blob: cdf042c2e75d8b580d3aa2eea48ce2c42c19ec43 [file] [log] [blame]
Doug Zongkereef39442009-04-02 12:14:19 -07001# Copyright (C) 2008 The Android Open Source Project
2#
3# Licensed under the Apache License, Version 2.0 (the "License");
4# you may not use this file except in compliance with the License.
5# You may obtain a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS,
11# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12# See the License for the specific language governing permissions and
13# limitations under the License.
14
Tao Bao89fbb0f2017-01-10 10:47:58 -080015from __future__ import print_function
16
Tao Baoda30cfa2017-12-01 16:19:46 -080017import base64
Yifan Hong10c530d2018-12-27 17:34:18 -080018import collections
Doug Zongkerea5d7a92010-09-12 15:26:16 -070019import copy
Kelvin Zhang0876c412020-06-23 15:06:58 -040020import datetime
Doug Zongker8ce7c252009-05-22 13:34:54 -070021import errno
Tao Bao0ff15de2019-03-20 11:26:06 -070022import fnmatch
Doug Zongkereef39442009-04-02 12:14:19 -070023import getopt
24import getpass
Narayan Kamatha07bf042017-08-14 14:49:21 +010025import gzip
Doug Zongker05d3dea2009-06-22 11:32:31 -070026import imp
Tao Bao32fcdab2018-10-12 10:30:39 -070027import json
28import logging
29import logging.config
Doug Zongkereef39442009-04-02 12:14:19 -070030import os
Ying Wang7e6d4e42010-12-13 16:25:36 -080031import platform
Doug Zongkereef39442009-04-02 12:14:19 -070032import re
T.R. Fullhart37e10522013-03-18 10:31:26 -070033import shlex
Doug Zongkereef39442009-04-02 12:14:19 -070034import shutil
35import subprocess
36import sys
37import tempfile
Doug Zongkerea5d7a92010-09-12 15:26:16 -070038import threading
39import time
Doug Zongker048e7ca2009-06-15 14:31:53 -070040import zipfile
Tao Bao12d87fc2018-01-31 12:18:52 -080041from hashlib import sha1, sha256
Doug Zongkereef39442009-04-02 12:14:19 -070042
Tianjie Xu41976c72019-07-03 13:57:01 -070043import images
Kelvin Zhang27324132021-03-22 15:38:38 -040044import rangelib
Tao Baoc765cca2018-01-31 17:32:40 -080045import sparse_img
Tianjie Xu41976c72019-07-03 13:57:01 -070046from blockimgdiff import BlockImageDiff
Doug Zongkerab7ca1d2014-08-26 10:40:28 -070047
Tao Bao32fcdab2018-10-12 10:30:39 -070048logger = logging.getLogger(__name__)
49
Tao Bao986ee862018-10-04 15:46:16 -070050
Dan Albert8b72aef2015-03-23 19:13:21 -070051class Options(object):
Tao Baoafd92a82019-10-10 22:44:22 -070052
Dan Albert8b72aef2015-03-23 19:13:21 -070053 def __init__(self):
Tao Baoafd92a82019-10-10 22:44:22 -070054 # Set up search path, in order to find framework/ and lib64/. At the time of
55 # running this function, user-supplied search path (`--path`) hasn't been
56 # available. So the value set here is the default, which might be overridden
57 # by commandline flag later.
Kelvin Zhang0876c412020-06-23 15:06:58 -040058 exec_path = os.path.realpath(sys.argv[0])
Tao Baoafd92a82019-10-10 22:44:22 -070059 if exec_path.endswith('.py'):
60 script_name = os.path.basename(exec_path)
61 # logger hasn't been initialized yet at this point. Use print to output
62 # warnings.
63 print(
64 'Warning: releasetools script should be invoked as hermetic Python '
Kelvin Zhang0876c412020-06-23 15:06:58 -040065 'executable -- build and run `{}` directly.'.format(
66 script_name[:-3]),
Tao Baoafd92a82019-10-10 22:44:22 -070067 file=sys.stderr)
Kelvin Zhang0876c412020-06-23 15:06:58 -040068 self.search_path = os.path.dirname(os.path.dirname(exec_path))
Pavel Salomatov32676552019-03-06 20:00:45 +030069
Dan Albert8b72aef2015-03-23 19:13:21 -070070 self.signapk_path = "framework/signapk.jar" # Relative to search_path
Kelvin Zhang4fc3aa02021-11-16 18:58:58 -080071 if not os.path.exists(os.path.join(self.search_path, self.signapk_path)):
72 if "ANDROID_HOST_OUT" in os.environ:
73 self.search_path = os.environ["ANDROID_HOST_OUT"]
Alex Klyubin9667b182015-12-10 13:38:50 -080074 self.signapk_shared_library_path = "lib64" # Relative to search_path
Melisa Carranza Zunigae0a977a2022-06-16 18:44:27 +020075 self.sign_sepolicy_path = None
Dan Albert8b72aef2015-03-23 19:13:21 -070076 self.extra_signapk_args = []
Melisa Carranza Zunigae0a977a2022-06-16 18:44:27 +020077 self.extra_sign_sepolicy_args = []
Martin Stjernholm58472e82022-01-07 22:08:47 +000078 self.aapt2_path = "aapt2"
Dan Albert8b72aef2015-03-23 19:13:21 -070079 self.java_path = "java" # Use the one on the path by default.
Tao Baoe95540e2016-11-08 12:08:53 -080080 self.java_args = ["-Xmx2048m"] # The default JVM args.
Tianjie Xu88a759d2020-01-23 10:47:54 -080081 self.android_jar_path = None
Dan Albert8b72aef2015-03-23 19:13:21 -070082 self.public_key_suffix = ".x509.pem"
83 self.private_key_suffix = ".pk8"
Dan Albertcd9ecc02015-03-27 16:37:23 -070084 # use otatools built boot_signer by default
Dan Albert8b72aef2015-03-23 19:13:21 -070085 self.verbose = False
86 self.tempfiles = []
87 self.device_specific = None
88 self.extras = {}
89 self.info_dict = None
Tao Bao6f0b2192015-10-13 16:37:12 -070090 self.source_info_dict = None
91 self.target_info_dict = None
Dan Albert8b72aef2015-03-23 19:13:21 -070092 self.worker_threads = None
Tao Bao575d68a2015-08-07 19:49:45 -070093 # Stash size cannot exceed cache_size * threshold.
94 self.cache_size = None
95 self.stash_threshold = 0.8
Yifan Hong30910932019-10-25 20:36:55 -070096 self.logfile = None
Yifan Hong8e332ff2020-07-29 17:51:55 -070097 self.host_tools = {}
Melisa Carranza Zunigae0a977a2022-06-16 18:44:27 +020098 self.sepolicy_name = 'sepolicy.apex'
Dan Albert8b72aef2015-03-23 19:13:21 -070099
100
101OPTIONS = Options()
Doug Zongkereef39442009-04-02 12:14:19 -0700102
Tao Bao71197512018-10-11 14:08:45 -0700103# The block size that's used across the releasetools scripts.
