blob: 4f1b172ddf3ba9f405790b83f9df83e28187d7d4 [file] [log] [blame]
David Vincze03368b82020-04-01 12:53:53 +02001# Copyright (c) 2017-2020 Linaro Limited
David Vinczec3084132020-02-18 14:50:47 +01002# Copyright (c) 2020 Arm Limited
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02003#
4# SPDX-License-Identifier: Apache-2.0
5#
6
Marti Bolivar0e091c92018-04-12 11:23:16 -04007mainmenu "MCUboot configuration"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +02008
Marti Bolivar0e091c92018-04-12 11:23:16 -04009comment "MCUboot-specific configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +020010
Emanuele Di Santo865777d2018-11-08 11:28:15 +010011# Hidden option to mark a project as MCUboot
12config MCUBOOT
13 default y
14 bool
Rajavardhan Gundi07ba28f2018-12-10 15:44:48 +053015 select MPU_ALLOW_FLASH_WRITE if ARM_MPU
Marcin Niestrojc6be76a2020-03-22 14:39:35 +010016 select USE_DT_CODE_PARTITION if HAS_FLASH_LOAD_OFFSET
Emanuele Di Santo865777d2018-11-08 11:28:15 +010017
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040018config BOOT_USE_MBEDTLS
19 bool
20 # Hidden option
21 default n
22 help
23 Use mbedTLS for crypto primitives.
24
25config BOOT_USE_TINYCRYPT
26 bool
27 # Hidden option
28 default n
Sebastian Bøe913a3852019-01-22 13:53:12 +010029 # When building for ECDSA, we use our own copy of mbedTLS, so the
30 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
31 # will collide.
32 depends on ! MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040033 help
34 Use TinyCrypt for crypto primitives.
35
Sigvart Hovlandebd05032019-03-21 10:47:32 +010036config BOOT_USE_CC310
37 bool
38 # Hidden option
39 default n
40 # When building for ECDSA, we use our own copy of mbedTLS, so the
41 # Zephyr one must not be enabled or the MBEDTLS_CONFIG_FILE macros
42 # will collide.
43 depends on ! MBEDTLS
44 help
45 Use cc310 for crypto primitives.
46
47config BOOT_USE_NRF_CC310_BL
48 bool
49 default n
50
51config NRFXLIB_CRYPTO
52 bool
53 default n
54
55config NRF_CC310_BL
56 bool
57 default n
58
Andrzej Puzdrowski97543282018-04-12 15:16:56 +020059menu "MCUBoot settings"
60
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040061choice
62 prompt "Signature type"
63 default BOOT_SIGNATURE_TYPE_RSA
64
65config BOOT_SIGNATURE_TYPE_RSA
66 bool "RSA signatures"
67 select BOOT_USE_MBEDTLS
Marti Bolivara4818a52018-04-12 13:02:38 -040068 select MBEDTLS
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040069
Fabio Utzig105b59a2019-05-13 15:08:12 -070070if BOOT_SIGNATURE_TYPE_RSA
71config BOOT_SIGNATURE_TYPE_RSA_LEN
72 int "RSA signature length"
73 range 2048 3072
74 default 2048
75endif
76
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040077config BOOT_SIGNATURE_TYPE_ECDSA_P256
78 bool "Elliptic curve digital signatures with curve P-256"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -040079
Sigvart Hovlandebd05032019-03-21 10:47:32 +010080if BOOT_SIGNATURE_TYPE_ECDSA_P256
81choice
82 prompt "Ecdsa implementation"
Fabio Utzig34e93a52020-02-03 09:59:53 -030083 default BOOT_ECDSA_TINYCRYPT
84config BOOT_ECDSA_TINYCRYPT
Sigvart Hovlandebd05032019-03-21 10:47:32 +010085 bool "Use tinycrypt"
86 select BOOT_USE_TINYCRYPT
87config BOOT_CC310
88 bool "Use CC310"
89 select BOOT_USE_NRF_CC310_BL if HAS_HW_NRF_CC310
90 select NRF_CC310_BL if HAS_HW_NRF_CC310
91 select NRFXLIB_CRYPTO if SOC_FAMILY_NRF
92 select BOOT_USE_CC310
93endchoice
94endif
Fabio Utzig34e93a52020-02-03 09:59:53 -030095
96config BOOT_SIGNATURE_TYPE_ED25519
97 bool "Edwards curve digital signatures using ed25519"
98
99if BOOT_SIGNATURE_TYPE_ED25519
100choice
101 prompt "Ecdsa implementation"
102 default BOOT_ED25519_TINYCRYPT
103config BOOT_ED25519_TINYCRYPT
104 bool "Use tinycrypt"
105 select BOOT_USE_TINYCRYPT
106config BOOT_ED25519_MBEDTLS
107 bool "Use mbedTLS"
108 select BOOT_USE_MBEDTLS
109 select MBEDTLS
110endchoice
111endif
112
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400113endchoice
114
Fabio Utzigc690c762018-04-26 10:51:09 -0300115config BOOT_SIGNATURE_KEY_FILE
116 string "PEM key file"
117 default ""
