blob: 0d0bed3d001f643ec2b81a57fa3d0d7a4654d33a [file] [log] [blame]
David Vincze03368b82020-04-01 12:53:53 +02001# Copyright (c) 2017-2020 Linaro Limited
David Vinczec3084132020-02-18 14:50:47 +01002# Copyright (c) 2020 Arm Limited
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02003#
4# SPDX-License-Identifier: Apache-2.0
5#
6
Marti Bolivar0e091c92018-04-12 11:23:16 -04007mainmenu "MCUboot configuration"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02008
Marti Bolivar0e091c92018-04-12 11:23:16 -04009comment "MCUboot-specific configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +020010
Emanuele Di Santo865777d2018-11-08 11:28:15 +010011# Hidden option to mark a project as MCUboot
12config MCUBOOT
13 default y
14 bool
Rajavardhan Gundi07ba28f2018-12-10 15:44:48 +053015 select MPU_ALLOW_FLASH_WRITE if ARM_MPU
Marcin Niestrojc6be76a2020-03-22 14:39:35 +010016 select USE_DT_CODE_PARTITION if HAS_FLASH_LOAD_OFFSET
Emanuele Di Santo865777d2018-11-08 11:28:15 +010017
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040018config BOOT_USE_MBEDTLS
19 bool
20 # Hidden option
21 default n
22 help
23 Use mbedTLS for crypto primitives.
24
25config BOOT_USE_TINYCRYPT
26 bool
27 # Hidden option
28 default n
Sebastian Bøe913a3852019-01-22 13:53:12 +010029 # When building for ECDSA, we use our own copy of mbedTLS, so the
30 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
31 # will collide.
32 depends on ! MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040033 help
34 Use TinyCrypt for crypto primitives.
35
Sigvart Hovlandebd05032019-03-21 10:47:32 +010036config BOOT_USE_CC310
37 bool
38 # Hidden option
39 default n
40 # When building for ECDSA, we use our own copy of mbedTLS, so the
41 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
42 # will collide.
43 depends on ! MBEDTLS
44 help
45 Use cc310 for crypto primitives.
46
47config BOOT_USE_NRF_CC310_BL
48 bool
49 default n
50
51config NRFXLIB_CRYPTO
52 bool
53 default n
54
55config NRF_CC310_BL
56 bool
57 default n
58
Andrzej Puzdrowski97543282018-04-12 15:16:56 +020059menu "MCUBoot settings"
60
Andrzej Puzdrowskifdff3e12020-09-15 08:23:25 +020061config SINGLE_APPLICATION_SLOT
62 bool "Single slot bootloader"
Dominik Ermel4dc3f442020-05-26 08:45:14 +000063 default n
64 help
65 Single image area is used for application which means that
66 uploading a new application overwrites the one that previously
67 occupied the area.
68
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040069choice
70 prompt "Signature type"
71 default BOOT_SIGNATURE_TYPE_RSA
72
Arvin Farahmandfb5ec182020-05-05 11:44:12 -040073config BOOT_SIGNATURE_TYPE_NONE
74 bool "No signature; use only hash check"
75 select BOOT_USE_TINYCRYPT
76
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040077config BOOT_SIGNATURE_TYPE_RSA
78 bool "RSA signatures"
79 select BOOT_USE_MBEDTLS
Marti Bolivara4818a52018-04-12 13:02:38 -040080 select MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040081
Fabio Utzig105b59a2019-05-13 15:08:12 -070082if BOOT_SIGNATURE_TYPE_RSA
83config BOOT_SIGNATURE_TYPE_RSA_LEN
84 int "RSA signature length"
85 range 2048 3072
86 default 2048
87endif
88
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040089config BOOT_SIGNATURE_TYPE_ECDSA_P256
90 bool "Elliptic curve digital signatures with curve P-256"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040091
Sigvart Hovlandebd05032019-03-21 10:47:32 +010092if BOOT_SIGNATURE_TYPE_ECDSA_P256
