blob: f08a35512043b881e40bc4740dcf619d6dedb56f [file] [log] [blame]
Mate Toth-Pal65c935e2018-01-17 18:42:13 +01001#-------------------------------------------------------------------------------
Jamie Fox17c30bb2019-01-10 13:39:33 +00002# Copyright (c) 2018-2019, Arm Limited. All rights reserved.
Mate Toth-Pal65c935e2018-01-17 18:42:13 +01003#
4# SPDX-License-Identifier: BSD-3-Clause
5#
6#-------------------------------------------------------------------------------
7
8if(NOT DEFINED REGRESSION)
9 message(FATAL_ERROR "ERROR: Incomplete Configuration: REGRESSION not defined, Include this file from a Config*.cmake")
10elseif(NOT DEFINED CORE_TEST)
11 message(FATAL_ERROR "ERROR: Incomplete Configuration: CORE_TEST not defined, Include this file from a Config*.cmake")
Tamas Band90c81b2018-08-15 15:03:42 +010012elseif(NOT DEFINED TFM_LVL)
13 message(FATAL_ERROR "ERROR: Incomplete Configuration: TFM_LVL not defined, Include this file from a Config*.cmake")
David Huf2cfa122019-08-27 15:32:38 +080014elseif(NOT DEFINED CORE_IPC)
15 message(FATAL_ERROR "ERROR: Incomplete Configuration: CORE_IPC not deinfed. Include this file from a Config*.cmake")
Mate Toth-Pal65c935e2018-01-17 18:42:13 +010016endif()
17
Mate Toth-Palee551bc2018-06-12 16:40:45 +020018if(NOT DEFINED COMPILER)
19 message(FATAL_ERROR "ERROR: COMPILER is not set in command line")
20elseif((NOT ${COMPILER} STREQUAL "ARMCLANG") AND (NOT ${COMPILER} STREQUAL "GNUARM"))
21 message(FATAL_ERROR "ERROR: Compiler \"${COMPILER}\" is not supported.")
22endif()
23
Edison Aicb0ecf62019-07-10 18:43:51 +080024if(CORE_IPC)
25 if (TFM_LVL EQUAL 3)
26 message(FATAL_ERROR "ERROR: Invalid isolation level!")
27 endif()
28else()
29 if(NOT TFM_LVL EQUAL 1)
30 message(FATAL_ERROR "ERROR: Invalid isolation level!")
31 endif()
32endif()
33
David Vincze4638b2a2019-05-24 10:14:23 +020034#BL2 bootloader (MCUBoot) related settings
David Vincze54d05552019-08-05 12:58:47 +020035include(${CMAKE_CURRENT_LIST_DIR}/bl2/ext/mcuboot/MCUBootConfig.cmake)
David Vincze4638b2a2019-05-24 10:14:23 +020036
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010037set(BUILD_CMSIS_CORE Off)
38set(BUILD_RETARGET Off)
39set(BUILD_NATIVE_DRIVERS Off)
40set(BUILD_TIME Off)
41set(BUILD_STARTUP Off)
42set(BUILD_TARGET_CFG Off)
43set(BUILD_TARGET_HARDWARE_KEYS Off)
Marc Moreno Berengue4cc81fc2018-08-10 14:32:01 +010044set(BUILD_TARGET_NV_COUNTERS Off)
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010045set(BUILD_CMSIS_DRIVERS Off)
46set(BUILD_UART_STDOUT Off)
47set(BUILD_FLASH Off)
Tamas Ban3681ce02018-11-22 15:19:24 +000048set(BUILD_BOOT_SEED Off)
Tamas Ban38e17312018-11-22 15:26:35 +000049set(BUILD_DEVICE_ID Off)
Mate Toth-Pald3c77662019-02-20 16:23:00 +010050set(BUILD_PLAT_TEST Off)
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010051if(NOT DEFINED PLATFORM_CMAKE_FILE)
52 message (FATAL_ERROR "Platform specific CMake is not defined. Please set PLATFORM_CMAKE_FILE.")
