blob: 638bd91cc69e1b8bc64d18b1fa69acd44762f9a5 [file] [log] [blame]
Marti Bolivarbf909a12017-11-13 19:43:46 -05001# CMakeLists.txt for building mcuboot as a Zephyr project
2#
3# Copyright (c) 2017 Open Source Foundries Limited
4#
5# SPDX-License-Identifier: Apache-2.0
6
Martí Bolívar0e3fa722019-10-22 14:39:33 -06007cmake_minimum_required(VERSION 3.13.1)
Rajavardhan Gundi40c28e32018-12-09 13:32:01 +05308
Marti Bolivaraefbd462017-12-15 03:43:46 -05009# Enable Zephyr runner options which request mass erase if so
10# configured.
11#
12# Note that this also disables the default "leave" option when
13# targeting STM32 DfuSe devices with dfu-util, making the chip stay in
14# the bootloader after flashing.
15#
16# That's the right thing, because mcuboot has nothing to do since the
17# chip was just erased. The next thing the user is going to want to do
18# is flash the application. (Developers can reset DfuSE devices
19# manually to test mcuboot behavior on an otherwise erased flash
20# device.)
21macro(app_set_runner_args)
Marti Bolivar53e2c262018-04-12 14:13:28 -040022 if(CONFIG_ZEPHYR_TRY_MASS_ERASE)
Marti Bolivaraefbd462017-12-15 03:43:46 -050023 board_runner_args(dfu-util "--dfuse-modifiers=force:mass-erase")
Maureen Helm4df602a2019-02-18 17:26:39 -060024 board_runner_args(pyocd "--flash-opt=-e=chip")
Marti Bolivar23e38532018-03-26 13:14:22 -040025 board_runner_args(nrfjprog "--erase")
Marti Bolivaraefbd462017-12-15 03:43:46 -050026 endif()
27endmacro()
28
Torsten Rasmussen43004b82020-05-28 12:34:15 +020029# find_package(Zephyr) in order to load application boilerplate:
Marti Bolivarbf909a12017-11-13 19:43:46 -050030# http://docs.zephyrproject.org/application/application.html
Torsten Rasmussen43004b82020-05-28 12:34:15 +020031find_package(Zephyr REQUIRED HINTS $ENV{ZEPHYR_BASE})
Marti Bolivarbf909a12017-11-13 19:43:46 -050032project(NONE)
33
34# Path to "boot" subdirectory of repository root.
35get_filename_component(BOOT_DIR ${APPLICATION_SOURCE_DIR} DIRECTORY)
36# Path to top-level repository root directory.
37get_filename_component(MCUBOOT_DIR ${BOOT_DIR} DIRECTORY)
38# Path to tinycrypt library source subdirectory of MCUBOOT_DIR.
39set(TINYCRYPT_DIR "${MCUBOOT_DIR}/ext/tinycrypt/lib")
Sigvart Hovlandebd05032019-03-21 10:47:32 +010040assert_exists(TINYCRYPT_DIR)
Fabio Utzig34e93a52020-02-03 09:59:53 -030041set(TINYCRYPT_SHA512_DIR "${MCUBOOT_DIR}/ext/tinycrypt-sha512/lib")
42assert_exists(TINYCRYPT_SHA512_DIR)
Fabio Utzig1171df92019-05-10 19:26:38 -030043# Path to crypto-fiat
44set(FIAT_DIR "${MCUBOOT_DIR}/ext/fiat")
45assert_exists(FIAT_DIR)
Fabio Utzig28ee5b02017-12-12 08:10:40 -020046# Path to mbed-tls' asn1 parser library.
