blob: 1356f4e69b75f4c5fffd817dd4dcc0e94765ff11 [file] [log] [blame]
Marti Bolivarbf909a12017-11-13 19:43:46 -05001# CMakeLists.txt for building mcuboot as a Zephyr project
2#
3# Copyright (c) 2017 Open Source Foundries Limited
4#
5# SPDX-License-Identifier: Apache-2.0
6
Martí Bolívar0e3fa722019-10-22 14:39:33 -06007cmake_minimum_required(VERSION 3.13.1)
Rajavardhan Gundi40c28e32018-12-09 13:32:01 +05308
Torsten Rasmussen43004b82020-05-28 12:34:15 +02009# find_package(Zephyr) in order to load application boilerplate:
Marti Bolivarbf909a12017-11-13 19:43:46 -050010# http://docs.zephyrproject.org/application/application.html
Torsten Rasmussen43004b82020-05-28 12:34:15 +020011find_package(Zephyr REQUIRED HINTS $ENV{ZEPHYR_BASE})
Marti Bolivarbf909a12017-11-13 19:43:46 -050012project(NONE)
13
14# Path to "boot" subdirectory of repository root.
15get_filename_component(BOOT_DIR ${APPLICATION_SOURCE_DIR} DIRECTORY)
16# Path to top-level repository root directory.
17get_filename_component(MCUBOOT_DIR ${BOOT_DIR} DIRECTORY)
18# Path to tinycrypt library source subdirectory of MCUBOOT_DIR.
19set(TINYCRYPT_DIR "${MCUBOOT_DIR}/ext/tinycrypt/lib")
Sigvart Hovlandebd05032019-03-21 10:47:32 +010020assert_exists(TINYCRYPT_DIR)
Fabio Utzig34e93a52020-02-03 09:59:53 -030021set(TINYCRYPT_SHA512_DIR "${MCUBOOT_DIR}/ext/tinycrypt-sha512/lib")
22assert_exists(TINYCRYPT_SHA512_DIR)
Fabio Utzig1171df92019-05-10 19:26:38 -030023# Path to crypto-fiat
24set(FIAT_DIR "${MCUBOOT_DIR}/ext/fiat")
25assert_exists(FIAT_DIR)
Fabio Utzig28ee5b02017-12-12 08:10:40 -020026# Path to mbed-tls' asn1 parser library.
David Brownb748f6f2019-10-11 10:07:31 -060027set(MBEDTLS_ASN1_DIR "${MCUBOOT_DIR}/ext/mbedtls-asn1")
Sigvart Hovlandebd05032019-03-21 10:47:32 +010028assert_exists(MBEDTLS_ASN1_DIR)
29set(NRF_DIR "${MCUBOOT_DIR}/ext/nrf")
30
31if(CONFIG_BOOT_USE_NRF_CC310_BL)
Torsten Rasmussen33fbef52020-06-03 20:21:13 +020032set(NRFXLIB_DIR ${ZEPHYR_BASE}/../nrfxlib)
Andrzej Puzdrowskif0ef8b62020-10-01 13:51:48 +020033if(NOT EXISTS ${NRFXLIB_DIR})
34 message(FATAL_ERROR "
35 ------------------------------------------------------------------------
36 No such file or directory: ${NRFXLIB_DIR}
37 The current configuration enables nRF CC310 crypto accelerator hardware
38 with the `CONFIG_BOOT_USE_NRF_CC310_BL` option. Please follow
39 `ext/nrf/README.md` guide to fix your setup or use tinycrypt instead of
40 the HW accelerator.
41 To use the tinycrypt set `CONFIG_BOOT_ECDSA_TINYCRYPT` to y.
42 ------------------------------------------------------------------------")
43endif()
Sigvart Hovlandebd05032019-03-21 10:47:32 +010044# Don't include this if we are using west
45 add_subdirectory(${NRFXLIB_DIR} ${PROJECT_BINARY_DIR}/nrfxlib)
46endif()
Marti Bolivarbf909a12017-11-13 19:43:46 -050047
Sebastian Bøebe972172019-01-22 14:05:14 +010048zephyr_library_include_directories(
49 include
50 targets
51 )
52if(EXISTS targets/${BOARD}.h)
53 zephyr_library_compile_definitions(MCUBOOT_TARGET_CONFIG="${BOARD}.h")
Marti Bolivarbf909a12017-11-13 19:43:46 -050054endif()
55
56# Zephyr port-specific sources.