93choice
94 prompt "Ecdsa implementation"
Fabio Utzig34e93a52020-02-03 09:59:53 -030095 default BOOT_ECDSA_TINYCRYPT
Håkon Øye Amundsenee7282d2020-09-28 09:48:29 +000096
Fabio Utzig34e93a52020-02-03 09:59:53 -030097config BOOT_ECDSA_TINYCRYPT
Sigvart Hovlandebd05032019-03-21 10:47:32 +010098 bool "Use tinycrypt"
99 select BOOT_USE_TINYCRYPT
Håkon Øye Amundsenee7282d2020-09-28 09:48:29 +0000100
101config BOOT_ECDSA_CC310
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100102 bool "Use CC310"
Håkon Øye Amundsenee7282d2020-09-28 09:48:29 +0000103 depends on HAS_HW_NRF_CC310
104 select BOOT_USE_NRF_CC310_BL
105 select NRF_CC310_BL
106 select NRFXLIB_CRYPTO
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100107 select BOOT_USE_CC310
Håkon Øye Amundsenee7282d2020-09-28 09:48:29 +0000108endchoice # Ecdsa implementation
Sigvart Hovlandebd05032019-03-21 10:47:32 +0100109endif
Fabio Utzig34e93a52020-02-03 09:59:53 -0300110
111config BOOT_SIGNATURE_TYPE_ED25519
112 bool "Edwards curve digital signatures using ed25519"
113
114if BOOT_SIGNATURE_TYPE_ED25519
115choice
116 prompt "Ecdsa implementation"
117 default BOOT_ED25519_TINYCRYPT
118config BOOT_ED25519_TINYCRYPT
119 bool "Use tinycrypt"
120 select BOOT_USE_TINYCRYPT
121config BOOT_ED25519_MBEDTLS
122 bool "Use mbedTLS"
123 select BOOT_USE_MBEDTLS
124 select MBEDTLS
125endchoice
126endif
127
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400128endchoice
129
Fabio Utzigc690c762018-04-26 10:51:09 -0300130config BOOT_SIGNATURE_KEY_FILE
131 string "PEM key file"
Håkon Øye Amundsen705c6c22020-09-28 09:45:40 +0000132 default "root-ec-p256.pem" if BOOT_SIGNATURE_TYPE_ECDSA_P256
133 default "root-ed25519.pem" if BOOT_SIGNATURE_TYPE_ED25519
134 default "root-rsa-3072.pem" if BOOT_SIGNATURE_TYPE_RSA && BOOT_SIGNATURE_TYPE_RSA_LEN=3072
135 default "root-rsa-2048.pem" if BOOT_SIGNATURE_TYPE_RSA && BOOT_SIGNATURE_TYPE_RSA_LEN=2048
Fabio Utzigc690c762018-04-26 10:51:09 -0300136 default ""
137 help
Marek Pietabdcfc852020-08-04 02:22:55 -0700138 You can use either absolute or relative path.
139 In case relative path is used, the build system assumes that it starts
140 from the directory where the MCUBoot KConfig configuration file is
141 located. If the key file is not there, the build system uses relative
142 path that starts from the MCUBoot repository root directory.
Fabio Utzigc690c762018-04-26 10:51:09 -0300143 The key file will be parsed by imgtool's getpub command and a .c source
144 with the public key information will be written in a format expected by
145 MCUboot.
146
Andrzej Puzdrowski9a605b62020-03-16 13:34:30 +0100147config MCUBOOT_CLEANUP_ARM_CORE
148 bool "Perform core cleanup before chain-load the application"
149 depends on CPU_CORTEX_M
Ioannis Glaropoulos518d93a2020-10-22 14:22:14 +0200150 default y if !ARCH_SUPPORTS_ARCH_HW_INIT
151 help
152 This option instructs MCUboot to perform a clean-up of a set of
153 architecture core HW registers before junping to the application
154 firmware. The clean-up sets these registers to their warm-reset
155 values as specified by the architecture.
156
157 By default, this option is enabled only if the architecture does
158 not have the functionality to perform such a register clean-up
159 during application firmware boot.
160
161 Zephyr applications on Cortex-M will perform this register clean-up
162 by default, if they are chain-loadable by MCUboot, so MCUboot does
163 not need to perform such a cleanup itself.
