blob: 36a0dcd902302120a4a2087f77c4a8c43a2d2c21 [file] [log] [blame]
David Brown63902772017-07-12 09:47:49 -06001// Build mcuboot as a library, based on the requested features.
2
Fabio Utzig455cad52018-10-15 14:36:33 -07003extern crate cc;
David Brown63902772017-07-12 09:47:49 -06004
5use std::env;
6use std::fs;
7use std::io;
8use std::path::Path;
9
10fn main() {
11 // Feature flags.
12 let sig_rsa = env::var("CARGO_FEATURE_SIG_RSA").is_ok();
Fabio Utzig39297432019-05-08 18:51:10 -030013 let sig_rsa3072 = env::var("CARGO_FEATURE_SIG_RSA3072").is_ok();
David Brown63902772017-07-12 09:47:49 -060014 let sig_ecdsa = env::var("CARGO_FEATURE_SIG_ECDSA").is_ok();
Fabio Utzig97710282019-05-24 17:44:49 -030015 let sig_ed25519 = env::var("CARGO_FEATURE_SIG_ED25519").is_ok();
David Brown63902772017-07-12 09:47:49 -060016 let overwrite_only = env::var("CARGO_FEATURE_OVERWRITE_ONLY").is_ok();
Fabio Utzig031eb7d2019-11-28 10:13:14 -030017 let swap_move = env::var("CARGO_FEATURE_SWAP_MOVE").is_ok();
David Vincze2d736ad2019-02-18 11:50:22 +010018 let validate_primary_slot =
19 env::var("CARGO_FEATURE_VALIDATE_PRIMARY_SLOT").is_ok();
Fabio Utzig1e48b912018-09-18 09:04:18 -030020 let enc_rsa = env::var("CARGO_FEATURE_ENC_RSA").is_ok();
21 let enc_kw = env::var("CARGO_FEATURE_ENC_KW").is_ok();
Fabio Utzig90f449e2019-10-24 07:43:53 -030022 let enc_ec256 = env::var("CARGO_FEATURE_ENC_EC256").is_ok();
Fabio Utzig3fa72ca2020-04-02 11:20:37 -030023 let enc_x25519 = env::var("CARGO_FEATURE_ENC_X25519").is_ok();
Fabio Utzig9b97b132018-12-18 17:21:51 -020024 let bootstrap = env::var("CARGO_FEATURE_BOOTSTRAP").is_ok();
David Brown5e6f5e02019-04-04 10:50:05 +070025 let multiimage = env::var("CARGO_FEATURE_MULTIIMAGE").is_ok();
David Brown2ee5f7f2020-01-13 14:04:01 -070026 let downgrade_prevention = env::var("CARGO_FEATURE_DOWNGRADE_PREVENTION").is_ok();
David Brown63902772017-07-12 09:47:49 -060027
Fabio Utzig455cad52018-10-15 14:36:33 -070028 let mut conf = cc::Build::new();
David Brown63902772017-07-12 09:47:49 -060029 conf.define("__BOOTSIM__", None);
Fabio Utzig08fcfe92018-11-26 10:18:18 -020030 conf.define("MCUBOOT_HAVE_LOGGING", None);
David Brown63902772017-07-12 09:47:49 -060031 conf.define("MCUBOOT_USE_FLASH_AREA_GET_SECTORS", None);
Marti Bolivar248da082018-04-24 15:11:39 -040032 conf.define("MCUBOOT_HAVE_ASSERT_H", None);
Marti Bolivarf9bfddd2018-04-24 14:28:33 -040033 conf.define("MCUBOOT_MAX_IMG_SECTORS", Some("128"));
David Brown5e6f5e02019-04-04 10:50:05 +070034 conf.define("MCUBOOT_IMAGE_NUMBER", Some(if multiimage { "2" } else { "1" }));
Fabio Utzigebdc9692017-11-23 16:28:25 -020035
David Brown2ee5f7f2020-01-13 14:04:01 -070036 if downgrade_prevention && !overwrite_only {
37 panic!("Downgrade prevention requires overwrite only");
38 }
39
Fabio Utzig9b97b132018-12-18 17:21:51 -020040 if bootstrap {
41 conf.define("MCUBOOT_BOOTSTRAP", None);
Fabio Utzig3c9d5c42020-10-04 10:12:53 -030042 conf.define("MCUBOOT_OVERWRITE_ONLY_FAST", None);
Fabio Utzig9b97b132018-12-18 17:21:51 -020043 }
44
David Vincze2d736ad2019-02-18 11:50:22 +010045 if validate_primary_slot {
46 conf.define("MCUBOOT_VALIDATE_PRIMARY_SLOT", None);
Fabio Utzigebdc9692017-11-23 16:28:25 -020047 }
David Brown63902772017-07-12 09:47:49 -060048
David Brown2ee5f7f2020-01-13 14:04:01 -070049 if downgrade_prevention {
50 conf.define("MCUBOOT_DOWNGRADE_PREVENTION", None);
51 }
52
Fabio Utzig39297432019-05-08 18:51:10 -030053 // Currently no more than one sig type can be used simultaneously.