53elseif(NOT EXISTS ${PLATFORM_CMAKE_FILE})
54 message (FATAL_ERROR "Platform specific CMake \"${PLATFORM_CMAKE_FILE}\" file does not exist. Please fix value of PLATFORM_CMAKE_FILE.")
55else()
56 include(${PLATFORM_CMAKE_FILE})
57endif()
58
David Hufeae0f92019-06-17 13:42:20 +080059if (DEFINED TFM_MULTI_CORE_TOPOLOGY AND TFM_MULTI_CORE_TOPOLOGY)
60 # CMSE is unnecessary in multi-core scenarios.
61 # TODO: Need further discussion about if CMSE is required when an Armv8-M
62 # core acts as secure core in multi-core scenario.
63 set (CMSE_FLAGS "")
64 set (ARM_FEATURE_CMSE 0)
65else()
66 set (CMSE_FLAGS "-mcmse")
67 set (ARM_FEATURE_CMSE 3)
68endif()
69
Mate Toth-Palee551bc2018-06-12 16:40:45 +020070if(${COMPILER} STREQUAL "ARMCLANG")
Mate Toth-Pal76867262018-03-09 13:15:36 +010071 #Use any ARMCLANG version found on PATH. Note: Only versions supported by the
72 #build system will work. A file cmake/Common/CompilerArmClangXY.cmake
73 #must be present with a matching version.
74 include("Common/FindArmClang")
75 include("Common/${ARMCLANG_MODULE}")
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010076
David Hufeae0f92019-06-17 13:42:20 +080077 set (COMMON_COMPILE_FLAGS -fshort-enums -fshort-wchar -funsigned-char -mfpu=none ${CMSE_FLAGS} -ffunction-sections -fdata-sections)
Tamas Bandb69d522018-03-01 10:04:41 +000078 ##Shared compiler settings.
79 function(config_setting_shared_compiler_flags tgt)
Mate Toth-Pal76867262018-03-09 13:15:36 +010080 embedded_set_target_compile_flags(TARGET ${tgt} LANGUAGE C FLAGS -xc -std=c99 ${COMMON_COMPILE_FLAGS} -Wall -Werror)
Tamas Bandb69d522018-03-01 10:04:41 +000081 endfunction()
82
83 ##Shared linker settings.
84 function(config_setting_shared_linker_flags tgt)
Antonio de Angelis3302f452019-07-19 10:36:33 +010085 embedded_set_target_link_flags(TARGET ${tgt} FLAGS --strict --map --symbols --xref --entry=Reset_Handler --remove --info=summarysizes,sizes,totals,unused,veneers)
Mate Toth-Pal76867262018-03-09 13:15:36 +010086 endfunction()
87elseif(${COMPILER} STREQUAL "GNUARM")
88 #Use any GNUARM version found on PATH. Note: Only versions supported by the
89 #build system will work. A file cmake/Common/CompilerGNUARMXY.cmake
90 #must be present with a matching version.
91 include("Common/FindGNUARM")
92 include("Common/${GNUARM_MODULE}")
Mate Toth-Pal48fc6a02018-01-24 09:50:14 +010093
David Hufeae0f92019-06-17 13:42:20 +080094 set (COMMON_COMPILE_FLAGS -fshort-enums -fshort-wchar -funsigned-char -msoft-float ${CMSE_FLAGS} -ffunction-sections -fdata-sections --specs=nano.specs)
Mate Toth-Pal76867262018-03-09 13:15:36 +010095 ##Shared compiler and linker settings.
Tamas Bandb69d522018-03-01 10:04:41 +000096 function(config_setting_shared_compiler_flags tgt)
Mate Toth-Pal76867262018-03-09 13:15:36 +010097 embedded_set_target_compile_flags(TARGET ${tgt} LANGUAGE C FLAGS -xc -std=c99 ${COMMON_COMPILE_FLAGS} -Wall -Werror -Wno-format -Wno-return-type -Wno-unused-but-set-variable)
Tamas Bandb69d522018-03-01 10:04:41 +000098 endfunction()
99
100 ##Shared linker settings.
101 function(config_setting_shared_linker_flags tgt)
Mate Toth-Pal76867262018-03-09 13:15:36 +0100102 #--no-wchar-size-warning flag is added because TF-M sources are compiled
103 #with short wchars, however the standard library is compiled with normal
104 #wchar, and this generates linker time warnings. TF-M code does not use
105 #wchar, so the warning can be suppressed.
Antonio de Angelis3302f452019-07-19 10:36:33 +0100106 embedded_set_target_link_flags(TARGET ${tgt} FLAGS -Wl,-check-sections,-fatal-warnings,--gc-sections,--no-wchar-size-warning,--print-memory-usage --entry=Reset_Handler --specs=nano.specs)
Mate Toth-Pal76867262018-03-09 13:15:36 +0100107 endfunction()
Mate Toth-Pal76867262018-03-09 13:15:36 +0100108endif()
109
110#Create a string from the compile flags list, so that it can be used later
111#in this file to set mbedtls and BL2 flags
Tamas Bandb69d522018-03-01 10:04:41 +0000112list_to_string(COMMON_COMPILE_FLAGS_STR ${COMMON_COMPILE_FLAGS})
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100113
114#Settings which shall be set for all projects the same way based
115# on the variables above.
Mate Toth-Pal349714a2018-02-23 15:30:24 +0100116set (TFM_PARTITION_TEST_CORE OFF)
Jamie Foxadf02552019-05-16 17:44:52 +0100117set (TFM_PARTITION_TEST_CORE_IPC OFF)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100118set (CORE_TEST_POSITIVE OFF)
119set (CORE_TEST_INTERACTIVE OFF)
Miklos Balintf13ec022018-04-06 17:21:22 +0200120set (REFERENCE_PLATFORM OFF)
Ben Davis6d7256b2018-04-18 14:16:53 +0100121set (TFM_PARTITION_TEST_SECURE_SERVICES OFF)
Tamas Band90c81b2018-08-15 15:03:42 +0100122set (SERVICES_TEST_ENABLED OFF)
Marc Moreno Berenguecae2c532018-10-09 12:58:46 +0100123set (TEST_FRAMEWORK_S OFF)
124set (TEST_FRAMEWORK_NS OFF)
Edison Aiec109cd2018-07-17 16:04:14 +0800125set (TFM_PSA_API OFF)
Miklos Balint87da2512018-04-19 13:45:50 +0200126set (TFM_LEGACY_API ON)
Miklos Balintf13ec022018-04-06 17:21:22 +0200127
Jamie Foxc78c62c2019-05-23 13:42:17 +0100128option(TFM_PARTITION_AUDIT_LOG "Enable the TF-M Audit Log partition" ON)
Mingyang Sun9511e5e2019-05-29 18:18:44 +0800129option(TFM_PARTITION_PLATFORM "Enable the TF-M Platform partition" ON)
Jamie Foxc78c62c2019-05-23 13:42:17 +0100130
Marton Berke6fd21f12019-07-02 13:43:07 +0200131if(${TARGET_PLATFORM} STREQUAL "AN521" OR ${TARGET_PLATFORM} STREQUAL "AN519" OR ${TARGET_PLATFORM} STREQUAL "AN539")
Miklos Balintf13ec022018-04-06 17:21:22 +0200132 set (REFERENCE_PLATFORM ON)
