ADAC: Authenticated Debug Access Control

The commit adds the impelementation of ADAC protocol towards the
target side.

Following components are part of the commit:-
    Core   : ADAC protocol core
    SDA    : Secure Debug Agent

The commit also demonstrates the porting of a platform from
trusted-firmware-m. Corstone1000 platform is used for the purpose.

Change-Id: I50b93f9e48789cf5927736b4d1cb35b9a47c38db
Signed-off-by: Satish Kumar <satish.kumar01@arm.com>
diff --git a/cmake/psa_adac.cmake b/cmake/psa_adac.cmake
new file mode 100644
index 0000000..54c5c5d
--- /dev/null
+++ b/cmake/psa_adac.cmake
@@ -0,0 +1,55 @@
+#-------------------------------------------------------------------------------
+# Copyright (c) 2020-2021, Arm Limited. All rights reserved.
+#
+# SPDX-License-Identifier: BSD-3-Clause
+#
+#-------------------------------------------------------------------------------
+
+
+list(APPEND CMAKE_MODULE_PATH ${PSA_ADAC_ROOT}/cmake)
+
+set(PSA_ADAC_TOOLCHAIN    TRUE    CACHE BOOL "Whether to use psa-adac toolchain.")
+
+set(PSA_ADAC_EC_P256 On CACHE BOOL "Enable support for ECDSA P-256")
+set(PSA_ADAC_EC_P521 On CACHE BOOL "Enable support for ECDSA P-521")
+set(PSA_ADAC_RSA3072 On CACHE BOOL "Enable support for RSA 3072")
+set(PSA_ADAC_RSA4096 On CACHE BOOL "Enable support for RSA 4096")
+set(PSA_ADAC_ED25519 Off CACHE BOOL "Enable support for EdDSA Ed25519")
+set(PSA_ADAC_ED448 Off CACHE BOOL "Enable support for EdDSA Ed448")
+set(PSA_ADAC_SM2SM3 Off CACHE BOOL "Enable support for SM2/SM3")
+set(PSA_ADAC_CMAC On CACHE BOOL "Enable support for CMAC AES-128")
+set(PSA_ADAC_HMAC On CACHE BOOL "Enable support for HMAC SHA-256")
+set(PSA_ADAC_HW_CRYPTO Off CACHE BOOL "Support for hardware cryptography")
+set(PSA_ADAC_DEBUG Off CACHE BOOL "Enable debug")
+set(PSA_ADAC_QUIET Off CACHE BOOL "Disable console output")
+set(PSA_ADAC_QEMU Off CACHE BOOL "The image will be built to run on QEMU")
+set(PSA_ADAC_MINIMUM_SIZE_CONFIG Off CACHE BOOL "Size-optimized build (reduced features)")
+
+if (CMAKE_BUILD_TYPE STREQUAL "Debug")
+    set(PSA_ADAC_DEBUG On)
+    set(PSA_ADAC_TRACE Off)
+elseif (CMAKE_BUILD_TYPE STREQUAL "MinSizeRel")
+    set(PSA_ADAC_QUIET On)
+    set(PSA_ADAC_DEBUG Off)
+endif ()
+
+if (ROM_POC) # TODO: this is just for transition, remove soon
+    set(PSA_ADAC_MINIMUM_SIZE_CONFIG On)
+endif ()
+
+if (PSA_ADAC_MINIMUM_SIZE_CONFIG AND NOT (PLATFORM_NAME STREQUAL "native"))
+    # set(PSA_ADAC_EC_P256 On)
+    set(PSA_ADAC_EC_P521 Off)
+    set(PSA_ADAC_RSA3072 Off)
+    set(PSA_ADAC_RSA4096 Off)
+    set(PSA_ADAC_ED25519 Off)
+    set(PSA_ADAC_ED448 Off)
+    set(PSA_ADAC_SM2SM3 Off)
+    set(PSA_ADAC_CMAC Off)
+    set(PSA_ADAC_HMAC Off)
+endif ()
+
+find_program(CCACHE_PROGRAM ccache)
+if (CCACHE_PROGRAM)
+    set_property(GLOBAL PROPERTY RULE_LAUNCH_COMPILE "${CCACHE_PROGRAM}")
+endif ()
diff --git a/cmake/set_extensions.cmake b/cmake/set_extensions.cmake
new file mode 100644
index 0000000..2753337
--- /dev/null
+++ b/cmake/set_extensions.cmake
@@ -0,0 +1,12 @@
+#-------------------------------------------------------------------------------
+# Copyright (c) 2020, Arm Limited. All rights reserved.