Sebastian Bøebe972172019-01-22 14:05:14 +010057zephyr_library_sources(
58 main.c
Jamie McCrae433b8482023-08-16 07:33:24 +010059 io.c
Sebastian Bøebe972172019-01-22 14:05:14 +010060 flash_map_extended.c
61 os.c
62 keys.c
63 )
64
Dominik Ermel428d3ee2021-08-17 07:55:54 +000065if(DEFINED CONFIG_ENABLE_MGMT_PERUSER)
66 zephyr_library_sources(
67 boot_serial_extensions.c
68 )
Jamie McCrae268433e2023-08-29 15:37:15 +010069
70 zephyr_linker_sources_ifdef(
71 CONFIG_ENABLE_MGMT_PERUSER
72 SECTIONS include/boot_serial/boot_serial.ld
73 )
74
75 if(DEFINED CONFIG_BOOT_MGMT_CUSTOM_STORAGE_ERASE OR DEFINED CONFIG_BOOT_MGMT_CUSTOM_IMG_LIST)
76 zephyr_library_sources(
77 boot_serial_extension_zephyr_basic.c
78 )
79 endif()
Dominik Ermel428d3ee2021-08-17 07:55:54 +000080endif()
81
Marti Bolivarbf909a12017-11-13 19:43:46 -050082if(NOT DEFINED CONFIG_FLASH_PAGE_LAYOUT)
Sebastian Bøebe972172019-01-22 14:05:14 +010083 zephyr_library_sources(
Fabio Utzigccc02802019-11-05 07:55:14 -030084 flash_map_legacy.c
85 )
Marti Bolivarbf909a12017-11-13 19:43:46 -050086endif()
87
Jamie McCrae4da51012023-08-03 16:23:02 +010088if(DEFINED CONFIG_BOOT_SHARE_BACKEND_RETENTION)
89 zephyr_library_sources(
90 shared_data.c
91 )
92endif()
93
Marti Bolivarbf909a12017-11-13 19:43:46 -050094# Generic bootutil sources and includes.
Sebastian Bøebe972172019-01-22 14:05:14 +010095zephyr_library_include_directories(${BOOT_DIR}/bootutil/include)
96zephyr_library_sources(
Dominik Ermel8101c0c2020-05-19 13:01:16 +000097 ${BOOT_DIR}/bootutil/src/image_validate.c
98 ${BOOT_DIR}/bootutil/src/tlv.c
99 ${BOOT_DIR}/bootutil/src/encrypted.c
100 ${BOOT_DIR}/bootutil/src/image_rsa.c
Antonio de Angelis10529d32023-04-21 21:43:14 +0100101 ${BOOT_DIR}/bootutil/src/image_ecdsa.c
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000102 ${BOOT_DIR}/bootutil/src/image_ed25519.c
Dominik Ermel9b48d082020-06-08 12:40:06 +0000103 ${BOOT_DIR}/bootutil/src/bootutil_misc.c
Tamas Banfce87332020-07-10 12:40:11 +0100104 ${BOOT_DIR}/bootutil/src/fault_injection_hardening.c
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000105 )
106
Jamie McCrae4da51012023-08-03 16:23:02 +0100107if(DEFINED CONFIG_MEASURED_BOOT OR DEFINED CONFIG_BOOT_SHARE_DATA)
108 zephyr_library_sources(
109 ${BOOT_DIR}/bootutil/src/boot_record.c
110 )
111
112 # Set a define for this file which will allow inclusion of the Zephyr version
113 # include file
114 set_source_files_properties(
115 ${BOOT_DIR}/bootutil/src/boot_record.c
116 PROPERTIES COMPILE_FLAGS -DZEPHYR_VER_INCLUDE=1
117 )
118endif()
119
Andrzej Puzdrowskif573b392020-11-10 14:35:15 +0100120# library which might be common source code for MCUBoot and an application
121zephyr_link_libraries(MCUBOOT_BOOTUTIL)
122
Tamas Banfce87332020-07-10 12:40:11 +0100123if(CONFIG_BOOT_FIH_PROFILE_HIGH)
124zephyr_library_sources(
125 ${BOOT_DIR}/bootutil/src/fault_injection_hardening_delay_rng_mbedtls.c
126 )
127endif()
128
