board_common.mk 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134
  1. #
  2. # Copyright (c) 2015-2023, Arm Limited and Contributors. All rights reserved.
  3. #
  4. # SPDX-License-Identifier: BSD-3-Clause
  5. #
  6. PLAT_BL_COMMON_SOURCES += drivers/arm/pl011/${ARCH}/pl011_console.S \
  7. plat/arm/board/common/${ARCH}/board_arm_helpers.S
  8. BL1_SOURCES += drivers/cfi/v2m/v2m_flash.c
  9. BL2_SOURCES += drivers/cfi/v2m/v2m_flash.c
  10. ifneq (${TRUSTED_BOARD_BOOT},0)
  11. ARM_ROTPK_S = plat/arm/board/common/rotpk/arm_dev_rotpk.S
  12. # ROTPK hash location
  13. ifeq (${ARM_ROTPK_LOCATION}, regs)
  14. ARM_ROTPK_LOCATION_ID = ARM_ROTPK_REGS_ID
  15. else ifeq (${ARM_ROTPK_LOCATION}, devel_rsa)
  16. CRYPTO_ALG=rsa
  17. ARM_ROTPK_LOCATION_ID = ARM_ROTPK_DEVEL_RSA_ID
  18. ARM_ROTPK_HASH = plat/arm/board/common/rotpk/arm_rotpk_rsa_sha256.bin
  19. $(eval $(call add_define_val,ARM_ROTPK_HASH,'"$(ARM_ROTPK_HASH)"'))
  20. $(BUILD_PLAT)/bl2/arm_dev_rotpk.o : $(ARM_ROTPK_HASH)
  21. $(warning Development keys support for FVP is deprecated. Use `regs` \
  22. option instead)
  23. else ifeq (${ARM_ROTPK_LOCATION}, devel_ecdsa)
  24. CRYPTO_ALG=ec
  25. ARM_ROTPK_LOCATION_ID = ARM_ROTPK_DEVEL_ECDSA_ID
  26. ARM_ROTPK_HASH = plat/arm/board/common/rotpk/arm_rotpk_ecdsa_sha256.bin
  27. $(eval $(call add_define_val,ARM_ROTPK_HASH,'"$(ARM_ROTPK_HASH)"'))
  28. $(BUILD_PLAT)/bl2/arm_dev_rotpk.o : $(ARM_ROTPK_HASH)
  29. $(warning Development keys support for FVP is deprecated. Use `regs` \
  30. option instead)
  31. else ifeq (${ARM_ROTPK_LOCATION}, devel_full_dev_rsa_key)
  32. CRYPTO_ALG=rsa
  33. ARM_ROTPK_LOCATION_ID = ARM_ROTPK_DEVEL_FULL_DEV_RSA_KEY_ID
  34. ARM_ROTPK_S = plat/arm/board/common/rotpk/arm_full_dev_rsa_rotpk.S
  35. $(warning Development keys support for FVP is deprecated. Use `regs` \
  36. option instead)
  37. else ifeq (${ARM_ROTPK_LOCATION}, devel_full_dev_ecdsa_key)
  38. CRYPTO_ALG=ec
  39. ARM_ROTPK_LOCATION_ID = ARM_ROTPK_DEVEL_FULL_DEV_ECDSA_KEY_ID
  40. ifeq (${KEY_SIZE},384)
  41. ARM_ROTPK_S = plat/arm/board/common/rotpk/arm_full_dev_ecdsa_p384_rotpk.S
  42. else
  43. ARM_ROTPK_S = plat/arm/board/common/rotpk/arm_full_dev_ecdsa_p256_rotpk.S
  44. endif
  45. $(warning Development keys support for FVP is deprecated. Use `regs` \
  46. option instead)
  47. else
  48. $(error "Unsupported ARM_ROTPK_LOCATION value")
  49. endif
  50. $(eval $(call add_define,ARM_ROTPK_LOCATION_ID))
  51. ifeq (${ENABLE_RME}, 1)
  52. COT := cca
  53. endif
  54. # Force generation of the new hash if ROT_KEY is specified
  55. ifdef ROT_KEY
  56. HASH_PREREQUISITES = $(ROT_KEY) FORCE
  57. endif
  58. $(ARM_ROTPK_HASH) : $(HASH_PREREQUISITES)
  59. ifndef ROT_KEY
  60. $(error Cannot generate hash: no ROT_KEY defined)
  61. endif
  62. ${OPENSSL_BIN_PATH}/openssl ${CRYPTO_ALG} -in $< -pubout -outform DER | \
  63. ${OPENSSL_BIN_PATH}/openssl dgst -sha256 -binary > $@
  64. # Certificate NV-Counters. Use values corresponding to tied off values in
  65. # ARM development platforms
  66. TFW_NVCTR_VAL ?= 31
  67. NTFW_NVCTR_VAL ?= 223
  68. # The CCA Non-Volatile Counter only exists on some Arm development platforms.