+#
+# SPDX-License-Identifier: BSD-3-Clause
+#
+#-------------------------------------------------------------------------------
+
+set(CMAKE_C_OUTPUT_EXTENSION ".o")
+set(CMAKE_C_OUTPUT_EXTENSION_REPLACE 1)
+
+set(CMAKE_ASM_OUTPUT_EXTENSION ".o")
+set(CMAKE_ASM_OUTPUT_EXTENSION_REPLACE 1)
diff --git a/cmake/toolchain.cmake b/cmake/toolchain.cmake
new file mode 100644
index 0000000..3f01947
--- /dev/null
+++ b/cmake/toolchain.cmake
@@ -0,0 +1,52 @@
+#-------------------------------------------------------------------------------
+# Copyright (c) 2020-2021, Arm Limited. All rights reserved.
+#
+# SPDX-License-Identifier: BSD-3-Clause
+#
+#-------------------------------------------------------------------------------
+
+set(CMAKE_C_COMPILER_FORCED true)
+set(CROSS_COMPILE arm-none-eabi CACHE STRING "Cross-compilation triplet")
+
+if (NOT (COMPILER))
+    set(COMPILER "GNUARM")
+endif ()
+
+if (COMPILER STREQUAL "GNUARM")
+
+    include(${PSA_ADAC_ROOT}/cmake/toolchain_GNUARM.cmake)
+
+    if (CMAKE_BUILD_TYPE STREQUAL "MinSizeRel")
+        add_compile_options(-flto -Os)
+        add_link_options(-Wl,--as-needed -flto -flto-partition=none -Os -ffunction-sections -fuse-linker-plugin)
+        add_compile_options($<$<COMPILE_LANGUAGE:C>:-DNDEBUG>)
+    endif ()
+
+elseif(COMPILER STREQUAL "ARMCLANG")
+
+    include(${PSA_ADAC_ROOT}/cmake/toolchain_ARMCLANG.cmake)
+
+    if (CMAKE_BUILD_TYPE STREQUAL "MinSizeRel")
+        add_compile_options($<$<COMPILE_LANGUAGE:C>:-Oz>)
+        # # Can't enable LTO for all targets because static libraries (like mbedcrypto)
+        # # are not supported.
+        # add_compile_options(-flto)
+        # add_link_options(--lto)
+        add_compile_options($<$<COMPILE_LANGUAGE:C>:-DNDEBUG>)
+    endif ()
+
+elseif(COMPILER STREQUAL "IARARM")
+
+    include(${PSA_ADAC_ROOT}/cmake/toolchain_IARARM.cmake)
+
+    if (CMAKE_BUILD_TYPE STREQUAL "MinSizeRel")
+        add_compile_options(--mfc)
+        add_link_options(--vfe)
+        add_compile_options($<$<COMPILE_LANGUAGE:C>:-DNDEBUG>)
+    endif()
+
+else()
+
+    message(FATAL_ERROR "\nValid values for COMPILER are 'GNUARM' (default), 'ARMCLANG' and 'IARARM'\n")
+
+endif()
diff --git a/cmake/toolchain_ARMCLANG.cmake b/cmake/toolchain_ARMCLANG.cmake
new file mode 100644
index 0000000..8fef6fa
--- /dev/null
+++ b/cmake/toolchain_ARMCLANG.cmake
@@ -0,0 +1,218 @@
+#-------------------------------------------------------------------------------
+# Copyright (c) 2020, Arm Limited. All rights reserved.
+#
+# SPDX-License-Identifier: BSD-3-Clause
+#
+#-------------------------------------------------------------------------------
+cmake_minimum_required(VERSION 3.15)
+
+SET(CMAKE_SYSTEM_NAME Generic)
+
+set(CMAKE_C_COMPILER armclang)
+set(CMAKE_ASM_COMPILER armasm)
+
+set(LINKER_VENEER_OUTPUT_FLAG --import_cmse_lib_out=)
+set(COMPILER_CMSE_FLAG $<$<COMPILE_LANGUAGE:C>:-mcmse>)
+
+# This variable name is a bit of a misnomer. The file it is set to is included
+# at a particular step in the compiler initialisation. It is used here to
+# configure the extensions for object files. Despite the name, it also works
+# with the Ninja generator.