133endif()
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100134
Miklos Balint6cbeba62018-04-12 17:31:34 +0200135# Option to demonstrate usage of secure-only peripheral
136set (SECURE_UART1 OFF)
137
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100138if (REGRESSION)
139 set(SERVICES_TEST_ENABLED ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100140endif()
141
Edison Aiec109cd2018-07-17 16:04:14 +0800142if (CORE_IPC)
143 set(TFM_PSA_API ON)
David Huf2cfa122019-08-27 15:32:38 +0800144
145 # Disable IPC Test by default if the config or platform doesn't explicitly
146 # require it
147 if (NOT DEFINED IPC_TEST)
148 set(IPC_TEST OFF)
149 endif()
150else()
151 set(IPC_TEST OFF)
Edison Aiec109cd2018-07-17 16:04:14 +0800152endif()
153
Miklos Balint87da2512018-04-19 13:45:50 +0200154if (TFM_PSA_API)
155 add_definitions(-DTFM_PSA_API)
156endif()
157
158if (TFM_LEGACY_API)
159 add_definitions(-DTFM_LEGACY_API)
160endif()
161
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100162if (SERVICES_TEST_ENABLED)
163 set(SERVICE_TEST_S ON)
164 set(SERVICE_TEST_NS ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100165endif()
166
167if (CORE_TEST)
Mate Toth-Pal6569a592019-06-07 12:09:50 +0200168 set(CORE_TEST_POSITIVE ON)
169 set(CORE_TEST_INTERACTIVE OFF)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100170endif()
171
Ben Davis6d7256b2018-04-18 14:16:53 +0100172if (CORE_TEST_INTERACTIVE)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100173 add_definitions(-DCORE_TEST_INTERACTIVE)
174 set(TEST_FRAMEWORK_NS ON)
Mate Toth-Pal349714a2018-02-23 15:30:24 +0100175 set(TFM_PARTITION_TEST_CORE ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100176endif()
177
Ben Davis6d7256b2018-04-18 14:16:53 +0100178if (CORE_TEST_POSITIVE)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100179 add_definitions(-DCORE_TEST_POSITIVE)
180 set(TEST_FRAMEWORK_NS ON)
Mate Toth-Pal349714a2018-02-23 15:30:24 +0100181 set(TFM_PARTITION_TEST_CORE ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100182endif()
183
David Hu33f2fd22019-08-16 15:32:39 +0800184if (TFM_PARTITION_TEST_CORE)
185 # If the platform or the topology doesn't specify whether IRQ test is
186 # supported, enable it by default.
187 if (NOT DEFINED TFM_ENABLE_IRQ_TEST)
188 set(TFM_ENABLE_IRQ_TEST ON)
189 endif()
190
191 if (TFM_ENABLE_IRQ_TEST)
192 add_definitions(-DTFM_ENABLE_IRQ_TEST)
193 endif()
194else()
195 set(TFM_ENABLE_IRQ_TEST OFF)
196endif()
197
David Huf2cfa122019-08-27 15:32:38 +0800198if (IPC_TEST)
199 add_definitions(-DENABLE_IPC_TEST)
Jamie Foxadf02552019-05-16 17:44:52 +0100200 set(TEST_FRAMEWORK_NS ON)
201 set(TFM_PARTITION_TEST_CORE_IPC ON)
Edison Aiec109cd2018-07-17 16:04:14 +0800202endif()
203
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100204if (SERVICE_TEST_S)
205 add_definitions(-DSERVICES_TEST_S)