  69. # On others, we mock it by aliasing it to the Trusted Firmware Non-Volatile counter,
  70. # hence we set both counters to the same default value.
  71. CCAFW_NVCTR_VAL ?= 31
  72. BL1_SOURCES += plat/arm/board/common/board_arm_trusted_boot.c \
  73. ${ARM_ROTPK_S}
  74. BL2_SOURCES += plat/arm/board/common/board_arm_trusted_boot.c \
  75. ${ARM_ROTPK_S}
  76. # Allows platform code to provide implementation variants depending on the
  77. # selected chain of trust.
  78. $(eval $(call add_define,ARM_COT_${COT}))
  79. ifeq (${COT},dualroot)
  80. # Platform Root of Trust key files.
  81. ARM_PROT_KEY := plat/arm/board/common/protpk/arm_protprivk_rsa.pem
  82. ARM_PROTPK_HASH := plat/arm/board/common/protpk/arm_protpk_rsa_sha256.bin
  83. # Provide the private key to cert_create tool. It needs it to sign the images.
  84. PROT_KEY := ${ARM_PROT_KEY}
  85. $(eval $(call add_define_val,ARM_PROTPK_HASH,'"$(ARM_PROTPK_HASH)"'))
  86. BL1_SOURCES += plat/arm/board/common/protpk/arm_dev_protpk.S
  87. BL2_SOURCES += plat/arm/board/common/protpk/arm_dev_protpk.S
  88. $(BUILD_PLAT)/bl1/arm_dev_protpk.o: $(ARM_PROTPK_HASH)
  89. $(BUILD_PLAT)/bl2/arm_dev_protpk.o: $(ARM_PROTPK_HASH)
  90. endif
  91. ifeq (${COT},cca)
  92. # Platform and Secure World Root of Trust key files.
  93. ARM_PROT_KEY := plat/arm/board/common/protpk/arm_protprivk_rsa.pem
  94. ARM_PROTPK_HASH := plat/arm/board/common/protpk/arm_protpk_rsa_sha256.bin
  95. ARM_SWD_ROT_KEY := plat/arm/board/common/swd_rotpk/arm_swd_rotprivk_rsa.pem
  96. ARM_SWD_ROTPK_HASH := plat/arm/board/common/swd_rotpk/arm_swd_rotpk_rsa_sha256.bin
  97. # Provide the private keys to cert_create tool. It needs them to sign the images.
  98. PROT_KEY := ${ARM_PROT_KEY}
  99. SWD_ROT_KEY := ${ARM_SWD_ROT_KEY}
  100. $(eval $(call add_define_val,ARM_PROTPK_HASH,'"$(ARM_PROTPK_HASH)"'))
  101. $(eval $(call add_define_val,ARM_SWD_ROTPK_HASH,'"$(ARM_SWD_ROTPK_HASH)"'))
  102. BL1_SOURCES += plat/arm/board/common/protpk/arm_dev_protpk.S \
  103. plat/arm/board/common/swd_rotpk/arm_dev_swd_rotpk.S
  104. BL2_SOURCES += plat/arm/board/common/protpk/arm_dev_protpk.S \
  105. plat/arm/board/common/swd_rotpk/arm_dev_swd_rotpk.S
  106. $(BUILD_PLAT)/bl1/arm_dev_protpk.o: $(ARM_PROTPK_HASH)
  107. $(BUILD_PLAT)/bl1/arm_dev_swd_rotpk.o: $(ARM_SWD_ROTPK_HASH)
  108. $(BUILD_PLAT)/bl2/arm_dev_protpk.o: $(ARM_PROTPK_HASH)
  109. $(BUILD_PLAT)/bl2/arm_dev_swd_rotpk.o: $(ARM_SWD_ROTPK_HASH)
  110. endif
  111. endif