blob: c67d9e35510f32f46477b34278f0cb84cb47e7f2 [file] [log] [blame]
David Vincze03368b82020-04-01 12:53:53 +02001# Copyright (c) 2017-2020 Linaro Limited
David Vinczec3084132020-02-18 14:50:47 +01002# Copyright (c) 2020 Arm Limited
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02003#
4# SPDX-License-Identifier: Apache-2.0
5#
6
Marti Bolivar0e091c92018-04-12 11:23:16 -04007mainmenu "MCUboot configuration"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02008
Marti Bolivar0e091c92018-04-12 11:23:16 -04009comment "MCUboot-specific configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +020010
Emanuele Di Santo865777d2018-11-08 11:28:15 +010011# Hidden option to mark a project as MCUboot
12config MCUBOOT
13 default y
14 bool
Rajavardhan Gundi07ba28f2018-12-10 15:44:48 +053015 select MPU_ALLOW_FLASH_WRITE if ARM_MPU
Marcin Niestrojc6be76a2020-03-22 14:39:35 +010016 select USE_DT_CODE_PARTITION if HAS_FLASH_LOAD_OFFSET
Andrzej Puzdrowskif573b392020-11-10 14:35:15 +010017 select MCUBOOT_BOOTUTIL_LIB
Emanuele Di Santo865777d2018-11-08 11:28:15 +010018
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040019config BOOT_USE_MBEDTLS
20 bool
21 # Hidden option
22 default n
23 help
24 Use mbedTLS for crypto primitives.
25
26config BOOT_USE_TINYCRYPT
27 bool
28 # Hidden option
29 default n
Sebastian Bøe913a3852019-01-22 13:53:12 +010030 # When building for ECDSA, we use our own copy of mbedTLS, so the
31 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
32 # will collide.
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040033 help
34 Use TinyCrypt for crypto primitives.
35
Sigvart Hovlandebd05032019-03-21 10:47:32 +010036config BOOT_USE_CC310
37 bool
38 # Hidden option
39 default n
40 # When building for ECDSA, we use our own copy of mbedTLS, so the
41 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
42 # will collide.
Sigvart Hovlandebd05032019-03-21 10:47:32 +010043 help
44 Use cc310 for crypto primitives.
45
46config BOOT_USE_NRF_CC310_BL
47 bool
48 default n
49
50config NRFXLIB_CRYPTO
51 bool
52 default n
53
54config NRF_CC310_BL
55 bool
56 default n
57
Andrzej Puzdrowski97543282018-04-12 15:16:56 +020058menu "MCUBoot settings"
59
Andrzej Puzdrowskifdff3e12020-09-15 08:23:25 +020060config SINGLE_APPLICATION_SLOT
61 bool "Single slot bootloader"
Dominik Ermel4dc3f442020-05-26 08:45:14 +000062 default n
63 help
64 Single image area is used for application which means that
65 uploading a new application overwrites the one that previously
66 occupied the area.
67
Håkon Øye Amundsen21f03762021-11-12 08:21:31 +000068choice BOOT_SIGNATURE_TYPE
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040069 prompt "Signature type"
70 default BOOT_SIGNATURE_TYPE_RSA
71
Arvin Farahmandfb5ec182020-05-05 11:44:12 -040072config BOOT_SIGNATURE_TYPE_NONE
73 bool "No signature; use only hash check"
74 select BOOT_USE_TINYCRYPT
75
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040076config BOOT_SIGNATURE_TYPE_RSA
77 bool "RSA signatures"
78 select BOOT_USE_MBEDTLS
Marti Bolivara4818a52018-04-12 13:02:38 -040079 select MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040080
Fabio Utzig105b59a2019-05-13 15:08:12 -070081if BOOT_SIGNATURE_TYPE_RSA
82config BOOT_SIGNATURE_TYPE_RSA_LEN
83 int "RSA signature length"
84 range 2048 3072
85 default 2048
86endif
87
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040088config BOOT_SIGNATURE_TYPE_ECDSA_P256
89 bool "Elliptic curve digital signatures with curve P-256"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040090
