arch/arm/imxrt: Add support for ELE FW for imxrt1180-evk

Add support for loading the secure element firmware.

Signed-off-by: Jukka Laitinen <jukka.laitinen@tii.ae>
This commit is contained in:
Jukka Laitinen 2026-09-18 08:32:32 +03:00 • committed by Xiang Xiao
parent af24d2094a
commit be5bf6133b
6 changed files with 168 additions and 1 deletions

View file

@ -457,6 +457,49 @@ config IMXRT_ELE
(arch/arm/src/imxrt/imxrt118x_ele.c). Present on RT118x-class
SoCs.
config IMXRT_ELE_FW
bool "Use a separate ELE firmware image"
depends on IMXRT_ELE
default n
---help---
Use a separate NXP EdgeLock Enclave firmware AHAB container
(CONFIG_IMXRT_ELE_FW_PATH) instead of relying solely on the
ELE code already built into the RT118x boot ROM.
When disabled (the default), no separate ELE firmware is used
at all.
config IMXRT_ELE_FW_DOWNLOAD
bool "Download the ELE firmware image"
depends on IMXRT_ELE_FW
default y
---help---
Download the pinned NXP EdgeLock Enclave firmware AHAB
container into CONFIG_IMXRT_ELE_FW_PATH as part of the build.
The container is proprietary NXP object code; running the build
implies acceptance of NXP's LA_OPT NXP Software License.
config IMXRT_ELE_LOAD_FW
bool "Load ELE firmware from NuttX at boot"
depends on IMXRT_ELE_FW
default y
---help---
Embed the ELE firmware AHAB container (CONFIG_IMXRT_ELE_FW_PATH)
in the NuttX image and hand it to the EdgeLock Enclave with a
LOAD_FW command early in imxrt118x_ele_init().
When disabled, the ELE firmware is instead packed as its own
AHAB container in the boot image, loaded by ROM code.
config IMXRT_ELE_FW_PATH
string "ELE firmware AHAB container path"
depends on IMXRT_ELE_FW
default "tools/imxrt1180/.cache/ele-fw/mxrt1180b0-ahab-container.img"
---help---
Path (relative to the NuttX top-level directory, or absolute) to
the NXP EdgeLock Enclave firmware AHAB container.
config IMXRT_CM7_BOOT
bool
default n

View file

@ -172,6 +172,15 @@ endif
ifeq ($(CONFIG_IMXRT_ELE),y)
CHIP_CSRCS += imxrt118x_ele.c
ifeq ($(CONFIG_IMXRT_ELE_LOAD_FW),y)
# Pass CONFIG_IMXRT_ELE_FW_PATH back to imxrt118x_ele.c via a -D override
# so the .incbin directive can find the file no matter what the
# compiler's CWD happens to be.
CFLAGS += -DIMXRT_ELE_FW_ABS_PATH=\"$(IMXRT_ELE_FW_ABS)\"
imxrt118x_ele.o: $(IMXRT_ELE_FW_ABS)
endif
endif
ifeq ($(CONFIG_IMXRT_CM7_BOOT),y)

View file

@ -42,6 +42,15 @@
* Pre-processor Definitions
****************************************************************************/
#ifdef CONFIG_IMXRT_ELE_LOAD_FW
# ifndef IMXRT_ELE_FW_ABS_PATH
# error "IMXRT_ELE_FW_ABS_PATH must be set via CFLAGS"
# endif
# define STR2(m) #m
# define STR(m) STR2(m)
#endif
/* The M7 core is Armv7-M and the M33 core is Armv8-M; pick whichever
* D-Cache line size macro chip.h provided for the core we're building
* for.
@ -78,6 +87,27 @@ struct ele_trng_state
static struct ele_msg g_msg;
#ifdef CONFIG_IMXRT_ELE_LOAD_FW
/* Embeds the NXP EdgeLock Enclave firmware AHAB container (path from
* CONFIG_IMXRT_ELE_FW_PATH) directly into the driver image.
*
* This is legacy/fallback support: the RT118x ROM can also load the ELE
* FW automatically from a properly packed AHAB container, in which case
* CONFIG_IMXRT_ELE_LOAD_FW should be disabled.
*/
__asm__ (
".section .rodata.imxrt118x_ele_fw, \"a\"\n"
".balign 8\n"
".globl imxrt118x_ele_fw\n"
"imxrt118x_ele_fw:\n"
".incbin " STR(IMXRT_ELE_FW_ABS_PATH) "\n"
".balign 8\n"
".globl imxrt118x_ele_fw_end\n"
"imxrt118x_ele_fw_end:\n"
);
#endif
/****************************************************************************
* Private Functions
****************************************************************************/
@ -156,6 +186,12 @@ void imxrt118x_ele_init(void)
putreg32(0, ELE_MU_TCR);
putreg32(0, ELE_MU_RCR);
#ifdef CONFIG_IMXRT_ELE_LOAD_FW
/* Load the ELE firmware via mailbox */
imxrt118x_ele_load_fw((uint32_t)(uintptr_t)imxrt118x_ele_fw);
#endif
imxrt118x_ele_check_fw_version();
}