206 set(TEST_FRAMEWORK_S ON)
207endif()
208
209if (SERVICE_TEST_NS)
210 add_definitions(-DSERVICES_TEST_NS)
211 set(TEST_FRAMEWORK_NS ON)
212endif()
213
Ben Davis6d7256b2018-04-18 14:16:53 +0100214if (TEST_FRAMEWORK_S)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100215 add_definitions(-DTEST_FRAMEWORK_S)
Jamie Fox56da0992019-05-28 14:35:06 +0100216 # The secure client partition is required to run secure tests
217 set(TFM_PARTITION_TEST_SECURE_SERVICES ON)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100218endif()
219
Ben Davis6d7256b2018-04-18 14:16:53 +0100220if (TEST_FRAMEWORK_NS)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100221 add_definitions(-DTEST_FRAMEWORK_NS)
222endif()
223
Jamie Foxc78c62c2019-05-23 13:42:17 +0100224if (CORE_IPC)
225 set(TFM_PARTITION_AUDIT_LOG OFF)
Mingyang Sun9511e5e2019-05-29 18:18:44 +0800226 set(TFM_PARTITION_PLATFORM OFF)
Jamie Foxc78c62c2019-05-23 13:42:17 +0100227endif()
228
229if (TFM_PARTITION_AUDIT_LOG)
230 add_definitions(-DTFM_PARTITION_AUDIT_LOG)
231endif()
232
Mingyang Sun9511e5e2019-05-29 18:18:44 +0800233if (TFM_PARTITION_PLATFORM)
234 add_definitions(-DTFM_PARTITION_PLATFORM)
235endif()
236
Mate Toth-Pal349714a2018-02-23 15:30:24 +0100237if (TFM_PARTITION_TEST_CORE)
238 add_definitions(-DTFM_PARTITION_TEST_CORE)
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100239endif()
240
Jamie Foxadf02552019-05-16 17:44:52 +0100241if (TFM_PARTITION_TEST_CORE_IPC)
242 add_definitions(-DTFM_PARTITION_TEST_CORE_IPC)
243endif()
244
Jamie Foxc78c62c2019-05-23 13:42:17 +0100245if (TFM_PARTITION_TEST_SECURE_SERVICES)
246 add_definitions(-DTFM_PARTITION_TEST_SECURE_SERVICES)
247endif()
248
Jamie Fox17c30bb2019-01-10 13:39:33 +0000249if (PSA_API_TEST)
250 add_definitions(-DPSA_API_TEST_NS)
251 set(PSA_API_TEST_NS ON)
252 if (NOT DEFINED PSA_API_TEST_CRYPTO)
253 set(PSA_API_TEST_CRYPTO OFF)
254 endif()
255 if (NOT DEFINED PSA_API_TEST_SECURE_STORAGE)
256 set(PSA_API_TEST_SECURE_STORAGE OFF)
257 endif()
258 if (NOT DEFINED PSA_API_TEST_ATTESTATION)
259 set(PSA_API_TEST_ATTESTATION OFF)
260 endif()
261endif()
262
Marc Moreno Berenguec2e4db82018-09-14 16:32:24 +0100263# This flag indicates if the non-secure OS is capable of identify the non-secure clients
Mingyang Sun9ac02372019-08-26 15:59:14 +0800264# which call the secure services. It is diabled in IPC model.
Marc Moreno Berenguec2e4db82018-09-14 16:32:24 +0100265if (NOT DEFINED TFM_NS_CLIENT_IDENTIFICATION)
Mingyang Sun9ac02372019-08-26 15:59:14 +0800266 if (TFM_PSA_API)
267 set(TFM_NS_CLIENT_IDENTIFICATION OFF)
268 else()
269 set(TFM_NS_CLIENT_IDENTIFICATION ON)
270 endif()
Marc Moreno Berenguec2e4db82018-09-14 16:32:24 +0100271endif()
272
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100273if (BL2)
David Vincze63eda7a2019-08-09 17:42:51 +0200274 # Add MCUBOOT_IMAGE_NUMBER definition to the compiler command line.