Sigvart Hovlandebd05032019-03-21 10:47:32 +010091if BOOT_SIGNATURE_TYPE_ECDSA_P256
Håkon Øye Amundsen21f03762021-11-12 08:21:31 +000092choice BOOT_ECDSA_IMPLEMENTATION
Sigvart Hovlandebd05032019-03-21 10:47:32 +010093 prompt "Ecdsa implementation"
Fabio Utzig34e93a52020-02-03 09:59:53 -030094 default BOOT_ECDSA_TINYCRYPT
Håkon Øye Amundsenee7282d2020-09-28 09:48:29 +000095
Fabio Utzig34e93a52020-02-03 09:59:53 -030096config BOOT_ECDSA_TINYCRYPT
Sigvart Hovlandebd05032019-03-21 10:47:32 +010097 bool "Use tinycrypt"
98 select BOOT_USE_TINYCRYPT
Håkon Øye Amundsenee7282d2020-09-28 09:48:29 +000099
100config BOOT_ECDSA_CC310
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100101 bool "Use CC310"
Håkon Øye Amundsenee7282d2020-09-28 09:48:29 +0000102 depends on HAS_HW_NRF_CC310
103 select BOOT_USE_NRF_CC310_BL
104 select NRF_CC310_BL
105 select NRFXLIB_CRYPTO
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100106 select BOOT_USE_CC310
Håkon Øye Amundsenee7282d2020-09-28 09:48:29 +0000107endchoice # Ecdsa implementation
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100108endif
Fabio Utzig34e93a52020-02-03 09:59:53 -0300109
110config BOOT_SIGNATURE_TYPE_ED25519
111 bool "Edwards curve digital signatures using ed25519"
112
113if BOOT_SIGNATURE_TYPE_ED25519
Håkon Øye Amundsen21f03762021-11-12 08:21:31 +0000114choice BOOT_ED25519_IMPLEMENTATION
Fabio Utzig34e93a52020-02-03 09:59:53 -0300115 prompt "Ecdsa implementation"
116 default BOOT_ED25519_TINYCRYPT
117config BOOT_ED25519_TINYCRYPT
118 bool "Use tinycrypt"
119 select BOOT_USE_TINYCRYPT
120config BOOT_ED25519_MBEDTLS
121 bool "Use mbedTLS"
122 select BOOT_USE_MBEDTLS
123 select MBEDTLS
124endchoice
125endif
126
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400127endchoice
128
Fabio Utzigc690c762018-04-26 10:51:09 -0300129config BOOT_SIGNATURE_KEY_FILE
130 string "PEM key file"
Håkon Øye Amundsen705c6c22020-09-28 09:45:40 +0000131 default "root-ec-p256.pem" if BOOT_SIGNATURE_TYPE_ECDSA_P256
132 default "root-ed25519.pem" if BOOT_SIGNATURE_TYPE_ED25519
133 default "root-rsa-3072.pem" if BOOT_SIGNATURE_TYPE_RSA && BOOT_SIGNATURE_TYPE_RSA_LEN=3072
134 default "root-rsa-2048.pem" if BOOT_SIGNATURE_TYPE_RSA && BOOT_SIGNATURE_TYPE_RSA_LEN=2048
Fabio Utzigc690c762018-04-26 10:51:09 -0300135 default ""
136 help
Marek Pietabdcfc852020-08-04 02:22:55 -0700137 You can use either absolute or relative path.
138 In case relative path is used, the build system assumes that it starts
139 from the directory where the MCUBoot KConfig configuration file is
140 located. If the key file is not there, the build system uses relative
141 path that starts from the MCUBoot repository root directory.
Fabio Utzigc690c762018-04-26 10:51:09 -0300142 The key file will be parsed by imgtool's getpub command and a .c source
143 with the public key information will be written in a format expected by
144 MCUboot.
145
Andrzej Puzdrowski9a605b62020-03-16 13:34:30 +0100146config MCUBOOT_CLEANUP_ARM_CORE
147 bool "Perform core cleanup before chain-load the application"
148 depends on CPU_CORTEX_M
Ioannis Glaropoulos518d93a2020-10-22 14:22:14 +0200149 default y if !ARCH_SUPPORTS_ARCH_HW_INIT
150 help
151 This option instructs MCUboot to perform a clean-up of a set of
152 architecture core HW registers before junping to the application
153 firmware. The clean-up sets these registers to their warm-reset
154 values as specified by the architecture.
155
156 By default, this option is enabled only if the architecture does
157 not have the functionality to perform such a register clean-up
158 during application firmware boot.