Andrzej Puzdrowski9a605b62020-03-16 13:34:30 +0100164
Marti Bolivara4818a52018-04-12 13:02:38 -0400165config MBEDTLS_CFG_FILE
166 default "mcuboot-mbedtls-cfg.h"
167
David Vincze03368b82020-04-01 12:53:53 +0200168config BOOT_HW_KEY
169 bool "Use HW key for image verification"
170 default n
171 help
172 Use HW key for image verification, otherwise the public key is embedded
173 in MCUBoot. If enabled the public key is appended to the signed image
174 and requires the hash of the public key to be provisioned to the device
175 beforehand.
176
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400177config BOOT_VALIDATE_SLOT0
David Vincze2d736ad2019-02-18 11:50:22 +0100178 bool "Validate image in the primary slot on every boot"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400179 default y
180 help
David Vincze2d736ad2019-02-18 11:50:22 +0100181 If y, the bootloader attempts to validate the signature of the
182 primary slot every boot. This adds the signature check time to
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400183 every boot, but can mitigate against some changes that are
184 able to modify the flash image itself.
185
Andrzej Puzdrowskifdff3e12020-09-15 08:23:25 +0200186if !SINGLE_APPLICATION_SLOT
David Vincze5a6e1812020-06-29 13:34:42 +0200187choice
188 prompt "Image upgrade modes"
189 default BOOT_SWAP_USING_MOVE if SOC_FAMILY_NRF
190 default BOOT_SWAP_USING_SCRATCH
191
192config BOOT_SWAP_USING_SCRATCH
193 bool "Swap mode that run with the scratch partition"
194 help
195 This is the most conservative swap mode but it can work even on
196 devices with heterogeneous flash page layout.
197
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400198config BOOT_UPGRADE_ONLY
199 bool "Overwrite image updates instead of swapping"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400200 help
David Vincze2d736ad2019-02-18 11:50:22 +0100201 If y, overwrite the primary slot with the upgrade image instead
202 of swapping them. This prevents the fallback recovery, but
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400203 uses a much simpler code path.
204
Fabio Utzigc58842e2019-11-28 10:30:01 -0300205config BOOT_SWAP_USING_MOVE
Fabio Utzigdd2b6802020-01-06 09:10:45 -0300206 bool "Swap mode that can run without a scratch partition"
Fabio Utzigc58842e2019-11-28 10:30:01 -0300207 help
208 If y, the swap upgrade is done in two steps, where first every
209 sector of the primary slot is moved up one sector, then for
210 each sector X in the secondary slot, it is moved to index X in
211 the primary slot, then the sector at X+1 in the primary is
212 moved to index X in the secondary.
213 This allows a swap upgrade without using a scratch partition,
214 but is currently limited to all sectors in both slots being of
215 the same size.
David Vincze5a6e1812020-06-29 13:34:42 +0200216
217config BOOT_DIRECT_XIP
218 bool "Run the latest image directly from its slot"
219 help
220 If y, mcuboot selects the newest valid image based on the image version
221 numbers, thereafter the selected image can run directly from its slot
222 without having to move/copy it into the primary slot. For this reason the
223 images must be linked to be executed from the given image slot. Using this
224 mode results in a simpler code path and smaller code size.
225
226endchoice
Fabio Utzigc58842e2019-11-28 10:30:01 -0300227
David Vincze505fba22020-10-22 13:53:29 +0200228config BOOT_DIRECT_XIP_REVERT
229 bool "Enable the revert mechanism in direct-xip mode"
Andrzej Puzdrowski32342e72020-11-18 17:04:44 +0100230 depends on BOOT_DIRECT_XIP
David Vincze505fba22020-10-22 13:53:29 +0200231 default n
232 help
233 If y, enables the revert mechanism in direct-xip similar to the one in
234 swap mode. It requires the trailer magic to be added to the signed image.
235 When a reboot happens without the image being confirmed at runtime, the
236 bootloader considers the image faulty and erases it. After this it will
237 attempt to boot the previous image. The images can also be made permanent
238 (marked as confirmed in advance) just like in swap mode.
