blob: 2519623cddf590b0c23ebc4e27bded790a1cd648 [file] [log] [blame]
fbrosson533407a2018-04-04 21:44:29 +00001#!/usr/bin/env perl
SimonB60f2cf92016-04-03 14:16:08 +01002#
3# This file is part of mbed TLS (https://tls.mbed.org)
4#
5# Copyright (c) 2014-2016, ARM Limited, All Rights Reserved
6#
7# Purpose
8#
9# Comments and uncomments #define lines in the given header file and optionally
Simon Butcher4ae86912016-06-21 10:09:25 +010010# sets their value or can get the value. This is to provide scripting control of
11# what preprocessor symbols, and therefore what build time configuration flags
12# are set in the 'config.h' file.
SimonB60f2cf92016-04-03 14:16:08 +010013#
14# Usage: config.pl [-f <file> | --file <file>] [-o | --force]
Simon Butcher4ae86912016-06-21 10:09:25 +010015# [set <symbol> <value> | unset <symbol> | get <symbol> |
16# full | realfull]
SimonB60f2cf92016-04-03 14:16:08 +010017#
18# Full usage description provided below.
19#
Hanno Becker7c0f17d2017-09-28 11:49:46 +010020# The following options are disabled instead of enabled with "full".
SimonB60f2cf92016-04-03 14:16:08 +010021#
Simon Butcherab5df402016-06-11 02:31:21 +010022# MBEDTLS_TEST_NULL_ENTROPY
SimonB60f2cf92016-04-03 14:16:08 +010023# MBEDTLS_DEPRECATED_REMOVED
24# MBEDTLS_HAVE_SSE2
25# MBEDTLS_PLATFORM_NO_STD_FUNCTIONS
26# MBEDTLS_ECP_DP_M221_ENABLED
27# MBEDTLS_ECP_DP_M383_ENABLED
28# MBEDTLS_ECP_DP_M511_ENABLED
Hanno Becker307dfcd2019-02-26 13:51:00 +000029# MBEDTLS_MEMORY_BACKTRACE
30# MBEDTLS_MEMORY_BUFFER_ALLOC_C
SimonB60f2cf92016-04-03 14:16:08 +010031# MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES
32# MBEDTLS_NO_PLATFORM_ENTROPY
33# MBEDTLS_REMOVE_ARC4_CIPHERSUITES
Andres Amaya Garcia5d8aade2018-10-30 18:21:41 +000034# MBEDTLS_REMOVE_3DES_CIPHERSUITES
Manuel Pégourié-Gonnard0956e3e2019-07-17 16:58:56 +020035# MBEDTLS_SHA256_NO_SHA224
SimonB60f2cf92016-04-03 14:16:08 +010036# MBEDTLS_SSL_HW_RECORD_ACCEL
Manuel Pégourié-Gonnardba8b1eb2019-06-17 15:21:07 +020037# MBEDTLS_SSL_PROTO_NO_DTLS
Manuel Pégourié-Gonnard26ac9c42019-07-01 10:07:28 +020038# MBEDTLS_SSL_NO_SESSION_CACHE
39# MBEDTLS_SSL_NO_SESSION_RESUMPTION
Hanno Becker7c0f17d2017-09-28 11:49:46 +010040# MBEDTLS_RSA_NO_CRT
Hanno Becker8239fad2019-08-27 15:45:44 +010041# MBEDTLS_USE_TINYCRYPT
SimonB60f2cf92016-04-03 14:16:08 +010042# MBEDTLS_X509_ALLOW_EXTENSIONS_NON_V3
43# MBEDTLS_X509_ALLOW_UNSUPPORTED_CRITICAL_EXTENSION
44# - this could be enabled if the respective tests were adapted
Hanno Beckerb4d967a2019-06-12 13:59:14 +010045# MBEDTLS_X509_REMOVE_INFO
Hanno Becker843b71a2019-06-25 09:39:21 +010046# MBEDTLS_X509_CRT_REMOVE_TIME
Hanno Beckerd07614c2019-06-25 10:19:58 +010047# MBEDTLS_X509_CRT_REMOVE_SUBJECT_ISSUER_ID
Teppo Järvelin4009d8f2019-08-19 14:48:09 +030048# MBEDTLS_X509_REMOVE_HOSTNAME_VERIFICATION