159
160 Zephyr applications on Cortex-M will perform this register clean-up
161 by default, if they are chain-loadable by MCUboot, so MCUboot does
162 not need to perform such a cleanup itself.
Andrzej Puzdrowski9a605b62020-03-16 13:34:30 +0100163
Marti Bolivara4818a52018-04-12 13:02:38 -0400164config MBEDTLS_CFG_FILE
165 default "mcuboot-mbedtls-cfg.h"
166
David Vincze03368b82020-04-01 12:53:53 +0200167config BOOT_HW_KEY
168 bool "Use HW key for image verification"
169 default n
170 help
171 Use HW key for image verification, otherwise the public key is embedded
172 in MCUBoot. If enabled the public key is appended to the signed image
173 and requires the hash of the public key to be provisioned to the device
174 beforehand.
175
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400176config BOOT_VALIDATE_SLOT0
David Vincze2d736ad2019-02-18 11:50:22 +0100177 bool "Validate image in the primary slot on every boot"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400178 default y
179 help
David Vincze2d736ad2019-02-18 11:50:22 +0100180 If y, the bootloader attempts to validate the signature of the
181 primary slot every boot. This adds the signature check time to
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400182 every boot, but can mitigate against some changes that are
183 able to modify the flash image itself.
184
Wouter Cappellebb7a39d2021-05-03 16:44:44 +0200185config BOOT_VALIDATE_SLOT0_ONCE
186 bool "Validate image in the primary slot just once after after upgrade"
187 depends on !BOOT_VALIDATE_SLOT0 && SINGLE_APPLICATION_SLOT
188 default n
189 help
190 If y, the bootloader attempts to validate the signature of the
191 primary slot only once after an upgrade of the main slot.
192 It caches the result in the magic area, which makes it an unsecure
193 method. This option is usefull for lowering the boot up time for
194 low end devices with as a compromise lowering the security level.
195 If unsure, leave at the default value.
196
Andrzej Puzdrowskifdff3e12020-09-15 08:23:25 +0200197if !SINGLE_APPLICATION_SLOT
Håkon Øye Amundsen21f03762021-11-12 08:21:31 +0000198choice BOOT_IMAGE_UPGRADE_MODE
David Vincze5a6e1812020-06-29 13:34:42 +0200199 prompt "Image upgrade modes"
200 default BOOT_SWAP_USING_MOVE if SOC_FAMILY_NRF
201 default BOOT_SWAP_USING_SCRATCH
202
203config BOOT_SWAP_USING_SCRATCH
204 bool "Swap mode that run with the scratch partition"
205 help
206 This is the most conservative swap mode but it can work even on
207 devices with heterogeneous flash page layout.
208
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400209config BOOT_UPGRADE_ONLY
210 bool "Overwrite image updates instead of swapping"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400211 help
David Vincze2d736ad2019-02-18 11:50:22 +0100212 If y, overwrite the primary slot with the upgrade image instead
213 of swapping them. This prevents the fallback recovery, but
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400214 uses a much simpler code path.
215
Fabio Utzigc58842e2019-11-28 10:30:01 -0300216config BOOT_SWAP_USING_MOVE
Fabio Utzigdd2b6802020-01-06 09:10:45 -0300217 bool "Swap mode that can run without a scratch partition"
Fabio Utzigc58842e2019-11-28 10:30:01 -0300218 help
219 If y, the swap upgrade is done in two steps, where first every
220 sector of the primary slot is moved up one sector, then for
221 each sector X in the secondary slot, it is moved to index X in
222 the primary slot, then the sector at X+1 in the primary is
223 moved to index X in the secondary.
224 This allows a swap upgrade without using a scratch partition,
225 but is currently limited to all sectors in both slots being of
226 the same size.
David Vincze5a6e1812020-06-29 13:34:42 +0200227
228config BOOT_DIRECT_XIP
229 bool "Run the latest image directly from its slot"
230 help
231 If y, mcuboot selects the newest valid image based on the image version
232 numbers, thereafter the selected image can run directly from its slot
233 without having to move/copy it into the primary slot. For this reason the
234 images must be linked to be executed from the given image slot. Using this
235 mode results in a simpler code path and smaller code size.
236
Johan Öhmanb5889072022-04-01 09:10:28 +0200237config BOOT_RAM_LOAD
238 bool "RAM load"
239 help
240 If y, mcuboot selects the newest valid image based on the image version
241 numbers, thereafter the selected image is copied to RAM and executed from
242 there. For this reason, the image has to be linked to be executed from RAM.