104BLOCK_SIZE = 4096
105
Doug Zongkerf6a53aa2009-12-15 15:06:55 -0800106# Values for "certificate" in apkcerts that mean special things.
107SPECIAL_CERT_STRINGS = ("PRESIGNED", "EXTERNAL")
108
Tao Bao5cc0abb2019-03-21 10:18:05 -0700109# The partitions allowed to be signed by AVB (Android Verified Boot 2.0). Note
110# that system_other is not in the list because we don't want to include its
Tianjiebf0b8a82021-03-03 17:31:04 -0800111# descriptor into vbmeta.img. When adding a new entry here, the
112# AVB_FOOTER_ARGS_BY_PARTITION in sign_target_files_apks need to be updated
113# accordingly.
Devin Mooreafdd7c72021-12-13 22:04:08 +0000114AVB_PARTITIONS = ('boot', 'init_boot', 'dtbo', 'odm', 'product', 'pvmfw', 'recovery',
Lucas Wei03230252022-04-18 16:00:40 +0800115 'system', 'system_ext', 'vendor', 'vendor_boot', 'vendor_kernel_boot',
Ramji Jiyani13a41372022-01-27 07:05:08 +0000116 'vendor_dlkm', 'odm_dlkm', 'system_dlkm')
Tao Bao9dd909e2017-11-14 11:27:32 -0800117
Tao Bao08c190f2019-06-03 23:07:58 -0700118# Chained VBMeta partitions.
119AVB_VBMETA_PARTITIONS = ('vbmeta_system', 'vbmeta_vendor')
120
Tianjie Xu861f4132018-09-12 11:49:33 -0700121# Partitions that should have their care_map added to META/care_map.pb
Kelvin Zhang39aea442020-08-17 11:04:25 -0400122PARTITIONS_WITH_CARE_MAP = [
Yifan Hongcfb917a2020-05-07 14:58:20 -0700123 'system',
124 'vendor',
125 'product',
126 'system_ext',
127 'odm',
128 'vendor_dlkm',
Yifan Hongf496f1b2020-07-15 16:52:59 -0700129 'odm_dlkm',
Ramji Jiyani13a41372022-01-27 07:05:08 +0000130 'system_dlkm',
Kelvin Zhang39aea442020-08-17 11:04:25 -0400131]
Tianjie Xu861f4132018-09-12 11:49:33 -0700132
Yifan Hong5057b952021-01-07 14:09:57 -0800133# Partitions with a build.prop file
Devin Mooreafdd7c72021-12-13 22:04:08 +0000134PARTITIONS_WITH_BUILD_PROP = PARTITIONS_WITH_CARE_MAP + ['boot', 'init_boot']
Yifan Hong5057b952021-01-07 14:09:57 -0800135
Yifan Hongc65a0542021-01-07 14:21:01 -0800136# See sysprop.mk. If file is moved, add new search paths here; don't remove
137# existing search paths.
138RAMDISK_BUILD_PROP_REL_PATHS = ['system/etc/ramdisk/build.prop']
Tianjie Xu861f4132018-09-12 11:49:33 -0700139
Kelvin Zhang563750f2021-04-28 12:46:17 -0400140
Tianjie Xu209db462016-05-24 17:34:52 -0700141class ErrorCode(object):
142 """Define error_codes for failures that happen during the actual
143 update package installation.
144
145 Error codes 0-999 are reserved for failures before the package
146 installation (i.e. low battery, package verification failure).
147 Detailed code in 'bootable/recovery/error_code.h' """
148
149 SYSTEM_VERIFICATION_FAILURE = 1000
150 SYSTEM_UPDATE_FAILURE = 1001
151 SYSTEM_UNEXPECTED_CONTENTS = 1002
152 SYSTEM_NONZERO_CONTENTS = 1003
153 SYSTEM_RECOVER_FAILURE = 1004
154 VENDOR_VERIFICATION_FAILURE = 2000
155 VENDOR_UPDATE_FAILURE = 2001
156 VENDOR_UNEXPECTED_CONTENTS = 2002
157 VENDOR_NONZERO_CONTENTS = 2003
158 VENDOR_RECOVER_FAILURE = 2004
159 OEM_PROP_MISMATCH = 3000
160 FINGERPRINT_MISMATCH = 3001
161 THUMBPRINT_MISMATCH = 3002
162 OLDER_BUILD = 3003
163 DEVICE_MISMATCH = 3004
164 BAD_PATCH_FILE = 3005
165 INSUFFICIENT_CACHE_SPACE = 3006
166 TUNE_PARTITION_FAILURE = 3007
167 APPLY_PATCH_FAILURE = 3008
Doug Zongkerf6a53aa2009-12-15 15:06:55 -0800168
Tao Bao80921982018-03-21 21:02:19 -0700169
Dan Albert8b72aef2015-03-23 19:13:21 -0700170class ExternalError(RuntimeError):
171 pass
Doug Zongkereef39442009-04-02 12:14:19 -0700172
173
Tao Bao32fcdab2018-10-12 10:30:39 -0700174def InitLogging():
175 DEFAULT_LOGGING_CONFIG = {
176 'version': 1,
177 'disable_existing_loggers': False,
178 'formatters': {
179 'standard': {
180 'format':
181 '%(asctime)s - %(filename)s - %(levelname)-8s: %(message)s',
182 'datefmt': '%Y-%m-%d %H:%M:%S',
183 },
184 },
185 'handlers': {
186 'default': {
187 'class': 'logging.StreamHandler',
188 'formatter': 'standard',
Yifan Hong30910932019-10-25 20:36:55 -0700189 'level': 'WARNING',
Tao Bao32fcdab2018-10-12 10:30:39 -0700190 },
191 },
192 'loggers': {
193 '': {
194 'handlers': ['default'],
Tao Bao32fcdab2018-10-12 10:30:39 -0700195 'propagate': True,
Yifan Hong30910932019-10-25 20:36:55 -0700196 'level': 'INFO',
Tao Bao32fcdab2018-10-12 10:30:39 -0700197 }
198 }
199 }
200 env_config = os.getenv('LOGGING_CONFIG')
201 if env_config:
202 with open(env_config) as f:
203 config = json.load(f)
204 else:
205 config = DEFAULT_LOGGING_CONFIG
206
207 # Increase the logging level for verbose mode.
