1*91f16700Schasinglulu# 2*91f16700Schasinglulu# Copyright (c) 2015-2023, Arm Limited and Contributors. All rights reserved. 3*91f16700Schasinglulu# 4*91f16700Schasinglulu# SPDX-License-Identifier: BSD-3-Clause 5*91f16700Schasinglulu# 6*91f16700Schasinglulu 7*91f16700SchasingluluPLAT_BL_COMMON_SOURCES += drivers/arm/pl011/${ARCH}/pl011_console.S \ 8*91f16700Schasinglulu plat/arm/board/common/${ARCH}/board_arm_helpers.S 9*91f16700Schasinglulu 10*91f16700SchasingluluBL1_SOURCES += drivers/cfi/v2m/v2m_flash.c 11*91f16700Schasinglulu 12*91f16700SchasingluluBL2_SOURCES += drivers/cfi/v2m/v2m_flash.c 13*91f16700Schasinglulu 14*91f16700Schasingluluifneq (${TRUSTED_BOARD_BOOT},0) 15*91f16700SchasingluluARM_ROTPK_S = plat/arm/board/common/rotpk/arm_dev_rotpk.S 16*91f16700Schasinglulu 17*91f16700Schasinglulu# ROTPK hash location 18*91f16700Schasingluluifeq (${ARM_ROTPK_LOCATION}, regs) 19*91f16700Schasinglulu ARM_ROTPK_LOCATION_ID = ARM_ROTPK_REGS_ID 20*91f16700Schasingluluelse ifeq (${ARM_ROTPK_LOCATION}, devel_rsa) 21*91f16700Schasinglulu CRYPTO_ALG=rsa 22*91f16700Schasinglulu ARM_ROTPK_LOCATION_ID = ARM_ROTPK_DEVEL_RSA_ID 23*91f16700Schasinglulu ARM_ROTPK_HASH = plat/arm/board/common/rotpk/arm_rotpk_rsa_sha256.bin 24*91f16700Schasinglulu$(eval $(call add_define_val,ARM_ROTPK_HASH,'"$(ARM_ROTPK_HASH)"')) 25*91f16700Schasinglulu$(BUILD_PLAT)/bl2/arm_dev_rotpk.o : $(ARM_ROTPK_HASH) 26*91f16700Schasinglulu$(warning Development keys support for FVP is deprecated. Use `regs` \ 27*91f16700Schasingluluoption instead) 28*91f16700Schasingluluelse ifeq (${ARM_ROTPK_LOCATION}, devel_ecdsa) 29*91f16700Schasinglulu CRYPTO_ALG=ec 30*91f16700Schasinglulu ARM_ROTPK_LOCATION_ID = ARM_ROTPK_DEVEL_ECDSA_ID 31*91f16700Schasinglulu ARM_ROTPK_HASH = plat/arm/board/common/rotpk/arm_rotpk_ecdsa_sha256.bin 32*91f16700Schasinglulu$(eval $(call add_define_val,ARM_ROTPK_HASH,'"$(ARM_ROTPK_HASH)"')) 33*91f16700Schasinglulu$(BUILD_PLAT)/bl2/arm_dev_rotpk.o : $(ARM_ROTPK_HASH) 34*91f16700Schasinglulu$(warning Development keys support for FVP is deprecated. Use `regs` \ 35*91f16700Schasingluluoption instead) 36*91f16700Schasingluluelse ifeq (${ARM_ROTPK_LOCATION}, devel_full_dev_rsa_key) 37*91f16700Schasinglulu CRYPTO_ALG=rsa 38*91f16700Schasinglulu ARM_ROTPK_LOCATION_ID = ARM_ROTPK_DEVEL_FULL_DEV_RSA_KEY_ID 39*91f16700Schasinglulu ARM_ROTPK_S = plat/arm/board/common/rotpk/arm_full_dev_rsa_rotpk.S 40*91f16700Schasinglulu$(warning Development keys support for FVP is deprecated. Use `regs` \ 41*91f16700Schasingluluoption instead) 42*91f16700Schasingluluelse ifeq (${ARM_ROTPK_LOCATION}, devel_full_dev_ecdsa_key) 43*91f16700Schasinglulu CRYPTO_ALG=ec 44*91f16700Schasinglulu ARM_ROTPK_LOCATION_ID = ARM_ROTPK_DEVEL_FULL_DEV_ECDSA_KEY_ID 45*91f16700Schasingluluifeq (${KEY_SIZE},384) 46*91f16700Schasinglulu ARM_ROTPK_S = plat/arm/board/common/rotpk/arm_full_dev_ecdsa_p384_rotpk.S 47*91f16700Schasingluluelse 48*91f16700Schasinglulu ARM_ROTPK_S = plat/arm/board/common/rotpk/arm_full_dev_ecdsa_p256_rotpk.S 49*91f16700Schasingluluendif 50*91f16700Schasinglulu$(warning Development keys support for FVP is deprecated. Use `regs` \ 51*91f16700Schasingluluoption instead) 52*91f16700Schasingluluelse 53*91f16700Schasinglulu$(error "Unsupported ARM_ROTPK_LOCATION value") 54*91f16700Schasingluluendif 55*91f16700Schasinglulu 56*91f16700Schasinglulu$(eval $(call add_define,ARM_ROTPK_LOCATION_ID)) 57*91f16700Schasinglulu 58*91f16700Schasingluluifeq (${ENABLE_RME}, 1) 59*91f16700SchasingluluCOT := cca 60*91f16700Schasingluluendif 61*91f16700Schasinglulu 62*91f16700Schasinglulu# Force generation of the new hash if ROT_KEY is specified 63*91f16700Schasingluluifdef ROT_KEY 64*91f16700Schasinglulu HASH_PREREQUISITES = $(ROT_KEY) FORCE 65*91f16700Schasingluluendif 66*91f16700Schasinglulu 67*91f16700Schasinglulu$(ARM_ROTPK_HASH) : $(HASH_PREREQUISITES) 68*91f16700Schasingluluifndef ROT_KEY 69*91f16700Schasinglulu $(error Cannot generate hash: no ROT_KEY defined) 70*91f16700Schasingluluendif 71*91f16700Schasinglulu ${OPENSSL_BIN_PATH}/openssl ${CRYPTO_ALG} -in $< -pubout -outform DER | \ 72*91f16700Schasinglulu ${OPENSSL_BIN_PATH}/openssl dgst -sha256 -binary > $@ 73*91f16700Schasinglulu 74*91f16700Schasinglulu# Certificate NV-Counters. Use values corresponding to tied off values in 75*91f16700Schasinglulu# ARM development platforms 76*91f16700SchasingluluTFW_NVCTR_VAL ?= 31 77*91f16700SchasingluluNTFW_NVCTR_VAL ?= 223 78*91f16700Schasinglulu# The CCA Non-Volatile Counter only exists on some Arm development platforms. 79*91f16700Schasinglulu# On others, we mock it by aliasing it to the Trusted Firmware Non-Volatile counter, 80*91f16700Schasinglulu# hence we set both counters to the same default value. 81*91f16700SchasingluluCCAFW_NVCTR_VAL ?= 31 82*91f16700Schasinglulu 83*91f16700SchasingluluBL1_SOURCES += plat/arm/board/common/board_arm_trusted_boot.c \ 84*91f16700Schasinglulu ${ARM_ROTPK_S} 85*91f16700SchasingluluBL2_SOURCES += plat/arm/board/common/board_arm_trusted_boot.c \ 86*91f16700Schasinglulu ${ARM_ROTPK_S} 87*91f16700Schasinglulu 88*91f16700Schasinglulu# Allows platform code to provide implementation variants depending on the 89*91f16700Schasinglulu# selected chain of trust. 90*91f16700Schasinglulu$(eval $(call add_define,ARM_COT_${COT})) 91*91f16700Schasinglulu 92*91f16700Schasingluluifeq (${COT},dualroot) 93*91f16700Schasinglulu# Platform Root of Trust key files. 