View file

@ -38,6 +38,18 @@
* Public Function Prototypes
****************************************************************************/
#ifdef CONFIG_IMXRT_ELE_LOAD_FW
/* Embedded ELE firmware container, incbin'd directly from
* CONFIG_IMXRT_ELE_FW_PATH (see imxrt118x_ele.c). Only needed when the
* driver is responsible for handing the FW to the ELE at runtime; when
* the FW is instead packed into the boot AHAB container for the ROM to
* load automatically, this blob is not built into the image at all.
*/
extern const uint8_t imxrt118x_ele_fw[];
extern const uint8_t imxrt118x_ele_fw_end[];
#endif
/****************************************************************************
* Name: imxrt118x_ele_init
*

View file

@ -60,13 +60,34 @@ AFLAGS := $(CFLAGS) -D__ASSEMBLY__
FLASH_BUILDER = $(TOPDIR)$(DELIM)tools$(DELIM)imxrt1180$(DELIM)build_flash_image.sh
ifeq ($(CONFIG_IMXRT_ELE_FW),y)
include $(TOPDIR)/tools/imxrt1180/Config.mk
# Restore "all" as the default goal: Config.mk's FW target would
# otherwise become it, since this file is included before "all" is
# defined.
.DEFAULT_GOAL := all
endif
ifeq ($(CONFIG_IMXRT_ELE_FW),y)
ifeq ($(CONFIG_IMXRT_ELE_LOAD_FW),y)
FLASH_BUILDER_ELE_FW_ARGS =
else
FLASH_BUILDER_ELE_FW_ARGS = --ele-fw $(IMXRT_ELE_FW_ABS)
endif
else
FLASH_BUILDER_ELE_FW_ARGS =
endif
ifeq ($(CONFIG_ARCH_CORTEXM33),y)
define POSTBUILD
$(Q) echo "Assembling MIMXRT1180-EVK FlexSPI NOR image (CM33 target)"
$(Q) $(OBJCOPY) -O binary -R .bss -R .initstack $(BIN) nuttx.bin
$(if $(IMXRT_ELE_FW_ABS),$(Q) $(MAKE) $(IMXRT_ELE_FW_ABS))
$(Q) $(FLASH_BUILDER) \
--m33 nuttx.bin \
--out flash.bin
--out flash.bin \
$(FLASH_BUILDER_ELE_FW_ARGS)
$(Q) echo "flash.bin" >> nuttx.manifest
endef
else

46
tools/imxrt1180/Config.mk Normal file
View file

@ -0,0 +1,46 @@
############################################################################
# tools/imxrt1180/Config.mk
#
# SPDX-License-Identifier: Apache-2.0
#
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership. The
# ASF licenses this file to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance with the
# License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
# License for the specific language governing permissions and limitations
# under the License.
#
############################################################################
# Resolves the location of the pinned NXP EdgeLock Enclave firmware AHAB
# container. When CONFIG_IMXRT_ELE_FW_DOWNLOAD is enabled, also defines a
# Make target that downloads it into the shared build cache.
ifeq ($(CONFIG_IMXRT_ELE_FW),y)
ELE_FW_URL_BASE = https://raw.githubusercontent.com/nxp-mcuxpresso/mcux-sdk/6f3fd257cdcf978a4d26e7d6e9eed9240037422b/firmware/edgelock
ELE_FW_NAME = mxrt1180b0-ahab-container.img
ELE_FW_PATH := $(strip $(subst ",,$(CONFIG_IMXRT_ELE_FW_PATH)))
IMXRT_ELE_FW_ABS := $(if $(filter /%,$(ELE_FW_PATH)),$(ELE_FW_PATH),$(TOPDIR)/$(ELE_FW_PATH))
ifeq ($(CONFIG_IMXRT_ELE_FW_DOWNLOAD),y)
$(IMXRT_ELE_FW_ABS):
$(Q) mkdir -p $(dir $@)
$(call DOWNLOAD,$(ELE_FW_URL_BASE),$(ELE_FW_NAME),$@)
else
$(IMXRT_ELE_FW_ABS):
$(Q) test -f $@ || \
{ echo "error: ELE firmware not found at $@"; \
echo " (CONFIG_IMXRT_ELE_FW_DOWNLOAD is disabled, so it must be provided)"; \
exit 1; }
endif
endif