blob: 2f1f658caaad7bfd06ba934f36f2613034bfa564 [file] [log] [blame]
Pascal Brand6044eb52016-02-23 15:48:31 +01001################################################################################
2# Following variables defines how the NS_USER (Non Secure User - Client
3# Application), NS_KERNEL (Non Secure Kernel), S_KERNEL (Secure Kernel) and
4# S_USER (Secure User - TA) are compiled
5################################################################################
Pascal Brandefe56592016-03-03 10:46:52 +01006COMPILE_NS_USER ?= 64
7override COMPILE_NS_KERNEL := 64
Pascal Brand6044eb52016-02-23 15:48:31 +01008COMPILE_S_USER ?= 64
9COMPILE_S_KERNEL ?= 64
10
Etienne Carriere3768a2b2019-05-14 17:13:19 +020011OPTEE_OS_PLATFORM = vexpress-fvp
12
Victor Chong7a716512017-09-11 15:18:44 +010013include common.mk
Pascal Brandd6536da2015-09-01 10:38:43 +020014
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000015################################################################################
16# Variables used for TPM configuration.
17################################################################################
18BR2_ROOTFS_OVERLAY = $(ROOT)/build/br-ext/board/fvp/overlay
19BR2_PACKAGE_FTPM_OPTEE_EXT_SITE ?= $(CURDIR)/br-ext/package/ftpm_optee_ext
20BR2_PACKAGE_FTPM_OPTEE_PACKAGE_SITE ?= $(ROOT)/ms-tpm-20-ref
21
22# The fTPM implementation is based on ARM32 architecture whereas the rest of the
23# system is built to run on 64-bit mode (COMPILE_S_USER = 64). Therefore set
24# BR2_PACKAGE_FTPM_OPTEE_EXT_SDK manually to the arm32 OPTEE toolkit rather than
25# relying on OPTEE_OS_TA_DEV_KIT_DIR variable.
26BR2_PACKAGE_FTPM_OPTEE_EXT_SDK ?= $(OPTEE_OS_PATH)/out/arm/export-ta_arm32
27
28BR2_PACKAGE_LINUX_FTPM_MOD_EXT_SITE ?= $(CURDIR)/br-ext/package/linux_ftpm_mod_ext
29BR2_PACKAGE_LINUX_FTPM_MOD_EXT_PATH ?= $(LINUX_PATH)
Joakim Bech427dd632015-05-04 15:52:33 +020030
31################################################################################
32# Paths to git projects and various binaries
33################################################################################
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000034MEASURED_BOOT ?= n
Victor Chongdf54b112019-08-11 15:58:12 +010035TF_A_PATH ?= $(ROOT)/trusted-firmware-a
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000036ifeq ($(MEASURED_BOOT),y)
37# Prefer release mode for TF-A if using Measured Boot, debug may exhaust memory.