208 if OPTIONS.verbose:
Yifan Hong30910932019-10-25 20:36:55 -0700209 config = copy.deepcopy(config)
210 config['handlers']['default']['level'] = 'INFO'
211
212 if OPTIONS.logfile:
213 config = copy.deepcopy(config)
214 config['handlers']['logfile'] = {
Kelvin Zhang0876c412020-06-23 15:06:58 -0400215 'class': 'logging.FileHandler',
216 'formatter': 'standard',
217 'level': 'INFO',
218 'mode': 'w',
219 'filename': OPTIONS.logfile,
Yifan Hong30910932019-10-25 20:36:55 -0700220 }
221 config['loggers']['']['handlers'].append('logfile')
Tao Bao32fcdab2018-10-12 10:30:39 -0700222
223 logging.config.dictConfig(config)
224
225
Yifan Hong8e332ff2020-07-29 17:51:55 -0700226def SetHostToolLocation(tool_name, location):
227 OPTIONS.host_tools[tool_name] = location
228
Kelvin Zhang563750f2021-04-28 12:46:17 -0400229
Jiyong Parkc8c94ac2020-11-20 03:03:57 +0900230def FindHostToolPath(tool_name):
231 """Finds the path to the host tool.
232
233 Args:
234 tool_name: name of the tool to find
235 Returns:
236 path to the tool if found under either one of the host_tools map or under
237 the same directory as this binary is located at. If not found, tool_name
238 is returned.
239 """
240 if tool_name in OPTIONS.host_tools:
241 return OPTIONS.host_tools[tool_name]
242
243 my_dir = os.path.dirname(os.path.realpath(sys.argv[0]))
244 tool_path = os.path.join(my_dir, tool_name)
245 if os.path.exists(tool_path):
246 return tool_path
247
248 return tool_name
Yifan Hong8e332ff2020-07-29 17:51:55 -0700249
Kelvin Zhang563750f2021-04-28 12:46:17 -0400250
Tao Bao39451582017-05-04 11:10:47 -0700251def Run(args, verbose=None, **kwargs):
Tao Bao73dd4f42018-10-04 16:25:33 -0700252 """Creates and returns a subprocess.Popen object.
Tao Bao39451582017-05-04 11:10:47 -0700253
Tao Bao73dd4f42018-10-04 16:25:33 -0700254 Args:
255 args: The command represented as a list of strings.
Tao Bao32fcdab2018-10-12 10:30:39 -0700256 verbose: Whether the commands should be shown. Default to the global
257 verbosity if unspecified.
Tao Bao73dd4f42018-10-04 16:25:33 -0700258 kwargs: Any additional args to be passed to subprocess.Popen(), such as env,
259 stdin, etc. stdout and stderr will default to subprocess.PIPE and
260 subprocess.STDOUT respectively unless caller specifies any of them.
Tao Baoda30cfa2017-12-01 16:19:46 -0800261 universal_newlines will default to True, as most of the users in
262 releasetools expect string output.
Tao Bao73dd4f42018-10-04 16:25:33 -0700263
264 Returns:
265 A subprocess.Popen object.
Tao Bao39451582017-05-04 11:10:47 -0700266 """
Tao Bao73dd4f42018-10-04 16:25:33 -0700267 if 'stdout' not in kwargs and 'stderr' not in kwargs:
268 kwargs['stdout'] = subprocess.PIPE
269 kwargs['stderr'] = subprocess.STDOUT
Tao Baoda30cfa2017-12-01 16:19:46 -0800270 if 'universal_newlines' not in kwargs:
271 kwargs['universal_newlines'] = True
Yifan Hong8e332ff2020-07-29 17:51:55 -0700272
Jiyong Parkc8c94ac2020-11-20 03:03:57 +0900273 if args:
274 # Make a copy of args in case client relies on the content of args later.
Yifan Hong8e332ff2020-07-29 17:51:55 -0700275 args = args[:]
Jiyong Parkc8c94ac2020-11-20 03:03:57 +0900276 args[0] = FindHostToolPath(args[0])
Yifan Hong8e332ff2020-07-29 17:51:55 -0700277
Kelvin Zhang766eea72021-06-03 09:36:08 -0400278 if verbose is None:
279 verbose = OPTIONS.verbose
280
Tao Bao32fcdab2018-10-12 10:30:39 -0700281 # Don't log any if caller explicitly says so.
Kelvin Zhang0876c412020-06-23 15:06:58 -0400282 if verbose:
Tao Bao32fcdab2018-10-12 10:30:39 -0700283 logger.info(" Running: \"%s\"", " ".join(args))
Doug Zongkereef39442009-04-02 12:14:19 -0700284 return subprocess.Popen(args, **kwargs)
285
286
Tao Bao986ee862018-10-04 15:46:16 -0700287def RunAndCheckOutput(args, verbose=None, **kwargs):
288 """Runs the given command and returns the output.
289
290 Args:
291 args: The command represented as a list of strings.
Tao Bao32fcdab2018-10-12 10:30:39 -0700292 verbose: Whether the commands should be shown. Default to the global
293 verbosity if unspecified.
Tao Bao986ee862018-10-04 15:46:16 -0700294 kwargs: Any additional args to be passed to subprocess.Popen(), such as env,
295 stdin, etc. stdout and stderr will default to subprocess.PIPE and
296 subprocess.STDOUT respectively unless caller specifies any of them.
297
298 Returns:
299 The output string.
300
301 Raises:
302 ExternalError: On non-zero exit from the command.
303 """
Tao Bao986ee862018-10-04 15:46:16 -0700304 proc = Run(args, verbose=verbose, **kwargs)
305 output, _ = proc.communicate()
Regnier, Philippe2f7e11e2019-05-22 10:10:57 +0800306 if output is None:
307 output = ""
Tao Bao32fcdab2018-10-12 10:30:39 -0700308 # Don't log any if caller explicitly says so.
Kelvin Zhang0876c412020-06-23 15:06:58 -0400309 if verbose:
Tao Bao32fcdab2018-10-12 10:30:39 -0700310 logger.info("%s", output.rstrip())
Tao Bao986ee862018-10-04 15:46:16 -0700311 if proc.returncode != 0:
312 raise ExternalError(
313 "Failed to run command '{}' (exit code {}):\n{}".format(
314 args, proc.returncode, output))
315 return output
316
317
Tao Baoc765cca2018-01-31 17:32:40 -0800318def RoundUpTo4K(value):
319 rounded_up = value + 4095
320 return rounded_up - (rounded_up % 4096)
321
322
Ying Wang7e6d4e42010-12-13 16:25:36 -0800323def CloseInheritedPipes():
324 """ Gmake in MAC OS has file descriptor (PIPE) leak. We close those fds
325 before doing other work."""
