blob: 13f5fc48f45333543cb0428afc09129130891b57 [file] [log] [blame]
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02001# Copyright (c) 2017 Linaro Limited
2#
3# SPDX-License-Identifier: Apache-2.0
4#
5
Marti Bolivar0e091c92018-04-12 11:23:16 -04006mainmenu "MCUboot configuration"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02007
Marti Bolivar0e091c92018-04-12 11:23:16 -04008comment "MCUboot-specific configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02009
Emanuele Di Santo865777d2018-11-08 11:28:15 +010010# Hidden option to mark a project as MCUboot
11config MCUBOOT
12 default y
13 bool
Rajavardhan Gundi07ba28f2018-12-10 15:44:48 +053014 select MPU_ALLOW_FLASH_WRITE if ARM_MPU
Andrzej Puzdrowski23d3c662019-03-18 14:12:22 +010015 select USE_CODE_PARTITION if HAS_FLASH_LOAD_OFFSET
Emanuele Di Santo865777d2018-11-08 11:28:15 +010016
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040017config BOOT_USE_MBEDTLS
18 bool
19 # Hidden option
20 default n
21 help
22 Use mbedTLS for crypto primitives.
23
24config BOOT_USE_TINYCRYPT
25 bool
26 # Hidden option
27 default n
Sebastian Bøe913a3852019-01-22 13:53:12 +010028 # When building for ECDSA, we use our own copy of mbedTLS, so the
29 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
30 # will collide.
31 depends on ! MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040032 help
33 Use TinyCrypt for crypto primitives.
34
Sigvart Hovlandebd05032019-03-21 10:47:32 +010035config BOOT_USE_CC310
36 bool
37 # Hidden option
38 default n
39 # When building for ECDSA, we use our own copy of mbedTLS, so the
40 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
41 # will collide.
42 depends on ! MBEDTLS
43 help
44 Use cc310 for crypto primitives.
45
46config BOOT_USE_NRF_CC310_BL
47 bool
48 default n
49
50config NRFXLIB_CRYPTO
51 bool
52 default n
53
54config NRF_CC310_BL
55 bool
56 default n
57
Andrzej Puzdrowski97543282018-04-12 15:16:56 +020058menu "MCUBoot settings"
59
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040060choice
61 prompt "Signature type"
62 default BOOT_SIGNATURE_TYPE_RSA
63
64config BOOT_SIGNATURE_TYPE_RSA
65 bool "RSA signatures"
66 select BOOT_USE_MBEDTLS
Marti Bolivara4818a52018-04-12 13:02:38 -040067 select MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040068
69config BOOT_SIGNATURE_TYPE_ECDSA_P256
70 bool "Elliptic curve digital signatures with curve P-256"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040071
Sigvart Hovlandebd05032019-03-21 10:47:32 +010072if BOOT_SIGNATURE_TYPE_ECDSA_P256
73choice
74 prompt "Ecdsa implementation"
75 default BOOT_TINYCRYPT
76config BOOT_TINYCRYPT
77 bool "Use tinycrypt"
78 select BOOT_USE_TINYCRYPT
79config BOOT_CC310
80 bool "Use CC310"
81 select BOOT_USE_NRF_CC310_BL if HAS_HW_NRF_CC310
82 select NRF_CC310_BL if HAS_HW_NRF_CC310
83 select NRFXLIB_CRYPTO if SOC_FAMILY_NRF
84 select BOOT_USE_CC310
85endchoice
86endif
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040087endchoice
88
Fabio Utzigc690c762018-04-26 10:51:09 -030089config BOOT_SIGNATURE_KEY_FILE
90 string "PEM key file"
91 default ""
92 help
93 The key file will be parsed by imgtool's getpub command and a .c source
94 with the public key information will be written in a format expected by
95 MCUboot.
96
Marti Bolivara4818a52018-04-12 13:02:38 -040097config MBEDTLS_CFG_FILE
98 default "mcuboot-mbedtls-cfg.h"
99
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400100config BOOT_VALIDATE_SLOT0
David Vincze2d736ad2019-02-18 11:50:22 +0100101 bool "Validate image in the primary slot on every boot"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400102 default y
103 help
David Vincze2d736ad2019-02-18 11:50:22 +0100104 If y, the bootloader attempts to validate the signature of the
105 primary slot every boot. This adds the signature check time to
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400106 every boot, but can mitigate against some changes that are
107 able to modify the flash image itself.