Fabio Utzig97710282019-05-24 17:44:49 -030054 if vec![sig_rsa, sig_rsa3072, sig_ecdsa, sig_ed25519].iter()
Fabio Utzig39297432019-05-08 18:51:10 -030055 .fold(0, |sum, &v| sum + v as i32) > 1 {
56 panic!("mcuboot does not support more than one sig type at the same time");
David Brown704ac6f2017-07-12 10:14:47 -060057 }
David Brown63902772017-07-12 09:47:49 -060058
Fabio Utzig39297432019-05-08 18:51:10 -030059 if sig_rsa || sig_rsa3072 {
David Brown63902772017-07-12 09:47:49 -060060 conf.define("MCUBOOT_SIGN_RSA", None);
Fabio Utzig39297432019-05-08 18:51:10 -030061 // The Kconfig style defines must be added here as well because
62 // they are used internally by "config-rsa.h"
63 if sig_rsa {
64 conf.define("MCUBOOT_SIGN_RSA_LEN", "2048");
Fabio Utzig46268532020-01-04 21:12:55 -030065 conf.define("CONFIG_BOOT_SIGNATURE_TYPE_RSA_LEN", "2048");
Fabio Utzig39297432019-05-08 18:51:10 -030066 } else {
67 conf.define("MCUBOOT_SIGN_RSA_LEN", "3072");
Fabio Utzig46268532020-01-04 21:12:55 -030068 conf.define("CONFIG_BOOT_SIGNATURE_TYPE_RSA_LEN", "3072");
Fabio Utzig39297432019-05-08 18:51:10 -030069 }
David Brown63902772017-07-12 09:47:49 -060070 conf.define("MCUBOOT_USE_MBED_TLS", None);
71
Fabio Utzige60b12f2020-02-06 07:15:30 -030072 conf.include("../../ext/mbedtls/crypto/include");
73 conf.file("../../ext/mbedtls/crypto/library/sha256.c");
Fabio Utzig806af0e2018-04-26 10:53:54 -030074 conf.file("csupport/keys.c");
David Brown63902772017-07-12 09:47:49 -060075
Fabio Utzige60b12f2020-02-06 07:15:30 -030076 conf.file("../../ext/mbedtls/crypto/library/rsa.c");
77 conf.file("../../ext/mbedtls/crypto/library/bignum.c");
78 conf.file("../../ext/mbedtls/crypto/library/platform.c");
79 conf.file("../../ext/mbedtls/crypto/library/platform_util.c");
80 conf.file("../../ext/mbedtls/crypto/library/asn1parse.c");
David Brown704ac6f2017-07-12 10:14:47 -060081 } else if sig_ecdsa {
Fabio Utzigc7865402017-12-05 08:50:52 -020082 conf.define("MCUBOOT_SIGN_EC256", None);
David Brown63902772017-07-12 09:47:49 -060083 conf.define("MCUBOOT_USE_TINYCRYPT", None);
Fabio Utzigc7865402017-12-05 08:50:52 -020084
Fabio Utzigb4d20c82018-12-27 16:08:39 -020085 if !enc_kw {
David Brownb748f6f2019-10-11 10:07:31 -060086 conf.include("../../ext/mbedtls-asn1/include");
Fabio Utzigb4d20c82018-12-27 16:08:39 -020087 }
Fabio Utzigc7865402017-12-05 08:50:52 -020088 conf.include("../../ext/tinycrypt/lib/include");
89
Fabio Utzig806af0e2018-04-26 10:53:54 -030090 conf.file("csupport/keys.c");
Fabio Utzigc7865402017-12-05 08:50:52 -020091
92 conf.file("../../ext/tinycrypt/lib/source/utils.c");
93 conf.file("../../ext/tinycrypt/lib/source/sha256.c");
94 conf.file("../../ext/tinycrypt/lib/source/ecc.c");
95 conf.file("../../ext/tinycrypt/lib/source/ecc_dsa.c");
96 conf.file("../../ext/tinycrypt/lib/source/ecc_platform_specific.c");
97