326 if platform.system() != "Darwin":
327 return
328 for d in range(3, 1025):
329 try:
330 stat = os.fstat(d)
331 if stat is not None:
332 pipebit = stat[0] & 0x1000
333 if pipebit != 0:
334 os.close(d)
335 except OSError:
336 pass
337
338
Tao Bao1c320f82019-10-04 23:25:12 -0700339class BuildInfo(object):
340 """A class that holds the information for a given build.
341
342 This class wraps up the property querying for a given source or target build.
343 It abstracts away the logic of handling OEM-specific properties, and caches
344 the commonly used properties such as fingerprint.
345
346 There are two types of info dicts: a) build-time info dict, which is generated
347 at build time (i.e. included in a target_files zip); b) OEM info dict that is
348 specified at package generation time (via command line argument
349 '--oem_settings'). If a build doesn't use OEM-specific properties (i.e. not
350 having "oem_fingerprint_properties" in build-time info dict), all the queries
351 would be answered based on build-time info dict only. Otherwise if using
352 OEM-specific properties, some of them will be calculated from two info dicts.
353
354 Users can query properties similarly as using a dict() (e.g. info['fstab']),
Daniel Normand5fe8622020-01-08 17:01:11 -0800355 or to query build properties via GetBuildProp() or GetPartitionBuildProp().
Tao Bao1c320f82019-10-04 23:25:12 -0700356
357 Attributes:
358 info_dict: The build-time info dict.
359 is_ab: Whether it's a build that uses A/B OTA.
360 oem_dicts: A list of OEM dicts.
361 oem_props: A list of OEM properties that should be read from OEM dicts; None
362 if the build doesn't use any OEM-specific property.
363 fingerprint: The fingerprint of the build, which would be calculated based
364 on OEM properties if applicable.
365 device: The device name, which could come from OEM dicts if applicable.
366 """
367
368 _RO_PRODUCT_RESOLVE_PROPS = ["ro.product.brand", "ro.product.device",
369 "ro.product.manufacturer", "ro.product.model",
370 "ro.product.name"]
Steven Laver8e2086e2020-04-27 16:26:31 -0700371 _RO_PRODUCT_PROPS_DEFAULT_SOURCE_ORDER_CURRENT = [
372 "product", "odm", "vendor", "system_ext", "system"]
373 _RO_PRODUCT_PROPS_DEFAULT_SOURCE_ORDER_ANDROID_10 = [
374 "product", "product_services", "odm", "vendor", "system"]
375 _RO_PRODUCT_PROPS_DEFAULT_SOURCE_ORDER_LEGACY = []
Tao Bao1c320f82019-10-04 23:25:12 -0700376
Tianjiefdda51d2021-05-05 14:46:35 -0700377 # The length of vbmeta digest to append to the fingerprint
378 _VBMETA_DIGEST_SIZE_USED = 8
379
380 def __init__(self, info_dict, oem_dicts=None, use_legacy_id=False):
Tao Bao1c320f82019-10-04 23:25:12 -0700381 """Initializes a BuildInfo instance with the given dicts.
382
383 Note that it only wraps up the given dicts, without making copies.
384
385 Arguments:
386 info_dict: The build-time info dict.
387 oem_dicts: A list of OEM dicts (which is parsed from --oem_settings). Note
388 that it always uses the first dict to calculate the fingerprint or the
389 device name. The rest would be used for asserting OEM properties only
390 (e.g. one package can be installed on one of these devices).
Tianjiefdda51d2021-05-05 14:46:35 -0700391 use_legacy_id: Use the legacy build id to construct the fingerprint. This
392 is used when we need a BuildInfo class, while the vbmeta digest is
393 unavailable.
Tao Bao1c320f82019-10-04 23:25:12 -0700394
395 Raises:
396 ValueError: On invalid inputs.
397 """
398 self.info_dict = info_dict
399 self.oem_dicts = oem_dicts
400
401 self._is_ab = info_dict.get("ab_update") == "true"
Tianjiefdda51d2021-05-05 14:46:35 -0700402 self.use_legacy_id = use_legacy_id
Tao Bao1c320f82019-10-04 23:25:12 -0700403
Hongguang Chend7c160f2020-05-03 21:24:26 -0700404 # Skip _oem_props if oem_dicts is None to use BuildInfo in
405 # sign_target_files_apks
406 if self.oem_dicts:
407 self._oem_props = info_dict.get("oem_fingerprint_properties")
408 else:
409 self._oem_props = None
Tao Bao1c320f82019-10-04 23:25:12 -0700410
Daniel Normand5fe8622020-01-08 17:01:11 -0800411 def check_fingerprint(fingerprint):
412 if (" " in fingerprint or any(ord(ch) > 127 for ch in fingerprint)):
413 raise ValueError(
414 'Invalid build fingerprint: "{}". See the requirement in Android CDD '
415 "3.2.2. Build Parameters.".format(fingerprint))
416
Daniel Normand5fe8622020-01-08 17:01:11 -0800417 self._partition_fingerprints = {}
Yifan Hong5057b952021-01-07 14:09:57 -0800418 for partition in PARTITIONS_WITH_BUILD_PROP:
Daniel Normand5fe8622020-01-08 17:01:11 -0800419 try:
420 fingerprint = self.CalculatePartitionFingerprint(partition)
421 check_fingerprint(fingerprint)
422 self._partition_fingerprints[partition] = fingerprint
423 except ExternalError:
424 continue
425 if "system" in self._partition_fingerprints:
Yifan Hong5057b952021-01-07 14:09:57 -0800426 # system_other is not included in PARTITIONS_WITH_BUILD_PROP, but does
Daniel Normand5fe8622020-01-08 17:01:11 -0800427 # need a fingerprint when creating the image.
428 self._partition_fingerprints[
429 "system_other"] = self._partition_fingerprints["system"]
430
Tao Bao1c320f82019-10-04 23:25:12 -0700431 # These two should be computed only after setting self._oem_props.