David Brownb748f6f2019-10-11 10:07:31 -060047set(MBEDTLS_ASN1_DIR "${MCUBOOT_DIR}/ext/mbedtls-asn1")
Sigvart Hovlandebd05032019-03-21 10:47:32 +010048assert_exists(MBEDTLS_ASN1_DIR)
49set(NRF_DIR "${MCUBOOT_DIR}/ext/nrf")
50
51if(CONFIG_BOOT_USE_NRF_CC310_BL)
Torsten Rasmussen33fbef52020-06-03 20:21:13 +020052set(NRFXLIB_DIR ${ZEPHYR_BASE}/../nrfxlib)
Andrzej Puzdrowskif0ef8b62020-10-01 13:51:48 +020053if(NOT EXISTS ${NRFXLIB_DIR})
54 message(FATAL_ERROR "
55 ------------------------------------------------------------------------
56 No such file or directory: ${NRFXLIB_DIR}
57 The current configuration enables nRF CC310 crypto accelerator hardware
58 with the `CONFIG_BOOT_USE_NRF_CC310_BL` option. Please follow
59 `ext/nrf/README.md` guide to fix your setup or use tinycrypt instead of
60 the HW accelerator.
61 To use the tinycrypt set `CONFIG_BOOT_ECDSA_TINYCRYPT` to y.
62 ------------------------------------------------------------------------")
63endif()
Sigvart Hovlandebd05032019-03-21 10:47:32 +010064# Don't include this if we are using west
65 add_subdirectory(${NRFXLIB_DIR} ${PROJECT_BINARY_DIR}/nrfxlib)
66endif()
Marti Bolivarbf909a12017-11-13 19:43:46 -050067
Sebastian Bøebe972172019-01-22 14:05:14 +010068zephyr_library_include_directories(
69 include
70 targets
71 )
72if(EXISTS targets/${BOARD}.h)
73 zephyr_library_compile_definitions(MCUBOOT_TARGET_CONFIG="${BOARD}.h")
Marti Bolivarbf909a12017-11-13 19:43:46 -050074endif()
75
76# Zephyr port-specific sources.
Sebastian Bøebe972172019-01-22 14:05:14 +010077zephyr_library_sources(
78 main.c
79 flash_map_extended.c
80 os.c
81 keys.c
82 )
83
Dominik Ermel428d3ee2021-08-17 07:55:54 +000084if(DEFINED CONFIG_ENABLE_MGMT_PERUSER)
85 zephyr_library_sources(
86 boot_serial_extensions.c
87 )
88endif()
89
Marti Bolivarbf909a12017-11-13 19:43:46 -050090if(NOT DEFINED CONFIG_FLASH_PAGE_LAYOUT)
Sebastian Bøebe972172019-01-22 14:05:14 +010091 zephyr_library_sources(
Fabio Utzigccc02802019-11-05 07:55:14 -030092 flash_map_legacy.c
93 )
Marti Bolivarbf909a12017-11-13 19:43:46 -050094endif()
95
Jamie McCrae4da51012023-08-03 16:23:02 +010096if(DEFINED CONFIG_BOOT_SHARE_BACKEND_RETENTION)
97 zephyr_library_sources(
98 shared_data.c
99 )
100endif()
101
Marti Bolivarbf909a12017-11-13 19:43:46 -0500102# Generic bootutil sources and includes.