David Brownb748f6f2019-10-11 10:07:31 -060098 conf.file("../../ext/mbedtls-asn1/src/platform_util.c");
99 conf.file("../../ext/mbedtls-asn1/src/asn1parse.c");
Fabio Utzig97710282019-05-24 17:44:49 -0300100 } else if sig_ed25519 {
101 conf.define("MCUBOOT_SIGN_ED25519", None);
Fabio Utziga1c142d2020-01-03 08:28:11 -0300102 conf.define("MCUBOOT_USE_TINYCRYPT", None);
Fabio Utzig97710282019-05-24 17:44:49 -0300103
Fabio Utziga1c142d2020-01-03 08:28:11 -0300104 conf.include("../../ext/tinycrypt/lib/include");
105 conf.include("../../ext/tinycrypt-sha512/lib/include");
106 conf.include("../../ext/mbedtls-asn1/include");
107 conf.file("../../ext/tinycrypt/lib/source/sha256.c");
108 conf.file("../../ext/tinycrypt-sha512/lib/source/sha512.c");
109 conf.file("../../ext/tinycrypt/lib/source/utils.c");
Fabio Utzig97710282019-05-24 17:44:49 -0300110 conf.file("csupport/keys.c");
111 conf.file("../../ext/fiat/src/curve25519.c");
Fabio Utziga1c142d2020-01-03 08:28:11 -0300112 conf.file("../../ext/mbedtls-asn1/src/platform_util.c");
113 conf.file("../../ext/mbedtls-asn1/src/asn1parse.c");
Fabio Utzig3fa72ca2020-04-02 11:20:37 -0300114 } else if !enc_ec256 && !enc_x25519 {
Fabio Utzig90f449e2019-10-24 07:43:53 -0300115 // No signature type, only sha256 validation. The default
Marti Bolivara4818a52018-04-12 13:02:38 -0400116 // configuration file bundled with mbedTLS is sufficient.
Fabio Utzig90f449e2019-10-24 07:43:53 -0300117 // When using ECIES-P256 rely on Tinycrypt.
David Brown704ac6f2017-07-12 10:14:47 -0600118 conf.define("MCUBOOT_USE_MBED_TLS", None);
Fabio Utzige60b12f2020-02-06 07:15:30 -0300119 conf.include("../../ext/mbedtls/crypto/include");
120 conf.file("../../ext/mbedtls/crypto/library/sha256.c");
David Brown63902772017-07-12 09:47:49 -0600121 }
122
123 if overwrite_only {
124 conf.define("MCUBOOT_OVERWRITE_ONLY", None);
125 }
126
Fabio Utzig031eb7d2019-11-28 10:13:14 -0300127 if swap_move {
128 conf.define("MCUBOOT_SWAP_USING_MOVE", None);
129 }
130
Fabio Utzig1e48b912018-09-18 09:04:18 -0300131 if enc_rsa {
132 conf.define("MCUBOOT_ENCRYPT_RSA", None);
133 conf.define("MCUBOOT_ENC_IMAGES", None);
134 conf.define("MCUBOOT_USE_MBED_TLS", None);
Fabio Utzig1e48b912018-09-18 09:04:18 -0300135
136 conf.file("../../boot/bootutil/src/encrypted.c");
137 conf.file("csupport/keys.c");
138
Fabio Utzige60b12f2020-02-06 07:15:30 -0300139 conf.include("../../ext/mbedtls/crypto/include");
140 conf.file("../../ext/mbedtls/crypto/library/sha256.c");
Fabio Utzig1e48b912018-09-18 09:04:18 -0300141
Fabio Utzige60b12f2020-02-06 07:15:30 -0300142 conf.file("../../ext/mbedtls/crypto/library/platform.c");
143 conf.file("../../ext/mbedtls/crypto/library/platform_util.c");
144 conf.file("../../ext/mbedtls/crypto/library/rsa.c");
145 conf.file("../../ext/mbedtls/crypto/library/rsa_internal.c");
146 conf.file("../../ext/mbedtls/crypto/library/md.c");
147 conf.file("../../ext/mbedtls/crypto/library/aes.c");