243 The address that the image is copied to is specified using the load-addr
244 argument to the imgtool.py script which writes it to the image header.
245
David Vincze5a6e1812020-06-29 13:34:42 +0200246endchoice
Fabio Utzigc58842e2019-11-28 10:30:01 -0300247
Johan Öhmanb5889072022-04-01 09:10:28 +0200248# Workaround for not being able to have commas in macro arguments
249DT_CHOSEN_Z_SRAM := zephyr,sram
250
251if BOOT_RAM_LOAD
252config BOOT_IMAGE_EXECUTABLE_RAM_START
253 hex "Boot image executable ram start"
254 default $(dt_chosen_reg_addr_hex,$(DT_CHOSEN_Z_SRAM))
255
256config BOOT_IMAGE_EXECUTABLE_RAM_SIZE
257 int "Boot image executable base size"
258 default $(dt_chosen_reg_size_int,$(DT_CHOSEN_Z_SRAM),0)
259endif
260
David Vincze505fba22020-10-22 13:53:29 +0200261config BOOT_DIRECT_XIP_REVERT
262 bool "Enable the revert mechanism in direct-xip mode"
Andrzej Puzdrowski32342e72020-11-18 17:04:44 +0100263 depends on BOOT_DIRECT_XIP
David Vincze505fba22020-10-22 13:53:29 +0200264 default n
265 help
266 If y, enables the revert mechanism in direct-xip similar to the one in
267 swap mode. It requires the trailer magic to be added to the signed image.
268 When a reboot happens without the image being confirmed at runtime, the
269 bootloader considers the image faulty and erases it. After this it will
270 attempt to boot the previous image. The images can also be made permanent
271 (marked as confirmed in advance) just like in swap mode.
272
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200273config BOOT_BOOTSTRAP
Sam Bristowd0ca0ff2019-10-30 20:51:35 +1300274 bool "Bootstrap erased the primary slot from the secondary slot"
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200275 default n
276 help
277 If y, enables bootstraping support. Bootstrapping allows an erased
David Vincze2d736ad2019-02-18 11:50:22 +0100278 primary slot to be initialized from a valid image in the secondary slot.
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200279 If unsure, leave at the default value.
280
Fabio Utzigca8ead22019-12-20 07:06:04 -0300281config BOOT_SWAP_SAVE_ENCTLV
282 bool "Save encrypted key TLVs instead of plaintext keys in swap metadata"
283 default n
284 help
285 If y, instead of saving the encrypted image keys in plaintext in the
286 swap resume metadata, save the encrypted image TLVs. This should be used
287 when there is no security mechanism protecting the data in the primary
288 slot from being dumped. If n is selected (default), the keys are written
289 after being decrypted from the image TLVs and could be read by an
290 attacker who has access to the flash contents of the primary slot (eg
291 JTAG/SWD or primary slot in external flash).
292 If unsure, leave at the default value.
293
Håkon Øye Amundsene829e9d2021-11-12 14:01:01 +0000294config BOOT_ENCRYPT_IMAGE
295 bool
296 help
297 Hidden option used to check if any image encryption is enabled.
298
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300299config BOOT_ENCRYPT_RSA
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300300 bool "Support for encrypted upgrade images using RSA"
Håkon Øye Amundsene829e9d2021-11-12 14:01:01 +0000301 select BOOT_ENCRYPT_IMAGE
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300302 help
David Vincze2d736ad2019-02-18 11:50:22 +0100303 If y, images in the secondary slot can be encrypted and are decrypted
304 on the fly when upgrading to the primary slot, as well as encrypted
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300305 back when swapping from the primary slot to the secondary slot. The
306 encryption mechanism used in this case is RSA-OAEP (2048 bits).
307
308config BOOT_ENCRYPT_EC256
309 bool "Support for encrypted upgrade images using ECIES-P256"
Håkon Øye Amundsene829e9d2021-11-12 14:01:01 +0000310 select BOOT_ENCRYPT_IMAGE
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300311 help
312 If y, images in the secondary slot can be encrypted and are decrypted
313 on the fly when upgrading to the primary slot, as well as encrypted
314 back when swapping from the primary slot to the secondary slot. The
315 encryption mechanism used in this case is ECIES using primitives
316 described under "ECIES-P256 encryption" in docs/encrypted_images.md.
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300317
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300318config BOOT_ENCRYPT_X25519
319 bool "Support for encrypted upgrade images using ECIES-X25519"
Håkon Øye Amundsene829e9d2021-11-12 14:01:01 +0000320 select BOOT_ENCRYPT_IMAGE
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300321 help
322 If y, images in the secondary slot can be encrypted and are decrypted
323 on the fly when upgrading to the primary slot, as well as encrypted
324 back when swapping from the primary slot to the secondary slot. The
325 encryption mechanism used in this case is ECIES using primitives
326 described under "ECIES-X25519 encryption" in docs/encrypted_images.md.
David Vincze505fba22020-10-22 13:53:29 +0200327endif # !SINGLE_APPLICATION_SLOT
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300328
Wouter Cappelle953a7612021-05-03 16:53:05 +0200329config BOOT_ENCRYPTION_KEY_FILE
330 string "encryption key file"
331 depends on BOOT_ENCRYPT_EC256 || BOOT_SERIAL_ENCRYPT_EC256
332 default "enc-ec256-priv.pem" if BOOT_SIGNATURE_TYPE_ECDSA_P256
333 default ""
334 help
335 You can use either absolute or relative path.
336 In case relative path is used, the build system assumes that it starts
337 from the directory where the MCUBoot KConfig configuration file is
338 located. If the key file is not there, the build system uses relative
339 path that starts from the MCUBoot repository root directory.
340 The key file will be parsed by imgtool's getpriv command and a .c source
341 with the public key information will be written in a format expected by
342 MCUboot.
343
Marti Bolivar0e091c92018-04-12 11:23:16 -0400344config BOOT_MAX_IMG_SECTORS
345 int "Maximum number of sectors per image slot"
346 default 128
347 help
348 This option controls the maximum number of sectors that each of
349 the two image areas can contain. Smaller values reduce MCUboot's
350 memory usage; larger values allow it to support larger images.
351 If unsure, leave at the default value.
352
David Vincze1cf11b52020-03-24 07:51:09 +0100353config MEASURED_BOOT
354 bool "Store the boot state/measurements in shared memory"
355 default n
356 help
357 If enabled, the bootloader will store certain boot measurements such as
358 the hash of the firmware image in a shared memory area. This data can
359 be used later by runtime services (e.g. by a device attestation service).
360
361config BOOT_SHARE_DATA
362 bool "Save application specific data in shared memory area"
363 default n
364
Håkon Øye Amundsen21f03762021-11-12 08:21:31 +0000365choice BOOT_FAULT_INJECTION_HARDENING_PROFILE
Tamas Banfce87332020-07-10 12:40:11 +0100366 prompt "Fault injection hardening profile"
367 default BOOT_FIH_PROFILE_OFF
368
369config BOOT_FIH_PROFILE_OFF
370 bool "No hardening against hardware level fault injection"
371 help
372 No hardening in SW against hardware level fault injection: power or
373 clock glitching, etc.
374
375config BOOT_FIH_PROFILE_LOW
376 bool "Moderate level hardening against hardware level fault injection"
377 help
378 Moderate level hardening: Long global fail loop to avoid break out,
379 control flow integrity check to discover discrepancy in expected code
380 flow.
381
382config BOOT_FIH_PROFILE_MEDIUM
383 bool "Medium level hardening against hardware level fault injection"
384 help
385 Medium level hardening: Long global fail loop to avoid break out,
386 control flow integrity check to discover discrepancy in expected code
387 flow, double variables to discover register or memory corruption.
388
389config BOOT_FIH_PROFILE_HIGH
390 bool "Maximum level hardening against hardware level fault injection"
391 select MBEDTLS
392 help
393 Maximum level hardening: Long global fail loop to avoid break out,
394 control flow integrity check to discover discrepancy in expected code
395 flow, double variables to discover register or memory corruption, random
396 delays to make code execution less predictable. Random delays requires an
397 entropy source.