Andrzej Puzdrowskifdff3e12020-09-15 08:23:25 +0200129if(CONFIG_SINGLE_APPLICATION_SLOT)
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000130zephyr_library_sources(
131 ${BOOT_DIR}/zephyr/single_loader.c
132 )
133zephyr_library_include_directories(${BOOT_DIR}/bootutil/src)
Jamie McCrae215345f2023-08-16 07:37:18 +0100134elseif(CONFIG_BOOT_FIRMWARE_LOADER)
135zephyr_library_sources(
136 ${BOOT_DIR}/zephyr/firmware_loader.c
137 )
138zephyr_library_include_directories(${BOOT_DIR}/bootutil/src)
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000139else()
140zephyr_library_sources(
Sebastian Bøebe972172019-01-22 14:05:14 +0100141 ${BOOT_DIR}/bootutil/src/loader.c
Fabio Utzigc58842e2019-11-28 10:30:01 -0300142 ${BOOT_DIR}/bootutil/src/swap_misc.c
143 ${BOOT_DIR}/bootutil/src/swap_scratch.c
144 ${BOOT_DIR}/bootutil/src/swap_move.c
Sebastian Bøebe972172019-01-22 14:05:14 +0100145 ${BOOT_DIR}/bootutil/src/caps.c
146 )
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000147endif()
148
Jamie McCraec9fa6082023-07-21 10:23:17 +0100149if(CONFIG_BOOT_SIGNATURE_TYPE_ECDSA_P256 OR CONFIG_BOOT_ENCRYPT_EC256)
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100150 zephyr_library_include_directories(
Fabio Utzigccc02802019-11-05 07:55:14 -0300151 ${MBEDTLS_ASN1_DIR}/include
152 )
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100153 zephyr_library_sources(
Fabio Utzigccc02802019-11-05 07:55:14 -0300154 # Additionally pull in just the ASN.1 parser from mbedTLS.
155 ${MBEDTLS_ASN1_DIR}/src/asn1parse.c
156 ${MBEDTLS_ASN1_DIR}/src/platform_util.c
157 )
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100158 if(CONFIG_BOOT_USE_TINYCRYPT)
Marti Bolivara4818a52018-04-12 13:02:38 -0400159 # When using ECDSA signatures, pull in our copy of the tinycrypt library.
Sebastian Bøebe972172019-01-22 14:05:14 +0100160 zephyr_library_include_directories(
Fabio Utzigccc02802019-11-05 07:55:14 -0300161 ${BOOT_DIR}/zephyr/include
162 ${TINYCRYPT_DIR}/include
163 )
Wouter Cappelle953a7612021-05-03 16:53:05 +0200164 zephyr_include_directories(${TINYCRYPT_DIR}/include)
Marti Bolivarbf909a12017-11-13 19:43:46 -0500165
Sebastian Bøebe972172019-01-22 14:05:14 +0100166 zephyr_library_sources(
Fabio Utzigccc02802019-11-05 07:55:14 -0300167 ${TINYCRYPT_DIR}/source/ecc.c
168 ${TINYCRYPT_DIR}/source/ecc_dsa.c
169 ${TINYCRYPT_DIR}/source/sha256.c
170 ${TINYCRYPT_DIR}/source/utils.c
171 )
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100172 elseif(CONFIG_BOOT_USE_NRF_CC310_BL)
173 zephyr_library_sources(${NRF_DIR}/cc310_glue.c)
174 zephyr_library_include_directories(${NRF_DIR})
175 zephyr_link_libraries(nrfxlib_crypto)
176 endif()
Fabio Utzig28ee5b02017-12-12 08:10:40 -0200177
Ding Taof97cb712018-06-08 14:37:13 +0000178 # Since here we are not using Zephyr's mbedTLS but rather our own, we need
Carles Cufi69c61d02018-06-05 15:56:08 +0200179 # to set MBEDTLS_CONFIG_FILE ourselves. When using Zephyr's copy, this
180 # variable is set by its Kconfig in the Zephyr codebase.