148 conf.file("../../ext/mbedtls/crypto/library/bignum.c");
149 conf.file("../../ext/mbedtls/crypto/library/asn1parse.c");
Fabio Utzig1e48b912018-09-18 09:04:18 -0300150 }
151
152 if enc_kw {
153 conf.define("MCUBOOT_ENCRYPT_KW", None);
154 conf.define("MCUBOOT_ENC_IMAGES", None);
Fabio Utzig1e48b912018-09-18 09:04:18 -0300155
156 conf.file("../../boot/bootutil/src/encrypted.c");
157 conf.file("csupport/keys.c");
158
Fabio Utzig39297432019-05-08 18:51:10 -0300159 if sig_rsa || sig_rsa3072 {
Fabio Utzige60b12f2020-02-06 07:15:30 -0300160 conf.file("../../ext/mbedtls/crypto/library/sha256.c");
Fabio Utzigb4d20c82018-12-27 16:08:39 -0200161 }
Fabio Utzig1e48b912018-09-18 09:04:18 -0300162
Fabio Utzigb4d20c82018-12-27 16:08:39 -0200163 /* Simulator uses Mbed-TLS to wrap keys */
Fabio Utzige60b12f2020-02-06 07:15:30 -0300164 conf.include("../../ext/mbedtls/crypto/include");
165 conf.file("../../ext/mbedtls/crypto/library/platform.c");
166 conf.file("../../ext/mbedtls/crypto/library/platform_util.c");
167 conf.file("../../ext/mbedtls/crypto/library/nist_kw.c");
168 conf.file("../../ext/mbedtls/crypto/library/cipher.c");
169 conf.file("../../ext/mbedtls/crypto/library/cipher_wrap.c");
170 conf.file("../../ext/mbedtls/crypto/library/aes.c");
Fabio Utzigb4d20c82018-12-27 16:08:39 -0200171
172 if sig_ecdsa {
173 conf.define("MCUBOOT_USE_TINYCRYPT", None);
174
175 conf.include("../../ext/tinycrypt/lib/include");
176
177 conf.file("../../ext/tinycrypt/lib/source/utils.c");
178 conf.file("../../ext/tinycrypt/lib/source/sha256.c");
179 conf.file("../../ext/tinycrypt/lib/source/aes_encrypt.c");
180 conf.file("../../ext/tinycrypt/lib/source/aes_decrypt.c");
Blaž Hrastnik4f4833d2020-09-14 13:53:31 +0900181 conf.file("../../ext/tinycrypt/lib/source/ctr_mode.c");
Fabio Utzigb4d20c82018-12-27 16:08:39 -0200182 }
Fabio Utzig97710282019-05-24 17:44:49 -0300183
184 if sig_ed25519 {
185 panic!("ed25519 does not support image encryption with KW yet");
186 }
Fabio Utzig1e48b912018-09-18 09:04:18 -0300187 }
188
Fabio Utzig90f449e2019-10-24 07:43:53 -0300189 if enc_ec256 {
190 conf.define("MCUBOOT_ENCRYPT_EC256", None);
191 conf.define("MCUBOOT_ENC_IMAGES", None);
192 conf.define("MCUBOOT_USE_TINYCRYPT", None);
Fabio Utzig4b4ed982020-01-06 09:09:51 -0300193 conf.define("MCUBOOT_SWAP_SAVE_ENCTLV", None);
Fabio Utzig90f449e2019-10-24 07:43:53 -0300194
195 conf.file("../../boot/bootutil/src/encrypted.c");
196 conf.file("csupport/keys.c");
197
198 conf.include("../../ext/mbedtls-asn1/include");
199 conf.include("../../ext/tinycrypt/lib/include");
200
201 /* FIXME: fail with other signature schemes ? */
202
203 conf.file("../../ext/tinycrypt/lib/source/utils.c");
204 conf.file("../../ext/tinycrypt/lib/source/sha256.c");
205 conf.file("../../ext/tinycrypt/lib/source/ecc.c");
206 conf.file("../../ext/tinycrypt/lib/source/ecc_dsa.c");
