Skip to content

TFM: Remove TFM_MCUBOOT_PATH_DOWNLOAD Kconfig which downloads other things? In builds #98044

@nordicjm

Description

@nordicjm

Describe the bug

FAO @ceolin
It's been mentioned before that this option should be removed, strangely this option still seems present? The build system should not be letting a random module download random things for a build which firstly doesn't support offline building, secondly isn't related in any way to the west manifest (which should be used) and thirdly has absolutely no guarantee it isn't spoofed or manipulated.

If a user wants to use a custom MCUboot repo, they can (and always) have been able to do that with a custom west manifest which is the standard zephyr way for getting repositories, TFM should be no exception to this

Regression

  • This is a regression.

Steps to reproduce

No response

Relevant log output

Impact

Functional Limitation – Some features not working as expected, but system usable.

Environment

No response

Additional Context

No response

Metadata

Metadata

Assignees

Labels

area: TF-MARM Trusted Firmware-M (TF-M)bugThe issue is a bug, or the PR is fixing a bug

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions