blob: 9d5f17555db666d15f01febfaaaa74f28aa46d2c [file] [log] [blame]
Mate Toth-Pal65c935e2018-01-17 18:42:13 +01001#-------------------------------------------------------------------------------
Jamie Fox17c30bb2019-01-10 13:39:33 +00002# Copyright (c) 2018-2019, Arm Limited. All rights reserved.
Mate Toth-Pal65c935e2018-01-17 18:42:13 +01003#
4# SPDX-License-Identifier: BSD-3-Clause
5#
6#-------------------------------------------------------------------------------
7
8if(NOT DEFINED REGRESSION)
9 message(FATAL_ERROR "ERROR: Incomplete Configuration: REGRESSION not defined, Include this file from a Config*.cmake")
10elseif(NOT DEFINED CORE_TEST)
11 message(FATAL_ERROR "ERROR: Incomplete Configuration: CORE_TEST not defined, Include this file from a Config*.cmake")
Tamas Band90c81b2018-08-15 15:03:42 +010012elseif(NOT DEFINED TFM_LVL)
13 message(FATAL_ERROR "ERROR: Incomplete Configuration: TFM_LVL not defined, Include this file from a Config*.cmake")
David Huf2cfa122019-08-27 15:32:38 +080014elseif(NOT DEFINED CORE_IPC)
15 message(FATAL_ERROR "ERROR: Incomplete Configuration: CORE_IPC not deinfed. Include this file from a Config*.cmake")
Mate Toth-Pal65c935e2018-01-17 18:42:13 +010016endif()
17
Mate Toth-Palee551bc2018-06-12 16:40:45 +020018if(NOT DEFINED COMPILER)
19 message(FATAL_ERROR "ERROR: COMPILER is not set in command line")
20elseif((NOT ${COMPILER} STREQUAL "ARMCLANG") AND (NOT ${COMPILER} STREQUAL "GNUARM"))
21 message(FATAL_ERROR "ERROR: Compiler \"${COMPILER}\" is not supported.")
22endif()
23
Tamas Bandd10fe52019-09-18 11:52:32 +010024#Configure the default build type
25set(CMAKE_BUILD_TYPE "Debug" CACHE STRING "Build type (i.e. Debug)")
26
Raef Colesb321c0b2019-10-15 08:49:17 +010027#Ignore case on the cmake build types
28string(TOLOWER ${CMAKE_BUILD_TYPE} CMAKE_BUILD_TYPE)
29
Edison Aicb0ecf62019-07-10 18:43:51 +080030if(CORE_IPC)
31 if (TFM_LVL EQUAL 3)
32 message(FATAL_ERROR "ERROR: Invalid isolation level!")
33 endif()
34else()
35 if(NOT TFM_LVL EQUAL 1)
36 message(FATAL_ERROR "ERROR: Invalid isolation level!")
37 endif()
38endif()
39
David Vincze4638b2a2019-05-24 10:14:23 +020040#BL2 bootloader (MCUBoot) related settings
David Vincze54d05552019-08-05 12:58:47 +020041include(${CMAKE_CURRENT_LIST_DIR}/bl2/ext/mcuboot/MCUBootConfig.cmake)
David Vincze4638b2a2019-05-24 10:14:23 +020042
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010043set(BUILD_CMSIS_CORE Off)
44set(BUILD_RETARGET Off)
45set(BUILD_NATIVE_DRIVERS Off)
46set(BUILD_TIME Off)
47set(BUILD_STARTUP Off)
48set(BUILD_TARGET_CFG Off)
49set(BUILD_TARGET_HARDWARE_KEYS Off)
Marc Moreno Berengue4cc81fc2018-08-10 14:32:01 +010050set(BUILD_TARGET_NV_COUNTERS Off)
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010051set(BUILD_CMSIS_DRIVERS Off)
52set(BUILD_UART_STDOUT Off)
53set(BUILD_FLASH Off)
Mate Toth-Pald3c77662019-02-20 16:23:00 +010054set(BUILD_PLAT_TEST Off)
Tamas Band4bf3472019-09-06 12:59:56 +010055set(BUILD_BOOT_HAL Off)
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010056if(NOT DEFINED PLATFORM_CMAKE_FILE)
57 message (FATAL_ERROR "Platform specific CMake is not defined. Please set PLATFORM_CMAKE_FILE.")
58elseif(NOT EXISTS ${PLATFORM_CMAKE_FILE})
59 message (FATAL_ERROR "Platform specific CMake \"${PLATFORM_CMAKE_FILE}\" file does not exist. Please fix value of PLATFORM_CMAKE_FILE.")
60else()
61 include(${PLATFORM_CMAKE_FILE})
62endif()
63
David Hu857bfa52019-05-21 13:54:50 +080064# Select the corresponding CPU type and configuration according to current
65# building status in multi-core scenario.
66# The updated configuration will be used in following compiler setting.
67if (DEFINED TFM_MULTI_CORE_TOPOLOGY AND TFM_MULTI_CORE_TOPOLOGY)
David Hu104388f2019-11-18 14:37:32 +080068 if (NOT CORE_IPC)
69 message(FATAL_ERROR "CORE_IPC is OFF. Multi-core topology should work in IPC model.")
70 endif()
71
David Hu857bfa52019-05-21 13:54:50 +080072 include("Common/MultiCore")
73
74 if (NOT DEFINED TFM_BUILD_IN_SPE)
75 message(FATAL_ERROR "Flag of building in SPE is not specified. Please set TFM_BUILD_IN_SPE.")
76 else()
77 select_arm_cpu_type(${TFM_BUILD_IN_SPE})
78 endif()
David Hu857bfa52019-05-21 13:54:50 +080079
David Hufeae0f92019-06-17 13:42:20 +080080 # CMSE is unnecessary in multi-core scenarios.
81 # TODO: Need further discussion about if CMSE is required when an Armv8-M
82 # core acts as secure core in multi-core scenario.
83 set (CMSE_FLAGS "")
84 set (ARM_FEATURE_CMSE 0)
85else()
86 set (CMSE_FLAGS "-mcmse")
87 set (ARM_FEATURE_CMSE 3)
88endif()
89
Mate Toth-Palee551bc2018-06-12 16:40:45 +020090if(${COMPILER} STREQUAL "ARMCLANG")
Mate Toth-Pal76867262018-03-09 13:15:36 +010091 #Use any ARMCLANG version found on PATH. Note: Only versions supported by the
92 #build system will work. A file cmake/Common/CompilerArmClangXY.cmake
93 #must be present with a matching version.
94 include("Common/FindArmClang")
95 include("Common/${ARMCLANG_MODULE}")
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010096
David Hufeae0f92019-06-17 13:42:20 +080097 set (COMMON_COMPILE_FLAGS -fshort-enums -fshort-wchar -funsigned-char -mfpu=none ${CMSE_FLAGS} -ffunction-sections -fdata-sections)
Tamas Bandb69d522018-03-01 10:04:41 +000098 ##Shared compiler settings.
99 function(config_setting_shared_compiler_flags tgt)
Mate Toth-Pal76867262018-03-09 13:15:36 +0100100 embedded_set_target_compile_flags(TARGET ${tgt} LANGUAGE C FLAGS -xc -std=c99 ${COMMON_COMPILE_FLAGS} -Wall -Werror)
Tamas Bandb69d522018-03-01 10:04:41 +0000101 endfunction()
102
103 ##Shared linker settings.
104 function(config_setting_shared_linker_flags tgt)
Antonio de Angelis3302f452019-07-19 10:36:33 +0100105 embedded_set_target_link_flags(TARGET ${tgt} FLAGS --strict --map --symbols --xref --entry=Reset_Handler --remove --info=summarysizes,sizes,totals,unused,veneers)
Mate Toth-Pal76867262018-03-09 13:15:36 +0100106 endfunction()
107elseif(${COMPILER} STREQUAL "GNUARM")
108 #Use any GNUARM version found on PATH. Note: Only versions supported by the
109 #build system will work. A file cmake/Common/CompilerGNUARMXY.cmake
110 #must be present with a matching version.
111 include("Common/FindGNUARM")
112 include("Common/${GNUARM_MODULE}")
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +0100113
David Hufeae0f92019-06-17 13:42:20 +0800114 set (COMMON_COMPILE_FLAGS -fshort-enums -fshort-wchar -funsigned-char -msoft-float ${CMSE_FLAGS} -ffunction-sections -fdata-sections --specs=nano.specs)
Mate Toth-Pal76867262018-03-09 13:15:36 +0100115 ##Shared compiler and linker settings.
Tamas Bandb69d522018-03-01 10:04:41 +0000116 function(config_setting_shared_compiler_flags tgt)
Mate Toth-Pal76867262018-03-09 13:15:36 +0100117 embedded_set_target_compile_flags(TARGET ${tgt} LANGUAGE C FLAGS -xc -std=c99 ${COMMON_COMPILE_FLAGS} -Wall -Werror -Wno-format -Wno-return-type -Wno-unused-but-set-variable)
Tamas Bandb69d522018-03-01 10:04:41 +0000118 endfunction()
119
120 ##Shared linker settings.
121 function(config_setting_shared_linker_flags tgt)
Mate Toth-Pal76867262018-03-09 13:15:36 +0100122 #--no-wchar-size-warning flag is added because TF-M sources are compiled
123 #with short wchars, however the standard library is compiled with normal
124 #wchar, and this generates linker time warnings. TF-M code does not use
125 #wchar, so the warning can be suppressed.
Antonio de Angelis3302f452019-07-19 10:36:33 +0100126 embedded_set_target_link_flags(TARGET ${tgt} FLAGS -Wl,-check-sections,-fatal-warnings,--gc-sections,--no-wchar-size-warning,--print-memory-usage --entry=Reset_Handler --specs=nano.specs)
Mate Toth-Pal76867262018-03-09 13:15:36 +0100127 endfunction()
Mate Toth-Pal76867262018-03-09 13:15:36 +0100128endif()
129
130#Create a string from the compile flags list, so that it can be used later
131#in this file to set mbedtls and BL2 flags
Tamas Bandb69d522018-03-01 10:04:41 +0000132list_to_string(COMMON_COMPILE_FLAGS_STR ${COMMON_COMPILE_FLAGS})
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100133
134#Settings which shall be set for all projects the same way based
135# on the variables above.
Mate Toth-Pal349714a2018-02-23 15:30:24 +0100136set (TFM_PARTITION_TEST_CORE OFF)
Jamie Foxadf02552019-05-16 17:44:52 +0100137set (TFM_PARTITION_TEST_CORE_IPC OFF)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100138set (CORE_TEST_POSITIVE OFF)
139set (CORE_TEST_INTERACTIVE OFF)
Miklos Balintf13ec022018-04-06 17:21:22 +0200140set (REFERENCE_PLATFORM OFF)
Ben Davis6d7256b2018-04-18 14:16:53 +0100141set (TFM_PARTITION_TEST_SECURE_SERVICES OFF)
Jamie Fox0e823a02019-10-28 17:28:19 +0000142set (TFM_PARTITION_TEST_SST OFF)
Tamas Band90c81b2018-08-15 15:03:42 +0100143set (SERVICES_TEST_ENABLED OFF)
Marc Moreno Berenguecae2c532018-10-09 12:58:46 +0100144set (TEST_FRAMEWORK_S OFF)
145set (TEST_FRAMEWORK_NS OFF)
Edison Aiec109cd2018-07-17 16:04:14 +0800146set (TFM_PSA_API OFF)
Miklos Balint87da2512018-04-19 13:45:50 +0200147set (TFM_LEGACY_API ON)
Miklos Balintf13ec022018-04-06 17:21:22 +0200148
Jamie Foxc78c62c2019-05-23 13:42:17 +0100149option(TFM_PARTITION_AUDIT_LOG "Enable the TF-M Audit Log partition" ON)
Mingyang Sun9511e5e2019-05-29 18:18:44 +0800150option(TFM_PARTITION_PLATFORM "Enable the TF-M Platform partition" ON)
Kevin Pengc73130f2019-10-22 17:27:18 +0800151option(TFM_PARTITION_SECURE_STORAGE "Enable the TF-M secure storage partition" ON)
152option(TFM_PARTITION_INTERNAL_TRUSTED_STORAGE "Enable the TF-M internal trusted storage partition" ON)
153option(TFM_PARTITION_CRYPTO "Enable the TF-M crypto partition" ON)
154option(TFM_PARTITION_INITIAL_ATTESTATION "Enable the TF-M initial attestation partition" ON)
155
156if (TFM_PARTITION_INITIAL_ATTESTATION OR TFM_PARTITION_SECURE_STORAGE)
157 #PSA Initial Attestation and Protected storage rely on Cryptography API
158 set(TFM_PARTITION_CRYPTO ON)
159endif()
Jamie Foxc78c62c2019-05-23 13:42:17 +0100160
Marton Berke6fd21f12019-07-02 13:43:07 +0200161if(${TARGET_PLATFORM} STREQUAL "AN521" OR ${TARGET_PLATFORM} STREQUAL "AN519" OR ${TARGET_PLATFORM} STREQUAL "AN539")
Miklos Balintf13ec022018-04-06 17:21:22 +0200162 set (REFERENCE_PLATFORM ON)
163endif()
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100164
Miklos Balint6cbeba62018-04-12 17:31:34 +0200165# Option to demonstrate usage of secure-only peripheral
166set (SECURE_UART1 OFF)
167
Alan DeMars61844692019-10-22 08:23:29 -0700168if (PLATFORM_SVC_HANDLERS)
169 add_definitions(-DPLATFORM_SVC_HANDLERS)
170endif()
171
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100172if (REGRESSION)
173 set(SERVICES_TEST_ENABLED ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100174endif()
175
Edison Aiec109cd2018-07-17 16:04:14 +0800176if (CORE_IPC)
177 set(TFM_PSA_API ON)
David Huf2cfa122019-08-27 15:32:38 +0800178
179 # Disable IPC Test by default if the config or platform doesn't explicitly
180 # require it
181 if (NOT DEFINED IPC_TEST)
182 set(IPC_TEST OFF)
183 endif()
184else()
185 set(IPC_TEST OFF)
Edison Aiec109cd2018-07-17 16:04:14 +0800186endif()
187
Miklos Balint87da2512018-04-19 13:45:50 +0200188if (TFM_PSA_API)
189 add_definitions(-DTFM_PSA_API)
190endif()
191
David Hu104388f2019-11-18 14:37:32 +0800192if (DEFINED TFM_MULTI_CORE_TOPOLOGY AND TFM_MULTI_CORE_TOPOLOGY)
193 add_definitions(-DTFM_MULTI_CORE_TOPOLOGY)
194endif()
195
Miklos Balint87da2512018-04-19 13:45:50 +0200196if (TFM_LEGACY_API)
197 add_definitions(-DTFM_LEGACY_API)
198endif()
199
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100200if (SERVICES_TEST_ENABLED)
201 set(SERVICE_TEST_S ON)
202 set(SERVICE_TEST_NS ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100203endif()
204
205if (CORE_TEST)
Mate Toth-Pal6569a592019-06-07 12:09:50 +0200206 set(CORE_TEST_POSITIVE ON)
207 set(CORE_TEST_INTERACTIVE OFF)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100208endif()
209
Ben Davis6d7256b2018-04-18 14:16:53 +0100210if (CORE_TEST_INTERACTIVE)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100211 add_definitions(-DCORE_TEST_INTERACTIVE)
212 set(TEST_FRAMEWORK_NS ON)
Mate Toth-Pal349714a2018-02-23 15:30:24 +0100213 set(TFM_PARTITION_TEST_CORE ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100214endif()
215
Ben Davis6d7256b2018-04-18 14:16:53 +0100216if (CORE_TEST_POSITIVE)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100217 add_definitions(-DCORE_TEST_POSITIVE)
218 set(TEST_FRAMEWORK_NS ON)
Mate Toth-Pal349714a2018-02-23 15:30:24 +0100219 set(TFM_PARTITION_TEST_CORE ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100220endif()
221
David Hu33f2fd22019-08-16 15:32:39 +0800222if (TFM_PARTITION_TEST_CORE)
223 # If the platform or the topology doesn't specify whether IRQ test is
224 # supported, enable it by default.
225 if (NOT DEFINED TFM_ENABLE_IRQ_TEST)
226 set(TFM_ENABLE_IRQ_TEST ON)
227 endif()
228
229 if (TFM_ENABLE_IRQ_TEST)
230 add_definitions(-DTFM_ENABLE_IRQ_TEST)
231 endif()
232else()
233 set(TFM_ENABLE_IRQ_TEST OFF)
234endif()
235
David Huf2cfa122019-08-27 15:32:38 +0800236if (IPC_TEST)
237 add_definitions(-DENABLE_IPC_TEST)
Jamie Foxadf02552019-05-16 17:44:52 +0100238 set(TEST_FRAMEWORK_NS ON)
239 set(TFM_PARTITION_TEST_CORE_IPC ON)
Edison Aiec109cd2018-07-17 16:04:14 +0800240endif()
241
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100242if (SERVICE_TEST_S)
243 add_definitions(-DSERVICES_TEST_S)
244 set(TEST_FRAMEWORK_S ON)
245endif()
246
247if (SERVICE_TEST_NS)
248 add_definitions(-DSERVICES_TEST_NS)
249 set(TEST_FRAMEWORK_NS ON)
250endif()
251
Ben Davis6d7256b2018-04-18 14:16:53 +0100252if (TEST_FRAMEWORK_S)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100253 add_definitions(-DTEST_FRAMEWORK_S)
Jamie Fox56da0992019-05-28 14:35:06 +0100254 # The secure client partition is required to run secure tests
255 set(TFM_PARTITION_TEST_SECURE_SERVICES ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100256endif()
257
Ben Davis6d7256b2018-04-18 14:16:53 +0100258if (TEST_FRAMEWORK_NS)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100259 add_definitions(-DTEST_FRAMEWORK_NS)
260endif()
261
Jamie Foxc78c62c2019-05-23 13:42:17 +0100262if (CORE_IPC)
263 set(TFM_PARTITION_AUDIT_LOG OFF)
264endif()
265
Kevin Pengedde1de2019-10-25 17:12:45 +0800266include(${CMAKE_CURRENT_LIST_DIR}/test/TestConfig.cmake)
267
Jamie Foxc78c62c2019-05-23 13:42:17 +0100268if (TFM_PARTITION_AUDIT_LOG)
269 add_definitions(-DTFM_PARTITION_AUDIT_LOG)
270endif()
271
Mingyang Sun9511e5e2019-05-29 18:18:44 +0800272if (TFM_PARTITION_PLATFORM)
273 add_definitions(-DTFM_PARTITION_PLATFORM)
274endif()
275
Kevin Pengc73130f2019-10-22 17:27:18 +0800276if (TFM_PARTITION_SECURE_STORAGE)
277 add_definitions(-DTFM_PARTITION_SECURE_STORAGE)
278endif()
279
280if (TFM_PARTITION_INTERNAL_TRUSTED_STORAGE)
281 add_definitions(-DTFM_PARTITION_INTERNAL_TRUSTED_STORAGE)
282endif()
283
284if (TFM_PARTITION_CRYPTO)
285 add_definitions(-DTFM_PARTITION_CRYPTO)
286endif()
287
288if (TFM_PARTITION_INITIAL_ATTESTATION)
289 add_definitions(-DTFM_PARTITION_INITIAL_ATTESTATION)
290endif()
291
Mate Toth-Pal349714a2018-02-23 15:30:24 +0100292if (TFM_PARTITION_TEST_CORE)
293 add_definitions(-DTFM_PARTITION_TEST_CORE)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100294endif()
295
Jamie Foxadf02552019-05-16 17:44:52 +0100296if (TFM_PARTITION_TEST_CORE_IPC)
297 add_definitions(-DTFM_PARTITION_TEST_CORE_IPC)
298endif()
299
Jamie Foxc78c62c2019-05-23 13:42:17 +0100300if (TFM_PARTITION_TEST_SECURE_SERVICES)
301 add_definitions(-DTFM_PARTITION_TEST_SECURE_SERVICES)
302endif()
303
Jamie Fox17c30bb2019-01-10 13:39:33 +0000304if (PSA_API_TEST)
305 add_definitions(-DPSA_API_TEST_NS)
306 set(PSA_API_TEST_NS ON)
307 if (NOT DEFINED PSA_API_TEST_CRYPTO)
308 set(PSA_API_TEST_CRYPTO OFF)
309 endif()
Jamie Fox6b6a19b2019-09-30 16:54:17 +0100310 if (NOT DEFINED PSA_API_TEST_INTERNAL_TRUSTED_STORAGE)
311 set(PSA_API_TEST_INTERNAL_TRUSTED_STORAGE OFF)
312 endif()
Jamie Fox17c30bb2019-01-10 13:39:33 +0000313 if (NOT DEFINED PSA_API_TEST_SECURE_STORAGE)
314 set(PSA_API_TEST_SECURE_STORAGE OFF)
315 endif()
316 if (NOT DEFINED PSA_API_TEST_ATTESTATION)
317 set(PSA_API_TEST_ATTESTATION OFF)
318 endif()
319endif()
320
Marc Moreno Berenguec2e4db82018-09-14 16:32:24 +0100321# This flag indicates if the non-secure OS is capable of identify the non-secure clients
Mingyang Sun9ac02372019-08-26 15:59:14 +0800322# which call the secure services. It is diabled in IPC model.
Marc Moreno Berenguec2e4db82018-09-14 16:32:24 +0100323if (NOT DEFINED TFM_NS_CLIENT_IDENTIFICATION)
Mingyang Sun9ac02372019-08-26 15:59:14 +0800324 if (TFM_PSA_API)
325 set(TFM_NS_CLIENT_IDENTIFICATION OFF)
326 else()
327 set(TFM_NS_CLIENT_IDENTIFICATION ON)
328 endif()
Marc Moreno Berenguec2e4db82018-09-14 16:32:24 +0100329endif()
330
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100331if (BL2)
David Vincze63eda7a2019-08-09 17:42:51 +0200332 # Add MCUBOOT_IMAGE_NUMBER definition to the compiler command line.
333 add_definitions(-DMCUBOOT_IMAGE_NUMBER=${MCUBOOT_IMAGE_NUMBER})
334
David Vincze4638b2a2019-05-24 10:14:23 +0200335 if (${MCUBOOT_UPGRADE_STRATEGY} STREQUAL "NO_SWAP")
Tamas Bandb69d522018-03-01 10:04:41 +0000336 set(LINK_TO_BOTH_MEMORY_REGION ON)
337 endif()
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100338endif()
339
Raef Coles1bb168e2019-10-17 09:04:55 +0100340##Set Mbed Crypto compiler flags and variables for crypto service
341set(MBEDCRYPTO_C_FLAGS_SERVICES "-D__ARM_FEATURE_CMSE=${ARM_FEATURE_CMSE} -D__thumb2__ ${COMMON_COMPILE_FLAGS_STR} -I${CMAKE_CURRENT_LIST_DIR}/platform/ext/common")
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100342
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000343#Default TF-M secure storage flags.
344#These flags values can be overwritten by setting them in platform/ext/<TARGET_NAME>.cmake
Tamas Ban01f64c52019-08-26 13:46:21 +0100345#Documentation about these flags can be found in docs/user_guides/services/tfm_sst_integration_guide.rst
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000346if (NOT DEFINED SST_ENCRYPTION)
347 set (SST_ENCRYPTION ON)
348endif()
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000349
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000350if (NOT DEFINED SST_ROLLBACK_PROTECTION)
351 set (SST_ROLLBACK_PROTECTION OFF)
352endif()
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000353
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000354if (NOT DEFINED SST_CREATE_FLASH_LAYOUT)
355 set (SST_CREATE_FLASH_LAYOUT OFF)
356endif()
Marc Moreno Berengue184d2032018-08-14 12:51:43 +0100357
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000358if (NOT DEFINED SST_VALIDATE_METADATA_FROM_FLASH)
359 set (SST_VALIDATE_METADATA_FROM_FLASH ON)
360endif()
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000361
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000362if (NOT DEFINED SST_RAM_FS)
363 if (REGRESSION)
364 set (SST_RAM_FS ON)
365 else()
366 set (SST_RAM_FS OFF)
Marc Moreno Berengue02a23442018-08-15 14:28:45 +0100367 endif()
Marc Moreno Berengue792fc682018-02-20 11:53:30 +0000368endif()
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000369
Jamie Fox95bacd42019-03-21 18:14:15 +0000370if (NOT DEFINED SST_TEST_NV_COUNTERS)
Kevin Pengedde1de2019-10-25 17:12:45 +0800371 if (REGRESSION AND ENABLE_SECURE_STORAGE_SERVICE_TESTS)
Jamie Fox95bacd42019-03-21 18:14:15 +0000372 set(SST_TEST_NV_COUNTERS ON)
373 else()
374 set(SST_TEST_NV_COUNTERS OFF)
375 endif()
376endif()
377
Jamie Fox0e823a02019-10-28 17:28:19 +0000378# The SST NV counter tests depend on the SST test partition to call
379# sst_system_prepare().