239
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200240config BOOT_BOOTSTRAP
Sam Bristowd0ca0ff2019-10-30 20:51:35 +1300241 bool "Bootstrap erased the primary slot from the secondary slot"
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200242 default n
243 help
244 If y, enables bootstraping support. Bootstrapping allows an erased
David Vincze2d736ad2019-02-18 11:50:22 +0100245 primary slot to be initialized from a valid image in the secondary slot.
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200246 If unsure, leave at the default value.
247
Fabio Utzigca8ead22019-12-20 07:06:04 -0300248config BOOT_SWAP_SAVE_ENCTLV
249 bool "Save encrypted key TLVs instead of plaintext keys in swap metadata"
250 default n
251 help
252 If y, instead of saving the encrypted image keys in plaintext in the
253 swap resume metadata, save the encrypted image TLVs. This should be used
254 when there is no security mechanism protecting the data in the primary
255 slot from being dumped. If n is selected (default), the keys are written
256 after being decrypted from the image TLVs and could be read by an
257 attacker who has access to the flash contents of the primary slot (eg
258 JTAG/SWD or primary slot in external flash).
259 If unsure, leave at the default value.
260
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300261config BOOT_ENCRYPT_RSA
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300262 bool "Support for encrypted upgrade images using RSA"
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300263 default n
264 help
David Vincze2d736ad2019-02-18 11:50:22 +0100265 If y, images in the secondary slot can be encrypted and are decrypted
266 on the fly when upgrading to the primary slot, as well as encrypted
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300267 back when swapping from the primary slot to the secondary slot. The
268 encryption mechanism used in this case is RSA-OAEP (2048 bits).
269
270config BOOT_ENCRYPT_EC256
271 bool "Support for encrypted upgrade images using ECIES-P256"
272 default n
273 help
274 If y, images in the secondary slot can be encrypted and are decrypted
275 on the fly when upgrading to the primary slot, as well as encrypted
276 back when swapping from the primary slot to the secondary slot. The
277 encryption mechanism used in this case is ECIES using primitives
278 described under "ECIES-P256 encryption" in docs/encrypted_images.md.
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300279
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300280config BOOT_ENCRYPT_X25519
281 bool "Support for encrypted upgrade images using ECIES-X25519"
282 default n
283 help
284 If y, images in the secondary slot can be encrypted and are decrypted
285 on the fly when upgrading to the primary slot, as well as encrypted
286 back when swapping from the primary slot to the secondary slot. The
287 encryption mechanism used in this case is ECIES using primitives
288 described under "ECIES-X25519 encryption" in docs/encrypted_images.md.
David Vincze505fba22020-10-22 13:53:29 +0200289endif # !SINGLE_APPLICATION_SLOT
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300290
Marti Bolivar0e091c92018-04-12 11:23:16 -0400291config BOOT_MAX_IMG_SECTORS
292 int "Maximum number of sectors per image slot"
293 default 128
294 help
295 This option controls the maximum number of sectors that each of
296 the two image areas can contain. Smaller values reduce MCUboot's
297 memory usage; larger values allow it to support larger images.
298 If unsure, leave at the default value.
299
Emanuele Di Santo205c8c62018-07-20 11:42:31 +0200300config BOOT_ERASE_PROGRESSIVELY
301 bool "Erase flash progressively when receiving new firmware"
Bernt Johan Damsloraa2fad122019-09-20 18:25:34 +0200302 default y if SOC_FAMILY_NRF
Emanuele Di Santo205c8c62018-07-20 11:42:31 +0200303 help
304 If enabled, flash is erased as necessary when receiving new firmware,
305 instead of erasing the whole image slot at once. This is necessary
306 on some hardware that has long erase times, to prevent long wait
307 times at the beginning of the DFU process.
308
David Vincze1cf11b52020-03-24 07:51:09 +0100309config MEASURED_BOOT
310 bool "Store the boot state/measurements in shared memory"
311 default n
312 help
313 If enabled, the bootloader will store certain boot measurements such as
314 the hash of the firmware image in a shared memory area. This data can
315 be used later by runtime services (e.g. by a device attestation service).
316
317config BOOT_SHARE_DATA
318 bool "Save application specific data in shared memory area"
319 default n
320
Tamas Banfce87332020-07-10 12:40:11 +0100321choice
322 prompt "Fault injection hardening profile"
323 default BOOT_FIH_PROFILE_OFF
324
325config BOOT_FIH_PROFILE_OFF
326 bool "No hardening against hardware level fault injection"
327 help
328 No hardening in SW against hardware level fault injection: power or
329 clock glitching, etc.
