feat: add sbom Makefile target

Adds sbom target that produces CycloneDX and SPDX
SBOM files for a specific TARGET+SIGN combination.
Sources extracted from OBJS variable via wildcard.
wolfcrypt sources compiled into wolfBoot are listed
as wolfBoot's own sources (not a separate component).
Requires GEN_SBOM or WOLFBOOT_LIB_WOLFSSL set.
pull/815/head
Mark Atwood 2026-06-22 18:39:54 -07:00 committed by Daniele Lacamera
parent 76b023008b
commit f0b28d2df5
1 changed files with 56 additions and 1 deletions

View File

@ -790,6 +790,61 @@ src/x86/fsp_s.o: $(FSP_S_BIN)
pico-sdk-info: FORCE
@echo "To complete the build, check IDE/pico-sdk/rp2350"
## SBOM generation
# Usage: make sbom TARGET=<target> SIGN=<scheme> [HASH=SHA256] [EXT_FLASH=0]
#
# TARGET and SIGN select the build configuration; they default to stm32f4 and
# ED25519 (via tools/config.mk) if not supplied. Pass them explicitly to get
# an SBOM that reflects your actual build configuration.
#
# Extracts the configuration-specific C source list from OBJS (which is fully
# assembled by this point — core wolfBoot + wolfcrypt + HAL sources are all
# included), preprocesses wolfBoot's include dirs via cc -dM -E on the host,
# and calls gen-sbom to emit CycloneDX and SPDX output files.
#
# wolfcrypt sources are compiled directly into the wolfBoot image and are
# therefore listed as wolfBoot's own sources, not as a separate component.
#
# Optional make variables:
# CRA_PYTHON Python interpreter (default: python3)
WOLFBOOT_VERSION:=$(shell sed -n \
's/.*LIBWOLFBOOT_VERSION_STRING[[:space:]]*"\([^"]*\)".*/\1/p' \
include/wolfboot/version.h)
GEN_SBOM:=$(WOLFBOOT_LIB_WOLFSSL)/scripts/gen-sbom
SBOM_CDX_OUT:=wolfboot-$(WOLFBOOT_VERSION).cdx.json
SBOM_SPDX_OUT:=wolfboot-$(WOLFBOOT_VERSION).spdx.json
SBOM_PYTHON?=$(or $(CRA_PYTHON),python3)
sbom:
@echo "wolfBoot SBOM: version=$(WOLFBOOT_VERSION) target=$(TARGET) sign=$(SIGN)"
@echo " Outputs: $(SBOM_CDX_OUT) $(SBOM_SPDX_OUT)"
$(eval _SBOM_SRCS := $(wildcard $(patsubst %.o,%.c,$(OBJS))))
@if [ -z "$(_SBOM_SRCS)" ]; then \
echo "ERROR: no .c sources found in OBJS — check that TARGET and SIGN are correct." >&2; \
exit 1; \
fi
@set -e; \
_dh=$$(mktemp /tmp/wolfboot-sbom-defines.XXXXXX); \
trap 'rm -f "$$_dh"' EXIT; \
cc -dM -E \
-I"$(WOLFBOOT_ROOT)/include" \
-I"$(WOLFBOOT_LIB_WOLFSSL)" \
-I"$(WOLFBOOT_LIB_WOLFSSL)/wolfcrypt/src" \
-DWOLFSSL_USER_SETTINGS \
-x c /dev/null >"$$_dh" 2>/dev/null || \
{ echo "ERROR: cc -dM -E failed; install a host C compiler." >&2; exit 1; }; \
$(SBOM_PYTHON) "$(GEN_SBOM)" \
--name wolfboot \
--version "$(WOLFBOOT_VERSION)" \
--supplier "wolfSSL Inc." \
--license-file "$(WOLFBOOT_ROOT)/LICENSE" \
--options-h "$$_dh" \
--srcs $(_SBOM_SRCS) \
--cdx-out "$(SBOM_CDX_OUT)" \
--spdx-out "$(SBOM_SPDX_OUT)"
@echo "SBOM written: $(SBOM_CDX_OUT) $(SBOM_SPDX_OUT)"
FORCE:
.PHONY: FORCE clean keytool_check squashelf_check
.PHONY: FORCE clean keytool_check squashelf_check sbom