207 conf.file("../../ext/tinycrypt/lib/source/ecc_platform_specific.c");
208
209 conf.file("../../ext/mbedtls-asn1/src/platform_util.c");
210 conf.file("../../ext/mbedtls-asn1/src/asn1parse.c");
211
212 conf.file("../../ext/tinycrypt/lib/source/aes_encrypt.c");
213 conf.file("../../ext/tinycrypt/lib/source/aes_decrypt.c");
214 conf.file("../../ext/tinycrypt/lib/source/ctr_mode.c");
215 conf.file("../../ext/tinycrypt/lib/source/hmac.c");
216 conf.file("../../ext/tinycrypt/lib/source/ecc_dh.c");
217 }
218
Fabio Utzig3fa72ca2020-04-02 11:20:37 -0300219 if enc_x25519 {
220 conf.define("MCUBOOT_ENCRYPT_X25519", None);
221 conf.define("MCUBOOT_ENC_IMAGES", None);
222 conf.define("MCUBOOT_USE_TINYCRYPT", None);
223 conf.define("MCUBOOT_SWAP_SAVE_ENCTLV", None);
224
225 conf.file("../../boot/bootutil/src/encrypted.c");
226 conf.file("csupport/keys.c");
227
228 conf.include("../../ext/mbedtls-asn1/include");
229 conf.include("../../ext/tinycrypt/lib/include");
230 conf.include("../../ext/tinycrypt-sha512/lib/include");
231
232 conf.file("../../ext/fiat/src/curve25519.c");
233
234 conf.file("../../ext/tinycrypt/lib/source/utils.c");
235 conf.file("../../ext/tinycrypt/lib/source/sha256.c");
236
237 conf.file("../../ext/mbedtls-asn1/src/platform_util.c");
238 conf.file("../../ext/mbedtls-asn1/src/asn1parse.c");
239
240 conf.file("../../ext/tinycrypt/lib/source/aes_encrypt.c");
241 conf.file("../../ext/tinycrypt/lib/source/aes_decrypt.c");
242 conf.file("../../ext/tinycrypt/lib/source/ctr_mode.c");
243 conf.file("../../ext/tinycrypt/lib/source/hmac.c");
244 }
Fabio Utzig90f449e2019-10-24 07:43:53 -0300245
Fabio Utzig251ef1d2018-12-18 17:20:19 -0200246 if sig_rsa && enc_kw {
247 conf.define("MBEDTLS_CONFIG_FILE", Some("<config-rsa-kw.h>"));
Fabio Utzig39297432019-05-08 18:51:10 -0300248 } else if sig_rsa || sig_rsa3072 || enc_rsa {
Fabio Utzig04fd63e2018-12-14 06:43:31 -0200249 conf.define("MBEDTLS_CONFIG_FILE", Some("<config-rsa.h>"));
Fabio Utzig90f449e2019-10-24 07:43:53 -0300250 } else if (sig_ecdsa || enc_ec256) && !enc_kw {
Fabio Utzig04fd63e2018-12-14 06:43:31 -0200251 conf.define("MBEDTLS_CONFIG_FILE", Some("<config-asn1.h>"));
Fabio Utzig3fa72ca2020-04-02 11:20:37 -0300252 } else if sig_ed25519 || enc_x25519 {
Fabio Utziga1c142d2020-01-03 08:28:11 -0300253 conf.define("MBEDTLS_CONFIG_FILE", Some("<config-asn1.h>"));
Fabio Utzig04fd63e2018-12-14 06:43:31 -0200254 } else if enc_kw {
255 conf.define("MBEDTLS_CONFIG_FILE", Some("<config-kw.h>"));
256 }
257
David Brown704ac6f2017-07-12 10:14:47 -0600258 conf.file("../../boot/bootutil/src/image_validate.c");
Fabio Utzig39297432019-05-08 18:51:10 -0300259 if sig_rsa || sig_rsa3072 {
Fabio Utzigc7865402017-12-05 08:50:52 -0200260 conf.file("../../boot/bootutil/src/image_rsa.c");
261 } else if sig_ecdsa {
262 conf.file("../../boot/bootutil/src/image_ec256.c");