Sebastian Bøebe972172019-01-22 14:05:14 +0100181 zephyr_library_compile_definitions(
Fabio Utzigccc02802019-11-05 07:55:14 -0300182 MBEDTLS_CONFIG_FILE="${CMAKE_CURRENT_LIST_DIR}/include/mcuboot-mbedtls-cfg.h"
183 )
Arvin Farahmandfb5ec182020-05-05 11:44:12 -0400184elseif(CONFIG_BOOT_SIGNATURE_TYPE_NONE)
185 zephyr_library_include_directories(
186 ${BOOT_DIR}/zephyr/include
187 ${TINYCRYPT_DIR}/include
188 )
189
190 zephyr_library_sources(
191 ${TINYCRYPT_DIR}/source/sha256.c
192 ${TINYCRYPT_DIR}/source/utils.c
193 )
Marti Bolivara4818a52018-04-12 13:02:38 -0400194elseif(CONFIG_BOOT_SIGNATURE_TYPE_RSA)
195 # Use mbedTLS provided by Zephyr for RSA signatures. (Its config file
196 # is set using Kconfig.)
197 zephyr_include_directories(include)
Andrzej Puzdrowski5a325922021-11-08 14:07:56 +0100198 if(CONFIG_BOOT_ENCRYPT_RSA)
199 set_source_files_properties(
200 ${BOOT_DIR}/bootutil/src/encrypted.c
201 PROPERTIES
202 INCLUDE_DIRECTORIES ${ZEPHYR_MBEDTLS_MODULE_DIR}/library
203 )
204 endif()
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300205elseif(CONFIG_BOOT_SIGNATURE_TYPE_ED25519 OR CONFIG_BOOT_ENCRYPT_X25519)
Fabio Utzig34e93a52020-02-03 09:59:53 -0300206 if(CONFIG_BOOT_USE_TINYCRYPT)
207 zephyr_library_include_directories(
208 ${MBEDTLS_ASN1_DIR}/include
209 ${BOOT_DIR}/zephyr/include
210 ${TINYCRYPT_DIR}/include
211 ${TINYCRYPT_SHA512_DIR}/include
212 )
213 zephyr_library_sources(
214 ${TINYCRYPT_DIR}/source/sha256.c
215 ${TINYCRYPT_DIR}/source/utils.c
216 ${TINYCRYPT_SHA512_DIR}/source/sha512.c
217 # Additionally pull in just the ASN.1 parser from mbedTLS.