432 self._device = self.GetOemProperty("ro.product.device")
433 self._fingerprint = self.CalculateFingerprint()
Daniel Normand5fe8622020-01-08 17:01:11 -0800434 check_fingerprint(self._fingerprint)
Tao Bao1c320f82019-10-04 23:25:12 -0700435
436 @property
437 def is_ab(self):
438 return self._is_ab
439
440 @property
441 def device(self):
442 return self._device
443
444 @property
445 def fingerprint(self):
446 return self._fingerprint
447
448 @property
Kelvin Zhang563750f2021-04-28 12:46:17 -0400449 def is_vabc(self):
450 vendor_prop = self.info_dict.get("vendor.build.prop")
451 vabc_enabled = vendor_prop and \
452 vendor_prop.GetProp("ro.virtual_ab.compression.enabled") == "true"
453 return vabc_enabled
454
455 @property
Kelvin Zhanga9a87ec2022-05-04 16:44:52 -0700456 def is_android_r(self):
457 system_prop = self.info_dict.get("system.build.prop")
458 return system_prop and system_prop.GetProp("ro.build.version.release") == "11"
459
460 @property
Kelvin Zhangad427382021-08-12 16:19:09 -0700461 def is_vabc_xor(self):
462 vendor_prop = self.info_dict.get("vendor.build.prop")
463 vabc_xor_enabled = vendor_prop and \
464 vendor_prop.GetProp("ro.virtual_ab.compression.xor.enabled") == "true"
465 return vabc_xor_enabled
466
467 @property
Kelvin Zhang10eac082021-06-10 14:32:19 -0400468 def vendor_suppressed_vabc(self):
469 vendor_prop = self.info_dict.get("vendor.build.prop")
470 vabc_suppressed = vendor_prop and \
471 vendor_prop.GetProp("ro.vendor.build.dont_use_vabc")
472 return vabc_suppressed and vabc_suppressed.lower() == "true"
473
474 @property
Tao Bao1c320f82019-10-04 23:25:12 -0700475 def oem_props(self):
476 return self._oem_props
477
478 def __getitem__(self, key):
479 return self.info_dict[key]
480
481 def __setitem__(self, key, value):
482 self.info_dict[key] = value
483
484 def get(self, key, default=None):
485 return self.info_dict.get(key, default)
486
487 def items(self):
488 return self.info_dict.items()
489
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000490 def _GetRawBuildProp(self, prop, partition):
491 prop_file = '{}.build.prop'.format(
492 partition) if partition else 'build.prop'
493 partition_props = self.info_dict.get(prop_file)
494 if not partition_props:
495 return None
496 return partition_props.GetProp(prop)
497
Daniel Normand5fe8622020-01-08 17:01:11 -0800498 def GetPartitionBuildProp(self, prop, partition):
499 """Returns the inquired build property for the provided partition."""
Yifan Hong10482a22021-01-07 14:38:41 -0800500
Kelvin Zhang8250d2c2022-03-23 19:46:09 +0000501 # Boot image and init_boot image uses ro.[product.]bootimage instead of boot.
Devin Mooreb5195ff2022-02-11 18:44:26 +0000502 # This comes from the generic ramdisk
Kelvin Zhang8250d2c2022-03-23 19:46:09 +0000503 prop_partition = "bootimage" if partition == "boot" or partition == "init_boot" else partition
Yifan Hong10482a22021-01-07 14:38:41 -0800504
Daniel Normand5fe8622020-01-08 17:01:11 -0800505 # If provided a partition for this property, only look within that
506 # partition's build.prop.
507 if prop in BuildInfo._RO_PRODUCT_RESOLVE_PROPS:
Yifan Hong10482a22021-01-07 14:38:41 -0800508 prop = prop.replace("ro.product", "ro.product.{}".format(prop_partition))
Daniel Normand5fe8622020-01-08 17:01:11 -0800509 else:
Yifan Hong10482a22021-01-07 14:38:41 -0800510 prop = prop.replace("ro.", "ro.{}.".format(prop_partition))
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000511
512 prop_val = self._GetRawBuildProp(prop, partition)
513 if prop_val is not None:
514 return prop_val
515 raise ExternalError("couldn't find %s in %s.build.prop" %
516 (prop, partition))
Daniel Normand5fe8622020-01-08 17:01:11 -0800517
Tao Bao1c320f82019-10-04 23:25:12 -0700518 def GetBuildProp(self, prop):
Daniel Normand5fe8622020-01-08 17:01:11 -0800519 """Returns the inquired build property from the standard build.prop file."""
Tao Bao1c320f82019-10-04 23:25:12 -0700520 if prop in BuildInfo._RO_PRODUCT_RESOLVE_PROPS:
521 return self._ResolveRoProductBuildProp(prop)
522
Tianjiefdda51d2021-05-05 14:46:35 -0700523 if prop == "ro.build.id":
524 return self._GetBuildId()
525
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000526 prop_val = self._GetRawBuildProp(prop, None)
527 if prop_val is not None:
528 return prop_val
529
530 raise ExternalError("couldn't find %s in build.prop" % (prop,))
Tao Bao1c320f82019-10-04 23:25:12 -0700531
532 def _ResolveRoProductBuildProp(self, prop):
533 """Resolves the inquired ro.product.* build property"""
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000534 prop_val = self._GetRawBuildProp(prop, None)
Tao Bao1c320f82019-10-04 23:25:12 -0700535 if prop_val:
536 return prop_val
537
Steven Laver8e2086e2020-04-27 16:26:31 -0700538 default_source_order = self._GetRoProductPropsDefaultSourceOrder()
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000539 source_order_val = self._GetRawBuildProp(
540 "ro.product.property_source_order", None)
Tao Bao1c320f82019-10-04 23:25:12 -0700541 if source_order_val:
542 source_order = source_order_val.split(",")
543 else:
Steven Laver8e2086e2020-04-27 16:26:31 -0700544 source_order = default_source_order
Tao Bao1c320f82019-10-04 23:25:12 -0700545
546 # Check that all sources in ro.product.property_source_order are valid
Steven Laver8e2086e2020-04-27 16:26:31 -0700547 if any([x not in default_source_order for x in source_order]):
Tao Bao1c320f82019-10-04 23:25:12 -0700548 raise ExternalError(
549 "Invalid ro.product.property_source_order '{}'".format(source_order))
550
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000551 for source_partition in source_order:
Tao Bao1c320f82019-10-04 23:25:12 -0700552 source_prop = prop.replace(
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000553 "ro.product", "ro.product.{}".format(source_partition), 1)
554 prop_val = self._GetRawBuildProp(source_prop, source_partition)
Tao Bao1c320f82019-10-04 23:25:12 -0700555 if prop_val:
556 return prop_val
557
558 raise ExternalError("couldn't resolve {}".format(prop))
559
Steven Laver8e2086e2020-04-27 16:26:31 -0700560 def _GetRoProductPropsDefaultSourceOrder(self):
561 # NOTE: refer to CDDs and android.os.Build.VERSION for the definition and
562 # values of these properties for each Android release.
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000563 android_codename = self._GetRawBuildProp("ro.build.version.codename", None)
Steven Laver8e2086e2020-04-27 16:26:31 -0700564 if android_codename == "REL":
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000565 android_version = self._GetRawBuildProp("ro.build.version.release", None)
Steven Laver8e2086e2020-04-27 16:26:31 -0700566 if android_version == "10":
567 return BuildInfo._RO_PRODUCT_PROPS_DEFAULT_SOURCE_ORDER_ANDROID_10
568 # NOTE: float() conversion of android_version will have rounding error.
569 # We are checking for "9" or less, and using "< 10" is well outside of
570 # possible floating point rounding.