Sebastian Bøebe972172019-01-22 14:05:14 +0100103zephyr_library_include_directories(${BOOT_DIR}/bootutil/include)
104zephyr_library_sources(
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000105 ${BOOT_DIR}/bootutil/src/image_validate.c
106 ${BOOT_DIR}/bootutil/src/tlv.c
107 ${BOOT_DIR}/bootutil/src/encrypted.c
108 ${BOOT_DIR}/bootutil/src/image_rsa.c
Antonio de Angelis10529d32023-04-21 21:43:14 +0100109 ${BOOT_DIR}/bootutil/src/image_ecdsa.c
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000110 ${BOOT_DIR}/bootutil/src/image_ed25519.c
Dominik Ermel9b48d082020-06-08 12:40:06 +0000111 ${BOOT_DIR}/bootutil/src/bootutil_misc.c
Tamas Banfce87332020-07-10 12:40:11 +0100112 ${BOOT_DIR}/bootutil/src/fault_injection_hardening.c
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000113 )
114
Jamie McCrae4da51012023-08-03 16:23:02 +0100115if(DEFINED CONFIG_MEASURED_BOOT OR DEFINED CONFIG_BOOT_SHARE_DATA)
116 zephyr_library_sources(
117 ${BOOT_DIR}/bootutil/src/boot_record.c
118 )
119
120 # Set a define for this file which will allow inclusion of the Zephyr version
121 # include file
122 set_source_files_properties(
123 ${BOOT_DIR}/bootutil/src/boot_record.c
124 PROPERTIES COMPILE_FLAGS -DZEPHYR_VER_INCLUDE=1
125 )
126endif()
127
Andrzej Puzdrowskif573b392020-11-10 14:35:15 +0100128# library which might be common source code for MCUBoot and an application
129zephyr_link_libraries(MCUBOOT_BOOTUTIL)
130
Tamas Banfce87332020-07-10 12:40:11 +0100131if(CONFIG_BOOT_FIH_PROFILE_HIGH)
132zephyr_library_sources(
133 ${BOOT_DIR}/bootutil/src/fault_injection_hardening_delay_rng_mbedtls.c
134 )
135endif()
136
Andrzej Puzdrowskifdff3e12020-09-15 08:23:25 +0200137if(CONFIG_SINGLE_APPLICATION_SLOT)
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000138zephyr_library_sources(
139 ${BOOT_DIR}/zephyr/single_loader.c
140 )
141zephyr_library_include_directories(${BOOT_DIR}/bootutil/src)
142else()
143zephyr_library_sources(
Sebastian Bøebe972172019-01-22 14:05:14 +0100144 ${BOOT_DIR}/bootutil/src/loader.c
Fabio Utzigc58842e2019-11-28 10:30:01 -0300145 ${BOOT_DIR}/bootutil/src/swap_misc.c
146 ${BOOT_DIR}/bootutil/src/swap_scratch.c
147 ${BOOT_DIR}/bootutil/src/swap_move.c
Sebastian Bøebe972172019-01-22 14:05:14 +0100148 ${BOOT_DIR}/bootutil/src/caps.c
149 )
Dominik Ermel8101c0c2020-05-19 13:01:16 +0000150endif()
151
Jamie McCraec9fa6082023-07-21 10:23:17 +0100152if(CONFIG_BOOT_SIGNATURE_TYPE_ECDSA_P256 OR CONFIG_BOOT_ENCRYPT_EC256)
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100153 zephyr_library_include_directories(
Fabio Utzigccc02802019-11-05 07:55:14 -0300154 ${MBEDTLS_ASN1_DIR}/include
155 )
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100156 zephyr_library_sources(
Fabio Utzigccc02802019-11-05 07:55:14 -0300157 # Additionally pull in just the ASN.1 parser from mbedTLS.
158 ${MBEDTLS_ASN1_DIR}/src/asn1parse.c
159 ${MBEDTLS_ASN1_DIR}/src/platform_util.c
160 )
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100161 if(CONFIG_BOOT_USE_TINYCRYPT)
Marti Bolivara4818a52018-04-12 13:02:38 -0400162 # When using ECDSA signatures, pull in our copy of the tinycrypt library.
Sebastian Bøebe972172019-01-22 14:05:14 +0100163 zephyr_library_include_directories(
Fabio Utzigccc02802019-11-05 07:55:14 -0300164 ${BOOT_DIR}/zephyr/include
165 ${TINYCRYPT_DIR}/include
166 )
Wouter Cappelle953a7612021-05-03 16:53:05 +0200167 zephyr_include_directories(${TINYCRYPT_DIR}/include)
Marti Bolivarbf909a12017-11-13 19:43:46 -0500168
Sebastian Bøebe972172019-01-22 14:05:14 +0100169 zephyr_library_sources(
Fabio Utzigccc02802019-11-05 07:55:14 -0300170 ${TINYCRYPT_DIR}/source/ecc.c
171 ${TINYCRYPT_DIR}/source/ecc_dsa.c
172 ${TINYCRYPT_DIR}/source/sha256.c
173 ${TINYCRYPT_DIR}/source/utils.c
174 )
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100175 elseif(CONFIG_BOOT_USE_NRF_CC310_BL)
176 zephyr_library_sources(${NRF_DIR}/cc310_glue.c)
177 zephyr_library_include_directories(${NRF_DIR})
178 zephyr_link_libraries(nrfxlib_crypto)
179 endif()
Fabio Utzig28ee5b02017-12-12 08:10:40 -0200180
Ding Taof97cb712018-06-08 14:37:13 +0000181 # Since here we are not using Zephyr's mbedTLS but rather our own, we need
Carles Cufi69c61d02018-06-05 15:56:08 +0200182 # to set MBEDTLS_CONFIG_FILE ourselves. When using Zephyr's copy, this
183 # variable is set by its Kconfig in the Zephyr codebase.
