mirror of
https://github.com/apache/nuttx.git
synced 2026-10-03 04:07:55 +00:00
arch/arm/imxrt: Add support for ELE FW for imxrt1180-evk
Add support for loading the secure element firmware. Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
This commit is contained in:
parent
af24d2094a
commit
be5bf6133b
6 changed files with 168 additions and 1 deletions
|
|
@ -457,6 +457,49 @@ config IMXRT_ELE
|
|||
(arch/arm/src/imxrt/imxrt118x_ele.c). Present on RT118x-class
|
||||
SoCs.
|
||||
|
||||
config IMXRT_ELE_FW
|
||||
bool "Use a separate ELE firmware image"
|
||||
depends on IMXRT_ELE
|
||||
default n
|
||||
---help---
|
||||
Use a separate NXP EdgeLock Enclave firmware AHAB container
|
||||
(CONFIG_IMXRT_ELE_FW_PATH) instead of relying solely on the
|
||||
ELE code already built into the RT118x boot ROM.
|
||||
|
||||
When disabled (the default), no separate ELE firmware is used
|
||||
at all.
|
||||
|
||||
config IMXRT_ELE_FW_DOWNLOAD
|
||||
bool "Download the ELE firmware image"
|
||||
depends on IMXRT_ELE_FW
|
||||
default y
|
||||
---help---
|
||||
Download the pinned NXP EdgeLock Enclave firmware AHAB
|
||||
container into CONFIG_IMXRT_ELE_FW_PATH as part of the build.
|
||||
|
||||
The container is proprietary NXP object code; running the build
|
||||
implies acceptance of NXP's LA_OPT NXP Software License.
|
||||
|
||||
config IMXRT_ELE_LOAD_FW
|
||||
bool "Load ELE firmware from NuttX at boot"
|
||||
depends on IMXRT_ELE_FW
|
||||
default y
|
||||
---help---
|
||||
Embed the ELE firmware AHAB container (CONFIG_IMXRT_ELE_FW_PATH)
|
||||
in the NuttX image and hand it to the EdgeLock Enclave with a
|
||||
LOAD_FW command early in imxrt118x_ele_init().
|
||||
|
||||
When disabled, the ELE firmware is instead packed as its own
|
||||
AHAB container in the boot image, loaded by ROM code.
|
||||
|
||||
config IMXRT_ELE_FW_PATH
|
||||
string "ELE firmware AHAB container path"
|
||||
depends on IMXRT_ELE_FW
|
||||
default "tools/imxrt1180/.cache/ele-fw/mxrt1180b0-ahab-container.img"
|
||||
---help---
|
||||
Path (relative to the NuttX top-level directory, or absolute) to
|
||||
the NXP EdgeLock Enclave firmware AHAB container.
|
||||
|
||||
config IMXRT_CM7_BOOT
|
||||
bool
|
||||
default n
|
||||
|
|
|
|||
|
|
@ -172,6 +172,15 @@ endif
|
|||
|
||||
ifeq ($(CONFIG_IMXRT_ELE),y)
|
||||
CHIP_CSRCS += imxrt118x_ele.c
|
||||
|
||||
ifeq ($(CONFIG_IMXRT_ELE_LOAD_FW),y)
|
||||
# Pass CONFIG_IMXRT_ELE_FW_PATH back to imxrt118x_ele.c via a -D override
|
||||
# so the .incbin directive can find the file no matter what the
|
||||
# compiler's CWD happens to be.
|
||||
CFLAGS += -DIMXRT_ELE_FW_ABS_PATH=\"$(IMXRT_ELE_FW_ABS)\"
|
||||
|
||||
imxrt118x_ele.o: $(IMXRT_ELE_FW_ABS)
|
||||
endif
|
||||
endif
|
||||
|
||||
ifeq ($(CONFIG_IMXRT_CM7_BOOT),y)
|
||||
|
|
|
|||
|
|
@ -42,6 +42,15 @@
|
|||
* Pre-processor Definitions
|
||||
****************************************************************************/
|
||||
|
||||
#ifdef CONFIG_IMXRT_ELE_LOAD_FW
|
||||
# ifndef IMXRT_ELE_FW_ABS_PATH
|
||||
# error "IMXRT_ELE_FW_ABS_PATH must be set via CFLAGS"
|
||||
# endif
|
||||
|
||||
# define STR2(m) #m
|
||||
# define STR(m) STR2(m)
|
||||
#endif
|
||||
|
||||
/* The M7 core is Armv7-M and the M33 core is Armv8-M; pick whichever
|
||||
* D-Cache line size macro chip.h provided for the core we're building
|
||||
* for.