330
331config BOOT_FIH_PROFILE_LOW
332 bool "Moderate level hardening against hardware level fault injection"
333 help
334 Moderate level hardening: Long global fail loop to avoid break out,
335 control flow integrity check to discover discrepancy in expected code
336 flow.
337
338config BOOT_FIH_PROFILE_MEDIUM
339 bool "Medium level hardening against hardware level fault injection"
340 help
341 Medium level hardening: Long global fail loop to avoid break out,
342 control flow integrity check to discover discrepancy in expected code
343 flow, double variables to discover register or memory corruption.
344
345config BOOT_FIH_PROFILE_HIGH
346 bool "Maximum level hardening against hardware level fault injection"
347 select MBEDTLS
348 help
349 Maximum level hardening: Long global fail loop to avoid break out,
350 control flow integrity check to discover discrepancy in expected code
351 flow, double variables to discover register or memory corruption, random
352 delays to make code execution less predictable. Random delays requires an
353 entropy source.
354
355endchoice
356
Rajavardhan Gundi51c9d702019-02-20 14:08:52 +0530357config BOOT_WAIT_FOR_USB_DFU
358 bool "Wait for a prescribed duration to see if USB DFU is invoked"
359 default n
360 select USB
361 select USB_DFU_CLASS
362 select IMG_MANAGER
363 help
364 If y, MCUboot waits for a prescribed duration of time to allow
365 for USB DFU to be invoked. Please note DFU always updates the
366 slot1 image.
367
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400368config ZEPHYR_TRY_MASS_ERASE
369 bool "Try to mass erase flash when flashing MCUboot image"
370 default y
371 help
372 If y, attempt to configure the Zephyr build system's "flash"
373 target to mass-erase the flash device before flashing the
374 MCUboot image. This ensures the scratch and other partitions
375 are in a consistent state.
376
377 This is not available for all targets.
378
David Brownf6d14c22019-12-10 15:36:36 -0700379config BOOT_USE_BENCH
380 bool "Enable benchmark code"
381 default n
382 help
383 If y, adds support for simple benchmarking that can record
384 time intervals between two calls. The time printed depends
385 on the particular Zephyr target, and is generally ticks of a
386 specific board-specific timer.
387
Michael Scott74ceae52019-02-01 14:01:09 -0800388module = MCUBOOT
Piotr Mienkowski15aa6ef2019-04-08 22:48:15 +0200389module-str = MCUBoot bootloader
Michael Scott74ceae52019-02-01 14:01:09 -0800390source "subsys/logging/Kconfig.template.log_config"
Michael Scott74ceae52019-02-01 14:01:09 -0800391
Andrzej Puzdrowskiaf148532020-02-25 12:51:26 +0100392config MCUBOOT_LOG_THREAD_STACK_SIZE
393 int "Stack size for the MCUBoot log processing thread"
394 depends on LOG && !LOG_IMMEDIATE
395 default 2048 if COVERAGE_GCOV
396 default 1024 if NO_OPTIMIZATIONS
397 default 1024 if XTENSA
398 default 4096 if (X86 && X86_64)
399 default 4096 if ARM64
400 default 768
401 help
402 Set the internal stack size for MCUBoot log processing thread.
403
Marti Bolivar0e091c92018-04-12 11:23:16 -0400404menuconfig MCUBOOT_SERIAL
405 bool "MCUboot serial recovery"
406 default n
407 select REBOOT
Emanuele Di Santo30a92652019-01-16 14:01:08 +0100408 select GPIO
Marti Bolivar0e091c92018-04-12 11:23:16 -0400409 select SERIAL
Emanuele Di Santo30a92652019-01-16 14:01:08 +0100410 select UART_INTERRUPT_DRIVEN
