blob: 09d5a9d596d3b10628966e9621825f849bca9239 [file] [log] [blame]
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02001# Copyright (c) 2017 Linaro Limited
2#
3# SPDX-License-Identifier: Apache-2.0
4#
5
Marti Bolivar0e091c92018-04-12 11:23:16 -04006mainmenu "MCUboot configuration"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02007
Marti Bolivar0e091c92018-04-12 11:23:16 -04008comment "MCUboot-specific configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02009
Emanuele Di Santo865777d2018-11-08 11:28:15 +010010# Hidden option to mark a project as MCUboot
11config MCUBOOT
12 default y
13 bool
Rajavardhan Gundi07ba28f2018-12-10 15:44:48 +053014 select MPU_ALLOW_FLASH_WRITE if ARM_MPU
Andrzej Puzdrowski23d3c662019-03-18 14:12:22 +010015 select USE_CODE_PARTITION if HAS_FLASH_LOAD_OFFSET
Emanuele Di Santo865777d2018-11-08 11:28:15 +010016
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040017config BOOT_USE_MBEDTLS
18 bool
19 # Hidden option
20 default n
21 help
22 Use mbedTLS for crypto primitives.
23
24config BOOT_USE_TINYCRYPT
25 bool
26 # Hidden option
27 default n
Sebastian Bøe913a3852019-01-22 13:53:12 +010028 # When building for ECDSA, we use our own copy of mbedTLS, so the
29 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
30 # will collide.
31 depends on ! MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040032 help
33 Use TinyCrypt for crypto primitives.
34
Sigvart Hovlandebd05032019-03-21 10:47:32 +010035config BOOT_USE_CC310
36 bool
37 # Hidden option
38 default n
39 # When building for ECDSA, we use our own copy of mbedTLS, so the
40 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
41 # will collide.
42 depends on ! MBEDTLS
43 help
44 Use cc310 for crypto primitives.
45
46config BOOT_USE_NRF_CC310_BL
47 bool
48 default n
49
50config NRFXLIB_CRYPTO
51 bool
52 default n
53
54config NRF_CC310_BL
55 bool
56 default n
57
Andrzej Puzdrowski97543282018-04-12 15:16:56 +020058menu "MCUBoot settings"
59
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040060choice
61 prompt "Signature type"
62 default BOOT_SIGNATURE_TYPE_RSA
63
64config BOOT_SIGNATURE_TYPE_RSA
65 bool "RSA signatures"
66 select BOOT_USE_MBEDTLS
Marti Bolivara4818a52018-04-12 13:02:38 -040067 select MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040068
Fabio Utzig105b59a2019-05-13 15:08:12 -070069if BOOT_SIGNATURE_TYPE_RSA
70config BOOT_SIGNATURE_TYPE_RSA_LEN
71 int "RSA signature length"
72 range 2048 3072
73 default 2048
74endif
75
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040076config BOOT_SIGNATURE_TYPE_ECDSA_P256
77 bool "Elliptic curve digital signatures with curve P-256"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040078
Sigvart Hovlandebd05032019-03-21 10:47:32 +010079if BOOT_SIGNATURE_TYPE_ECDSA_P256
80choice
81 prompt "Ecdsa implementation"
Fabio Utzig34e93a52020-02-03 09:59:53 -030082 default BOOT_ECDSA_TINYCRYPT
83config BOOT_ECDSA_TINYCRYPT
Sigvart Hovlandebd05032019-03-21 10:47:32 +010084 bool "Use tinycrypt"
85 select BOOT_USE_TINYCRYPT
86config BOOT_CC310
87 bool "Use CC310"
88 select BOOT_USE_NRF_CC310_BL if HAS_HW_NRF_CC310
89 select NRF_CC310_BL if HAS_HW_NRF_CC310
90 select NRFXLIB_CRYPTO if SOC_FAMILY_NRF
91 select BOOT_USE_CC310
92endchoice
93endif
Fabio Utzig34e93a52020-02-03 09:59:53 -030094
95config BOOT_SIGNATURE_TYPE_ED25519
96 bool "Edwards curve digital signatures using ed25519"
97
98if BOOT_SIGNATURE_TYPE_ED25519
99choice
100 prompt "Ecdsa implementation"
101 default BOOT_ED25519_TINYCRYPT
102config BOOT_ED25519_TINYCRYPT
103 bool "Use tinycrypt"
104 select BOOT_USE_TINYCRYPT
105config BOOT_ED25519_MBEDTLS
106 bool "Use mbedTLS"
107 select BOOT_USE_MBEDTLS
108 select MBEDTLS
109endchoice
110endif
111
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400112endchoice
113
Fabio Utzigc690c762018-04-26 10:51:09 -0300114config BOOT_SIGNATURE_KEY_FILE
115 string "PEM key file"
116 default ""
117 help
118 The key file will be parsed by imgtool's getpub command and a .c source
119 with the public key information will be written in a format expected by
120 MCUboot.
121
Marti Bolivara4818a52018-04-12 13:02:38 -0400122config MBEDTLS_CFG_FILE
123 default "mcuboot-mbedtls-cfg.h"
124
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400125config BOOT_VALIDATE_SLOT0
David Vincze2d736ad2019-02-18 11:50:22 +0100126 bool "Validate image in the primary slot on every boot"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400127 default y
128 help
David Vincze2d736ad2019-02-18 11:50:22 +0100129 If y, the bootloader attempts to validate the signature of the
130 primary slot every boot. This adds the signature check time to
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400131 every boot, but can mitigate against some changes that are
132 able to modify the flash image itself.
133
134config BOOT_UPGRADE_ONLY
135 bool "Overwrite image updates instead of swapping"
136 default n
137 help
David Vincze2d736ad2019-02-18 11:50:22 +0100138 If y, overwrite the primary slot with the upgrade image instead
139 of swapping them. This prevents the fallback recovery, but
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400140 uses a much simpler code path.
141
Fabio Utzigc58842e2019-11-28 10:30:01 -0300142config BOOT_SWAP_USING_MOVE
Fabio Utzigdd2b6802020-01-06 09:10:45 -0300143 bool "Swap mode that can run without a scratch partition"
Håkon Øye Amundsen09be7832020-01-24 14:34:49 +0000144 default y if SOC_FAMILY_NRF
Fabio Utzigc58842e2019-11-28 10:30:01 -0300145 default n
146 help
147 If y, the swap upgrade is done in two steps, where first every
148 sector of the primary slot is moved up one sector, then for
149 each sector X in the secondary slot, it is moved to index X in
150 the primary slot, then the sector at X+1 in the primary is
151 moved to index X in the secondary.
152 This allows a swap upgrade without using a scratch partition,
153 but is currently limited to all sectors in both slots being of
154 the same size.
155
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200156config BOOT_BOOTSTRAP
Sam Bristowd0ca0ff2019-10-30 20:51:35 +1300157 bool "Bootstrap erased the primary slot from the secondary slot"
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200158 default n
159 help
160 If y, enables bootstraping support. Bootstrapping allows an erased
David Vincze2d736ad2019-02-18 11:50:22 +0100161 primary slot to be initialized from a valid image in the secondary slot.
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200162 If unsure, leave at the default value.
163
Fabio Utzigca8ead22019-12-20 07:06:04 -0300164config BOOT_SWAP_SAVE_ENCTLV
165 bool "Save encrypted key TLVs instead of plaintext keys in swap metadata"
166 default n
167 help
168 If y, instead of saving the encrypted image keys in plaintext in the
169 swap resume metadata, save the encrypted image TLVs. This should be used
170 when there is no security mechanism protecting the data in the primary
171 slot from being dumped. If n is selected (default), the keys are written
172 after being decrypted from the image TLVs and could be read by an
173 attacker who has access to the flash contents of the primary slot (eg
174 JTAG/SWD or primary slot in external flash).
175 If unsure, leave at the default value.
176
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300177config BOOT_ENCRYPT_RSA
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300178 bool "Support for encrypted upgrade images using RSA"
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300179 default n
180 help
David Vincze2d736ad2019-02-18 11:50:22 +0100181 If y, images in the secondary slot can be encrypted and are decrypted
182 on the fly when upgrading to the primary slot, as well as encrypted
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300183 back when swapping from the primary slot to the secondary slot. The
184 encryption mechanism used in this case is RSA-OAEP (2048 bits).
185
186config BOOT_ENCRYPT_EC256
187 bool "Support for encrypted upgrade images using ECIES-P256"
188 default n
189 help
190 If y, images in the secondary slot can be encrypted and are decrypted
191 on the fly when upgrading to the primary slot, as well as encrypted
192 back when swapping from the primary slot to the secondary slot. The
193 encryption mechanism used in this case is ECIES using primitives
194 described under "ECIES-P256 encryption" in docs/encrypted_images.md.