|
||||
|
|
@ -78,6 +87,27 @@ struct ele_trng_state
|
|||
|
||||
static struct ele_msg g_msg;
|
||||
|
||||
#ifdef CONFIG_IMXRT_ELE_LOAD_FW
|
||||
/* Embeds the NXP EdgeLock Enclave firmware AHAB container (path from
|
||||
* CONFIG_IMXRT_ELE_FW_PATH) directly into the driver image.
|
||||
*
|
||||
* This is legacy/fallback support: the RT118x ROM can also load the ELE
|
||||
* FW automatically from a properly packed AHAB container, in which case
|
||||
* CONFIG_IMXRT_ELE_LOAD_FW should be disabled.
|
||||
*/
|
||||
|
||||
__asm__ (
|
||||
".section .rodata.imxrt118x_ele_fw, \"a\"\n"
|
||||
".balign 8\n"
|
||||
".globl imxrt118x_ele_fw\n"
|
||||
"imxrt118x_ele_fw:\n"
|
||||
".incbin " STR(IMXRT_ELE_FW_ABS_PATH) "\n"
|
||||
".balign 8\n"
|
||||
".globl imxrt118x_ele_fw_end\n"
|
||||
"imxrt118x_ele_fw_end:\n"
|
||||
);
|
||||
#endif
|
||||
|
||||
/****************************************************************************
|
||||
* Private Functions
|
||||
****************************************************************************/
|
||||
|
|
@ -156,6 +186,12 @@ void imxrt118x_ele_init(void)
|
|||
putreg32(0, ELE_MU_TCR);
|
||||
putreg32(0, ELE_MU_RCR);
|
||||
|
||||
#ifdef CONFIG_IMXRT_ELE_LOAD_FW
|
||||
/* Load the ELE firmware via mailbox */
|
||||
|
||||
imxrt118x_ele_load_fw((uint32_t)(uintptr_t)imxrt118x_ele_fw);
|
||||
#endif
|
||||
|
||||
imxrt118x_ele_check_fw_version();
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -38,6 +38,18 @@
|
|||
* Public Function Prototypes
|
||||
****************************************************************************/
|
||||
|
||||
#ifdef CONFIG_IMXRT_ELE_LOAD_FW
|
||||
/* Embedded ELE firmware container, incbin'd directly from
|
||||
* CONFIG_IMXRT_ELE_FW_PATH (see imxrt118x_ele.c). Only needed when the
|
||||
* driver is responsible for handing the FW to the ELE at runtime; when
|
||||
* the FW is instead packed into the boot AHAB container for the ROM to
|
||||
* load automatically, this blob is not built into the image at all.
|
||||
*/
|
||||
|
||||
extern const uint8_t imxrt118x_ele_fw[];
|
||||
extern const uint8_t imxrt118x_ele_fw_end[];
|
||||
#endif
|
||||
|
||||
/****************************************************************************
|
||||
* Name: imxrt118x_ele_init
|
||||
*
|
||||
|
|
|
|||
|
|
@ -60,13 +60,34 @@ AFLAGS := $(CFLAGS) -D__ASSEMBLY__
|
|||
|
||||
FLASH_BUILDER = $(TOPDIR)$(DELIM)tools$(DELIM)imxrt1180$(DELIM)build_flash_image.sh
|
||||
|
||||
ifeq ($(CONFIG_IMXRT_ELE_FW),y)