398
399endchoice
400
Josh Gao837cf882020-11-13 18:51:27 -0800401choice BOOT_USB_DFU
402 prompt "USB DFU"
403 default BOOT_USB_DFU_NO
404
405config BOOT_USB_DFU_NO
406 prompt "Disabled"
407
408config BOOT_USB_DFU_WAIT
Rajavardhan Gundi51c9d702019-02-20 14:08:52 +0530409 bool "Wait for a prescribed duration to see if USB DFU is invoked"
Johann Fischer25852972021-08-02 13:20:09 +0200410 select USB_DEVICE_STACK
Rajavardhan Gundi51c9d702019-02-20 14:08:52 +0530411 select USB_DFU_CLASS
412 select IMG_MANAGER
413 help
414 If y, MCUboot waits for a prescribed duration of time to allow
415 for USB DFU to be invoked. Please note DFU always updates the
416 slot1 image.
417
Josh Gao837cf882020-11-13 18:51:27 -0800418config BOOT_USB_DFU_GPIO
419 bool "Use GPIO to detect whether to trigger DFU mode"
Johann Fischer25852972021-08-02 13:20:09 +0200420 select USB_DEVICE_STACK
Josh Gao837cf882020-11-13 18:51:27 -0800421 select USB_DFU_CLASS
422 select IMG_MANAGER
423 help
424 If y, MCUboot uses GPIO to detect whether to invoke USB DFU.
425
426endchoice
427
428config BOOT_USB_DFU_WAIT_DELAY_MS
429 int "USB DFU wait duration"
430 depends on BOOT_USB_DFU_WAIT
431 default 12000
432 help
433 Milliseconds to wait for USB DFU to be invoked.
434
435if BOOT_USB_DFU_GPIO
436
437config BOOT_USB_DFU_DETECT_PORT
438 string "GPIO device to trigger USB DFU mode"
439 default GPIO_0 if SOC_FAMILY_NRF
440 help
441 Zephyr GPIO device that contains the pin used to trigger
442 USB DFU.
443
444config BOOT_USB_DFU_DETECT_PIN
445 int "Pin to trigger USB DFU mode"
446 default 6 if BOARD_NRF9160DK_NRF9160
447 default 11 if BOARD_NRF52840DK_NRF52840
448 default 13 if BOARD_NRF52DK_NRF52832
Martí Bolívar994816d2021-07-28 12:16:06 -0700449 default 23 if BOARD_NRF5340_DK_NRF5340_CPUAPP || BOARD_NRF5340_DK_NRF5340_CPUAPP_NS
450 default 43 if BOARD_BL5340_DVK_CPUAPP || BOARD_BL5340_DVK_CPUAPP_NS
Josh Gao837cf882020-11-13 18:51:27 -0800451 help
452 Pin on the DFU detect port that triggers DFU mode.
453
454config BOOT_USB_DFU_DETECT_PIN_VAL
455 int "USB DFU detect pin trigger value"
456 default 0
457 range 0 1
458 help
459 Logic value of the detect pin that triggers USB DFU mode.
460
461config BOOT_USB_DFU_DETECT_DELAY
462 int "Serial detect pin detection delay time [ms]"
463 default 0
464 help
465 Used to prevent the bootloader from loading on button press.
466 Useful for powering on when using the same button as
467 the one used to place the device in bootloader mode.
468
469endif # BOOT_USB_DFU_GPIO
470
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400471config ZEPHYR_TRY_MASS_ERASE
472 bool "Try to mass erase flash when flashing MCUboot image"
473 default y
474 help
475 If y, attempt to configure the Zephyr build system's "flash"
476 target to mass-erase the flash device before flashing the
477 MCUboot image. This ensures the scratch and other partitions
478 are in a consistent state.
479
480 This is not available for all targets.
481
David Brownf6d14c22019-12-10 15:36:36 -0700482config BOOT_USE_BENCH
483 bool "Enable benchmark code"
484 default n
485 help
486 If y, adds support for simple benchmarking that can record
487 time intervals between two calls. The time printed depends
488 on the particular Zephyr target, and is generally ticks of a
489 specific board-specific timer.