+set(CMAKE_USER_MAKE_RULES_OVERRIDE ${CMAKE_CURRENT_LIST_DIR}/set_extensions.cmake)
+
+macro(arm_toolchain_reset_compiler_flags)
+    set_property(DIRECTORY PROPERTY COMPILE_OPTIONS "")
+    string(REGEX REPLACE "\\+nodsp" ".no_dsp" CMAKE_ASM_CPU_FLAG "${CMAKE_SYSTEM_PROCESSOR}")
+
+    add_compile_options(
+        $<$<COMPILE_LANGUAGE:C>:-Wno-ignored-optimization-argument>
+        $<$<COMPILE_LANGUAGE:C>:-Wno-unused-command-line-argument>
+        $<$<COMPILE_LANGUAGE:C>:-Wall>
+        # Don't error when the MBEDTLS_NULL_ENTROPY warning is shown
+        $<$<COMPILE_LANGUAGE:C>:-Wno-error=cpp>
+        $<$<COMPILE_LANGUAGE:C>:-c>
+        $<$<COMPILE_LANGUAGE:C>:-fdata-sections>
+        $<$<COMPILE_LANGUAGE:C>:-ffunction-sections>
+        $<$<COMPILE_LANGUAGE:C>:-fno-builtin>
+        $<$<COMPILE_LANGUAGE:C>:-fshort-enums>
+        $<$<COMPILE_LANGUAGE:C>:-fshort-wchar>
+        $<$<COMPILE_LANGUAGE:C>:-funsigned-char>
+        $<$<COMPILE_LANGUAGE:C>:-masm=auto>
+        $<$<COMPILE_LANGUAGE:C>:-nostdlib>
+        $<$<COMPILE_LANGUAGE:C>:-std=c99>
+        $<$<AND:$<COMPILE_LANGUAGE:C>,$<NOT:$<BOOL:${ARM_SYSTEM_FP}>>>:-mfpu=none>
+        $<$<AND:$<COMPILE_LANGUAGE:ASM>,$<NOT:$<BOOL:${ARM_SYSTEM_FP}>>>:--fpu=none>
+        $<$<COMPILE_LANGUAGE:ASM>:--cpu=${CMAKE_ASM_CPU_FLAG}>
+    )
+endmacro()
+
+macro(arm_toolchain_reset_linker_flags)
+    set_property(DIRECTORY PROPERTY LINK_OPTIONS "")
+
+    add_link_options(
+        --info=summarysizes,sizes,totals,unused,veneers
+        --strict
+        --symbols
+        --xref
+        # Suppress link warnings that are consistant (and therefore hopefully
+        # harmless)
+        # https://developer.arm.com/documentation/100074/0608/linker-errors-and-warnings/list-of-the-armlink-error-and-warning-messages
+        # Empty region description
+        --diag_suppress=6312
+        # Ns section matches pattern
+        --diag_suppress=6314
+        # Duplicate input files
+        --diag_suppress=6304
+        $<$<NOT:$<BOOL:${ARM_SYSTEM_FP}>>:--fpu=softvfp>
+    )
+endmacro()
+
+macro(arm_toolchain_set_processor_arch)
+    set(CMAKE_SYSTEM_PROCESSOR       ${ARM_SYSTEM_PROCESSOR})
+    set(CMAKE_SYSTEM_ARCHITECTURE    ${ARM_SYSTEM_ARCHITECTURE})
+
+    set(CMAKE_C_COMPILER_TARGET      arm-${CROSS_COMPILE})
+    set(CMAKE_ASM_COMPILER_TARGET    arm-${CROSS_COMPILE})
+
+    if (DEFINED ARM_SYSTEM_DSP)
+        if(NOT ARM_SYSTEM_DSP)
+            string(APPEND CMAKE_SYSTEM_PROCESSOR "+nodsp")
+        endif()
+
+    # Cmake's ARMClang support has several issues with compiler validation. To
+    # avoid these, we set the list of supported -mcpu and -march variables to
+    # the ones we intend to use so that the validation will never fail.