94*91f16700SchasingluluARM_PROT_KEY := plat/arm/board/common/protpk/arm_protprivk_rsa.pem 95*91f16700SchasingluluARM_PROTPK_HASH := plat/arm/board/common/protpk/arm_protpk_rsa_sha256.bin 96*91f16700Schasinglulu 97*91f16700Schasinglulu# Provide the private key to cert_create tool. It needs it to sign the images. 98*91f16700SchasingluluPROT_KEY := ${ARM_PROT_KEY} 99*91f16700Schasinglulu 100*91f16700Schasinglulu$(eval $(call add_define_val,ARM_PROTPK_HASH,'"$(ARM_PROTPK_HASH)"')) 101*91f16700Schasinglulu 102*91f16700SchasingluluBL1_SOURCES += plat/arm/board/common/protpk/arm_dev_protpk.S 103*91f16700SchasingluluBL2_SOURCES += plat/arm/board/common/protpk/arm_dev_protpk.S 104*91f16700Schasinglulu 105*91f16700Schasinglulu$(BUILD_PLAT)/bl1/arm_dev_protpk.o: $(ARM_PROTPK_HASH) 106*91f16700Schasinglulu$(BUILD_PLAT)/bl2/arm_dev_protpk.o: $(ARM_PROTPK_HASH) 107*91f16700Schasingluluendif 108*91f16700Schasinglulu 109*91f16700Schasingluluifeq (${COT},cca) 110*91f16700Schasinglulu# Platform and Secure World Root of Trust key files. 111*91f16700SchasingluluARM_PROT_KEY := plat/arm/board/common/protpk/arm_protprivk_rsa.pem 112*91f16700SchasingluluARM_PROTPK_HASH := plat/arm/board/common/protpk/arm_protpk_rsa_sha256.bin 113*91f16700SchasingluluARM_SWD_ROT_KEY := plat/arm/board/common/swd_rotpk/arm_swd_rotprivk_rsa.pem 114*91f16700SchasingluluARM_SWD_ROTPK_HASH := plat/arm/board/common/swd_rotpk/arm_swd_rotpk_rsa_sha256.bin 115*91f16700Schasinglulu 116*91f16700Schasinglulu# Provide the private keys to cert_create tool. It needs them to sign the images. 117*91f16700SchasingluluPROT_KEY := ${ARM_PROT_KEY} 118*91f16700SchasingluluSWD_ROT_KEY := ${ARM_SWD_ROT_KEY} 119*91f16700Schasinglulu 120*91f16700Schasinglulu$(eval $(call add_define_val,ARM_PROTPK_HASH,'"$(ARM_PROTPK_HASH)"')) 121*91f16700Schasinglulu$(eval $(call add_define_val,ARM_SWD_ROTPK_HASH,'"$(ARM_SWD_ROTPK_HASH)"')) 122*91f16700Schasinglulu 123*91f16700SchasingluluBL1_SOURCES += plat/arm/board/common/protpk/arm_dev_protpk.S \ 124*91f16700Schasinglulu plat/arm/board/common/swd_rotpk/arm_dev_swd_rotpk.S 125*91f16700SchasingluluBL2_SOURCES += plat/arm/board/common/protpk/arm_dev_protpk.S \ 126*91f16700Schasinglulu plat/arm/board/common/swd_rotpk/arm_dev_swd_rotpk.S 127*91f16700Schasinglulu 128*91f16700Schasinglulu$(BUILD_PLAT)/bl1/arm_dev_protpk.o: $(ARM_PROTPK_HASH) 129*91f16700Schasinglulu$(BUILD_PLAT)/bl1/arm_dev_swd_rotpk.o: $(ARM_SWD_ROTPK_HASH) 130*91f16700Schasinglulu$(BUILD_PLAT)/bl2/arm_dev_protpk.o: $(ARM_PROTPK_HASH) 131*91f16700Schasinglulu$(BUILD_PLAT)/bl2/arm_dev_swd_rotpk.o: $(ARM_SWD_ROTPK_HASH) 132*91f16700Schasingluluendif 133*91f16700Schasinglulu 134*91f16700Schasingluluendif 135