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300195
Marti Bolivar0e091c92018-04-12 11:23:16 -0400196config BOOT_MAX_IMG_SECTORS
197 int "Maximum number of sectors per image slot"
198 default 128
199 help
200 This option controls the maximum number of sectors that each of
201 the two image areas can contain. Smaller values reduce MCUboot's
202 memory usage; larger values allow it to support larger images.
203 If unsure, leave at the default value.
204
Emanuele Di Santo205c8c62018-07-20 11:42:31 +0200205config BOOT_ERASE_PROGRESSIVELY
206 bool "Erase flash progressively when receiving new firmware"
207 default y if SOC_NRF52840
208 help
209 If enabled, flash is erased as necessary when receiving new firmware,
210 instead of erasing the whole image slot at once. This is necessary
211 on some hardware that has long erase times, to prevent long wait
212 times at the beginning of the DFU process.
213
Rajavardhan Gundi51c9d702019-02-20 14:08:52 +0530214config BOOT_WAIT_FOR_USB_DFU
215 bool "Wait for a prescribed duration to see if USB DFU is invoked"
216 default n
217 select USB
218 select USB_DFU_CLASS
219 select IMG_MANAGER
220 help
221 If y, MCUboot waits for a prescribed duration of time to allow
222 for USB DFU to be invoked. Please note DFU always updates the
223 slot1 image.
224
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400225config ZEPHYR_TRY_MASS_ERASE
226 bool "Try to mass erase flash when flashing MCUboot image"
227 default y
228 help
229 If y, attempt to configure the Zephyr build system's "flash"
230 target to mass-erase the flash device before flashing the
231 MCUboot image. This ensures the scratch and other partitions
232 are in a consistent state.
233
234 This is not available for all targets.
235
David Brownf6d14c22019-12-10 15:36:36 -0700236config BOOT_USE_BENCH
237 bool "Enable benchmark code"
238 default n
239 help
240 If y, adds support for simple benchmarking that can record
241 time intervals between two calls. The time printed depends
242 on the particular Zephyr target, and is generally ticks of a
243 specific board-specific timer.
244
Michael Scott74ceae52019-02-01 14:01:09 -0800245module = MCUBOOT
Piotr Mienkowski15aa6ef2019-04-08 22:48:15 +0200246module-str = MCUBoot bootloader
Michael Scott74ceae52019-02-01 14:01:09 -0800247source "subsys/logging/Kconfig.template.log_config"
Michael Scott74ceae52019-02-01 14:01:09 -0800248
Marti Bolivar0e091c92018-04-12 11:23:16 -0400249menuconfig MCUBOOT_SERIAL
250 bool "MCUboot serial recovery"
251 default n
252 select REBOOT
Emanuele Di Santo30a92652019-01-16 14:01:08 +0100253 select GPIO
Marti Bolivar0e091c92018-04-12 11:23:16 -0400254 select SERIAL
Emanuele Di Santo30a92652019-01-16 14:01:08 +0100255 select UART_INTERRUPT_DRIVEN
Marti Bolivar0e091c92018-04-12 11:23:16 -0400256 select BASE64
257 select TINYCBOR
258 help
259 If y, enables a serial-port based update mode. This allows
260 MCUboot itself to load update images into flash over a UART.
261 If unsure, leave at the default value.
262
263if MCUBOOT_SERIAL
264
Emanuele Di Santoc4bf7802018-07-20 11:39:57 +0200265choice
266 prompt "Serial device"
267 default BOOT_SERIAL_UART if !BOARD_NRF52840_PCA10059
268 default BOOT_SERIAL_CDC_ACM if BOARD_NRF52840_PCA10059
269
270config BOOT_SERIAL_UART
271 bool "UART"
272 # SERIAL and UART_INTERRUPT_DRIVEN already selected
273
274config BOOT_SERIAL_CDC_ACM
275 bool "CDC ACM"
276 select USB
277 select USB_DEVICE_STACK
278 select USB_CDC_ACM
279
280endchoice
281
Marti Bolivar0e091c92018-04-12 11:23:16 -0400282config BOOT_MAX_LINE_INPUT_LEN
283 int "Maximum command line length"
284 default 512
285 help
286 Maximum length of commands transported over the serial port.
287
288config BOOT_SERIAL_DETECT_PORT
289 string "GPIO device to trigger serial recovery mode"
290 default GPIO_0 if SOC_FAMILY_NRF
291 help
292 Zephyr GPIO device which contains the pin used to trigger
293 serial recovery mode.