118 help
119 The key file will be parsed by imgtool's getpub command and a .c source
120 with the public key information will be written in a format expected by
121 MCUboot.
122
Andrzej Puzdrowski9a605b62020-03-16 13:34:30 +0100123config MCUBOOT_CLEANUP_ARM_CORE
124 bool "Perform core cleanup before chain-load the application"
125 depends on CPU_CORTEX_M
126 default y
127
Marti Bolivara4818a52018-04-12 13:02:38 -0400128config MBEDTLS_CFG_FILE
129 default "mcuboot-mbedtls-cfg.h"
130
David Vincze03368b82020-04-01 12:53:53 +0200131config BOOT_HW_KEY
132 bool "Use HW key for image verification"
133 default n
134 help
135 Use HW key for image verification, otherwise the public key is embedded
136 in MCUBoot. If enabled the public key is appended to the signed image
137 and requires the hash of the public key to be provisioned to the device
138 beforehand.
139
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400140config BOOT_VALIDATE_SLOT0
David Vincze2d736ad2019-02-18 11:50:22 +0100141 bool "Validate image in the primary slot on every boot"
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400142 default y
143 help
David Vincze2d736ad2019-02-18 11:50:22 +0100144 If y, the bootloader attempts to validate the signature of the
145 primary slot every boot. This adds the signature check time to
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400146 every boot, but can mitigate against some changes that are
147 able to modify the flash image itself.
148
149config BOOT_UPGRADE_ONLY
150 bool "Overwrite image updates instead of swapping"
151 default n
152 help
David Vincze2d736ad2019-02-18 11:50:22 +0100153 If y, overwrite the primary slot with the upgrade image instead
154 of swapping them. This prevents the fallback recovery, but
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400155 uses a much simpler code path.
156
Fabio Utzigc58842e2019-11-28 10:30:01 -0300157config BOOT_SWAP_USING_MOVE
Fabio Utzigdd2b6802020-01-06 09:10:45 -0300158 bool "Swap mode that can run without a scratch partition"
Håkon Øye Amundsen09be7832020-01-24 14:34:49 +0000159 default y if SOC_FAMILY_NRF
Fabio Utzigc58842e2019-11-28 10:30:01 -0300160 default n
161 help
162 If y, the swap upgrade is done in two steps, where first every
163 sector of the primary slot is moved up one sector, then for
164 each sector X in the secondary slot, it is moved to index X in
165 the primary slot, then the sector at X+1 in the primary is
166 moved to index X in the secondary.
167 This allows a swap upgrade without using a scratch partition,
168 but is currently limited to all sectors in both slots being of
169 the same size.
170
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200171config BOOT_BOOTSTRAP
Sam Bristowd0ca0ff2019-10-30 20:51:35 +1300172 bool "Bootstrap erased the primary slot from the secondary slot"
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200173 default n
174 help
175 If y, enables bootstraping support. Bootstrapping allows an erased
David Vincze2d736ad2019-02-18 11:50:22 +0100176 primary slot to be initialized from a valid image in the secondary slot.
Fabio Utzigd0533ed2018-12-19 07:56:33 -0200177 If unsure, leave at the default value.