Hanno Becker9ec3fe02019-07-01 17:36:12 +010049# MBEDTLS_X509_REMOVE_VERIFY_CALLBACK
SimonB60f2cf92016-04-03 14:16:08 +010050# MBEDTLS_ZLIB_SUPPORT
51# MBEDTLS_PKCS11_C
Andrzej Kurek87621012019-09-09 05:25:05 -040052# MBEDTLS_NO_UDBL_DIVISION
53# MBEDTLS_NO_64BIT_MULTIPLICATION
Arto Kinnunen265d1622019-10-16 10:17:48 +030054# MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH
Arto Kinnunen14804442019-10-16 13:43:59 +030055# MBEDTLS_AES_ONLY_ENCRYPT
Arto Kinnunen22311382019-10-14 15:18:27 +030056# MBEDTLS_AES_SCA_COUNTERMEASURES
SimonB60f2cf92016-04-03 14:16:08 +010057# and any symbol beginning _ALT
58#
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +020059
60use warnings;
61use strict;
62
SimonB60f2cf92016-04-03 14:16:08 +010063my $config_file = "include/mbedtls/config.h";
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +020064my $usage = <<EOU;
SimonB60f2cf92016-04-03 14:16:08 +010065$0 [-f <file> | --file <file>] [-o | --force]
Simon Butcher4ae86912016-06-21 10:09:25 +010066 [set <symbol> <value> | unset <symbol> | get <symbol> |
Azim Khanc3c3a682017-12-21 15:19:53 +000067 full | realfull | baremetal]
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +020068
SimonB60f2cf92016-04-03 14:16:08 +010069Commands
Simon Butcher4ae86912016-06-21 10:09:25 +010070 set <symbol> [<value>] - Uncomments or adds a #define for the <symbol> to
SimonB60f2cf92016-04-03 14:16:08 +010071 the configuration file, and optionally making it
72 of <value>.
73 If the symbol isn't present in the file an error
74 is returned.
Simon Butcher4ae86912016-06-21 10:09:25 +010075 unset <symbol> - Comments out the #define for the given symbol if
76 present in the configuration file.
77 get <symbol> - Finds the #define for the given symbol, returning
Gilles Peskined98e9e82017-10-09 16:56:18 +020078 an exitcode of 0 if the symbol is found, and 1 if
Simon Butcher4ae86912016-06-21 10:09:25 +010079 not. The value of the symbol is output if one is
80 specified in the configuration file.
SimonB60f2cf92016-04-03 14:16:08 +010081 full - Uncomments all #define's in the configuration file
Simon Butcher4ae86912016-06-21 10:09:25 +010082 excluding some reserved symbols, until the
SimonB60f2cf92016-04-03 14:16:08 +010083 'Module configuration options' section
84 realfull - Uncomments all #define's with no exclusions
Azim Khanc3c3a682017-12-21 15:19:53 +000085 baremetal - Sets full configuration suitable for baremetal build.
SimonB60f2cf92016-04-03 14:16:08 +010086
87Options
88 -f | --file <filename> - The file or file path for the configuration file
89 to edit. When omitted, the following default is
90 used:
91 $config_file
92 -o | --force - If the symbol isn't present in the configuration
Brian J Murray2adecba2016-11-06 04:45:15 -080093 file when setting its value, a #define is
SimonB60f2cf92016-04-03 14:16:08 +010094 appended to the end of the file.