38TF_A_BUILD ?= release
39endif
Victor Chongeca7cfd2019-11-08 09:18:05 +000040ifeq ($(DEBUG),1)
41TF_A_BUILD ?= debug
42else
43TF_A_BUILD ?= release
44endif
Pascal Brandd6536da2015-09-01 10:38:43 +020045EDK2_PATH ?= $(ROOT)/edk2
Joakim Bechab622612017-11-15 10:45:28 +010046EDK2_PLATFORMS_PATH ?= $(ROOT)/edk2-platforms
Victor Chongd79d6672019-11-08 09:50:30 +000047EDK2_TOOLCHAIN ?= GCC49
48EDK2_ARCH ?= AARCH64
Victor Chongeca7cfd2019-11-08 09:18:05 +000049ifeq ($(DEBUG),1)
50EDK2_BUILD ?= DEBUG
51else
52EDK2_BUILD ?= RELEASE
53endif
Victor Chongd79d6672019-11-08 09:50:30 +000054EDK2_BIN ?= $(EDK2_PLATFORMS_PATH)/Build/ArmVExpress-FVP-AArch64/$(EDK2_BUILD)_$(EDK2_TOOLCHAIN)/FV/FVP_$(EDK2_ARCH)_EFI.fd
Balint Dobszayc394dcd2022-05-23 18:32:57 +020055FVP_USE_BASE_PLAT ?= n
56ifeq ($(FVP_USE_BASE_PLAT),y)
57FVP_PATH ?= $(ROOT)/Base_RevC_AEMvA_pkg/models/Linux64_GCC-9.3
58FVP_BIN ?= FVP_Base_RevC-2xAEMvA
59FVP_LINUX_DTB ?= $(LINUX_PATH)/arch/arm64/boot/dts/arm/fvp-base-revc.dtb
60else
Balint Dobszay5e188572022-06-07 13:10:34 +020061FVP_PATH ?= $(ROOT)/Foundation_Platformpkg/models/Linux64_GCC-9.3
62FVP_BIN ?= Foundation_Platform
Balint Dobszayc394dcd2022-05-23 18:32:57 +020063FVP_LINUX_DTB ?= $(LINUX_PATH)/arch/arm64/boot/dts/arm/foundation-v8-gicv3-psci.dtb
64endif
Balint Dobszay5e188572022-06-07 13:10:34 +020065ifeq ($(wildcard $(FVP_PATH)),)
66$(error $(FVP_PATH) does not exist)
Pascal Brand9a0f50f2015-09-08 15:34:17 +020067endif
Joakim Bech277ddad2017-11-15 09:33:21 +010068GRUB_PATH ?= $(ROOT)/grub
69GRUB_CONFIG_PATH ?= $(BUILD_PATH)/fvp/grub
70OUT_PATH ?= $(ROOT)/out
71GRUB_BIN ?= $(OUT_PATH)/bootaa64.efi
Joakim Bechab622612017-11-15 10:45:28 +010072BOOT_IMG ?= $(OUT_PATH)/boot-fat.uefi.img
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000073FTPM_PATH ?= $(ROOT)/ms-tpm-20-ref/Samples/ARM32-FirmwareTPM/optee_ta
74
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000075ifeq ($(MEASURED_BOOT),y)
Balint Dobszay35e60992022-06-10 16:19:10 +020076# By default enable FTPM for backwards compatibility.
77MEASURED_BOOT_FTPM ?= y
78else
79$(call force,MEASURED_BOOT_FTPM,n,requires MEASURED_BOOT enabled)
80endif
81
82# Build ancillary components to access fTPM if Measured Boot is enabled.
83ifeq ($(MEASURED_BOOT_FTPM),y)
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000084DEFCONFIG_FTPM ?= --br-defconfig build/br-ext/configs/ftpm_optee
85DEFCONFIG_TPM_MODULE ?= --br-defconfig build/br-ext/configs/linux_ftpm
86DEFCONFIG_TSS ?= --br-defconfig build/br-ext/configs/tss
87endif
Joakim Bech427dd632015-05-04 15:52:33 +020088
89################################################################################
Joakim Bech427dd632015-05-04 15:52:33 +020090# Targets
91################################################################################
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000092all: arm-tf optee-os ftpm boot-img linux edk2
Jens Wiklander41a0dfe2018-02-05 22:55:02 +010093clean: arm-tf-clean boot-img-clean buildroot-clean edk2-clean grub-clean \
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +000094 ftpm-clean optee-os-clean
Joakim Bech427dd632015-05-04 15:52:33 +020095
Victor Chong7a716512017-09-11 15:18:44 +010096include toolchain.mk
Joakim Bech427dd632015-05-04 15:52:33 +020097
98################################################################################
Joakim Bech277ddad2017-11-15 09:33:21 +010099# Folders
100################################################################################
101$(OUT_PATH):
102 mkdir -p $@
103
104################################################################################
Balint Dobszay276212d2022-05-24 18:45:34 +0200105# Shared folder
106################################################################################
107# Enable accessing the host directory FVP_VIRTFS_HOST_DIR from the FVP.