Marti Bolivar0e091c92018-04-12 11:23:16 -0400411 select BASE64
412 select TINYCBOR
413 help
414 If y, enables a serial-port based update mode. This allows
415 MCUboot itself to load update images into flash over a UART.
416 If unsure, leave at the default value.
417
418if MCUBOOT_SERIAL
419
Emanuele Di Santoc4bf7802018-07-20 11:39:57 +0200420choice
421 prompt "Serial device"
Andrzej Puzdrowskif4a9a9d2020-04-24 12:31:51 +0200422 default BOOT_SERIAL_UART if !BOARD_NRF52840DONGLE_NRF52840
423 default BOOT_SERIAL_CDC_ACM if BOARD_NRF52840DONGLE_NRF52840
Emanuele Di Santoc4bf7802018-07-20 11:39:57 +0200424
425config BOOT_SERIAL_UART
426 bool "UART"
427 # SERIAL and UART_INTERRUPT_DRIVEN already selected
428
429config BOOT_SERIAL_CDC_ACM
430 bool "CDC ACM"
431 select USB
432 select USB_DEVICE_STACK
433 select USB_CDC_ACM
434
435endchoice
436
Marti Bolivar0e091c92018-04-12 11:23:16 -0400437config BOOT_MAX_LINE_INPUT_LEN
438 int "Maximum command line length"
439 default 512
440 help
441 Maximum length of commands transported over the serial port.
442
443config BOOT_SERIAL_DETECT_PORT
444 string "GPIO device to trigger serial recovery mode"
445 default GPIO_0 if SOC_FAMILY_NRF
446 help
447 Zephyr GPIO device which contains the pin used to trigger
448 serial recovery mode.
449
450config BOOT_SERIAL_DETECT_PIN
451 int "Pin to trigger serial recovery mode"
Andrzej Puzdrowskif4a9a9d2020-04-24 12:31:51 +0200452 default 6 if BOARD_NRF9160DK_NRF9160
Andrzej Puzdrowskifefdea22020-03-27 09:41:14 +0100453 default 11 if BOARD_NRF52840DK_NRF52840
Andrzej Puzdrowskif4a9a9d2020-04-24 12:31:51 +0200454 default 13 if BOARD_NRF52DK_NRF52832
Ole Sæther83ec8422020-11-25 13:26:21 +0100455 default 23 if BOARD_NRF5340PDK_NRF5340_CPUAPP || BOARD_NRF5340PDK_NRF5340_CPUAPPNS || \
456 BOARD_NRF5340DK_NRF5340_CPUAPP || BOARD_NRF5340DK_NRF5340_CPUAPPNS
Marti Bolivar0e091c92018-04-12 11:23:16 -0400457 help
458 Pin on the serial detect port which triggers serial recovery mode.
459
460config BOOT_SERIAL_DETECT_PIN_VAL
461 int "Serial detect pin trigger value"
462 default 0
463 range 0 1
464 help
465 Logic value of the detect pin which triggers serial recovery
466 mode.
467
Andrzej Puzdrowskif0004802019-10-01 14:13:35 +0200468# Workaround for not being able to have commas in macro arguments
469DT_CHOSEN_Z_CONSOLE := zephyr,console
470
471config RECOVERY_UART_DEV_NAME
472 string "UART Device Name for Recovery UART"
473 default "$(dt_chosen_label,$(DT_CHOSEN_Z_CONSOLE))" if HAS_DTS
474 default "UART_0"
475 depends on BOOT_SERIAL_UART
476 help
477 This option specifies the name of UART device to be used for
478 serial recovery.
479
Marti Bolivar0e091c92018-04-12 11:23:16 -0400480endif # MCUBOOT_SERIAL
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200481
Rafał Kuźniad854bb62020-06-17 15:06:47 +0200482config BOOT_INTR_VEC_RELOC
483 bool "Relocate the interrupt vector to the application"
484 default n
485 depends on SW_VECTOR_RELAY || CPU_CORTEX_M_HAS_VTOR
486 help
487 Relocate the interrupt vector to the application before it is started.
488 Select this option if application requires vector relocation,
489 but it doesn't relocate vector in its reset handler.