380if (SST_TEST_NV_COUNTERS)
381 set(TFM_PARTITION_TEST_SST ON)
382 add_definitions(-DTFM_PARTITION_TEST_SST)
383endif()
384
TudorCretufb182bc2019-07-05 17:34:12 +0100385#Default TF-M internal trusted storage flags.
386#These flags values can be overwritten by setting them in platform/ext/<TARGET_NAME>.cmake
387#Documentation about these flags can be found in the TF-M ITS integration guide
388option(ITS_CREATE_FLASH_LAYOUT "Create an empty ITS Flash Layout" OFF)
389
390if (NOT DEFINED ITS_VALIDATE_METADATA_FROM_FLASH)
391 set (ITS_VALIDATE_METADATA_FROM_FLASH ON)
392endif()
393
394if (NOT DEFINED ITS_RAM_FS)
395 if (REGRESSION)
396 set (ITS_RAM_FS ON)
397 else()
398 set (ITS_RAM_FS OFF)
399 endif()
400endif()
401
Raef Coles1bb168e2019-10-17 09:04:55 +0100402if (NOT DEFINED MBEDCRYPTO_DEBUG)
403 set(MBEDCRYPTO_DEBUG OFF)
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000404endif()
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100405
Tamas Ban01f64c52019-08-26 13:46:21 +0100406#Default TF-M initial-attestation service flags.
407#Documentation about these flags can be found in docs/user_guides/services/tfm_attestation_integration_guide.rst
408if (NOT DEFINED ATTEST_INCLUDE_OPTIONAL_CLAIMS)
409 set(ATTEST_INCLUDE_OPTIONAL_CLAIMS ON)
410endif()
411
Raef Colesb321c0b2019-10-15 08:49:17 +0100412if (CMAKE_BUILD_TYPE STREQUAL "debug")
Tamas Ban303dd082019-08-27 10:43:03 +0100413 set(ATTEST_INCLUDE_TEST_CODE_AND_KEY_ID ON)
414else()
415 set(ATTEST_INCLUDE_TEST_CODE_AND_KEY_ID OFF)
416endif()
417
David Vincze00dceb12019-09-17 17:34:03 +0200418set(ATTEST_BOOT_INTERFACE "CBOR_ENCODED_CLAIMS" CACHE STRING "Set the format in which to pass the claims to the initial-attestation service.")
David Vincze219a1752019-10-14 11:35:09 +0200419set_property(CACHE ATTEST_BOOT_INTERFACE PROPERTY STRINGS "INDIVIDUAL_CLAIMS;CBOR_ENCODED_CLAIMS")
420validate_cache_value(ATTEST_BOOT_INTERFACE)
421
Tamas Bandb69d522018-03-01 10:04:41 +0000422##Set mbedTLS compiler flags for BL2 bootloader
David Vinczecea8b592019-10-29 16:09:51 +0100423set(MBEDCRYPTO_C_FLAGS_BL2 "-D__ARM_FEATURE_CMSE=${ARM_FEATURE_CMSE} -D__thumb2__ ${COMMON_COMPILE_FLAGS_STR} -DMBEDTLS_CONFIG_FILE=\\\\\\\"config-rsa.h\\\\\\\" -I${CMAKE_CURRENT_LIST_DIR}/bl2/ext/mcuboot/include")
Tamas Ban7801ed42019-05-20 13:21:53 +0100424if (MCUBOOT_SIGNATURE_TYPE STREQUAL "RSA-3072")
Raef Coles1bb168e2019-10-17 09:04:55 +0100425 string(APPEND MBEDCRYPTO_C_FLAGS_BL2 " -DMCUBOOT_SIGN_RSA_LEN=3072")
Jamie Foxc78c62c2019-05-23 13:42:17 +0100426endif()