Fabio Utzig97710282019-05-24 17:44:49 -0300263 } else if sig_ed25519 {
264 conf.file("../../boot/bootutil/src/image_ed25519.c");
Fabio Utzigc7865402017-12-05 08:50:52 -0200265 }
David Brown63902772017-07-12 09:47:49 -0600266 conf.file("../../boot/bootutil/src/loader.c");
Fabio Utzig031eb7d2019-11-28 10:13:14 -0300267 conf.file("../../boot/bootutil/src/swap_misc.c");
268 conf.file("../../boot/bootutil/src/swap_scratch.c");
269 conf.file("../../boot/bootutil/src/swap_move.c");
David Brown63902772017-07-12 09:47:49 -0600270 conf.file("../../boot/bootutil/src/caps.c");
271 conf.file("../../boot/bootutil/src/bootutil_misc.c");
Andrzej Puzdrowskif573b392020-11-10 14:35:15 +0100272 conf.file("../../boot/bootutil/src/bootutil_public.c");
Fabio Utzig61fd8882019-09-14 20:00:20 -0300273 conf.file("../../boot/bootutil/src/tlv.c");
Raef Colese8fe6cf2020-05-26 13:07:40 +0100274 conf.file("../../boot/bootutil/src/fault_injection_hardening.c");
David Brownd2b18532017-07-12 09:51:31 -0600275 conf.file("csupport/run.c");
David Brown63902772017-07-12 09:47:49 -0600276 conf.include("../../boot/bootutil/include");
Fabio Utzig57c40f72017-12-12 21:48:30 -0200277 conf.include("csupport");
Fabio Utzig9a4b9ba2018-05-07 08:31:27 -0300278 conf.include("../../boot/zephyr/include");
David Brown63902772017-07-12 09:47:49 -0600279 conf.debug(true);
280 conf.flag("-Wall");
David Brown0b693c02017-07-12 12:34:33 -0600281 conf.flag("-Werror");
David Brown63902772017-07-12 09:47:49 -0600282
Fabio Utzig0bccf9d2017-12-07 12:13:57 -0200283 // FIXME: travis-ci still uses gcc 4.8.4 which defaults to std=gnu90.
284 // It has incomplete std=c11 and std=c99 support but std=c99 was checked
285 // to build correctly so leaving it here to updated in the future...
286 conf.flag("-std=c99");
287
David Brown63902772017-07-12 09:47:49 -0600288 conf.compile("libbootutil.a");
289
290 walk_dir("../../boot").unwrap();
Fabio Utzigc7865402017-12-05 08:50:52 -0200291 walk_dir("../../ext/tinycrypt/lib/source").unwrap();
David Brownb748f6f2019-10-11 10:07:31 -0600292 walk_dir("../../ext/mbedtls-asn1").unwrap();
David Brownd2b18532017-07-12 09:51:31 -0600293 walk_dir("csupport").unwrap();
Fabio Utzige60b12f2020-02-06 07:15:30 -0300294 walk_dir("../../ext/mbedtls/crypto/include").unwrap();
295 walk_dir("../../ext/mbedtls/crypto/library").unwrap();
David Brown63902772017-07-12 09:47:49 -0600296}
297
298// Output the names of all files within a directory so that Cargo knows when to rebuild.
299fn walk_dir<P: AsRef<Path>>(path: P) -> io::Result<()> {
300 for ent in fs::read_dir(path.as_ref())? {
301 let ent = ent?;
302 let p = ent.path();
303 if p.is_dir() {
304 walk_dir(p)?;
305 } else {
306 // Note that non-utf8 names will fail.
307 let name = p.to_str().unwrap();
308 if name.ends_with(".c") || name.ends_with(".h") {
309 println!("cargo:rerun-if-changed={}", name);
310 }
311 }
312 }
313
314 Ok(())
315}