108
109config BOOT_UPGRADE_ONLY
110 bool "Overwrite image updates instead of swapping"
111 default n
112 help
David Vincze2d736ad2019-02-18 11:50:22 +0100113 If y, overwrite the primary slot with the upgrade image instead
114 of swapping them. This prevents the fallback recovery, but
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400115 uses a much simpler code path.
116
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200117config BOOT_BOOTSTRAP
David Vincze2d736ad2019-02-18 11:50:22 +0100118 bool "Boostrap erased the primary slot from the secondary slot"
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200119 default n
120 help
121 If y, enables bootstraping support. Bootstrapping allows an erased
David Vincze2d736ad2019-02-18 11:50:22 +0100122 primary slot to be initialized from a valid image in the secondary slot.
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200123 If unsure, leave at the default value.
124
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300125config BOOT_ENCRYPT_RSA
126 bool "Support for encrypted upgrade images"
127 default n
128 help
David Vincze2d736ad2019-02-18 11:50:22 +0100129 If y, images in the secondary slot can be encrypted and are decrypted
130 on the fly when upgrading to the primary slot, as well as encrypted
131 back when swapping from the primary slot to the secondary slot.
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300132
Marti Bolivar0e091c92018-04-12 11:23:16 -0400133config BOOT_MAX_IMG_SECTORS
134 int "Maximum number of sectors per image slot"
135 default 128
136 help
137 This option controls the maximum number of sectors that each of
138 the two image areas can contain. Smaller values reduce MCUboot's
139 memory usage; larger values allow it to support larger images.
140 If unsure, leave at the default value.
141
Emanuele Di Santo205c8c62018-07-20 11:42:31 +0200142config BOOT_ERASE_PROGRESSIVELY
143 bool "Erase flash progressively when receiving new firmware"
144 default y if SOC_NRF52840
145 help
146 If enabled, flash is erased as necessary when receiving new firmware,
147 instead of erasing the whole image slot at once. This is necessary
148 on some hardware that has long erase times, to prevent long wait
149 times at the beginning of the DFU process.
150
Rajavardhan Gundi51c9d702019-02-20 14:08:52 +0530151config BOOT_WAIT_FOR_USB_DFU
152 bool "Wait for a prescribed duration to see if USB DFU is invoked"
153 default n
154 select USB
155 select USB_DFU_CLASS
156 select IMG_MANAGER
157 help
158 If y, MCUboot waits for a prescribed duration of time to allow
159 for USB DFU to be invoked. Please note DFU always updates the
160 slot1 image.
161
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400162config ZEPHYR_TRY_MASS_ERASE
163 bool "Try to mass erase flash when flashing MCUboot image"
164 default y
165 help
166 If y, attempt to configure the Zephyr build system's "flash"
167 target to mass-erase the flash device before flashing the
168 MCUboot image. This ensures the scratch and other partitions
169 are in a consistent state.
170
171 This is not available for all targets.
172
Fabio Utzig9a4b9ba2018-05-07 08:31:27 -0300173config BOOT_HAVE_LOGGING
174 bool "MCUboot have logging enabled"
175 default y
Emanuele Di Santo9f1933d2018-11-20 10:59:59 +0100176 select LOG
Michael Scottcef44272019-02-01 11:12:15 -0800177 select LOG_IMMEDIATE
Fabio Utzig9a4b9ba2018-05-07 08:31:27 -0300178 help
179 If y, enables logging on the serial port. The log level can
Michael Scott74ceae52019-02-01 14:01:09 -0800180 be defined by setting `CONFIG_MCUBOOT_LOG_LEVEL_*`.
Fabio Utzig9a4b9ba2018-05-07 08:31:27 -0300181 If unsure, leave at the default value.