178
Fabio Utzigca8ead22019-12-20 07:06:04 -0300179config BOOT_SWAP_SAVE_ENCTLV
180 bool "Save encrypted key TLVs instead of plaintext keys in swap metadata"
181 default n
182 help
183 If y, instead of saving the encrypted image keys in plaintext in the
184 swap resume metadata, save the encrypted image TLVs. This should be used
185 when there is no security mechanism protecting the data in the primary
186 slot from being dumped. If n is selected (default), the keys are written
187 after being decrypted from the image TLVs and could be read by an
188 attacker who has access to the flash contents of the primary slot (eg
189 JTAG/SWD or primary slot in external flash).
190 If unsure, leave at the default value.
191
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300192config BOOT_ENCRYPT_RSA
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300193 bool "Support for encrypted upgrade images using RSA"
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300194 default n
195 help
David Vincze2d736ad2019-02-18 11:50:22 +0100196 If y, images in the secondary slot can be encrypted and are decrypted
197 on the fly when upgrading to the primary slot, as well as encrypted
Fabio Utzig42cc29a2019-11-05 07:54:41 -0300198 back when swapping from the primary slot to the secondary slot. The
199 encryption mechanism used in this case is RSA-OAEP (2048 bits).
200
201config BOOT_ENCRYPT_EC256
202 bool "Support for encrypted upgrade images using ECIES-P256"
203 default n
204 help
205 If y, images in the secondary slot can be encrypted and are decrypted
206 on the fly when upgrading to the primary slot, as well as encrypted
207 back when swapping from the primary slot to the secondary slot. The
208 encryption mechanism used in this case is ECIES using primitives
209 described under "ECIES-P256 encryption" in docs/encrypted_images.md.
Fabio Utzig5fe874c2018-08-31 07:41:50 -0300210
Fabio Utzigb6f014c2020-04-02 13:25:01 -0300211config BOOT_ENCRYPT_X25519
212 bool "Support for encrypted upgrade images using ECIES-X25519"
213 default n
214 help
215 If y, images in the secondary slot can be encrypted and are decrypted
216 on the fly when upgrading to the primary slot, as well as encrypted
217 back when swapping from the primary slot to the secondary slot. The
218 encryption mechanism used in this case is ECIES using primitives
219 described under "ECIES-X25519 encryption" in docs/encrypted_images.md.
220
Marti Bolivar0e091c92018-04-12 11:23:16 -0400221config BOOT_MAX_IMG_SECTORS
222 int "Maximum number of sectors per image slot"
223 default 128
224 help
225 This option controls the maximum number of sectors that each of
226 the two image areas can contain. Smaller values reduce MCUboot's
227 memory usage; larger values allow it to support larger images.
228 If unsure, leave at the default value.
229
Emanuele Di Santo205c8c62018-07-20 11:42:31 +0200230config BOOT_ERASE_PROGRESSIVELY
231 bool "Erase flash progressively when receiving new firmware"
232 default y if SOC_NRF52840
233 help
234 If enabled, flash is erased as necessary when receiving new firmware,
235 instead of erasing the whole image slot at once. This is necessary
236 on some hardware that has long erase times, to prevent long wait
237 times at the beginning of the DFU process.
238
David Vincze1cf11b52020-03-24 07:51:09 +0100239config MEASURED_BOOT
240 bool "Store the boot state/measurements in shared memory"
241 default n
242 help
243 If enabled, the bootloader will store certain boot measurements such as
244 the hash of the firmware image in a shared memory area. This data can
245 be used later by runtime services (e.g. by a device attestation service).
246
247config BOOT_SHARE_DATA
248 bool "Save application specific data in shared memory area"
249 default n
250
Rajavardhan Gundi51c9d702019-02-20 14:08:52 +0530251config BOOT_WAIT_FOR_USB_DFU
252 bool "Wait for a prescribed duration to see if USB DFU is invoked"
253 default n
254 select USB
255 select USB_DFU_CLASS
256 select IMG_MANAGER
257 help
258 If y, MCUboot waits for a prescribed duration of time to allow
259 for USB DFU to be invoked. Please note DFU always updates the
260 slot1 image.
261
Marti Bolivarbc2fa4e2018-04-12 12:18:32 -0400262config ZEPHYR_TRY_MASS_ERASE
263 bool "Try to mass erase flash when flashing MCUboot image"
264 default y
265 help
266 If y, attempt to configure the Zephyr build system's "flash"
267 target to mass-erase the flash device before flashing the
268 MCUboot image. This ensures the scratch and other partitions
269 are in a consistent state.
270
271 This is not available for all targets.
272
David Brownf6d14c22019-12-10 15:36:36 -0700273config BOOT_USE_BENCH
274 bool "Enable benchmark code"
275 default n
276 help
277 If y, adds support for simple benchmarking that can record
278 time intervals between two calls. The time printed depends
279 on the particular Zephyr target, and is generally ticks of a
280 specific board-specific timer.