490
Michael Scott74ceae52019-02-01 14:01:09 -0800491module = MCUBOOT
Piotr Mienkowski15aa6ef2019-04-08 22:48:15 +0200492module-str = MCUBoot bootloader
Michael Scott74ceae52019-02-01 14:01:09 -0800493source "subsys/logging/Kconfig.template.log_config"
Michael Scott74ceae52019-02-01 14:01:09 -0800494
Andrzej Puzdrowskiaf148532020-02-25 12:51:26 +0100495config MCUBOOT_LOG_THREAD_STACK_SIZE
496 int "Stack size for the MCUBoot log processing thread"
497 depends on LOG && !LOG_IMMEDIATE
498 default 2048 if COVERAGE_GCOV
499 default 1024 if NO_OPTIMIZATIONS
500 default 1024 if XTENSA
501 default 4096 if (X86 && X86_64)
502 default 4096 if ARM64
503 default 768
504 help
505 Set the internal stack size for MCUBoot log processing thread.
506
Andrzej Puzdrowski6c00b5e2022-04-01 16:51:27 +0200507config MCUBOOT_INDICATION_LED
508 bool "Turns on LED indication when device is in DFU"
509 default n
510 help
511 Device device activates the LED while in bootloader mode.
512 bootloader-led0 alias must be set in the device's .dts
513 definitions for this to work.
514
Andrzej Puzdrowski35f61d32022-04-01 17:00:08 +0200515rsource "Kconfig.serial_recovery"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200516
Rafał Kuźniad854bb62020-06-17 15:06:47 +0200517config BOOT_INTR_VEC_RELOC
518 bool "Relocate the interrupt vector to the application"
519 default n
520 depends on SW_VECTOR_RELAY || CPU_CORTEX_M_HAS_VTOR
521 help
522 Relocate the interrupt vector to the application before it is started.
523 Select this option if application requires vector relocation,
524 but it doesn't relocate vector in its reset handler.
525
Andrzej Puzdrowski16b6d152020-06-01 14:16:54 +0200526config UPDATEABLE_IMAGE_NUMBER
527 int "Number of updateable images"
528 default 1
Andrzej Puzdrowskifdff3e12020-09-15 08:23:25 +0200529 range 1 1 if SINGLE_APPLICATION_SLOT
Andrzej Puzdrowski16b6d152020-06-01 14:16:54 +0200530 help
531 Enables support of multi image update.
532
Håkon Øye Amundsen21f03762021-11-12 08:21:31 +0000533choice BOOT_DOWNGRADE_PREVENTION_CHOICE
Andrzej Puzdrowski16b6d152020-06-01 14:16:54 +0200534 prompt "Downgrade prevention"
535 optional
536
537config MCUBOOT_DOWNGRADE_PREVENTION
538 bool "SW based downgrade prevention"
539 depends on BOOT_UPGRADE_ONLY
540 help
541 Prevent downgrades by enforcing incrementing version numbers.
542 When this option is set, any upgrade must have greater major version
543 or greater minor version with equal major version. This mechanism
544 only protects against some attacks against version downgrades (for
545 example, a JTAG could be used to write an older version).
546
547config MCUBOOT_HW_DOWNGRADE_PREVENTION
548 bool "HW based downgrade prevention"
549 help
550 Prevent undesirable/malicious software downgrades. When this option is
551 set, any upgrade must have greater or equal security counter value.
552 Because of the acceptance of equal values it allows for software
553 downgrade to some extent.
554
555endchoice
556
Andrzej Puzdrowskid21442a2020-10-12 16:47:28 +0200557config BOOT_WATCHDOG_FEED
558 bool "Feed the watchdog while doing swap"
559 default y if SOC_FAMILY_NRF
560 imply NRFX_WDT
561 imply NRFX_WDT0
562 imply NRFX_WDT1
563 help
564 Enables implementation of MCUBOOT_WATCHDOG_FEED() macro which is
565 used to feed watchdog while doing time consuming operations.
566
Andrzej Puzdrowski914204d2021-07-09 19:20:46 +0200567config BOOT_IMAGE_ACCESS_HOOKS
568 bool "Enable hooks for overriding MCUboot's native routines"
569 help
570 Allow to provide procedures for override or extend native
571 MCUboot's routines required for access the image data and the image
572 update.
573
574config BOOT_IMAGE_ACCESS_HOOKS_FILE
575 string "Hooks implementation file path"
576 depends on BOOT_IMAGE_ACCESS_HOOKS
577 help
578 Path to the file which implements hooks.
579 You can use either absolute or relative path.
580 In case relative path is used, the build system assumes that it starts
581 from the directory where the MCUBoot KConfig configuration file is
582 located. If the key file is not there, the build system uses relative
583 path that starts from the zephyr port cmake directory (boot/zephyr/).