+    include(Compiler/ARMClang)
+    set(CMAKE_C_COMPILER_PROCESSOR_LIST ${CMAKE_SYSTEM_PROCESSOR})
+    set(CMAKE_C_COMPILER_ARCH_LIST ${CMAKE_SYSTEM_PROCESSOR})
+    set(CMAKE_ASM_COMPILER_PROCESSOR_LIST ${CMAKE_SYSTEM_PROCESSOR})
+    set(CMAKE_ASM_COMPILER_ARCH_LIST ${CMAKE_SYSTEM_PROCESSOR})
+    endif()
+endmacro()
+
+macro(arm_toolchain_reload_compiler)
+    arm_toolchain_set_processor_arch()
+    arm_toolchain_reset_compiler_flags()
+    arm_toolchain_reset_linker_flags()
+
+    unset(CMAKE_C_FLAGS_INIT)
+    unset(CMAKE_C_LINK_FLAGS)
+    unset(CMAKE_ASM_FLAGS_INIT)
+    unset(CMAKE_ASM_LINK_FLAGS)
+    unset(__mcpu_flag_set)
+    unset(__march_flag_set)
+
+    include(Compiler/ARMClang)
+    __compiler_armclang(C)
+    include(Compiler/ARMCC)
+    __compiler_armcc(ASM)
+
+    # Cmake's armclang support will set either mcpu or march, but march gives
+    # better code size so we manually set it.
+    set(CMAKE_C_FLAGS   "-march=${CMAKE_SYSTEM_ARCHITECTURE}")
+    set(CMAKE_ASM_FLAGS ${CMAKE_ASM_FLAGS_INIT})
+
+    set(CMAKE_C_LINK_FLAGS   "--cpu=${CMAKE_SYSTEM_PROCESSOR}")
+    set(CMAKE_ASM_LINK_FLAGS "--cpu=${CMAKE_SYSTEM_PROCESSOR}")
+    # But armlink doesn't support this +dsp syntax
+    string(REGEX REPLACE "\\+nodsp" "" CMAKE_C_LINK_FLAGS   "${CMAKE_C_LINK_FLAGS}")
+    string(REGEX REPLACE "\\+nodsp" "" CMAKE_ASM_LINK_FLAGS "${CMAKE_ASM_LINK_FLAGS}")
+    # And uses different syntax for +nofp
+    string(REGEX REPLACE "\\+nofp" ".no_fp" CMAKE_C_LINK_FLAGS   "${CMAKE_C_LINK_FLAGS}")
+    string(REGEX REPLACE "\\+nofp" ".no_fp" CMAKE_ASM_LINK_FLAGS "${CMAKE_ASM_LINK_FLAGS}")
+
+    # Workaround for issues with --depend-single-line with armasm and Ninja
+    if (CMAKE_GENERATOR STREQUAL "Ninja")
+        set( CMAKE_DEPFILE_FLAGS_ASM "--depend=<OBJECT>.d")
+    endif()
+
+    set(CMAKE_C_FLAGS_MINSIZEREL "-Oz -DNDEBUG")
+endmacro()
+
+# Configure environment for the compiler setup run by cmake at the first
+# `project` call in <tfm_root>/CMakeLists.txt. After this mandatory setup is
+# done, all further compiler setup is done via arm_toolchain_reload_compiler()
+arm_toolchain_set_processor_arch()
+arm_toolchain_reset_compiler_flags()
+arm_toolchain_reset_linker_flags()
+
+# Behaviour for handling scatter files is so wildly divergent between compilers
+# that this macro is required.
+macro(target_add_scatter_file target)
+    target_link_options(${target}
+        PRIVATE
+        --scatter=$<TARGET_OBJECTS:${target}_scatter>
+    )
+
+    add_dependencies(${target}
+        ${target}_scatter
+    )
+
+    add_library(${target}_scatter OBJECT)
+    foreach(scatter_file ${ARGN})
+        target_sources(${target}_scatter
+            PRIVATE
+                ${scatter_file}
+        )
+        # Cmake cannot use generator expressions in the
+        # set_source_file_properties command, so instead we just parse the regex
+        # for the filename and set the property on all files, regardless of if
+        # the generator expression would evaluate to true or not.
