT_DEFCONFIG_FILES)
Joakim Bech277ddad2017-11-15 09:33:21 +0100230
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200231.PHONY: u-boot-defconfig
232u-boot-defconfig: $(UBOOT_PATH)/.config
Joakim Bech277ddad2017-11-15 09:33:21 +0100233
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200234.PHONY: u-boot
235u-boot: u-boot-defconfig
236 $(MAKE) -C $(UBOOT_PATH) $(UBOOT_COMMON_FLAGS)
Joakim Bech277ddad2017-11-15 09:33:21 +0100237
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200238.PHONY: u-boot-clean
239u-boot-clean:
240 $(MAKE) -C $(UBOOT_PATH) $(UBOOT_COMMON_FLAGS) distclean
Joakim Bech277ddad2017-11-15 09:33:21 +0100241
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200242$(UBOOT_BOOT_SCRIPT): $(BUILD_PATH)/fvp/uboot_boot_cmd.txt u-boot | $(OUT_PATH)
243 $(MKIMAGE_PATH)/mkimage -A arm64 \
244 -O linux \
245 -T script \
246 -C none \
247 -d $(BUILD_PATH)/fvp/uboot_boot_cmd.txt \
248 $(UBOOT_BOOT_SCRIPT)
Joakim Bech277ddad2017-11-15 09:33:21 +0100249
250################################################################################
Joakim Bechab622612017-11-15 10:45:28 +0100251# Boot Image
252################################################################################
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000253
Joakim Bechab622612017-11-15 10:45:28 +0100254.PHONY: boot-img
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200255boot-img: buildroot u-boot $(UBOOT_BOOT_SCRIPT)
Joakim Bechab622612017-11-15 10:45:28 +0100256 rm -f $(BOOT_IMG)
257 mformat -i $(BOOT_IMG) -n 64 -h 255 -T 131072 -v "BOOT IMG" -C ::
258 mcopy -i $(BOOT_IMG) $(LINUX_PATH)/arch/arm64/boot/Image ::
Balint Dobszayc394dcd2022-05-23 18:32:57 +0200259 mcopy -i $(BOOT_IMG) $(FVP_LINUX_DTB) ::/fvp.dtb
Jens Wiklander41a0dfe2018-02-05 22:55:02 +0100260 mcopy -i $(BOOT_IMG) $(ROOT)/out-br/images/rootfs.cpio.gz ::/initrd.img
Balint Dobszayb80d8cb2024-04-24 14:09:18 +0200261 mcopy -i $(BOOT_IMG) $(UBOOT_BOOT_SCRIPT) ::
Joakim Bechab622612017-11-15 10:45:28 +0100262
263.PHONY: boot-img-clean
264boot-img-clean:
265 rm -f $(BOOT_IMG)
266
267################################################################################
Joakim Bech427dd632015-05-04 15:52:33 +0200268# Run targets
269################################################################################
270# This target enforces updating root fs etc
Pascal Brand15271692015-09-08 10:42:22 +0200271run: all
Pascal Brand15271692015-09-08 10:42:22 +0200272 $(MAKE) run-only
Joakim Bech427dd632015-05-04 15:52:33 +0200273
Balint Dobszayc394dcd2022-05-23 18:32:57 +0200274FVP_ARGS ?= \
275 -C bp.ve_sysregs.exit_on_shutdown=1 \
276 -C cache_state_modelled=0 \
277 -C pctl.startup=0.0.0.0 \
278 -C cluster0.NUM_CORES=4 \
279 -C cluster1.NUM_CORES=4 \
Balint Dobszay4791acb2023-04-24 13:39:19 +0200280 -C cluster0.cpu0.enable_crc32=1 \
281 -C cluster0.cpu1.enable_crc32=1 \
282 -C cluster0.cpu2.enable_crc32=1 \
283 -C cluster0.cpu3.enable_crc32=1 \
284 -C cluster1.cpu0.enable_crc32=1 \
285 -C cluster1.cpu1.enable_crc32=1 \
286 -C cluster1.cpu2.enable_crc32=1 \
287 -C cluster1.cpu3.enable_crc32=1 \
Gyorgy Szing08d69742023-04-05 07:30:08 +0000288 -C cluster0.cpu0.semihosting-cwd="$(BINARIES_PATH)" \
289 -C cluster0.cpu1.semihosting-cwd="$(BINARIES_PATH)" \
290 -C cluster0.cpu2.semihosting-cwd="$(BINARIES_PATH)" \
291 -C cluster0.cpu3.semihosting-cwd="$(BINARIES_PATH)" \
292 -C cluster1.cpu0.semihosting-cwd="$(BINARIES_PATH)" \
293 -C cluster1.cpu1.semihosting-cwd="$(BINARIES_PATH)" \
294 -C cluster1.cpu2.semihosting-cwd="$(BINARIES_PATH)" \
295 -C cluster1.cpu3.semihosting-cwd="$(BINARIES_PATH)" \
Balint Dobszayc394dcd2022-05-23 18:32:57 +0200296 -C bp.secure_memory=1 \
297 -C bp.secureflashloader.fname=$(TF_A_PATH)/build/fvp/$(TF_A_BUILD)/bl1.bin \
298 -C bp.flashloader0.fname=$(TF_A_PATH)/build/fvp/$(TF_A_BUILD)/fip.bin \
299 -C bp.virtioblockdevice.image_path=$(BOOT_IMG)
Gabor Ambrus557af272023-08-16 12:59:55 +0200300ifeq ($(TS_LOGGING_SP),y)
301 FVP_ARGS += -C bp.pl011_uart2.out_file=$(TS_LOGGING_SP_LOG)
302endif
Balint Dobszay276212d2022-05-24 18:45:34 +0200303ifeq ($(FVP_VIRTFS_ENABLE),y)
304 FVP_ARGS += -C bp.virtiop9device.root_path=$(FVP_VIRTFS_HOST_DIR)
305endif
Balint Dobszay5e188572022-06-07 13:10:34 +0200306
307run-only:
Gabor Tothde2f8932023-03-09 12:12:46 +0100308 $(FVP_PATH)/$(FVP_BIN) $(FVP_ARGS) $(FVP_EXTRA_ARGS)