|
||||
include $(TOPDIR)/tools/imxrt1180/Config.mk
|
||||
|
||||
# Restore "all" as the default goal: Config.mk's FW target would
|
||||
# otherwise become it, since this file is included before "all" is
|
||||
# defined.
|
||||
.DEFAULT_GOAL := all
|
||||
endif
|
||||
|
||||
ifeq ($(CONFIG_IMXRT_ELE_FW),y)
|
||||
ifeq ($(CONFIG_IMXRT_ELE_LOAD_FW),y)
|
||||
FLASH_BUILDER_ELE_FW_ARGS =
|
||||
else
|
||||
FLASH_BUILDER_ELE_FW_ARGS = --ele-fw $(IMXRT_ELE_FW_ABS)
|
||||
endif
|
||||
else
|
||||
FLASH_BUILDER_ELE_FW_ARGS =
|
||||
endif
|
||||
|
||||
ifeq ($(CONFIG_ARCH_CORTEXM33),y)
|
||||
define POSTBUILD
|
||||
$(Q) echo "Assembling MIMXRT1180-EVK FlexSPI NOR image (CM33 target)"
|
||||
$(Q) $(OBJCOPY) -O binary -R .bss -R .initstack $(BIN) nuttx.bin
|
||||
$(if $(IMXRT_ELE_FW_ABS),$(Q) $(MAKE) $(IMXRT_ELE_FW_ABS))
|
||||
$(Q) $(FLASH_BUILDER) \
|
||||
--m33 nuttx.bin \
|
||||
--out flash.bin
|
||||
--out flash.bin \
|
||||
$(FLASH_BUILDER_ELE_FW_ARGS)
|
||||
$(Q) echo "flash.bin" >> nuttx.manifest
|
||||
endef
|
||||
else
|
||||
|
|
|
|||
46
tools/imxrt1180/Config.mk
Normal file
46
tools/imxrt1180/Config.mk
Normal file
|
|
@ -0,0 +1,46 @@
|
|||
############################################################################
|
||||
# tools/imxrt1180/Config.mk
|
||||
#
|
||||
# SPDX-License-Identifier: Apache-2.0
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership. The
|
||||
# ASF licenses this file to you under the Apache License, Version 2.0 (the
|
||||
# "License"); you may not use this file except in compliance with the
|
||||
# License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
|
||||
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
|
||||
# License for the specific language governing permissions and limitations
|
||||
# under the License.
|
||||
#
|
||||
############################################################################
|
||||
|
||||
# Resolves the location of the pinned NXP EdgeLock Enclave firmware AHAB
|
||||
# container. When CONFIG_IMXRT_ELE_FW_DOWNLOAD is enabled, also defines a
|
||||
# Make target that downloads it into the shared build cache.
|
||||
|
||||
ifeq ($(CONFIG_IMXRT_ELE_FW),y)
|
||||
|
||||
ELE_FW_URL_BASE = https://raw.githubusercontent.com/nxp-mcuxpresso/mcux-sdk/6f3fd257cdcf978a4d26e7d6e9eed9240037422b/firmware/edgelock
|
||||
ELE_FW_NAME = mxrt1180b0-ahab-container.img
|
||||
ELE_FW_PATH := $(strip $(subst ",,$(CONFIG_IMXRT_ELE_FW_PATH)))
|
||||
IMXRT_ELE_FW_ABS := $(if $(filter /%,$(ELE_FW_PATH)),$(ELE_FW_PATH),$(TOPDIR)/$(ELE_FW_PATH))
|
||||
|
||||
ifeq ($(CONFIG_IMXRT_ELE_FW_DOWNLOAD),y)
|
||||
$(IMXRT_ELE_FW_ABS):
|
||||
$(Q) mkdir -p $(dir $@)
|
||||
$(call DOWNLOAD,$(ELE_FW_URL_BASE),$(ELE_FW_NAME),$@)
|
||||
else
|
||||
$(IMXRT_ELE_FW_ABS):
|
||||
$(Q) test -f $@ || \
|
||||
{ echo "error: ELE firmware not found at $@"; \
|
||||
echo " (CONFIG_IMXRT_ELE_FW_DOWNLOAD is disabled, so it must be provided)"; \
|
||||
exit 1; }
|
||||
endif
|
||||
|
||||
endif
|
||||
Loading…
Add table
Add a link
Reference in a new issue