294
295config BOOT_SERIAL_DETECT_PIN
296 int "Pin to trigger serial recovery mode"
Andreas Vibeto704b8ba2019-04-25 10:51:23 +0200297 default 6 if BOARD_NRF9160_PCA10090
Marti Bolivar0e091c92018-04-12 11:23:16 -0400298 default 11 if BOARD_NRF52840_PCA10056
299 default 13 if BOARD_NRF52_PCA10040
300 help
301 Pin on the serial detect port which triggers serial recovery mode.
302
303config BOOT_SERIAL_DETECT_PIN_VAL
304 int "Serial detect pin trigger value"
305 default 0
306 range 0 1
307 help
308 Logic value of the detect pin which triggers serial recovery
309 mode.
310
Andrzej Puzdrowskif0004802019-10-01 14:13:35 +0200311# Workaround for not being able to have commas in macro arguments
312DT_CHOSEN_Z_CONSOLE := zephyr,console
313
314config RECOVERY_UART_DEV_NAME
315 string "UART Device Name for Recovery UART"
316 default "$(dt_chosen_label,$(DT_CHOSEN_Z_CONSOLE))" if HAS_DTS
317 default "UART_0"
318 depends on BOOT_SERIAL_UART
319 help
320 This option specifies the name of UART device to be used for
321 serial recovery.
322
Marti Bolivar0e091c92018-04-12 11:23:16 -0400323endif # MCUBOOT_SERIAL
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200324
Andrzej Puzdrowski97543282018-04-12 15:16:56 +0200325endmenu
326
Carles Cufi84ede582018-01-29 15:12:00 +0100327config MCUBOOT_DEVICE_SETTINGS
328 # Hidden selector for device-specific settings
329 bool
330 default y
331 # CPU options
332 select MCUBOOT_DEVICE_CPU_CORTEX_M0 if CPU_CORTEX_M0
Carles Cufi67c792e2018-01-29 15:14:31 +0100333 # Enable flash page layout if available
334 select FLASH_PAGE_LAYOUT if FLASH_HAS_PAGE_LAYOUT
Andrzej Puzdrowskib788c712018-04-12 12:42:49 +0200335 # Enable flash_map module as flash I/O back-end
336 select FLASH_MAP
Carles Cufi84ede582018-01-29 15:12:00 +0100337
338config MCUBOOT_DEVICE_CPU_CORTEX_M0
339 # Hidden selector for Cortex-M0 settings
340 bool
341 default n
342 select SW_VECTOR_RELAY if !CPU_CORTEX_M0_HAS_VECTOR_TABLE_REMAP
343
Marti Bolivar0e091c92018-04-12 11:23:16 -0400344comment "Zephyr configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200345
Marti Bolivarf84cc4b2019-08-20 16:06:56 -0700346# Disabling MULTITHREADING provides a code size advantage, but
347# it requires peripheral drivers (particularly a flash driver)
348# that works properly with the option enabled.
349#
350# If you know for sure that your hardware will work, you can default
351# it to n here. Otherwise, having it on by default makes the most
352# hardware work.
353config MULTITHREADING
354 default n if SOC_FAMILY_NRF
355 default y
356
Håkon Øye Amundsen954dd2b2019-09-23 09:24:13 +0000357config UPDATEABLE_IMAGE_NUMBER
358 int "Number of updateable images"
359 default 1
360 help
361 Enables support of multi image update.
362
Håkon Øye Amundsen2d1bac12020-01-03 13:08:09 +0000363config MCUBOOT_DOWNGRADE_PREVENTION
364 bool "Downgrade prevention"
365 depends on BOOT_UPGRADE_ONLY
366 help
367 Prevent downgrades by enforcing incrementing version numbers.
368 When this option is set, any upgrade must have greater major version
369 or greater minor version with equal major version. This mechanism
370 only protects against some attacks against version downgrades (for
371 example, a JTAG could be used to write an older version).
372
Robert Lubos1b19d2a2020-01-31 14:05:35 +0100373source "Kconfig.zephyr"