+        string(REGEX REPLACE ".*>:(.*)>$" "\\1" SCATTER_FILE_PATH "${scatter_file}")
+        set_source_files_properties(${SCATTER_FILE_PATH}
+            PROPERTIES
+            LANGUAGE C
+        )
+    endforeach()
+
+    target_link_libraries(${target}_scatter
+        platform_region_defs
+    )
+
+    target_compile_options(${target}_scatter
+        PRIVATE
+            -E
+            -xc
+    )
+endmacro()
+
+macro(add_convert_to_bin_target target)
+    get_target_property(bin_dir ${target} RUNTIME_OUTPUT_DIRECTORY)
+
+    add_custom_target(${target}_bin
+        SOURCES ${bin_dir}/${target}.bin
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.bin
+        DEPENDS ${target}
+        COMMAND fromelf
+            --bincombined $<TARGET_FILE:${target}>
+            --output=${bin_dir}/${target}.bin
+    )
+
+    add_custom_target(${target}_elf
+        SOURCES ${bin_dir}/${target}.elf
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.elf
+        DEPENDS ${target}
+        COMMAND fromelf
+            --elf $<TARGET_FILE:${target}>
+            --output=${bin_dir}/${target}.elf
+    )
+
+    add_custom_target(${target}_hex
+        SOURCES ${bin_dir}/${target}.hex
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.hex
+        DEPENDS ${target}
+        COMMAND fromelf
+            --i32combined $<TARGET_FILE:${target}>
+            --output=${bin_dir}/${target}.hex
+    )
+
+    add_custom_target(${target}_binaries
+        ALL
+        DEPENDS ${target}_bin
+        DEPENDS ${target}_elf
+        DEPENDS ${target}_hex
+    )
+endmacro()
diff --git a/cmake/toolchain_GNUARM.cmake b/cmake/toolchain_GNUARM.cmake
new file mode 100644
index 0000000..fc6fe4c
--- /dev/null
+++ b/cmake/toolchain_GNUARM.cmake
@@ -0,0 +1,176 @@
+#-------------------------------------------------------------------------------
+# Copyright (c) 2020, Arm Limited. All rights reserved.
+#
+# SPDX-License-Identifier: BSD-3-Clause
+#
+#-------------------------------------------------------------------------------
+
+set(CMAKE_SYSTEM_NAME Generic)
+
+find_program(CMAKE_C_COMPILER ${CROSS_COMPILE}-gcc)
+set(CMAKE_ASM_COMPILER ${CMAKE_C_COMPILER})
+
+#set(CMAKE_C_COMPILER ${CROSS_COMPILE}-gcc)
+#set(CMAKE_ASM_COMPILER ${CROSS_COMPILE}-gcc)
+set(CMAKE_AR ${CROSS_COMPILE}-gcc-ar)
+set(CMAKE_RANLIB ${CROSS_COMPILE}-gcc-ranlib)
+
+set(LINKER_VENEER_OUTPUT_FLAG -Wl,--cmse-implib,--out-implib=)
+set(COMPILER_CMSE_FLAG -mcmse)
+
+# This variable name is a bit of a misnomer. The file it is set to is included
+# at a particular step in the compiler initialisation. It is used here to
+# configure the extensions for object files. Despite the name, it also works
+# with the Ninja generator.