281
Michael Scott74ceae52019-02-01 14:01:09 -0800282module = MCUBOOT
Piotr Mienkowski15aa6ef2019-04-08 22:48:15 +0200283module-str = MCUBoot bootloader
Michael Scott74ceae52019-02-01 14:01:09 -0800284source "subsys/logging/Kconfig.template.log_config"
Michael Scott74ceae52019-02-01 14:01:09 -0800285
Andrzej Puzdrowskiaf148532020-02-25 12:51:26 +0100286config MCUBOOT_LOG_THREAD_STACK_SIZE
287 int "Stack size for the MCUBoot log processing thread"
288 depends on LOG && !LOG_IMMEDIATE
289 default 2048 if COVERAGE_GCOV
290 default 1024 if NO_OPTIMIZATIONS
291 default 1024 if XTENSA
292 default 4096 if (X86 && X86_64)
293 default 4096 if ARM64
294 default 768
295 help
296 Set the internal stack size for MCUBoot log processing thread.
297
Marti Bolivar0e091c92018-04-12 11:23:16 -0400298menuconfig MCUBOOT_SERIAL
299 bool "MCUboot serial recovery"
300 default n
301 select REBOOT
Emanuele Di Santo30a92652019-01-16 14:01:08 +0100302 select GPIO
Marti Bolivar0e091c92018-04-12 11:23:16 -0400303 select SERIAL
Emanuele Di Santo30a92652019-01-16 14:01:08 +0100304 select UART_INTERRUPT_DRIVEN
Marti Bolivar0e091c92018-04-12 11:23:16 -0400305 select BASE64
306 select TINYCBOR
307 help
308 If y, enables a serial-port based update mode. This allows
309 MCUboot itself to load update images into flash over a UART.
310 If unsure, leave at the default value.
311
312if MCUBOOT_SERIAL
313
Emanuele Di Santoc4bf7802018-07-20 11:39:57 +0200314choice
315 prompt "Serial device"
316 default BOOT_SERIAL_UART if !BOARD_NRF52840_PCA10059
317 default BOOT_SERIAL_CDC_ACM if BOARD_NRF52840_PCA10059
318
319config BOOT_SERIAL_UART
320 bool "UART"
321 # SERIAL and UART_INTERRUPT_DRIVEN already selected
322
323config BOOT_SERIAL_CDC_ACM
324 bool "CDC ACM"
325 select USB
326 select USB_DEVICE_STACK
327 select USB_CDC_ACM
328
329endchoice
330
Marti Bolivar0e091c92018-04-12 11:23:16 -0400331config BOOT_MAX_LINE_INPUT_LEN
332 int "Maximum command line length"
333 default 512
334 help
335 Maximum length of commands transported over the serial port.
336
337config BOOT_SERIAL_DETECT_PORT
338 string "GPIO device to trigger serial recovery mode"
339 default GPIO_0 if SOC_FAMILY_NRF
340 help
341 Zephyr GPIO device which contains the pin used to trigger
342 serial recovery mode.
343
344config BOOT_SERIAL_DETECT_PIN
345 int "Pin to trigger serial recovery mode"
Andreas Vibeto704b8ba2019-04-25 10:51:23 +0200346 default 6 if BOARD_NRF9160_PCA10090
Andrzej Puzdrowskifefdea22020-03-27 09:41:14 +0100347 default 11 if BOARD_NRF52840DK_NRF52840
Marti Bolivar0e091c92018-04-12 11:23:16 -0400348 default 13 if BOARD_NRF52_PCA10040
Håkon Øye Amundsen6fc25952020-01-02 15:15:42 +0000349 default 23 if BOARD_NRF5340_DK_NRF5340_CPUAPP || BOARD_NRF5340_DK_NRF5340_CPUAPPNS
Marti Bolivar0e091c92018-04-12 11:23:16 -0400350 help
351 Pin on the serial detect port which triggers serial recovery mode.
352
353config BOOT_SERIAL_DETECT_PIN_VAL
354 int "Serial detect pin trigger value"
355 default 0
356 range 0 1
357 help
358 Logic value of the detect pin which triggers serial recovery
359 mode.
360
Andrzej Puzdrowskif0004802019-10-01 14:13:35 +0200361# Workaround for not being able to have commas in macro arguments
362DT_CHOSEN_Z_CONSOLE := zephyr,console
363
364config RECOVERY_UART_DEV_NAME
365 string "UART Device Name for Recovery UART"
366 default "$(dt_chosen_label,$(DT_CHOSEN_Z_CONSOLE))" if HAS_DTS
367 default "UART_0"
368 depends on BOOT_SERIAL_UART
369 help
370 This option specifies the name of UART device to be used for
371 serial recovery.