108# The shared folder can be mounted in the following ways:
109# - Run 'mount -t 9p -o trans=virtio,version=9p2000.L FM <mount point>' or,
110# - enable FVP_VIRTFS_AUTOMOUNT.
111# The latter will use the Buildroot post-build script to add an entry to the
112# target's /etc/fstab, mounting the shared directory to FVP_VIRTFS_MOUNTPOINT
113# on the FVP.
114# Note: the post-build script can only append to fstab. If FVP_VIRTFS_AUTOMOUNT
115# is changed from "y" to "n", run 'rm -r ../out-br/build/skeleton-init-sysv' so
116# the target's fstab will be replaced with the unmodified original again.
117FVP_VIRTFS_ENABLE ?= n
118FVP_VIRTFS_HOST_DIR ?= $(ROOT)
119FVP_VIRTFS_AUTOMOUNT ?= n
120FVP_VIRTFS_MOUNTPOINT ?= /mnt/host
121
122ifeq ($(FVP_VIRTFS_AUTOMOUNT),y)
123$(call force,FVP_VIRTFS_ENABLE,y,required by FVP_VIRTFS_AUTOMOUNT)
124endif
125
126ifneq ($(FVP_USE_BASE_PLAT),y)
127$(call force,FVP_VIRTFS_ENABLE,n,only supported on FVP Base Platform)
128endif
129
130BR2_ROOTFS_POST_BUILD_SCRIPT = $(ROOT)/build/br-ext/board/fvp/post-build.sh
131BR2_ROOTFS_POST_SCRIPT_ARGS = "$(FVP_VIRTFS_AUTOMOUNT) $(FVP_VIRTFS_MOUNTPOINT)"
132
133################################################################################
Joakim Bech427dd632015-05-04 15:52:33 +0200134# ARM Trusted Firmware
135################################################################################
Victor Chong371d7c22019-08-08 17:17:14 +0100136TF_A_EXPORTS ?= \
Joakim Bech69a8a372016-04-26 11:05:04 +0200137 CROSS_COMPILE="$(CCACHE)$(AARCH64_CROSS_COMPILE)"
Pascal Brandb130ea22015-10-13 13:18:36 +0200138
Victor Chong371d7c22019-08-08 17:17:14 +0100139TF_A_FLAGS ?= \
Jens Wiklander0b3eb332017-09-01 09:32:34 +0200140 BL32=$(OPTEE_OS_HEADER_V2_BIN) \
141 BL32_EXTRA1=$(OPTEE_OS_PAGER_V2_BIN) \
142 BL32_EXTRA2=$(OPTEE_OS_PAGEABLE_V2_BIN) \
Joakim Bech427dd632015-05-04 15:52:33 +0200143 BL33=$(EDK2_BIN) \
Jens Wiklander6d923942016-01-08 15:33:03 +0100144 ARM_TSP_RAM_LOCATION=tdram \
Jerome Forissier0c761952018-11-09 11:09:26 +0100145 FVP_USE_GIC_DRIVER=FVP_GICV3 \
Pascal Brandb130ea22015-10-13 13:18:36 +0200146 PLAT=fvp \
147 SPD=opteed
148
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000149ifneq ($(MEASURED_BOOT),y)
Gyorgy09805302022-11-30 12:36:17 +0000150 TF_A_FLAGS += DEBUG=$(DEBUG) \
151 MEASURED_BOOT=0
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000152else
153 TF_A_FLAGS += DEBUG=0 \
154 MBEDTLS_DIR=$(ROOT)/mbedtls \
155 ARM_ROTPK_LOCATION=devel_rsa \
156 GENERATE_COT=1 \
157 MEASURED_BOOT=1 \
158 ROT_KEY=plat/arm/board/common/rotpk/arm_rotprivk_rsa.pem \
159 TPM_HASH_ALG=sha256 \
160 TRUSTED_BOARD_BOOT=1 \
161 EVENT_LOG_LEVEL=20
162endif
163
Pascal Brandb130ea22015-10-13 13:18:36 +0200164arm-tf: optee-os edk2
Victor Chong371d7c22019-08-08 17:17:14 +0100165 $(TF_A_EXPORTS) $(MAKE) -C $(TF_A_PATH) $(TF_A_FLAGS) all fip
Joakim Bech427dd632015-05-04 15:52:33 +0200166