490
Andrzej Puzdrowski16b6d152020-06-01 14:16:54 +0200491config UPDATEABLE_IMAGE_NUMBER
492 int "Number of updateable images"
493 default 1
Andrzej Puzdrowskifdff3e12020-09-15 08:23:25 +0200494 range 1 1 if SINGLE_APPLICATION_SLOT
Andrzej Puzdrowski16b6d152020-06-01 14:16:54 +0200495 help
496 Enables support of multi image update.
497
498choice
499 prompt "Downgrade prevention"
500 optional
501
502config MCUBOOT_DOWNGRADE_PREVENTION
503 bool "SW based downgrade prevention"
504 depends on BOOT_UPGRADE_ONLY
505 help
506 Prevent downgrades by enforcing incrementing version numbers.
507 When this option is set, any upgrade must have greater major version
508 or greater minor version with equal major version. This mechanism
509 only protects against some attacks against version downgrades (for
510 example, a JTAG could be used to write an older version).
511
512config MCUBOOT_HW_DOWNGRADE_PREVENTION
513 bool "HW based downgrade prevention"
514 help
515 Prevent undesirable/malicious software downgrades. When this option is
516 set, any upgrade must have greater or equal security counter value.
517 Because of the acceptance of equal values it allows for software
518 downgrade to some extent.
519
520endchoice
521
Andrzej Puzdrowskid21442a2020-10-12 16:47:28 +0200522config BOOT_WATCHDOG_FEED
523 bool "Feed the watchdog while doing swap"
524 default y if SOC_FAMILY_NRF
525 imply NRFX_WDT
526 imply NRFX_WDT0
527 imply NRFX_WDT1
528 help
529 Enables implementation of MCUBOOT_WATCHDOG_FEED() macro which is
530 used to feed watchdog while doing time consuming operations.
531
Andrzej Puzdrowski97543282018-04-12 15:16:56 +0200532endmenu
533
Carles Cufi84ede582018-01-29 15:12:00 +0100534config MCUBOOT_DEVICE_SETTINGS
535 # Hidden selector for device-specific settings
536 bool
537 default y
538 # CPU options
539 select MCUBOOT_DEVICE_CPU_CORTEX_M0 if CPU_CORTEX_M0
Carles Cufi67c792e2018-01-29 15:14:31 +0100540 # Enable flash page layout if available
541 select FLASH_PAGE_LAYOUT if FLASH_HAS_PAGE_LAYOUT
Andrzej Puzdrowskib788c712018-04-12 12:42:49 +0200542 # Enable flash_map module as flash I/O back-end
543 select FLASH_MAP
Carles Cufi84ede582018-01-29 15:12:00 +0100544
545config MCUBOOT_DEVICE_CPU_CORTEX_M0
546 # Hidden selector for Cortex-M0 settings
547 bool
548 default n
549 select SW_VECTOR_RELAY if !CPU_CORTEX_M0_HAS_VECTOR_TABLE_REMAP
550
Marti Bolivar0e091c92018-04-12 11:23:16 -0400551comment "Zephyr configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200552
Marti Bolivarf84cc4b2019-08-20 16:06:56 -0700553# Disabling MULTITHREADING provides a code size advantage, but
554# it requires peripheral drivers (particularly a flash driver)
555# that works properly with the option enabled.
556#
557# If you know for sure that your hardware will work, you can default
558# it to n here. Otherwise, having it on by default makes the most
559# hardware work.
560config MULTITHREADING
Andrzej Puzdrowski9a4946c2020-02-20 12:39:12 +0100561 default y if BOOT_SERIAL_CDC_ACM #usb driver requires MULTITHREADING
Marti Bolivarf84cc4b2019-08-20 16:06:56 -0700562 default n if SOC_FAMILY_NRF
563 default y
564
Andrzej Puzdrowski9a4946c2020-02-20 12:39:12 +0100565config LOG_IMMEDIATE
566 default n if MULTITHREADING
Andrzej Puzdrowski3f092bd2020-02-17 13:25:32 +0100567 default y
568
569config LOG_PROCESS_THREAD
570 default n # mcuboot has its own log processing thread
571
572# override USB device name
573config USB_DEVICE_PRODUCT
574 default "MCUBOOT"
Andrzej Puzdrowski9a4946c2020-02-20 12:39:12 +0100575
Robert Lubos1b19d2a2020-01-31 14:05:35 +0100576source "Kconfig.zephyr"