218 ${MBEDTLS_ASN1_DIR}/src/asn1parse.c
219 ${MBEDTLS_ASN1_DIR}/src/platform_util.c
220 )
221 zephyr_library_compile_definitions(
222 MBEDTLS_CONFIG_FILE="${CMAKE_CURRENT_LIST_DIR}/include/mcuboot-mbedtls-cfg.h"
223 )
224 else()
225 zephyr_include_directories(include)
226 endif()
Fabio Utzig1171df92019-05-10 19:26:38 -0300227
228 zephyr_library_include_directories(
229 ${BOOT_DIR}/zephyr/include
230 ${FIAT_DIR}/include/
231 )
232
233 zephyr_library_sources(
234 ${FIAT_DIR}/src/curve25519.c
235 )
Marti Bolivarbf909a12017-11-13 19:43:46 -0500236endif()
Andrzej Puzdrowski8e96b832017-09-08 16:49:14 +0200237
Jamie McCraec9fa6082023-07-21 10:23:17 +0100238if(CONFIG_BOOT_ENCRYPT_EC256 OR CONFIG_BOOT_ENCRYPT_X25519)
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300239 zephyr_library_sources(
240 ${TINYCRYPT_DIR}/source/aes_encrypt.c
241 ${TINYCRYPT_DIR}/source/aes_decrypt.c
242 ${TINYCRYPT_DIR}/source/ctr_mode.c
243 ${TINYCRYPT_DIR}/source/hmac.c
244 ${TINYCRYPT_DIR}/source/ecc_dh.c
245 )
246endif()
247
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300248if(CONFIG_BOOT_ENCRYPT_EC256)
249 zephyr_library_sources(
250 ${TINYCRYPT_DIR}/source/ecc_dh.c
251 )
252endif()
253
Sebastian Bøebe972172019-01-22 14:05:14 +0100254if(CONFIG_MCUBOOT_SERIAL)
Andrzej Puzdrowskic2e30cf2018-07-20 16:19:09 +0200255 zephyr_sources(${BOOT_DIR}/zephyr/serial_adapter.c)
256 zephyr_sources(${BOOT_DIR}/boot_serial/src/boot_serial.c)
Jamie McCraecb07e882023-04-14 09:28:24 +0100257 zephyr_sources(${BOOT_DIR}/boot_serial/src/zcbor_bulk.c)
Dominik Ermel88bd5672022-06-07 15:17:06 +0000258
Andrzej Puzdrowskic2e30cf2018-07-20 16:19:09 +0200259 zephyr_include_directories(${BOOT_DIR}/bootutil/include)
260 zephyr_include_directories(${BOOT_DIR}/boot_serial/include)
261 zephyr_include_directories(include)
Andrzej Puzdrowskic2e30cf2018-07-20 16:19:09 +0200262
Sebastian Bøebe972172019-01-22 14:05:14 +0100263 zephyr_include_directories_ifdef(
Fabio Utzigccc02802019-11-05 07:55:14 -0300264 CONFIG_BOOT_ERASE_PROGRESSIVELY
265 ${BOOT_DIR}/bootutil/src
266 )
Jamie McCraec9fa6082023-07-21 10:23:17 +0100267
268 if(CONFIG_BOOT_ENCRYPT_IMAGE)
269 zephyr_library_sources(
270 ${BOOT_DIR}/boot_serial/src/boot_serial_encryption.c
271 )
272 endif()
Andrzej Puzdrowski8e96b832017-09-08 16:49:14 +0200273endif()
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300274
275if(NOT CONFIG_BOOT_SIGNATURE_KEY_FILE STREQUAL "")
Nico Lastzkae16f52c2021-04-13 16:04:00 +0200276 # CONF_FILE points to the KConfig configuration files of the bootloader.