167arm-tf-clean:
Victor Chong371d7c22019-08-08 17:17:14 +0100168 $(TF_A_EXPORTS) $(MAKE) -C $(TF_A_PATH) $(TF_A_FLAGS) clean
Joakim Bech427dd632015-05-04 15:52:33 +0200169
170################################################################################
Joakim Bech427dd632015-05-04 15:52:33 +0200171# EDK2 / Tianocore
172################################################################################
Joakim Bechc94e95a2017-11-25 11:06:50 +0100173define edk2-env
174 export WORKSPACE=$(EDK2_PLATFORMS_PATH)
175endef
176
Pascal Brand9a0f50f2015-09-08 15:34:17 +0200177define edk2-call
Victor Chongd79d6672019-11-08 09:50:30 +0000178 $(EDK2_TOOLCHAIN)_$(EDK2_ARCH)_PREFIX=$(AARCH64_CROSS_COMPILE) \
179 build -n `getconf _NPROCESSORS_ONLN` -a $(EDK2_ARCH) \
180 -t $(EDK2_TOOLCHAIN) -p Platform/ARM/VExpressPkg/ArmVExpress-FVP-AArch64.dsc -b $(EDK2_BUILD)
Joakim Bech427dd632015-05-04 15:52:33 +0200181endef
182
Pascal Brand9a0f50f2015-09-08 15:34:17 +0200183edk2: edk2-common
Joakim Bech427dd632015-05-04 15:52:33 +0200184
Pascal Brand9a0f50f2015-09-08 15:34:17 +0200185edk2-clean: edk2-clean-common
Joakim Bech427dd632015-05-04 15:52:33 +0200186
187################################################################################
188# Linux kernel
189################################################################################
Jerome Forissiere1002382015-11-26 11:36:00 +0100190LINUX_DEFCONFIG_COMMON_ARCH := arm64
Balint Dobszay3730e012023-06-02 11:40:41 +0200191LINUX_DEFCONFIG_COMMON_FILES ?= \
Jerome Forissiere1002382015-11-26 11:36:00 +0100192 $(LINUX_PATH)/arch/arm64/configs/defconfig \
193 $(CURDIR)/kconfigs/fvp.conf
Joakim Bech427dd632015-05-04 15:52:33 +0200194
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000195.PHONY: linux-ftpm-module
196linux-ftpm-module: linux
Balint Dobszay35e60992022-06-10 16:19:10 +0200197ifeq ($(MEASURED_BOOT_FTPM),y)
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000198linux-ftpm-module:
199 $(MAKE) -C $(LINUX_PATH) $(LINUX_COMMON_FLAGS) M=drivers/char/tpm \
200 modules_install INSTALL_MOD_PATH=$(LINUX_PATH)
201endif
202
Joakim Bech427dd632015-05-04 15:52:33 +0200203linux-defconfig: $(LINUX_PATH)/.config
204
Pascal Brande3d85982015-09-10 17:20:42 +0200205LINUX_COMMON_FLAGS += ARCH=arm64
206
207linux: linux-common
208
209linux-defconfig-clean: linux-defconfig-clean-common
210
211LINUX_CLEAN_COMMON_FLAGS += ARCH=arm64
212
213linux-clean: linux-clean-common
214
215LINUX_CLEANER_COMMON_FLAGS += ARCH=arm64
216
217linux-cleaner: linux-cleaner-common
Joakim Bech427dd632015-05-04 15:52:33 +0200218
219################################################################################
220# OP-TEE
221################################################################################
Etienne Carriere3768a2b2019-05-14 17:13:19 +0200222OPTEE_OS_COMMON_FLAGS += CFG_ARM_GICV3=y
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000223