+set(CMAKE_USER_MAKE_RULES_OVERRIDE ${CMAKE_CURRENT_LIST_DIR}/set_extensions.cmake)
+
+macro(arm_toolchain_reset_compiler_flags)
+    set_property(DIRECTORY PROPERTY COMPILE_OPTIONS "")
+
+    add_compile_options(
+        --specs=nano.specs
+        -Wall
+        -Wno-format
+        -Wno-return-type
+        -Wno-unused-but-set-variable
+        -c
+        -fdata-sections
+        -ffunction-sections
+        -fno-builtin
+        -fshort-enums
+        -funsigned-char
+        -mthumb
+        -nostdlib
+        -std=c99
+        $<$<NOT:$<BOOL:${ARM_SYSTEM_FP}>>:-msoft-float>
+    )
+endmacro()
+
+macro(arm_toolchain_reset_linker_flags)
+    set_property(DIRECTORY PROPERTY LINK_OPTIONS "")
+
+    add_link_options(
+        --entry=Reset_Handler
+        --specs=nano.specs
+        LINKER:-check-sections
+        LINKER:-fatal-warnings
+        LINKER:--gc-sections
+        LINKER:--no-wchar-size-warning
+        LINKER:--print-memory-usage
+        LINKER:-Map=$<TARGET_FILE_BASE_NAME:$<TARGET_PROPERTY:NAME>>.map
+        LINKER:--cref
+    )
+endmacro()
+
+macro(arm_toolchain_set_processor_arch)
+    set(CMAKE_SYSTEM_PROCESSOR ${ARM_SYSTEM_PROCESSOR})
+    set(CMAKE_SYSTEM_ARCHITECTURE ${ARM_SYSTEM_ARCHITECTURE})
+
+    if (DEFINED ARM_SYSTEM_DSP)
+        if(NOT ARM_SYSTEM_DSP)
+            string(APPEND CMAKE_SYSTEM_PROCESSOR "+nodsp")
+        endif()
+    endif()
+endmacro()
+
+macro(arm_toolchain_reload_compiler)
+    arm_toolchain_set_processor_arch()
+    arm_toolchain_reset_compiler_flags()
+    arm_toolchain_reset_linker_flags()
+
+    unset(CMAKE_C_FLAGS_INIT)
+    unset(CMAKE_ASM_FLAGS_INIT)
+
+    set(CMAKE_C_FLAGS_INIT "-mcpu=${CMAKE_SYSTEM_PROCESSOR}")
+    set(CMAKE_ASM_FLAGS_INIT "-mcpu=${CMAKE_SYSTEM_PROCESSOR}")
+    set(CMAKE_C_LINK_FLAGS "-mcpu=${CMAKE_SYSTEM_PROCESSOR}")
+    set(CMAKE_ASM_LINK_FLAGS "-mcpu=${CMAKE_SYSTEM_PROCESSOR}")
+
+    set(CMAKE_C_FLAGS ${CMAKE_C_FLAGS_INIT})
+    set(CMAKE_ASM_FLAGS ${CMAKE_ASM_FLAGS_INIT})
+endmacro()
+
+# Configure environment for the compiler setup run by cmake at the first
+# `project` call in <tfm_root>/CMakeLists.txt. After this mandatory setup is
+# done, all further compiler setup is done via arm_toolchain_reload_compiler()
+arm_toolchain_reload_compiler()
+
+macro(target_add_scatter_file target)
+    target_link_options(${target}
+        PRIVATE
+        -T $<TARGET_OBJECTS:${target}_scatter>
+    )
+
+    add_dependencies(${target}
+        ${target}_scatter
+    )
+
+    add_library(${target}_scatter OBJECT)
+    foreach(scatter_file ${ARGN})
+        target_sources(${target}_scatter
+            PRIVATE
+                ${scatter_file}
+        )
+        # Cmake cannot use generator expressions in the
+        # set_source_file_properties command, so instead we just parse the regex
+        # for the filename and set the property on all files, regardless of if
+        # the generator expression would evaluate to true or not.
+        string(REGEX REPLACE ".*>:(.*)>$" "\\1" SCATTER_FILE_PATH "${scatter_file}")
+        set_source_files_properties(${SCATTER_FILE_PATH}
+            PROPERTIES
+            LANGUAGE C
+        )
+    endforeach()
+
+    target_link_libraries(${target}_scatter
+        platform_region_defs
+    )
+
+    target_compile_options(${target}_scatter
+        PRIVATE
+            -E
+            -P
+            -xc
+    )
+endmacro()
+
+macro(add_convert_to_bin_target target)
+    get_target_property(bin_dir ${target} RUNTIME_OUTPUT_DIRECTORY)
+
+    add_custom_target(${target}_bin
+        SOURCES ${bin_dir}/${target}.bin
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.bin
+        DEPENDS ${target}
+        COMMAND ${CMAKE_OBJCOPY}
+            -O binary $<TARGET_FILE:${target}>
+            ${bin_dir}/${target}.bin
+    )
+
+    add_custom_target(${target}_elf
+        SOURCES ${bin_dir}/${target}.elf
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.elf
+        DEPENDS ${target}
+        COMMAND ${CMAKE_OBJCOPY}
+            -O elf32-littlearm $<TARGET_FILE:${target}>
+            ${bin_dir}/${target}.elf
+    )
+
+    add_custom_target(${target}_hex
+        SOURCES ${bin_dir}/${target}.hex
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.hex
+        DEPENDS ${target}
+        COMMAND ${CMAKE_OBJCOPY}
+            -O ihex $<TARGET_FILE:${target}>
+            ${bin_dir}/${target}.hex
+    )
+
+    add_custom_target(${target}_binaries
+        ALL
+        DEPENDS ${target}_bin
+        DEPENDS ${target}_elf
+        DEPENDS ${target}_hex
+    )
+endmacro()
diff --git a/cmake/toolchain_IARARM.cmake b/cmake/toolchain_IARARM.cmake
new file mode 100644
index 0000000..48e34f9
--- /dev/null
+++ b/cmake/toolchain_IARARM.cmake
@@ -0,0 +1,178 @@
+#-------------------------------------------------------------------------------
+# Copyright (c) 2020, IAR Systems AB. All rights reserved.