Sebastian Bøebe972172019-01-22 14:05:14 +0100184 zephyr_library_compile_definitions(
Fabio Utzigccc02802019-11-05 07:55:14 -0300185 MBEDTLS_CONFIG_FILE="${CMAKE_CURRENT_LIST_DIR}/include/mcuboot-mbedtls-cfg.h"
186 )
Arvin Farahmandfb5ec182020-05-05 11:44:12 -0400187elseif(CONFIG_BOOT_SIGNATURE_TYPE_NONE)
188 zephyr_library_include_directories(
189 ${BOOT_DIR}/zephyr/include
190 ${TINYCRYPT_DIR}/include
191 )
192
193 zephyr_library_sources(
194 ${TINYCRYPT_DIR}/source/sha256.c
195 ${TINYCRYPT_DIR}/source/utils.c
196 )
Marti Bolivara4818a52018-04-12 13:02:38 -0400197elseif(CONFIG_BOOT_SIGNATURE_TYPE_RSA)
198 # Use mbedTLS provided by Zephyr for RSA signatures. (Its config file
199 # is set using Kconfig.)
200 zephyr_include_directories(include)
Andrzej Puzdrowski5a325922021-11-08 14:07:56 +0100201 if(CONFIG_BOOT_ENCRYPT_RSA)
202 set_source_files_properties(
203 ${BOOT_DIR}/bootutil/src/encrypted.c
204 PROPERTIES
205 INCLUDE_DIRECTORIES ${ZEPHYR_MBEDTLS_MODULE_DIR}/library
206 )
207 endif()
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300208elseif(CONFIG_BOOT_SIGNATURE_TYPE_ED25519 OR CONFIG_BOOT_ENCRYPT_X25519)
Fabio Utzig34e93a52020-02-03 09:59:53 -0300209 if(CONFIG_BOOT_USE_TINYCRYPT)
210 zephyr_library_include_directories(
211 ${MBEDTLS_ASN1_DIR}/include
212 ${BOOT_DIR}/zephyr/include
213 ${TINYCRYPT_DIR}/include
214 ${TINYCRYPT_SHA512_DIR}/include
215 )
216 zephyr_library_sources(
217 ${TINYCRYPT_DIR}/source/sha256.c
218 ${TINYCRYPT_DIR}/source/utils.c
219 ${TINYCRYPT_SHA512_DIR}/source/sha512.c
220 # Additionally pull in just the ASN.1 parser from mbedTLS.
