]> git.proxmox.com Git - efi-boot-shim.git/blame - Make.defaults
Improve how the dbx hashes are handled
[efi-boot-shim.git] / Make.defaults
CommitLineData
d184bf10
PJ
1COMPILER ?= gcc
2CC = $(CROSS_COMPILE)$(COMPILER)
b681123a
PJ
3LD = $(CROSS_COMPILE)ld
4OBJCOPY = $(CROSS_COMPILE)objcopy
dd707859
PJ
5DOS2UNIX ?= dos2unix
6D2UFLAGS ?= -r -l -F -f -n
b681123a
PJ
7OPENSSL ?= openssl
8HEXDUMP ?= hexdump
9INSTALL ?= install
10PK12UTIL ?= pk12util
11CERTUTIL ?= certutil
12PESIGN ?= pesign
13SBSIGN ?= sbsign
14prefix ?= /usr
15prefix := $(abspath $(prefix))
16datadir ?= $(prefix)/share/
17PKGNAME ?= shim
18ESPROOTDIR ?= boot/efi/
19EFIBOOTDIR ?= $(ESPROOTDIR)EFI/BOOT/
20TARGETDIR ?= $(ESPROOTDIR)EFI/$(EFIDIR)/
21DATATARGETDIR ?= $(datadir)/$(PKGNAME)/$(VERSION)$(DASHRELEASE)/$(ARCH_SUFFIX)/
22DEBUGINFO ?= $(prefix)/lib/debug/
23DEBUGSOURCE ?= $(prefix)/src/debug/
24OSLABEL ?= $(EFIDIR)
25DEFAULT_LOADER ?= \\\\grub$(ARCH_SUFFIX).efi
d184bf10 26DASHJ ?= -j$(shell echo $$(($$(grep -c "^model name" /proc/cpuinfo) + 1)))
b681123a
PJ
27
28ARCH ?= $(shell $(CC) -dumpmachine | cut -f1 -d- | sed s,i[3456789]86,ia32,)
29OBJCOPY_GTE224 = $(shell expr `$(OBJCOPY) --version |grep ^"GNU objcopy" | sed 's/^.*\((.*)\|version\) //g' | cut -f1-2 -d.` \>= 2.24)
4edb31fc 30OPTIMIZATIONS ?= -Os
b681123a
PJ
31
32SUBDIRS = $(TOPDIR)/Cryptlib $(TOPDIR)/lib
33
f2924073 34EFI_INCLUDE ?= /usr/include/efi
b681123a
PJ
35EFI_INCLUDES = -nostdinc -I$(TOPDIR)/Cryptlib -I$(TOPDIR)/Cryptlib/Include \
36 -I$(EFI_INCLUDE) -I$(EFI_INCLUDE)/$(ARCH) -I$(EFI_INCLUDE)/protocol \
37 -I$(TOPDIR)/include -iquote $(TOPDIR) -iquote $(shell pwd)
38
b681123a
PJ
39EFI_CRT_OBJS = $(EFI_PATH)/crt0-efi-$(ARCH).o
40EFI_LDS = $(TOPDIR)/elf_$(ARCH)_efi.lds
41
138deeff
PJ
42CLANG_BUGS = $(if $(findstring gcc,$(CC)),-maccumulate-outgoing-args,)
43
b681123a
PJ
44COMMIT_ID ?= $(shell if [ -e .git ] ; then git log -1 --pretty=format:%H ; elif [ -f commit ]; then cat commit ; else echo master; fi)
45
b681123a 46ifeq ($(ARCH),x86_64)
32f71225
PJ
47 ARCH_CFLAGS ?= -mno-mmx -mno-sse -mno-red-zone -nostdinc \
48 $(CLANG_BUGS) -m64 \
49 -DEFI_FUNCTION_WRAPPER -DGNU_EFI_USE_MS_ABI \
50 -DNO_BUILTIN_VA_FUNCS -DMDE_CPU_X64 \
51 -DPAGE_SIZE=4096
b681123a
PJ
52 LIBDIR ?= $(prefix)/lib64
53 ARCH_SUFFIX ?= x64
54 ARCH_SUFFIX_UPPER ?= X64
55 ARCH_LDFLAGS ?=
10d6e3d9 56 TIMESTAMP_LOCATION := 136
b681123a
PJ
57endif
58ifeq ($(ARCH),ia32)
32f71225
PJ
59 ARCH_CFLAGS ?= -mno-mmx -mno-sse -mno-red-zone -nostdinc \
60 $(CLANG_BUGS) -m32 \
61 -DMDE_CPU_IA32 -DPAGE_SIZE=4096
b681123a
PJ
62 LIBDIR ?= $(prefix)/lib
63 ARCH_SUFFIX ?= ia32
64 ARCH_SUFFIX_UPPER ?= IA32
65 ARCH_LDFLAGS ?=
32f71225 66 ARCH_CFLAGS ?= -m32
10d6e3d9 67 TIMESTAMP_LOCATION := 136
b681123a
PJ
68endif
69ifeq ($(ARCH),aarch64)
32f71225 70 ARCH_CFLAGS ?= -DMDE_CPU_AARCH64 -DPAGE_SIZE=4096 -mstrict-align
b681123a
PJ
71 LIBDIR ?= $(prefix)/lib64
72 ARCH_SUFFIX ?= aa64
73 ARCH_SUFFIX_UPPER ?= AA64
74 FORMAT := -O binary
75 SUBSYSTEM := 0xa
76 ARCH_LDFLAGS += --defsym=EFI_SUBSYSTEM=$(SUBSYSTEM)
32f71225 77 ARCH_CFLAGS ?=
10d6e3d9 78 TIMESTAMP_LOCATION := 72
b681123a
PJ
79endif
80ifeq ($(ARCH),arm)
7f080b30 81 ARCH_CFLAGS ?= -DMDE_CPU_ARM -DPAGE_SIZE=4096 -mno-unaligned-access
b681123a
PJ
82 LIBDIR ?= $(prefix)/lib
83 ARCH_SUFFIX ?= arm
84 ARCH_SUFFIX_UPPER ?= ARM
85 FORMAT := -O binary
86 SUBSYSTEM := 0xa
87 ARCH_LDFLAGS += --defsym=EFI_SUBSYSTEM=$(SUBSYSTEM)
10d6e3d9 88 TIMESTAMP_LOCATION := 72
b681123a
PJ
89endif
90
4edb31fc 91CFLAGS = -ggdb $(OPTIMIZATIONS) -fno-stack-protector -fno-strict-aliasing -fpic \
32f71225
PJ
92 -fshort-wchar -Wall -Wsign-compare -Werror -fno-builtin \
93 -Werror=sign-compare -ffreestanding -std=gnu89 \
94 -I$(shell $(CC) $(ARCH_CFLAGS) -print-file-name=include) \
95 "-DDEFAULT_LOADER=L\"$(DEFAULT_LOADER)\"" \
96 "-DDEFAULT_LOADER_CHAR=\"$(DEFAULT_LOADER)\"" \
97 $(EFI_INCLUDES) $(ARCH_CFLAGS)
98
99ifneq ($(origin OVERRIDE_SECURITY_POLICY), undefined)
100 CFLAGS += -DOVERRIDE_SECURITY_POLICY
101endif
102
32f71225
PJ
103ifneq ($(origin REQUIRE_TPM), undefined)
104 CFLAGS += -DREQUIRE_TPM
105endif
106
4b0a61dc
PM
107ifneq ($(origin DISABLE_EBS_PROTECTION), undefined)
108 CFLAGS += -DDISABLE_EBS_PROTECTION
109endif
110
32f71225
PJ
111LIB_GCC = $(shell $(CC) $(ARCH_CFLAGS) -print-libgcc-file-name)
112EFI_LIBS = -lefi -lgnuefi --start-group Cryptlib/libcryptlib.a Cryptlib/OpenSSL/libopenssl.a --end-group $(LIB_GCC)
b681123a 113FORMAT ?= --target efi-app-$(ARCH)
e5f7b252 114EFI_PATH ?= $(shell [ -d $(LIBDIR)/gnuefi ] && echo "$(LIBDIR)/gnuefi" || echo "$(LIBDIR)")
b681123a
PJ
115
116MMSTEM ?= mm$(ARCH_SUFFIX)
117MMNAME = $(MMSTEM).efi
118MMSONAME = $(MMSTEM).so
119FBSTEM ?= fb$(ARCH_SUFFIX)
120FBNAME = $(FBSTEM).efi
121FBSONAME = $(FBSTEM).so
122SHIMSTEM ?= shim$(ARCH_SUFFIX)
123SHIMNAME = $(SHIMSTEM).efi
124SHIMSONAME = $(SHIMSTEM).so
125SHIMHASHNAME = $(SHIMSTEM).hash
126BOOTEFINAME ?= BOOT$(ARCH_SUFFIX_UPPER).EFI
127BOOTCSVNAME ?= BOOT$(ARCH_SUFFIX_UPPER).CSV
128
129CFLAGS += "-DEFI_ARCH=L\"$(ARCH_SUFFIX)\"" "-DDEBUGDIR=L\"/usr/lib/debug/usr/share/shim/$(ARCH_SUFFIX)-$(VERSION)$(DASHRELEASE)/\""
130
dd3a5d71
PJ
131ifneq ($(origin VENDOR_DB_FILE), undefined)
132 CFLAGS += -DVENDOR_DB_FILE=\"$(VENDOR_DB_FILE)\"
133endif
b681123a
PJ
134ifneq ($(origin VENDOR_CERT_FILE), undefined)
135 CFLAGS += -DVENDOR_CERT_FILE=\"$(VENDOR_CERT_FILE)\"
136endif
137ifneq ($(origin VENDOR_DBX_FILE), undefined)
138 CFLAGS += -DVENDOR_DBX_FILE=\"$(VENDOR_DBX_FILE)\"
139endif
140
141LDFLAGS = --hash-style=sysv -nostdlib -znocombreloc -T $(EFI_LDS) -shared -Bsymbolic -L$(EFI_PATH) -L$(LIBDIR) -LCryptlib -LCryptlib/OpenSSL $(EFI_CRT_OBJS) --build-id=sha1 $(ARCH_LDFLAGS) --no-undefined