+# Copyright (c) 2020, Arm Limited. All rights reserved.
+#
+# SPDX-License-Identifier: BSD-3-Clause
+#
+#-------------------------------------------------------------------------------
+
+cmake_minimum_required(VERSION 3.15)
+
+SET(CMAKE_SYSTEM_NAME Generic)
+set(CMAKE_SYSTEM_PROCESSOR       ${ARM_SYSTEM_PROCESSOR})
+set(CMAKE_SYSTEM_ARCHITECTURE    ${ARM_SYSTEM_ARCHITECTURE})
+
+if(CROSS_COMPILE)
+    set(CMAKE_C_COMPILER_TARGET      arm-${CROSS_COMPILE})
+    set(CMAKE_ASM_COMPILER_TARGET    arm-${CROSS_COMPILE})
+else()
+    set(CMAKE_C_COMPILER_TARGET      arm-arm-none-eabi)
+    set(CMAKE_ASM_COMPILER_TARGET    arm-arm-none-eabi)
+endif()
+
+set(CMAKE_C_COMPILER iccarm)
+set(CMAKE_ASM_COMPILER iasmarm)
+
+set(LINKER_VENEER_OUTPUT_FLAG --import_cmse_lib_out= )
+set(COMPILER_CMSE_FLAG --cmse)
+
+# This variable name is a bit of a misnomer. The file it is set to is included
+# at a particular step in the compiler initialisation. It is used here to
+# configure the extensions for object files. Despite the name, it also works
+# with the Ninja generator.
+set(CMAKE_USER_MAKE_RULES_OVERRIDE ${CMAKE_CURRENT_LIST_DIR}/set_extensions.cmake)
+
+macro(arm_toolchain_reset_compiler_flags)
+    set_property(DIRECTORY PROPERTY COMPILE_OPTIONS "")
+
+    add_compile_options(
+        $<$<COMPILE_LANGUAGE:C,CXX>:-e>
+        $<$<COMPILE_LANGUAGE:C,CXX>:--dlib_config=full>
+        $<$<COMPILE_LANGUAGE:C,CXX>:--vla>
+        $<$<COMPILE_LANGUAGE:C,CXX>:--silent>
+        $<$<COMPILE_LANGUAGE:C,CXX>:-DNO_TYPEOF>
+        $<$<COMPILE_LANGUAGE:C,CXX>:-D_NO_DEFINITIONS_IN_HEADER_FILES>
+        $<$<COMPILE_LANGUAGE:C,CXX>:--diag_suppress=Pe546,Pe940,Pa082,Pa084>
+    )
+endmacro()
+
+macro(arm_toolchain_reset_linker_flags)
+    set_property(DIRECTORY PROPERTY LINK_OPTIONS "")
+
+    add_link_options(
+      --silent
+      --semihosting
+      --redirect __write=__write_buffered
+    )
+endmacro()
+
+macro(arm_toolchain_set_processor_arch)
+    if(${ARM_SYSTEM_PROCESSOR} STREQUAL "cortex-m0plus")
+      set(CMAKE_SYSTEM_PROCESSOR Cortex-M0+)
+    else()
+      set(CMAKE_SYSTEM_PROCESSOR ${ARM_SYSTEM_PROCESSOR})
+    endif()
+    set(CMAKE_SYSTEM_ARCHITECTURE ${ARM_SYSTEM_ARCHITECTURE})
+
+    if (DEFINED ARM_SYSTEM_DSP)
+        if(NOT ARM_SYSTEM_DSP)
+            string(APPEND CMAKE_SYSTEM_PROCESSOR ".no_dsp")
+        endif()
+    endif()
+endmacro()
+
+macro(arm_toolchain_reload_compiler)
+    arm_toolchain_set_processor_arch()
+    arm_toolchain_reset_compiler_flags()
+    arm_toolchain_reset_linker_flags()
+
+    unset(CMAKE_C_FLAGS_INIT)
+    unset(CMAKE_C_LINK_FLAGS)
+    unset(CMAKE_ASM_FLAGS_INIT)
+    unset(CMAKE_ASM_LINK_FLAGS)
+
+    set(CMAKE_C_FLAGS_INIT "--cpu ${CMAKE_SYSTEM_PROCESSOR}")
+    set(CMAKE_ASM_FLAGS_INIT "--cpu ${CMAKE_SYSTEM_PROCESSOR}")
+    set(CMAKE_C_LINK_FLAGS "--cpu ${CMAKE_SYSTEM_PROCESSOR}")