224ifeq ($(MEASURED_BOOT),y)
225 OPTEE_OS_COMMON_FLAGS += CFG_DT=y CFG_CORE_TPM_EVENT_LOG=y
226endif
227
Jerome Forissierae45fbf2015-09-04 09:40:17 +0200228optee-os: optee-os-common
Joakim Bech427dd632015-05-04 15:52:33 +0200229
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000230optee-os-clean: ftpm-clean optee-os-clean-common
231
232################################################################################
233# Buildroot
234################################################################################
235
236buildroot: linux-ftpm-module
Joakim Bech427dd632015-05-04 15:52:33 +0200237
Joakim Bech427dd632015-05-04 15:52:33 +0200238################################################################################
Joakim Bech277ddad2017-11-15 09:33:21 +0100239# grub
240################################################################################
241grub-flags := CC="$(CCACHE)gcc" \
242 TARGET_CC="$(AARCH64_CROSS_COMPILE)gcc" \
243 TARGET_OBJCOPY="$(AARCH64_CROSS_COMPILE)objcopy" \
244 TARGET_NM="$(AARCH64_CROSS_COMPILE)nm" \
245 TARGET_RANLIB="$(AARCH64_CROSS_COMPILE)ranlib" \
Jens Wiklander3b5d8f02018-06-27 09:16:24 +0200246 TARGET_STRIP="$(AARCH64_CROSS_COMPILE)strip" \
247 --disable-werror
Joakim Bech277ddad2017-11-15 09:33:21 +0100248
249GRUB_MODULES += boot chain configfile echo efinet eval ext2 fat font gettext \
250 gfxterm gzio help linux loadenv lsefi normal part_gpt \
251 part_msdos read regexp search search_fs_file search_fs_uuid \
252 search_label terminal terminfo test tftp time
253
254$(GRUB_PATH)/configure: $(GRUB_PATH)/configure.ac
255 cd $(GRUB_PATH) && ./autogen.sh
256
257$(GRUB_PATH)/Makefile: $(GRUB_PATH)/configure
258 cd $(GRUB_PATH) && ./configure --target=aarch64 --enable-boot-time $(grub-flags)
259
260.PHONY: grub
261grub: $(GRUB_PATH)/Makefile | $(OUT_PATH)
262 $(MAKE) -C $(GRUB_PATH) && \
263 cd $(GRUB_PATH) && ./grub-mkimage \
264 --output=$(GRUB_BIN) \
265 --config=$(GRUB_CONFIG_PATH)/grub.cfg \
266 --format=arm64-efi \
267 --directory=grub-core \
268 --prefix=/boot/grub \
269 $(GRUB_MODULES)
270
271.PHONY: grub-clean
272grub-clean:
273 @if [ -e $(GRUB_PATH)/Makefile ]; then $(MAKE) -C $(GRUB_PATH) clean; fi
274 @rm -f $(GRUB_BIN)
275 @rm -f $(GRUB_PATH)/configure
276
277
278################################################################################
Joakim Bechab622612017-11-15 10:45:28 +0100279# Boot Image
280################################################################################
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000281
Joakim Bechab622612017-11-15 10:45:28 +0100282.PHONY: boot-img
Javier Almansa Sobrinocf568482020-02-26 11:51:45 +0000283boot-img: grub buildroot
Joakim Bechab622612017-11-15 10:45:28 +0100284 rm -f $(BOOT_IMG)
285 mformat -i $(BOOT_IMG) -n 64 -h 255 -T 131072 -v "BOOT IMG" -C ::