221 ${MBEDTLS_ASN1_DIR}/src/asn1parse.c
222 ${MBEDTLS_ASN1_DIR}/src/platform_util.c
223 )
224 zephyr_library_compile_definitions(
225 MBEDTLS_CONFIG_FILE="${CMAKE_CURRENT_LIST_DIR}/include/mcuboot-mbedtls-cfg.h"
226 )
227 else()
228 zephyr_include_directories(include)
229 endif()
Fabio Utzig1171df92019-05-10 19:26:38 -0300230
231 zephyr_library_include_directories(
232 ${BOOT_DIR}/zephyr/include
233 ${FIAT_DIR}/include/
234 )
235
236 zephyr_library_sources(
237 ${FIAT_DIR}/src/curve25519.c
238 )
Marti Bolivarbf909a12017-11-13 19:43:46 -0500239endif()
Andrzej Puzdrowski8e96b832017-09-08 16:49:14 +0200240
Jamie McCraec9fa6082023-07-21 10:23:17 +0100241if(CONFIG_BOOT_ENCRYPT_EC256 OR CONFIG_BOOT_ENCRYPT_X25519)
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300242 zephyr_library_sources(
243 ${TINYCRYPT_DIR}/source/aes_encrypt.c
244 ${TINYCRYPT_DIR}/source/aes_decrypt.c
245 ${TINYCRYPT_DIR}/source/ctr_mode.c
246 ${TINYCRYPT_DIR}/source/hmac.c
247 ${TINYCRYPT_DIR}/source/ecc_dh.c
248 )
249endif()
250
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300251if(CONFIG_BOOT_ENCRYPT_EC256)
252 zephyr_library_sources(
253 ${TINYCRYPT_DIR}/source/ecc_dh.c
254 )
255endif()
256
Sebastian Bøebe972172019-01-22 14:05:14 +0100257if(CONFIG_MCUBOOT_SERIAL)
Andrzej Puzdrowskic2e30cf2018-07-20 16:19:09 +0200258 zephyr_sources(${BOOT_DIR}/zephyr/serial_adapter.c)
259 zephyr_sources(${BOOT_DIR}/boot_serial/src/boot_serial.c)
Jamie McCraecb07e882023-04-14 09:28:24 +0100260 zephyr_sources(${BOOT_DIR}/boot_serial/src/zcbor_bulk.c)
Dominik Ermel88bd5672022-06-07 15:17:06 +0000261
Andrzej Puzdrowskic2e30cf2018-07-20 16:19:09 +0200262 zephyr_include_directories(${BOOT_DIR}/bootutil/include)
263 zephyr_include_directories(${BOOT_DIR}/boot_serial/include)
264 zephyr_include_directories(include)
Andrzej Puzdrowskic2e30cf2018-07-20 16:19:09 +0200265
Sebastian Bøebe972172019-01-22 14:05:14 +0100266 zephyr_include_directories_ifdef(
Fabio Utzigccc02802019-11-05 07:55:14 -0300267 CONFIG_BOOT_ERASE_PROGRESSIVELY
268 ${BOOT_DIR}/bootutil/src
269 )
Jamie McCraec9fa6082023-07-21 10:23:17 +0100270
271 if(CONFIG_BOOT_ENCRYPT_IMAGE)
272 zephyr_library_sources(
273 ${BOOT_DIR}/boot_serial/src/boot_serial_encryption.c
274 )
275 endif()
Andrzej Puzdrowski8e96b832017-09-08 16:49:14 +0200276endif()
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300277
278if(NOT CONFIG_BOOT_SIGNATURE_KEY_FILE STREQUAL "")
Nico Lastzkae16f52c2021-04-13 16:04:00 +0200279 # CONF_FILE points to the KConfig configuration files of the bootloader.
280 foreach (filepath ${CONF_FILE})
281 file(READ ${filepath} temp_text)
282 string(FIND "${temp_text}" ${CONFIG_BOOT_SIGNATURE_KEY_FILE} match)
283 if (${match} GREATER_EQUAL 0)
284 if (NOT DEFINED CONF_DIR)
285 get_filename_component(CONF_DIR ${filepath} DIRECTORY)
286 else()
287 message(FATAL_ERROR "Signature key file defined in multiple conf files")
288 endif()
289 endif()
290 endforeach()
291
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300292 if(IS_ABSOLUTE ${CONFIG_BOOT_SIGNATURE_KEY_FILE})