277 foreach (filepath ${CONF_FILE})
278 file(READ ${filepath} temp_text)
279 string(FIND "${temp_text}" ${CONFIG_BOOT_SIGNATURE_KEY_FILE} match)
280 if (${match} GREATER_EQUAL 0)
281 if (NOT DEFINED CONF_DIR)
282 get_filename_component(CONF_DIR ${filepath} DIRECTORY)
283 else()
284 message(FATAL_ERROR "Signature key file defined in multiple conf files")
285 endif()
286 endif()
287 endforeach()
288
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300289 if(IS_ABSOLUTE ${CONFIG_BOOT_SIGNATURE_KEY_FILE})
290 set(KEY_FILE ${CONFIG_BOOT_SIGNATURE_KEY_FILE})
Marek Pietac1cdcae2020-08-12 04:29:12 -0700291 elseif((DEFINED CONF_DIR) AND
292 (EXISTS ${CONF_DIR}/${CONFIG_BOOT_SIGNATURE_KEY_FILE}))
Marek Pietabdcfc852020-08-04 02:22:55 -0700293 set(KEY_FILE ${CONF_DIR}/${CONFIG_BOOT_SIGNATURE_KEY_FILE})
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300294 else()
295 set(KEY_FILE ${MCUBOOT_DIR}/${CONFIG_BOOT_SIGNATURE_KEY_FILE})
296 endif()
Marek Pietac1cdcae2020-08-12 04:29:12 -0700297 message("MCUBoot bootloader key file: ${KEY_FILE}")
298
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300299 set(GENERATED_PUBKEY ${ZEPHYR_BINARY_DIR}/autogen-pubkey.c)
300 add_custom_command(
301 OUTPUT ${GENERATED_PUBKEY}
302 COMMAND
303 ${PYTHON_EXECUTABLE}
304 ${MCUBOOT_DIR}/scripts/imgtool.py
305 getpub
306 -k
307 ${KEY_FILE}
308 > ${GENERATED_PUBKEY}
309 DEPENDS ${KEY_FILE}
310 )
Sebastian Bøebe972172019-01-22 14:05:14 +0100311 zephyr_library_sources(${GENERATED_PUBKEY})
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300312endif()
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100313
Wouter Cappelle10a877c2022-01-28 08:40:28 +0100314if(CONFIG_BOOT_ENCRYPTION_KEY_FILE AND NOT CONFIG_BOOT_ENCRYPTION_KEY_FILE STREQUAL "")
315 # CONF_FILE points to the KConfig configuration files of the bootloader.
316 unset(CONF_DIR)
317 foreach(filepath ${CONF_FILE})
318 file(READ ${filepath} temp_text)
319 string(FIND "${temp_text}" ${CONFIG_BOOT_ENCRYPTION_KEY_FILE} match)
320 if(${match} GREATER_EQUAL 0)
321 if(NOT DEFINED CONF_DIR)
322 get_filename_component(CONF_DIR ${filepath} DIRECTORY)
323 else()
324 message(FATAL_ERROR "Encryption key file defined in multiple conf files")
325 endif()
Wouter Cappelle953a7612021-05-03 16:53:05 +0200326 endif()
Wouter Cappelle10a877c2022-01-28 08:40:28 +0100327 endforeach()
Wouter Cappelle953a7612021-05-03 16:53:05 +0200328
Wouter Cappelle953a7612021-05-03 16:53:05 +0200329 if(IS_ABSOLUTE ${CONFIG_BOOT_ENCRYPTION_KEY_FILE})
330 set(KEY_FILE ${CONFIG_BOOT_ENCRYPTION_KEY_FILE})
331 elseif((DEFINED CONF_DIR) AND
332 (EXISTS ${CONF_DIR}/${CONFIG_BOOT_ENCRYPTION_KEY_FILE}))
333 set(KEY_FILE ${CONF_DIR}/${CONFIG_BOOT_ENCRYPTION_KEY_FILE})
334 else()
335 set(KEY_FILE ${MCUBOOT_DIR}/${CONFIG_BOOT_ENCRYPTION_KEY_FILE})
336 endif()
Wouter Cappelle10a877c2022-01-28 08:40:28 +0100337 message("MCUBoot bootloader encryption key file: ${KEY_FILE}")
Wouter Cappelle953a7612021-05-03 16:53:05 +0200338
339 set(GENERATED_ENCKEY ${ZEPHYR_BINARY_DIR}/autogen-enckey.c)
340 add_custom_command(
341 OUTPUT ${GENERATED_ENCKEY}
342 COMMAND
343 ${PYTHON_EXECUTABLE}
344 ${MCUBOOT_DIR}/scripts/imgtool.py
345 getpriv
346 -k
347 ${KEY_FILE}
348 > ${GENERATED_ENCKEY}
349 DEPENDS ${KEY_FILE}
350 )
351 zephyr_library_sources(${GENERATED_ENCKEY})
352endif()
353
Andrzej Puzdrowski9a605b62020-03-16 13:34:30 +0100354if(CONFIG_MCUBOOT_CLEANUP_ARM_CORE)
355zephyr_library_sources(
356 ${BOOT_DIR}/zephyr/arm_cleanup.c
357)
358endif()