95
96EOU
97
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +020098my @excluded = qw(
Simon Butcherab5df402016-06-11 02:31:21 +010099MBEDTLS_TEST_NULL_ENTROPY
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200100MBEDTLS_DEPRECATED_REMOVED
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200101MBEDTLS_HAVE_SSE2
102MBEDTLS_PLATFORM_NO_STD_FUNCTIONS
103MBEDTLS_ECP_DP_M221_ENABLED
104MBEDTLS_ECP_DP_M383_ENABLED
105MBEDTLS_ECP_DP_M511_ENABLED
Hanno Beckerdfc97442019-06-03 16:33:18 +0100106MBEDTLS_MEMORY_DEBUG
Hanno Becker307dfcd2019-02-26 13:51:00 +0000107MBEDTLS_MEMORY_BACKTRACE
108MBEDTLS_MEMORY_BUFFER_ALLOC_C
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200109MBEDTLS_NO_DEFAULT_ENTROPY_SOURCES
110MBEDTLS_NO_PLATFORM_ENTROPY
Hanno Becker7c0f17d2017-09-28 11:49:46 +0100111MBEDTLS_RSA_NO_CRT
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200112MBEDTLS_REMOVE_ARC4_CIPHERSUITES
Andres Amaya Garcia5d8aade2018-10-30 18:21:41 +0000113MBEDTLS_REMOVE_3DES_CIPHERSUITES
Manuel Pégourié-Gonnard0956e3e2019-07-17 16:58:56 +0200114MBEDTLS_SHA256_NO_SHA224
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200115MBEDTLS_SSL_HW_RECORD_ACCEL
Manuel Pégourié-Gonnardba8b1eb2019-06-17 15:21:07 +0200116MBEDTLS_SSL_PROTO_NO_TLS
Manuel Pégourié-Gonnard26ac9c42019-07-01 10:07:28 +0200117MBEDTLS_SSL_NO_SESSION_CACHE
118MBEDTLS_SSL_NO_SESSION_RESUMPTION
Hanno Becker8239fad2019-08-27 15:45:44 +0100119MBEDTLS_USE_TINYCRYPT
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200120MBEDTLS_X509_ALLOW_EXTENSIONS_NON_V3
121MBEDTLS_X509_ALLOW_UNSUPPORTED_CRITICAL_EXTENSION
Hanno Beckerb4d967a2019-06-12 13:59:14 +0100122MBEDTLS_X509_REMOVE_INFO
Hanno Becker843b71a2019-06-25 09:39:21 +0100123MBEDTLS_X509_CRT_REMOVE_TIME
Hanno Beckerd07614c2019-06-25 10:19:58 +0100124MBEDTLS_X509_CRT_REMOVE_SUBJECT_ISSUER_ID
Teppo Järvelin4009d8f2019-08-19 14:48:09 +0300125MBEDTLS_X509_REMOVE_HOSTNAME_VERIFICATION
Hanno Becker9ec3fe02019-07-01 17:36:12 +0100126MBEDTLS_X509_REMOVE_VERIFY_CALLBACK
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200127MBEDTLS_ZLIB_SUPPORT
128MBEDTLS_PKCS11_C
Azim Khanc4e96942017-12-21 15:22:37 +0000129MBEDTLS_NO_UDBL_DIVISION
Manuel Pégourié-Gonnard2adb3752018-06-07 10:51:44 +0200130MBEDTLS_NO_64BIT_MULTIPLICATION
Manuel Pégourié-Gonnardafdc1b52019-05-09 11:24:11 +0200131MBEDTLS_USE_TINYCRYPT
Arto Kinnunen265d1622019-10-16 10:17:48 +0300132MBEDTLS_AES_ONLY_128_BIT_KEY_LENGTH
Arto Kinnunen14804442019-10-16 13:43:59 +0300133MBEDTLS_AES_ONLY_ENCRYPT
Arto Kinnunen22311382019-10-14 15:18:27 +0300134MBEDTLS_AES_SCA_COUNTERMEASURES
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200135_ALT\s*$
136);
137
Azim Khan0d445732017-12-21 09:28:39 +0000138# Things that should be disabled in "baremetal"
139my @excluded_baremetal = qw(
140MBEDTLS_NET_C
141MBEDTLS_TIMING_C
142MBEDTLS_FS_IO
143MBEDTLS_ENTROPY_NV_SEED
144MBEDTLS_HAVE_TIME
145MBEDTLS_HAVE_TIME_DATE
146MBEDTLS_DEPRECATED_WARNING
147MBEDTLS_HAVEGE_C
148MBEDTLS_THREADING_C
149MBEDTLS_THREADING_PTHREAD
150MBEDTLS_MEMORY_BACKTRACE
151MBEDTLS_MEMORY_BUFFER_ALLOC_C
152MBEDTLS_PLATFORM_TIME_ALT
153MBEDTLS_PLATFORM_FPRINTF_ALT
154);
155
Manuel Pégourié-Gonnardb7527152015-06-03 09:59:06 +0100156# Things that should be enabled in "full" even if they match @excluded
157my @non_excluded = qw(
158PLATFORM_[A-Z0-9]+_ALT
159);
160
Azim Khan0d445732017-12-21 09:28:39 +0000161# Things that should be enabled in "baremetal"
162my @non_excluded_baremetal = qw(
163MBEDTLS_NO_PLATFORM_ENTROPY
164);
165
SimonB60f2cf92016-04-03 14:16:08 +0100166# Process the command line arguments
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200167
SimonB60f2cf92016-04-03 14:16:08 +0100168my $force_option = 0;
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200169