293 set(KEY_FILE ${CONFIG_BOOT_SIGNATURE_KEY_FILE})
Marek Pietac1cdcae2020-08-12 04:29:12 -0700294 elseif((DEFINED CONF_DIR) AND
295 (EXISTS ${CONF_DIR}/${CONFIG_BOOT_SIGNATURE_KEY_FILE}))
Marek Pietabdcfc852020-08-04 02:22:55 -0700296 set(KEY_FILE ${CONF_DIR}/${CONFIG_BOOT_SIGNATURE_KEY_FILE})
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300297 else()
298 set(KEY_FILE ${MCUBOOT_DIR}/${CONFIG_BOOT_SIGNATURE_KEY_FILE})
299 endif()
Marek Pietac1cdcae2020-08-12 04:29:12 -0700300 message("MCUBoot bootloader key file: ${KEY_FILE}")
301
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300302 set(GENERATED_PUBKEY ${ZEPHYR_BINARY_DIR}/autogen-pubkey.c)
303 add_custom_command(
304 OUTPUT ${GENERATED_PUBKEY}
305 COMMAND
306 ${PYTHON_EXECUTABLE}
307 ${MCUBOOT_DIR}/scripts/imgtool.py
308 getpub
309 -k
310 ${KEY_FILE}
311 > ${GENERATED_PUBKEY}
312 DEPENDS ${KEY_FILE}
313 )
Sebastian Bøebe972172019-01-22 14:05:14 +0100314 zephyr_library_sources(${GENERATED_PUBKEY})
Fabio Utzigb1e0dc52018-04-26 10:53:19 -0300315endif()
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100316
Wouter Cappelle10a877c2022-01-28 08:40:28 +0100317if(CONFIG_BOOT_ENCRYPTION_KEY_FILE AND NOT CONFIG_BOOT_ENCRYPTION_KEY_FILE STREQUAL "")
318 # CONF_FILE points to the KConfig configuration files of the bootloader.
319 unset(CONF_DIR)
320 foreach(filepath ${CONF_FILE})
321 file(READ ${filepath} temp_text)
322 string(FIND "${temp_text}" ${CONFIG_BOOT_ENCRYPTION_KEY_FILE} match)
323 if(${match} GREATER_EQUAL 0)
324 if(NOT DEFINED CONF_DIR)
325 get_filename_component(CONF_DIR ${filepath} DIRECTORY)
326 else()
327 message(FATAL_ERROR "Encryption key file defined in multiple conf files")
328 endif()
Wouter Cappelle953a7612021-05-03 16:53:05 +0200329 endif()
Wouter Cappelle10a877c2022-01-28 08:40:28 +0100330 endforeach()
Wouter Cappelle953a7612021-05-03 16:53:05 +0200331
Wouter Cappelle953a7612021-05-03 16:53:05 +0200332 if(IS_ABSOLUTE ${CONFIG_BOOT_ENCRYPTION_KEY_FILE})
333 set(KEY_FILE ${CONFIG_BOOT_ENCRYPTION_KEY_FILE})
334 elseif((DEFINED CONF_DIR) AND
335 (EXISTS ${CONF_DIR}/${CONFIG_BOOT_ENCRYPTION_KEY_FILE}))
336 set(KEY_FILE ${CONF_DIR}/${CONFIG_BOOT_ENCRYPTION_KEY_FILE})
337 else()
338 set(KEY_FILE ${MCUBOOT_DIR}/${CONFIG_BOOT_ENCRYPTION_KEY_FILE})
339 endif()
Wouter Cappelle10a877c2022-01-28 08:40:28 +0100340 message("MCUBoot bootloader encryption key file: ${KEY_FILE}")
Wouter Cappelle953a7612021-05-03 16:53:05 +0200341
342 set(GENERATED_ENCKEY ${ZEPHYR_BINARY_DIR}/autogen-enckey.c)
343 add_custom_command(
344 OUTPUT ${GENERATED_ENCKEY}
345 COMMAND
346 ${PYTHON_EXECUTABLE}
347 ${MCUBOOT_DIR}/scripts/imgtool.py
348 getpriv
349 -k
350 ${KEY_FILE}
351 > ${GENERATED_ENCKEY}
352 DEPENDS ${KEY_FILE}
353 )
354 zephyr_library_sources(${GENERATED_ENCKEY})
355endif()
356
Andrzej Puzdrowski9a605b62020-03-16 13:34:30 +0100357if(CONFIG_MCUBOOT_CLEANUP_ARM_CORE)
358zephyr_library_sources(
359 ${BOOT_DIR}/zephyr/arm_cleanup.c
360)
361endif()