275 add_definitions(-DMCUBOOT_IMAGE_NUMBER=${MCUBOOT_IMAGE_NUMBER})
276
David Vincze4638b2a2019-05-24 10:14:23 +0200277 if (${MCUBOOT_UPGRADE_STRATEGY} STREQUAL "NO_SWAP")
Tamas Bandb69d522018-03-01 10:04:41 +0000278 set(LINK_TO_BOTH_MEMORY_REGION ON)
279 endif()
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100280endif()
281
Jamie Foxdaade492019-04-26 14:35:39 +0100282##Set Mbed TLS compiler flags and variables for audit log and crypto
David Hufeae0f92019-06-17 13:42:20 +0800283set(MBEDTLS_C_FLAGS_SERVICES "-D__ARM_FEATURE_CMSE=${ARM_FEATURE_CMSE} -D__thumb2__ ${COMMON_COMPILE_FLAGS_STR} -I${CMAKE_CURRENT_LIST_DIR}/platform/ext/common")
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100284
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000285#Default TF-M secure storage flags.
286#These flags values can be overwritten by setting them in platform/ext/<TARGET_NAME>.cmake
Marc Moreno Berenguef6a64f72018-07-26 17:33:38 +0100287#Documentation about these flags can be found in docs/user_guides/services/tfm_sst_integration_guide.md
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000288if (NOT DEFINED SST_ENCRYPTION)
289 set (SST_ENCRYPTION ON)
290endif()
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000291
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000292if (NOT DEFINED SST_ROLLBACK_PROTECTION)
293 set (SST_ROLLBACK_PROTECTION OFF)
294endif()
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000295
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000296if (NOT DEFINED SST_CREATE_FLASH_LAYOUT)
297 set (SST_CREATE_FLASH_LAYOUT OFF)
298endif()
Marc Moreno Berengue184d2032018-08-14 12:51:43 +0100299
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000300if (NOT DEFINED SST_VALIDATE_METADATA_FROM_FLASH)
301 set (SST_VALIDATE_METADATA_FROM_FLASH ON)
302endif()
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000303
Marc Moreno Berengue8385e8e2019-01-21 11:49:50 +0000304if (NOT DEFINED SST_RAM_FS)
305 if (REGRESSION)
306 set (SST_RAM_FS ON)
307 else()
308 set (SST_RAM_FS OFF)
Marc Moreno Berengue02a23442018-08-15 14:28:45 +0100309 endif()
Marc Moreno Berengue792fc682018-02-20 11:53:30 +0000310endif()
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000311
Jamie Fox95bacd42019-03-21 18:14:15 +0000312if (NOT DEFINED SST_TEST_NV_COUNTERS)
313 if (REGRESSION AND (TFM_LVL EQUAL 1))
314 set(SST_TEST_NV_COUNTERS ON)
315 else()
316 set(SST_TEST_NV_COUNTERS OFF)
317 endif()
318endif()
319
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000320if (NOT DEFINED MBEDTLS_DEBUG)
Jamie Fox287885f2018-10-24 14:09:34 +0100321 set(MBEDTLS_DEBUG OFF)
Marc Moreno Berengue6ffb22f2018-02-20 13:46:30 +0000322endif()
Mate Toth-Pal65c935e2018-01-17 18:42:13 +0100323
Tamas Bandb69d522018-03-01 10:04:41 +0000324##Set mbedTLS compiler flags for BL2 bootloader
David Hufeae0f92019-06-17 13:42:20 +0800325set(MBEDTLS_C_FLAGS_BL2 "-D__ARM_FEATURE_CMSE=${ARM_FEATURE_CMSE} -D__thumb2__ ${COMMON_COMPILE_FLAGS_STR} -DMBEDTLS_CONFIG_FILE=\\\\\\\"config-boot.h\\\\\\\" -I${CMAKE_CURRENT_LIST_DIR}/bl2/ext/mcuboot/include")
Tamas Ban7801ed42019-05-20 13:21:53 +0100326if (MCUBOOT_SIGNATURE_TYPE STREQUAL "RSA-3072")
327 string(APPEND MBEDTLS_C_FLAGS_BL2 " -DMCUBOOT_SIGN_RSA_LEN=3072")
Jamie Foxc78c62c2019-05-23 13:42:17 +0100328endif()