372
Marti Bolivar0e091c92018-04-12 11:23:16 -0400373endif # MCUBOOT_SERIAL
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200374
Andrzej Puzdrowski97543282018-04-12 15:16:56 +0200375endmenu
376
Carles Cufi84ede582018-01-29 15:12:00 +0100377config MCUBOOT_DEVICE_SETTINGS
378 # Hidden selector for device-specific settings
379 bool
380 default y
381 # CPU options
382 select MCUBOOT_DEVICE_CPU_CORTEX_M0 if CPU_CORTEX_M0
Carles Cufi67c792e2018-01-29 15:14:31 +0100383 # Enable flash page layout if available
384 select FLASH_PAGE_LAYOUT if FLASH_HAS_PAGE_LAYOUT
Andrzej Puzdrowskib788c712018-04-12 12:42:49 +0200385 # Enable flash_map module as flash I/O back-end
386 select FLASH_MAP
Carles Cufi84ede582018-01-29 15:12:00 +0100387
388config MCUBOOT_DEVICE_CPU_CORTEX_M0
389 # Hidden selector for Cortex-M0 settings
390 bool
391 default n
392 select SW_VECTOR_RELAY if !CPU_CORTEX_M0_HAS_VECTOR_TABLE_REMAP
393
Marti Bolivar0e091c92018-04-12 11:23:16 -0400394comment "Zephyr configuration options"
Andrzej Puzdrowski64ad0922017-09-22 11:33:41 +0200395
Marti Bolivarf84cc4b2019-08-20 16:06:56 -0700396# Disabling MULTITHREADING provides a code size advantage, but
397# it requires peripheral drivers (particularly a flash driver)
398# that works properly with the option enabled.
399#
400# If you know for sure that your hardware will work, you can default
401# it to n here. Otherwise, having it on by default makes the most
402# hardware work.
403config MULTITHREADING
Andrzej Puzdrowski9a4946c2020-02-20 12:39:12 +0100404 default y if BOOT_SERIAL_CDC_ACM #usb driver requires MULTITHREADING
Marti Bolivarf84cc4b2019-08-20 16:06:56 -0700405 default n if SOC_FAMILY_NRF
406 default y
407
Andrzej Puzdrowski9a4946c2020-02-20 12:39:12 +0100408config LOG_IMMEDIATE
409 default n if MULTITHREADING
Andrzej Puzdrowski3f092bd2020-02-17 13:25:32 +0100410 default y
411
412config LOG_PROCESS_THREAD
413 default n # mcuboot has its own log processing thread
414
415# override USB device name
416config USB_DEVICE_PRODUCT
417 default "MCUBOOT"
Andrzej Puzdrowski9a4946c2020-02-20 12:39:12 +0100418
Håkon Øye Amundsen954dd2b2019-09-23 09:24:13 +0000419config UPDATEABLE_IMAGE_NUMBER
420 int "Number of updateable images"
421 default 1
422 help
423 Enables support of multi image update.
424
David Vinczec3084132020-02-18 14:50:47 +0100425choice
426 prompt "Downgrade prevention"
427 optional
428
Håkon Øye Amundsen2d1bac12020-01-03 13:08:09 +0000429config MCUBOOT_DOWNGRADE_PREVENTION
David Vinczec3084132020-02-18 14:50:47 +0100430 bool "SW based downgrade prevention"
Håkon Øye Amundsen2d1bac12020-01-03 13:08:09 +0000431 depends on BOOT_UPGRADE_ONLY
432 help
433 Prevent downgrades by enforcing incrementing version numbers.
434 When this option is set, any upgrade must have greater major version
435 or greater minor version with equal major version. This mechanism
436 only protects against some attacks against version downgrades (for
437 example, a JTAG could be used to write an older version).
438
David Vinczec3084132020-02-18 14:50:47 +0100439config MCUBOOT_HW_DOWNGRADE_PREVENTION
440 bool "HW based downgrade prevention"
441 help
442 Prevent undesirable/malicious software downgrades. When this option is
443 set, any upgrade must have greater or equal security counter value.
444 Because of the acceptance of equal values it allows for software
445 downgrade to some extent.
446
447endchoice
448
Robert Lubos1b19d2a2020-01-31 14:05:35 +0100449source "Kconfig.zephyr"