584
Jamie McCrae56cb6102022-03-23 11:57:03 +0000585config MCUBOOT_ACTION_HOOKS
586 bool "Enable hooks for responding to MCUboot status changes"
587 help
588 This will call a handler when the MCUboot status changes which allows
589 for some level of user feedback, for instance to change LED status to
590 indicate a failure, using the callback:
591 'void mcuboot_status_change(mcuboot_status_type_t status)' where
592 'mcuboot_status_type_t' is listed in
593 boot/bootutil/include/bootutil/mcuboot_status.h
594
Andrzej Puzdrowski97543282018-04-12 15:16:56 +0200595endmenu
596
Carles Cufi84ede582018-01-29 15:12:00 +0100597config MCUBOOT_DEVICE_SETTINGS
598 # Hidden selector for device-specific settings
599 bool
600 default y
601 # CPU options
602 select MCUBOOT_DEVICE_CPU_CORTEX_M0 if CPU_CORTEX_M0
Carles Cufi67c792e2018-01-29 15:14:31 +0100603 # Enable flash page layout if available
604 select FLASH_PAGE_LAYOUT if FLASH_HAS_PAGE_LAYOUT
Andrzej Puzdrowskib788c712018-04-12 12:42:49 +0200605 # Enable flash_map module as flash I/O back-end
606 select FLASH_MAP
Carles Cufi84ede582018-01-29 15:12:00 +0100607
608config MCUBOOT_DEVICE_CPU_CORTEX_M0
609 # Hidden selector for Cortex-M0 settings
610 bool
611 default n
612 select SW_VECTOR_RELAY if !CPU_CORTEX_M0_HAS_VECTOR_TABLE_REMAP
613
Marti Bolivar0e091c92018-04-12 11:23:16 -0400614comment "Zephyr configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200615
Marti Bolivarf84cc4b2019-08-20 16:06:56 -0700616# Disabling MULTITHREADING provides a code size advantage, but
617# it requires peripheral drivers (particularly a flash driver)
618# that works properly with the option enabled.
619#
620# If you know for sure that your hardware will work, you can default
621# it to n here. Otherwise, having it on by default makes the most
622# hardware work.
623config MULTITHREADING
Andrzej Puzdrowski9a4946c2020-02-20 12:39:12 +0100624 default y if BOOT_SERIAL_CDC_ACM #usb driver requires MULTITHREADING
Josh Gao837cf882020-11-13 18:51:27 -0800625 default y if BOOT_USB_DFU_GPIO || BOOT_USB_DFU_WAIT
Marti Bolivarf84cc4b2019-08-20 16:06:56 -0700626 default n if SOC_FAMILY_NRF
627 default y
628
Andrzej Puzdrowski3f092bd2020-02-17 13:25:32 +0100629config LOG_PROCESS_THREAD
630 default n # mcuboot has its own log processing thread
631
632# override USB device name
633config USB_DEVICE_PRODUCT
634 default "MCUBOOT"
Andrzej Puzdrowski9a4946c2020-02-20 12:39:12 +0100635
Andrzej Puzdrowskif573b392020-11-10 14:35:15 +0100636# use MCUboot's own log configuration
637config MCUBOOT_BOOTUTIL_LIB_OWN_LOG
638 bool
639 default n
640
Håkon Øye Amundsene829e9d2021-11-12 14:01:01 +0000641config MCUBOOT_VERIFY_IMG_ADDRESS
642 bool "Verify reset address of image in secondary slot"
643 depends on UPDATEABLE_IMAGE_NUMBER > 1
644 depends on !BOOT_ENCRYPT_IMAGE
645 depends on ARM
646 default y if BOOT_UPGRADE_ONLY
647 help
648 Verify that the reset address in the image located in the secondary slot
649 is contained within the corresponding primary slot. This is recommended
650 if swapping is not used (that is, BOOT_UPGRADE_ONLY is set). If a user
651 incorrectly uploads an update for image 1 to image 0's secondary slot
652 MCUboot will overwrite image 0's primary slot with this image even
653 though it will not boot. If swapping is enabled this will be handled
654 since the image will not confirm itself. If, however, swapping is not
655 enabled then the only mitigation is serial recovery. This feature can
656 also be useful when BOOT_DIRECT_XIP is enabled, to ensure that the image
657 linked at the correct address is loaded.
658
Robert Lubos1b19d2a2020-01-31 14:05:35 +0100659source "Kconfig.zephyr"