mirror of https://github.com/wolfSSL/wolfBoot.git
wolfBoot ships as source. Users build it in many ways. Before this change, only the plain Make build could make an SBOM. So a user could not make an SBOM for the build that the user runs. This change adds one shared engine (tools/scripts/wolfboot-sbom.sh, which calls wolfSSL gen-sbom) and a front end for each build system. Every build makes a CycloneDX 1.6 and SPDX 2.3 document. The engine captures the configuration with the host compiler, so the SBOM is the same for GCC, Clang, LLVM, IAR, armcl, CCRX, and XC32. Routes: - Make, arch.mk, and vendor SDKs: make sbom TARGET=<t> SIGN=<a> - CMake and the Pico SDK: cmake --build <dir> --target sbom - IAR Embedded Workbench: ide-sbom/iar_sbom.py - Any IDE with a compilation database: ide-sbom/compdb_sbom.py - TI CCS, MPLAB X, Renesas, Xilinx: ide-sbom/route_through_sbom.sh - Per-HAL component: make sbom-hal TARGET=<t> - Zephyr module: ide-sbom/zephyr_sbom.py Make the SBOM reproducible. The captured macros can hold an absolute host path. For example, arch.mk passes -DPICO_SDK_PATH=$(PICO_SDK_PATH). The driver now redacts each absolute path but keeps the macro name, so the configuration record stays complete. Add --no-scrub for debug. Add a validator (ide-sbom/validate_sbom.py) and a CI canary (.github/workflows/test-sbom.yml) that runs and validates every route. The canary also checks that no host path leaks into the SBOM. Add docs/SBOM.md. The tools are product-neutral by design, so they can be shared across wolfSSL products later without logic changes. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> |
||
|---|---|---|
| .. | ||
| png | ||
| API.md | ||
| CMake.md | ||
| DICE.md | ||
| HAL.md | ||
| Loader.md | ||
| MCXN947-DICE.md | ||
| PQ.md | ||
| README.md | ||
| Renesas.md | ||
| SBOM.md | ||
| STM32-TZ.md | ||
| Signing.md | ||
| TPM.md | ||
| Targets.md | ||
| Windows.md | ||
| ata_security.md | ||
| azure_keyvault.md | ||
| compile.md | ||
| encrypted_partitions.md | ||
| firmware_image.md | ||
| firmware_update.md | ||
| flash-OTP.md | ||
| flash_partitions.md | ||
| fwTPM.md | ||
| hooks.md | ||
| keystore.md | ||
| lib.md | ||
| measured_boot.md | ||
| remote_flash.md | ||
| wolfHAL.md | ||
| wolfHSM.md | ||
README.md
wolfBoot Docs and Platform-Specific Details
See also: wolfBoot Product Overview and wolfBoot Manual.
- API.md - Overview of wolfBoot public APIs and how to use them.
- ata_security.md - ATA security features (lock/unlock, passwords) and wolfBoot integration.
- azure_keyvault.md - Using Azure Key Vault for key management and signing with wolfBoot.
- CMake.md - CMake-based build setup, presets, toolchains, and tips for building wolfBoot.
- compile.md - How to build/compile wolfBoot (toolchains, options, typical steps).
- encrypted_partitions.md - Creating and managing encrypted firmware/data partitions.
- firmware_image.md - wolfBoot firmware image format, layout, and metadata.
- firmware_update.md - Update flow: slots, verification, rollback, and recovery.
- flash-OTP.md - Using One-Time Programmable (OTP) regions in flash for secure data.
- flash_partitions.md - Flash partitioning schemes and configuration guidance.
- HAL.md - Hardware Abstraction Layer notes and porting considerations.
- hooks.md - User-defined hooks for injecting custom logic into the wolfBoot boot process.
- keystore.md - Keystore design, key storage, and access strategies.
- lib.md - Using wolfBoot as a library and linking/integration guidance.
- Loader.md - Loader/secondary stage behavior and handoff to application.
- measured_boot.md - Measured boot concepts and recording measurements (e.g., PCRs).
- png/ - Folder of images/diagrams referenced by the documentation.
- PQ.md - Post-quantum algorithms and PQC support in wolfBoot.
- README.md - Overview and index of the documentation set.
- remote_flash.md - Working with external/remote flash (SPI/QSPI, mapping, access).
- Renesas.md - Notes and specifics for Renesas platforms/ports.
- Signing.md - Keys, signatures, and the image signing workflow.
- STM32-TZ.md - STM32 TrustZone (Armv8-M) setup and usage with wolfBoot.
- STM32.md - STM32 platform notes, options, and integration tips.
- Targets.md - Supported targets and platform-specific configuration.
- TPM.md - TPM integration, measured boot, and attestation flows.
- wolfHSM.md - Integrating wolfHSM with wolfBoot for secure key operations.