286 mcopy -i $(BOOT_IMG) $(LINUX_PATH)/arch/arm64/boot/Image ::
Balint Dobszayc394dcd2022-05-23 18:32:57 +0200287 mcopy -i $(BOOT_IMG) $(FVP_LINUX_DTB) ::/fvp.dtb
Joakim Bechab622612017-11-15 10:45:28 +0100288 mmd -i $(BOOT_IMG) ::/EFI
289 mmd -i $(BOOT_IMG) ::/EFI/BOOT
Jens Wiklander41a0dfe2018-02-05 22:55:02 +0100290 mcopy -i $(BOOT_IMG) $(ROOT)/out-br/images/rootfs.cpio.gz ::/initrd.img
Joakim Bechab622612017-11-15 10:45:28 +0100291 mcopy -i $(BOOT_IMG) $(GRUB_BIN) ::/EFI/BOOT/bootaa64.efi
292 mcopy -i $(BOOT_IMG) $(GRUB_CONFIG_PATH)/grub.cfg ::/EFI/BOOT/grub.cfg
293
294.PHONY: boot-img-clean
295boot-img-clean:
296 rm -f $(BOOT_IMG)
297
298################################################################################
Joakim Bech427dd632015-05-04 15:52:33 +0200299# Run targets
300################################################################################
301# This target enforces updating root fs etc
Pascal Brand15271692015-09-08 10:42:22 +0200302run: all
Pascal Brand15271692015-09-08 10:42:22 +0200303 $(MAKE) run-only
Joakim Bech427dd632015-05-04 15:52:33 +0200304
Balint Dobszayc394dcd2022-05-23 18:32:57 +0200305ifeq ($(FVP_USE_BASE_PLAT),y)
306FVP_ARGS ?= \
307 -C bp.ve_sysregs.exit_on_shutdown=1 \
308 -C cache_state_modelled=0 \
309 -C pctl.startup=0.0.0.0 \
310 -C cluster0.NUM_CORES=4 \
311 -C cluster1.NUM_CORES=4 \
Balint Dobszay4791acb2023-04-24 13:39:19 +0200312 -C cluster0.cpu0.enable_crc32=1 \
313 -C cluster0.cpu1.enable_crc32=1 \
314 -C cluster0.cpu2.enable_crc32=1 \
315 -C cluster0.cpu3.enable_crc32=1 \
316 -C cluster1.cpu0.enable_crc32=1 \
317 -C cluster1.cpu1.enable_crc32=1 \
318 -C cluster1.cpu2.enable_crc32=1 \
319 -C cluster1.cpu3.enable_crc32=1 \
Balint Dobszayc394dcd2022-05-23 18:32:57 +0200320 -C bp.secure_memory=1 \
321 -C bp.secureflashloader.fname=$(TF_A_PATH)/build/fvp/$(TF_A_BUILD)/bl1.bin \
322 -C bp.flashloader0.fname=$(TF_A_PATH)/build/fvp/$(TF_A_BUILD)/fip.bin \
323 -C bp.virtioblockdevice.image_path=$(BOOT_IMG)
Balint Dobszay276212d2022-05-24 18:45:34 +0200324ifeq ($(FVP_VIRTFS_ENABLE),y)
325 FVP_ARGS += -C bp.virtiop9device.root_path=$(FVP_VIRTFS_HOST_DIR)
326endif
Balint Dobszayc394dcd2022-05-23 18:32:57 +0200327else
Balint Dobszay5e188572022-06-07 13:10:34 +0200328FVP_ARGS ?= \
Jens Wiklanderedaa02b2017-03-28 17:41:11 +0200329 --arm-v8.0 \
Joakim Bech427dd632015-05-04 15:52:33 +0200330 --cores=4 \
331 --secure-memory \
332 --visualization \
333 --gicv3 \
Victor Chongeca7cfd2019-11-08 09:18:05 +0000334 --data="$(TF_A_PATH)/build/fvp/$(TF_A_BUILD)/bl1.bin"@0x0 \
335 --data="$(TF_A_PATH)/build/fvp/$(TF_A_BUILD)/fip.bin"@0x8000000 \
Joakim Bechab622612017-11-15 10:45:28 +0100336 --block-device=$(BOOT_IMG)
Balint Dobszayc394dcd2022-05-23 18:32:57 +0200337endif
Balint Dobszay5e188572022-06-07 13:10:34 +0200338
339run-only:
Gabor Tothde2f8932023-03-09 12:12:46 +0100340 $(FVP_PATH)/$(FVP_BIN) $(FVP_ARGS) $(FVP_EXTRA_ARGS)