SimonB60f2cf92016-04-03 14:16:08 +0100170my ($arg, $name, $value, $action);
171
SimonB73883c12016-04-04 13:49:10 +0100172while ($arg = shift) {
SimonB60f2cf92016-04-03 14:16:08 +0100173
174 # Check if the argument is an option
SimonB73883c12016-04-04 13:49:10 +0100175 if ($arg eq "-f" || $arg eq "--file") {
SimonB60f2cf92016-04-03 14:16:08 +0100176 $config_file = shift;
177
178 -f $config_file or die "No such file: $config_file\n";
179
180 }
SimonB73883c12016-04-04 13:49:10 +0100181 elsif ($arg eq "-o" || $arg eq "--force") {
SimonB60f2cf92016-04-03 14:16:08 +0100182 $force_option = 1;
183
184 }
185 else
186 {
187 # ...else assume it's a command
188 $action = $arg;
189
Azim Khan0d445732017-12-21 09:28:39 +0000190 if ($action eq "full" || $action eq "realfull" || $action eq "baremetal" ) {
SimonB60f2cf92016-04-03 14:16:08 +0100191 # No additional parameters
192 die $usage if @ARGV;
193
194 }
Simon Butcher4ae86912016-06-21 10:09:25 +0100195 elsif ($action eq "unset" || $action eq "get") {
SimonB60f2cf92016-04-03 14:16:08 +0100196 die $usage unless @ARGV;
197 $name = shift;
198
199 }
200 elsif ($action eq "set") {
201 die $usage unless @ARGV;
202 $name = shift;
203 $value = shift if @ARGV;
204
205 }
206 else {
207 die "Command '$action' not recognised.\n\n".$usage;
208 }
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200209 }
210}
211
Simon Butcher3d265132016-06-23 21:57:06 +0100212# If no command was specified, exit...
213if ( not defined($action) ){ die $usage; }
214
SimonB60f2cf92016-04-03 14:16:08 +0100215# Check the config file is present
216if (! -f $config_file) {
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200217
Teppo Järveline06e0392019-11-25 15:22:42 +0200218 if ( -d 'importer' && -d 'inc' && -d 'src') {
219 $config_file = "inc/mbedtls/config.h";
220 }
221 else {
222 chdir '..' or die;
223 # Confirm this is the project root directory and try again
224 if ( !(-d 'scripts' && -d 'include' && -d 'library' && -f $config_file) ) {
225 die "If no file specified, must be run from the project root or scripts directory.\n";
226 }
SimonB60f2cf92016-04-03 14:16:08 +0100227 }
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200228}
SimonB60f2cf92016-04-03 14:16:08 +0100229
230
231# Now read the file and process the contents
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200232
233open my $config_read, '<', $config_file or die "read $config_file: $!\n";
234my @config_lines = <$config_read>;
235close $config_read;
236
Azim Khan0d445732017-12-21 09:28:39 +0000237# Add required baremetal symbols to the list that is included.
238if ( $action eq "baremetal" ) {
239 @non_excluded = ( @non_excluded, @non_excluded_baremetal );
240}
241
242my ($exclude_re, $no_exclude_re, $exclude_baremetal_re);
Manuel Pégourié-Gonnard1989caf2016-01-04 12:57:32 +0100243if ($action eq "realfull") {
244 $exclude_re = qr/^$/;
245 $no_exclude_re = qr/./;
246} else {
247 $exclude_re = join '|', @excluded;
248 $no_exclude_re = join '|', @non_excluded;
249}
Azim Khan0d445732017-12-21 09:28:39 +0000250if ( $action eq "baremetal" ) {
251 $exclude_baremetal_re = join '|', @excluded_baremetal;
252}
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200253
Gilles Peskine01f57e32017-10-09 16:54:28 +0200254my $config_write = undef;
255if ($action ne "get") {
256 open $config_write, '>', $config_file or die "write $config_file: $!\n";
257}
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200258
259my $done;
260for my $line (@config_lines) {
Azim Khan0d445732017-12-21 09:28:39 +0000261 if ($action eq "full" || $action eq "realfull" || $action eq "baremetal" ) {
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200262 if ($line =~ /name SECTION: Module configuration options/) {
263 $done = 1;
264 }
265
Manuel Pégourié-Gonnardb7527152015-06-03 09:59:06 +0100266 if (!$done && $line =~ m!^//\s?#define! &&
Azim Khan0d445732017-12-21 09:28:39 +0000267 ( $line !~ /$exclude_re/ || $line =~ /$no_exclude_re/ ) &&
268 ( $action ne "baremetal" || ( $line !~ /$exclude_baremetal_re/ ) ) ) {
Manuel Pégourié-Gonnardea0920f2015-03-24 09:50:15 +0100269 $line =~ s!^//\s?!!;
270 }
Manuel Pégourié-Gonnard7ee5ddd2015-06-03 10:33:55 +0100271 if (!$done && $line =~ m!^\s?#define! &&
Azim Khan0d445732017-12-21 09:28:39 +0000272 ! ( ( $line !~ /$exclude_re/ || $line =~ /$no_exclude_re/ ) &&
273 ( $action ne "baremetal" || ( $line !~ /$exclude_baremetal_re/ ) ) ) ) {
Manuel Pégourié-Gonnardea0920f2015-03-24 09:50:15 +0100274 $line =~ s!^!//!;
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200275 }
276 } elsif ($action eq "unset") {
Manuel Pégourié-Gonnard7f9049b2015-06-23 17:42:51 +0200277 if (!$done && $line =~ /^\s*#define\s*$name\b/) {
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200278 $line = '//' . $line;
279 $done = 1;
280 }
281 } elsif (!$done && $action eq "set") {
Manuel Pégourié-Gonnard7f9049b2015-06-23 17:42:51 +0200282 if ($line =~ m!^(?://)?\s*#define\s*$name\b!) {
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200283 $line = "#define $name";
284 $line .= " $value" if defined $value && $value ne "";
285 $line .= "\n";
286 $done = 1;
287 }
Simon Butcher4ae86912016-06-21 10:09:25 +0100288 } elsif (!$done && $action eq "get") {
Gilles Peskinef0f55cc2017-10-09 16:51:24 +0200289 if ($line =~ /^\s*#define\s*$name(?:\s+(.*?))\s*(?:$|\/\*|\/\/)/) {
Simon Butcher4ae86912016-06-21 10:09:25 +0100290 $value = $1;
291 $done = 1;
292 }
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200293 }
294
Gilles Peskine01f57e32017-10-09 16:54:28 +0200295 if (defined $config_write) {
Gilles Peskine8ca0e8f2017-10-10 11:26:45 +0200296 print $config_write $line or die "write $config_file: $!\n";
Gilles Peskine01f57e32017-10-09 16:54:28 +0200297 }
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200298}
299
SimonB60f2cf92016-04-03 14:16:08 +0100300# Did the set command work?
Gilles Peskined98e9e82017-10-09 16:56:18 +0200301if ($action eq "set" && $force_option && !$done) {
SimonB60f2cf92016-04-03 14:16:08 +0100302
303 # If the force option was set, append the symbol to the end of the file
304 my $line = "#define $name";
305 $line .= " $value" if defined $value && $value ne "";
306 $line .= "\n";
307 $done = 1;
308
Gilles Peskine01f57e32017-10-09 16:54:28 +0200309 print $config_write $line or die "write $config_file: $!\n";
SimonB60f2cf92016-04-03 14:16:08 +0100310}
311
Gilles Peskine01f57e32017-10-09 16:54:28 +0200312if (defined $config_write) {
313 close $config_write or die "close $config_file: $!\n";
314}
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200315
Simon Butcherdd9895d2016-06-21 15:12:00 +0100316if ($action eq "get") {
Gilles Peskined98e9e82017-10-09 16:56:18 +0200317 if ($done) {
Simon Butcherdd9895d2016-06-21 15:12:00 +0100318 if ($value ne '') {
Gilles Peskined98e9e82017-10-09 16:56:18 +0200319 print "$value\n";
Simon Butcherdd9895d2016-06-21 15:12:00 +0100320 }
321 exit 0;
322 } else {
323 # If the symbol was not found, return an error
Gilles Peskined98e9e82017-10-09 16:56:18 +0200324 exit 1;
Simon Butcher4ae86912016-06-21 10:09:25 +0100325 }
Simon Butcher4ae86912016-06-21 10:09:25 +0100326}
327
SimonB60f2cf92016-04-03 14:16:08 +0100328if ($action eq "full" && !$done) {
329 die "Configuration section was not found in $config_file\n";
330
331}
332
333if ($action ne "full" && $action ne "unset" && !$done) {
334 die "A #define for the symbol $name was not found in $config_file\n";
335}
Manuel Pégourié-Gonnardab3d8622014-07-12 03:19:18 +0200336
337__END__