+    set(CMAKE_ASM_LINK_FLAGS "--cpu ${CMAKE_SYSTEM_PROCESSOR}")
+
+    set(CMAKE_C_FLAGS ${CMAKE_C_FLAGS_INIT})
+    set(CMAKE_ASM_FLAGS ${CMAKE_ASM_FLAGS_INIT})
+endmacro()
+
+# Configure environment for the compiler setup run by cmake at the first
+# `project` call in <tfm_root>/CMakeLists.txt. After this mandatory setup is
+# done, all further compiler setup is done via arm_toolchain_reload_compiler()
+arm_toolchain_reload_compiler()
+
+# Behaviour for handling scatter files is so wildly divergent between compilers
+# that this macro is required.
+macro(target_add_scatter_file target)
+    target_link_options(${target}
+        PRIVATE
+        --config $<TARGET_OBJECTS:${target}_scatter>
+    )
+    add_dependencies(${target}
+        ${target}_scatter
+    )
+
+    add_library(${target}_scatter OBJECT)
+    foreach(scatter_file ${ARGN})
+        target_sources(${target}_scatter
+            PRIVATE
+                ${scatter_file}
+        )
+        # Cmake cannot use generator expressions in the
+        # set_source_file_properties command, so instead we just parse the regex
+        # for the filename and set the property on all files, regardless of if
+        # the generator expression would evaluate to true or not.
+        string(REGEX REPLACE ".*>:(.*)>$" "\\1" SCATTER_FILE_PATH "${scatter_file}")
+        set_source_files_properties(${SCATTER_FILE_PATH}
+            PROPERTIES
+            LANGUAGE C
+        )
+    endforeach()
+
+    target_link_libraries(${target}_scatter
+        platform_region_defs
+    )
+
+    target_compile_options(${target}_scatter
+        PRIVATE
+            --preprocess=sn $<TARGET_OBJECTS:${target}_scatter>
+    )
+endmacro()
+
+macro(add_convert_to_bin_target target)
+    get_target_property(bin_dir ${target} RUNTIME_OUTPUT_DIRECTORY)
+
+    add_custom_target(${target}_bin
+        SOURCES ${bin_dir}/${target}.bin
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.bin
+        DEPENDS ${target}
+        COMMAND ielftool
+            --silent
+            --bin $<TARGET_FILE:${target}>
+            ${bin_dir}/${target}.bin
+    )
+
+    add_custom_target(${target}_elf
+        SOURCES ${bin_dir}/${target}.elf
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.elf
+        DEPENDS ${target}
+        COMMAND ielftool
+            --silent
+            $<TARGET_FILE:${target}>
+            ${bin_dir}/${target}.elf
+    )
+
+    add_custom_target(${target}_hex
+        SOURCES ${bin_dir}/${target}.hex
+    )
+    add_custom_command(OUTPUT ${bin_dir}/${target}.hex
+        DEPENDS ${target}
+        COMMAND ielftool
+            --silent
+            --ihex $<TARGET_FILE:${target}>
+            ${bin_dir}/${target}.hex
+    )
+
+    add_custom_target(${target}_binaries
+        ALL
+        DEPENDS ${target}_bin
+        DEPENDS ${target}_elf
+        DEPENDS ${target}_hex
+    )
+endmacro()