182
Michael Scott74ceae52019-02-01 14:01:09 -0800183if BOOT_HAVE_LOGGING
184module = MCUBOOT
185module-dep = LOG
186module-str = Log level for MCUBOOT application
187source "subsys/logging/Kconfig.template.log_config"
188endif
189
Marti Bolivar0e091c92018-04-12 11:23:16 -0400190menuconfig MCUBOOT_SERIAL
191 bool "MCUboot serial recovery"
192 default n
193 select REBOOT
Emanuele Di Santo30a92652019-01-16 14:01:08 +0100194 select GPIO
Marti Bolivar0e091c92018-04-12 11:23:16 -0400195 select SERIAL
Emanuele Di Santo30a92652019-01-16 14:01:08 +0100196 select UART_INTERRUPT_DRIVEN
Marti Bolivar0e091c92018-04-12 11:23:16 -0400197 select BASE64
198 select TINYCBOR
199 help
200 If y, enables a serial-port based update mode. This allows
201 MCUboot itself to load update images into flash over a UART.
202 If unsure, leave at the default value.
203
204if MCUBOOT_SERIAL
205
Emanuele Di Santoc4bf7802018-07-20 11:39:57 +0200206choice
207 prompt "Serial device"
208 default BOOT_SERIAL_UART if !BOARD_NRF52840_PCA10059
209 default BOOT_SERIAL_CDC_ACM if BOARD_NRF52840_PCA10059
210
211config BOOT_SERIAL_UART
212 bool "UART"
213 # SERIAL and UART_INTERRUPT_DRIVEN already selected
214
215config BOOT_SERIAL_CDC_ACM
216 bool "CDC ACM"
217 select USB
218 select USB_DEVICE_STACK
219 select USB_CDC_ACM
220
221endchoice
222
Marti Bolivar0e091c92018-04-12 11:23:16 -0400223config BOOT_MAX_LINE_INPUT_LEN
224 int "Maximum command line length"
225 default 512
226 help
227 Maximum length of commands transported over the serial port.
228
229config BOOT_SERIAL_DETECT_PORT
230 string "GPIO device to trigger serial recovery mode"
231 default GPIO_0 if SOC_FAMILY_NRF
232 help
233 Zephyr GPIO device which contains the pin used to trigger
234 serial recovery mode.
235
236config BOOT_SERIAL_DETECT_PIN
237 int "Pin to trigger serial recovery mode"
238 default 11 if BOARD_NRF52840_PCA10056
239 default 13 if BOARD_NRF52_PCA10040
240 help
241 Pin on the serial detect port which triggers serial recovery mode.
242
243config BOOT_SERIAL_DETECT_PIN_VAL
244 int "Serial detect pin trigger value"
245 default 0
246 range 0 1
247 help
248 Logic value of the detect pin which triggers serial recovery
249 mode.
250
251endif # MCUBOOT_SERIAL
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200252
Andrzej Puzdrowski97543282018-04-12 15:16:56 +0200253endmenu
254
Carles Cufi84ede582018-01-29 15:12:00 +0100255config MCUBOOT_DEVICE_SETTINGS
256 # Hidden selector for device-specific settings
257 bool
258 default y
259 # CPU options
260 select MCUBOOT_DEVICE_CPU_CORTEX_M0 if CPU_CORTEX_M0
Carles Cufi67c792e2018-01-29 15:14:31 +0100261 # Enable flash page layout if available
262 select FLASH_PAGE_LAYOUT if FLASH_HAS_PAGE_LAYOUT
Andrzej Puzdrowskib788c712018-04-12 12:42:49 +0200263 # Enable flash_map module as flash I/O back-end
264 select FLASH_MAP
Carles Cufi84ede582018-01-29 15:12:00 +0100265
266config MCUBOOT_DEVICE_CPU_CORTEX_M0
267 # Hidden selector for Cortex-M0 settings
268 bool
269 default n
270 select SW_VECTOR_RELAY if !CPU_CORTEX_M0_HAS_VECTOR_TABLE_REMAP
271
Marti Bolivar0e091c92018-04-12 11:23:16 -0400272comment "Zephyr configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200273
Marti Bolivar0e091c92018-04-12 11:23:16 -0400274config ZEPHYR_BASE
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200275 string
Marti Bolivar0e091c92018-04-12 11:23:16 -0400276 option env="ZEPHYR_BASE"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200277
Marti Bolivar0e091c92018-04-12 11:23:16 -0400278source "$ZEPHYR_BASE/Kconfig.zephyr"