571 try:
572 android_version_val = float(android_version)
573 except ValueError:
574 android_version_val = 0
575 if android_version_val < 10:
576 return BuildInfo._RO_PRODUCT_PROPS_DEFAULT_SOURCE_ORDER_LEGACY
577 return BuildInfo._RO_PRODUCT_PROPS_DEFAULT_SOURCE_ORDER_CURRENT
578
Tianjieb37c5be2020-10-15 21:27:10 -0700579 def _GetPlatformVersion(self):
580 version_sdk = self.GetBuildProp("ro.build.version.sdk")
581 # init code switches to version_release_or_codename (see b/158483506). After
582 # API finalization, release_or_codename will be the same as release. This
583 # is the best effort to support pre-S dev stage builds.
584 if int(version_sdk) >= 30:
585 try:
586 return self.GetBuildProp("ro.build.version.release_or_codename")
587 except ExternalError:
588 logger.warning('Failed to find ro.build.version.release_or_codename')
589
590 return self.GetBuildProp("ro.build.version.release")
591
Tianjiefdda51d2021-05-05 14:46:35 -0700592 def _GetBuildId(self):
593 build_id = self._GetRawBuildProp("ro.build.id", None)
594 if build_id:
595 return build_id
596
597 legacy_build_id = self.GetBuildProp("ro.build.legacy.id")
598 if not legacy_build_id:
599 raise ExternalError("Couldn't find build id in property file")
600
601 if self.use_legacy_id:
602 return legacy_build_id
603
604 # Append the top 8 chars of vbmeta digest to the existing build id. The
605 # logic needs to match the one in init, so that OTA can deliver correctly.
606 avb_enable = self.info_dict.get("avb_enable") == "true"
607 if not avb_enable:
608 raise ExternalError("AVB isn't enabled when using legacy build id")
609
610 vbmeta_digest = self.info_dict.get("vbmeta_digest")
611 if not vbmeta_digest:
612 raise ExternalError("Vbmeta digest isn't provided when using legacy build"
613 " id")
614 if len(vbmeta_digest) < self._VBMETA_DIGEST_SIZE_USED:
615 raise ExternalError("Invalid vbmeta digest " + vbmeta_digest)
616
617 digest_prefix = vbmeta_digest[:self._VBMETA_DIGEST_SIZE_USED]
618 return legacy_build_id + '.' + digest_prefix
619
Tianjieb37c5be2020-10-15 21:27:10 -0700620 def _GetPartitionPlatformVersion(self, partition):
621 try:
622 return self.GetPartitionBuildProp("ro.build.version.release_or_codename",
623 partition)
624 except ExternalError:
625 return self.GetPartitionBuildProp("ro.build.version.release",
626 partition)
627
Tao Bao1c320f82019-10-04 23:25:12 -0700628 def GetOemProperty(self, key):
629 if self.oem_props is not None and key in self.oem_props:
630 return self.oem_dicts[0][key]
631 return self.GetBuildProp(key)
632
Daniel Normand5fe8622020-01-08 17:01:11 -0800633 def GetPartitionFingerprint(self, partition):
634 return self._partition_fingerprints.get(partition, None)
635
636 def CalculatePartitionFingerprint(self, partition):
637 try:
638 return self.GetPartitionBuildProp("ro.build.fingerprint", partition)
639 except ExternalError:
640 return "{}/{}/{}:{}/{}/{}:{}/{}".format(
641 self.GetPartitionBuildProp("ro.product.brand", partition),
642 self.GetPartitionBuildProp("ro.product.name", partition),
643 self.GetPartitionBuildProp("ro.product.device", partition),
Tianjieb37c5be2020-10-15 21:27:10 -0700644 self._GetPartitionPlatformVersion(partition),
Daniel Normand5fe8622020-01-08 17:01:11 -0800645 self.GetPartitionBuildProp("ro.build.id", partition),
Kelvin Zhang0876c412020-06-23 15:06:58 -0400646 self.GetPartitionBuildProp(
647 "ro.build.version.incremental", partition),
Daniel Normand5fe8622020-01-08 17:01:11 -0800648 self.GetPartitionBuildProp("ro.build.type", partition),
649 self.GetPartitionBuildProp("ro.build.tags", partition))
650
Tao Bao1c320f82019-10-04 23:25:12 -0700651 def CalculateFingerprint(self):
652 if self.oem_props is None:
653 try:
654 return self.GetBuildProp("ro.build.fingerprint")
655 except ExternalError:
656 return "{}/{}/{}:{}/{}/{}:{}/{}".format(
657 self.GetBuildProp("ro.product.brand"),
658 self.GetBuildProp("ro.product.name"),
659 self.GetBuildProp("ro.product.device"),
Tianjieb37c5be2020-10-15 21:27:10 -0700660 self._GetPlatformVersion(),
Tao Bao1c320f82019-10-04 23:25:12 -0700661 self.GetBuildProp("ro.build.id"),
662 self.GetBuildProp("ro.build.version.incremental"),
663 self.GetBuildProp("ro.build.type"),
664 self.GetBuildProp("ro.build.tags"))
665 return "%s/%s/%s:%s" % (
666 self.GetOemProperty("ro.product.brand"),
667 self.GetOemProperty("ro.product.name"),
668 self.GetOemProperty("ro.product.device"),
669 self.GetBuildProp("ro.build.thumbprint"))
670
671 def WriteMountOemScript(self, script):
672 assert self.oem_props is not None
673 recovery_mount_options = self.info_dict.get("recovery_mount_options")
674 script.Mount("/oem", recovery_mount_options)
675
676 def WriteDeviceAssertions(self, script, oem_no_mount):
677 # Read the property directly if not using OEM properties.
678 if not self.oem_props:
679 script.AssertDevice(self.device)
680 return
681
682 # Otherwise assert OEM properties.
683 if not self.oem_dicts:
684 raise ExternalError(
685 "No OEM file provided to answer expected assertions")
686
687 for prop in self.oem_props.split():
688 values = []
689 for oem_dict in self.oem_dicts:
690 if prop in oem_dict:
691 values.append(oem_dict[prop])
692 if not values:
693 raise ExternalError(
694 "The OEM file is missing the property %s" % (prop,))
695 script.AssertOemProperty(prop, values, oem_no_mount)
696
697
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000698def ReadFromInputFile(input_file, fn):
699 """Reads the contents of fn from input zipfile or directory."""
700 if isinstance(input_file, zipfile.ZipFile):
701 return input_file.read(fn).decode()
702 else:
703 path = os.path.join(input_file, *fn.split("/"))
704 try:
705 with open(path) as f:
706 return f.read()
707 except IOError as e:
708 if e.errno == errno.ENOENT:
709 raise KeyError(fn)
710
711
Yifan Hong10482a22021-01-07 14:38:41 -0800712def ExtractFromInputFile(input_file, fn):
713 """Extracts the contents of fn from input zipfile or directory into a file."""
714 if isinstance(input_file, zipfile.ZipFile):
715 tmp_file = MakeTempFile(os.path.basename(fn))
Kelvin Zhang645dcb82021-02-09 17:52:50 -0500716 with open(tmp_file, 'wb') as f:
Yifan Hong10482a22021-01-07 14:38:41 -0800717 f.write(input_file.read(fn))
718 return tmp_file
719 else:
720 file = os.path.join(input_file, *fn.split("/"))
721 if not os.path.exists(file):
722 raise KeyError(fn)
723 return file
724
Kelvin Zhang563750f2021-04-28 12:46:17 -0400725
jiajia tangf3f842b2021-03-17 21:49:44 +0800726class RamdiskFormat(object):
727 LZ4 = 1
728 GZ = 2
Yifan Hong10482a22021-01-07 14:38:41 -0800729
Kelvin Zhang563750f2021-04-28 12:46:17 -0400730
TJ Rhoades6f488e92022-05-01 22:16:22 -0700731def GetRamdiskFormat(info_dict):
jiajia tang836f76b2021-04-02 14:48:26 +0800732 if info_dict.get('lz4_ramdisks') == 'true':
733 ramdisk_format = RamdiskFormat.LZ4
734 else:
735 ramdisk_format = RamdiskFormat.GZ
736 return ramdisk_format
737
Kelvin Zhang563750f2021-04-28 12:46:17 -0400738
Tao Bao410ad8b2018-08-24 12:08:38 -0700739def LoadInfoDict(input_file, repacking=False):
740 """Loads the key/value pairs from the given input target_files.
741
Tianjiea85bdf02020-07-29 11:56:19 -0700742 It reads `META/misc_info.txt` file in the target_files input, does validation
Tao Bao410ad8b2018-08-24 12:08:38 -0700743 checks and returns the parsed key/value pairs for to the given build. It's
744 usually called early when working on input target_files files, e.g. when
745 generating OTAs, or signing builds. Note that the function may be called
746 against an old target_files file (i.e. from past dessert releases). So the
747 property parsing needs to be backward compatible.
748
749 In a `META/misc_info.txt`, a few properties are stored as links to the files
750 in the PRODUCT_OUT directory. It works fine with the build system. However,
751 they are no longer available when (re)generating images from target_files zip.
752 When `repacking` is True, redirect these properties to the actual files in the
753 unzipped directory.
754
755 Args:
756 input_file: The input target_files file, which could be an open
757 zipfile.ZipFile instance, or a str for the dir that contains the files
758 unzipped from a target_files file.
759 repacking: Whether it's trying repack an target_files file after loading the
760 info dict (default: False). If so, it will rewrite a few loaded
761 properties (e.g. selinux_fc, root_dir) to point to the actual files in
762 target_files file. When doing repacking, `input_file` must be a dir.
763
764 Returns:
765 A dict that contains the parsed key/value pairs.
766
767 Raises:
768 AssertionError: On invalid input arguments.
769 ValueError: On malformed input values.
770 """
771 if repacking:
772 assert isinstance(input_file, str), \
773 "input_file must be a path str when doing repacking"
Doug Zongkerc19a8d52010-07-01 15:30:11 -0700774
Doug Zongkerc9253822014-02-04 12:17:58 -0800775 def read_helper(fn):
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000776 return ReadFromInputFile(input_file, fn)
Tao Bao6cd54732017-02-27 15:12:05 -0800777
Doug Zongkerc19a8d52010-07-01 15:30:11 -0700778 try:
Michael Runge6e836112014-04-15 17:40:21 -0700779 d = LoadDictionaryFromLines(read_helper("META/misc_info.txt").split("\n"))
Doug Zongker37974732010-09-16 17:44:38 -0700780 except KeyError:
Tao Bao410ad8b2018-08-24 12:08:38 -0700781 raise ValueError("Failed to find META/misc_info.txt in input target-files")
Doug Zongkerc19a8d52010-07-01 15:30:11 -0700782
Tao Bao410ad8b2018-08-24 12:08:38 -0700783 if "recovery_api_version" not in d:
784 raise ValueError("Failed to find 'recovery_api_version'")
785 if "fstab_version" not in d:
786 raise ValueError("Failed to find 'fstab_version'")
Ken Sumrall3b07cf12013-02-19 17:35:29 -0800787
Tao Bao410ad8b2018-08-24 12:08:38 -0700788 if repacking:
Daniel Norman72c626f2019-05-13 15:58:14 -0700789 # "selinux_fc" properties should point to the file_contexts files
790 # (file_contexts.bin) under META/.
791 for key in d:
792 if key.endswith("selinux_fc"):
793 fc_basename = os.path.basename(d[key])
794 fc_config = os.path.join(input_file, "META", fc_basename)
795 assert os.path.exists(fc_config)
Tao Bao2c15d9e2015-07-09 11:51:16 -0700796
Daniel Norman72c626f2019-05-13 15:58:14 -0700797 d[key] = fc_config
Tao Bao2c15d9e2015-07-09 11:51:16 -0700798
Tom Cherryd14b8952018-08-09 14:26:00 -0700799 # Similarly we need to redirect "root_dir", and "root_fs_config".
Tao Bao410ad8b2018-08-24 12:08:38 -0700800 d["root_dir"] = os.path.join(input_file, "ROOT")
Tom Cherryd14b8952018-08-09 14:26:00 -0700801 d["root_fs_config"] = os.path.join(
Tao Bao410ad8b2018-08-24 12:08:38 -0700802 input_file, "META", "root_filesystem_config.txt")
Tao Bao84e75682015-07-19 02:38:53 -0700803
David Anderson0ec64ac2019-12-06 12:21:18 -0800804 # Redirect {partition}_base_fs_file for each of the named partitions.
Yifan Hongcfb917a2020-05-07 14:58:20 -0700805 for part_name in ["system", "vendor", "system_ext", "product", "odm",
Ramji Jiyani13a41372022-01-27 07:05:08 +0000806 "vendor_dlkm", "odm_dlkm", "system_dlkm"]:
David Anderson0ec64ac2019-12-06 12:21:18 -0800807 key_name = part_name + "_base_fs_file"
808 if key_name not in d:
809 continue
810 basename = os.path.basename(d[key_name])
811 base_fs_file = os.path.join(input_file, "META", basename)
812 if os.path.exists(base_fs_file):
813 d[key_name] = base_fs_file
Tao Baob079b502016-05-03 08:01:19 -0700814 else:
Tao Bao32fcdab2018-10-12 10:30:39 -0700815 logger.warning(
David Anderson0ec64ac2019-12-06 12:21:18 -0800816 "Failed to find %s base fs file: %s", part_name, base_fs_file)
817 del d[key_name]
Tao Baof54216f2016-03-29 15:12:37 -0700818
Doug Zongker37974732010-09-16 17:44:38 -0700819 def makeint(key):
820 if key in d:
821 d[key] = int(d[key], 0)
822
823 makeint("recovery_api_version")
824 makeint("blocksize")
825 makeint("system_size")
Daniel Rosenbergf4eabc32014-07-10 15:42:38 -0700826 makeint("vendor_size")
Doug Zongker37974732010-09-16 17:44:38 -0700827 makeint("userdata_size")
Ying Wang9f8e8db2011-11-04 11:37:01 -0700828 makeint("cache_size")
Doug Zongker37974732010-09-16 17:44:38 -0700829 makeint("recovery_size")
Ken Sumrall3b07cf12013-02-19 17:35:29 -0800830 makeint("fstab_version")
Doug Zongkerc19a8d52010-07-01 15:30:11 -0700831
Steve Muckle903a1ca2020-05-07 17:32:10 -0700832 boot_images = "boot.img"
833 if "boot_images" in d:
834 boot_images = d["boot_images"]
835 for b in boot_images.split():
Kelvin Zhang0876c412020-06-23 15:06:58 -0400836 makeint(b.replace(".img", "_size"))
Steve Muckle903a1ca2020-05-07 17:32:10 -0700837
Tao Bao765668f2019-10-04 22:03:00 -0700838 # Load recovery fstab if applicable.
839 d["fstab"] = _FindAndLoadRecoveryFstab(d, input_file, read_helper)
TJ Rhoades6f488e92022-05-01 22:16:22 -0700840 ramdisk_format = GetRamdiskFormat(d)
Tianjie Xucfa86222016-03-07 16:31:19 -0800841
Tianjie Xu861f4132018-09-12 11:49:33 -0700842 # Tries to load the build props for all partitions with care_map, including
843 # system and vendor.
Yifan Hong5057b952021-01-07 14:09:57 -0800844 for partition in PARTITIONS_WITH_BUILD_PROP:
Bowgo Tsai71a4d5c2019-05-17 23:21:48 +0800845 partition_prop = "{}.build.prop".format(partition)
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000846 d[partition_prop] = PartitionBuildProps.FromInputFile(
jiajia tangf3f842b2021-03-17 21:49:44 +0800847 input_file, partition, ramdisk_format=ramdisk_format)
Tianjie Xu861f4132018-09-12 11:49:33 -0700848 d["build.prop"] = d["system.build.prop"]
Tao Bao12d87fc2018-01-31 12:18:52 -0800849
Tao Bao3ed35d32019-10-07 20:48:48 -0700850 # Set up the salt (based on fingerprint) that will be used when adding AVB
851 # hash / hashtree footers.
Tao Bao12d87fc2018-01-31 12:18:52 -0800852 if d.get("avb_enable") == "true":
Tianjiefdda51d2021-05-05 14:46:35 -0700853 build_info = BuildInfo(d, use_legacy_id=True)
Yifan Hong5057b952021-01-07 14:09:57 -0800854 for partition in PARTITIONS_WITH_BUILD_PROP:
Daniel Normand5fe8622020-01-08 17:01:11 -0800855 fingerprint = build_info.GetPartitionFingerprint(partition)
856 if fingerprint:
Kelvin Zhang563750f2021-04-28 12:46:17 -0400857 d["avb_{}_salt".format(partition)] = sha256(
858 fingerprint.encode()).hexdigest()
Tianjiefdda51d2021-05-05 14:46:35 -0700859
860 # Set the vbmeta digest if exists
861 try:
862 d["vbmeta_digest"] = read_helper("META/vbmeta_digest.txt").rstrip()
863 except KeyError:
864 pass
865
Kelvin Zhang39aea442020-08-17 11:04:25 -0400866 try:
867 d["ab_partitions"] = read_helper("META/ab_partitions.txt").split("\n")
868 except KeyError:
869 logger.warning("Can't find META/ab_partitions.txt")
Doug Zongker1eb74dd2012-08-16 16:19:00 -0700870 return d
871
Tao Baod1de6f32017-03-01 16:38:48 -0800872
Daniel Norman4cc9df62019-07-18 10:11:07 -0700873def LoadListFromFile(file_path):
Kiyoung Kimebe7c9c2019-06-25 17:09:55 +0900874 with open(file_path) as f:
Daniel Norman4cc9df62019-07-18 10:11:07 -0700875 return f.read().splitlines()
Kiyoung Kimebe7c9c2019-06-25 17:09:55 +0900876
Daniel Norman4cc9df62019-07-18 10:11:07 -0700877
878def LoadDictionaryFromFile(file_path):
879 lines = LoadListFromFile(file_path)
Kiyoung Kimebe7c9c2019-06-25 17:09:55 +0900880 return LoadDictionaryFromLines(lines)
881
882
Michael Runge6e836112014-04-15 17:40:21 -0700883def LoadDictionaryFromLines(lines):
Doug Zongker1eb74dd2012-08-16 16:19:00 -0700884 d = {}
Michael Runge6e836112014-04-15 17:40:21 -0700885 for line in lines:
Doug Zongker1eb74dd2012-08-16 16:19:00 -0700886 line = line.strip()
Dan Albert8b72aef2015-03-23 19:13:21 -0700887 if not line or line.startswith("#"):
888 continue
Ying Wang114b46f2014-04-15 11:24:00 -0700889 if "=" in line:
890 name, value = line.split("=", 1)
891 d[name] = value
Doug Zongkerc19a8d52010-07-01 15:30:11 -0700892 return d
893
Tao Baod1de6f32017-03-01 16:38:48 -0800894
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000895class PartitionBuildProps(object):
896 """The class holds the build prop of a particular partition.
897
898 This class loads the build.prop and holds the build properties for a given
899 partition. It also partially recognizes the 'import' statement in the
900 build.prop; and calculates alternative values of some specific build
901 properties during runtime.
902
903 Attributes:
904 input_file: a zipped target-file or an unzipped target-file directory.
905 partition: name of the partition.
906 props_allow_override: a list of build properties to search for the
907 alternative values during runtime.
Tianjie Xu9afb2212020-05-10 21:48:15 +0000908 build_props: a dict of build properties for the given partition.
909 prop_overrides: a set of props that are overridden by import.
910 placeholder_values: A dict of runtime variables' values to replace the
911 placeholders in the build.prop file. We expect exactly one value for
912 each of the variables.
jiajia tangf3f842b2021-03-17 21:49:44 +0800913 ramdisk_format: If name is "boot", the format of ramdisk inside the
914 boot image. Otherwise, its value is ignored.
915 Use lz4 to decompress by default. If its value is gzip, use minigzip.
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000916 """
Kelvin Zhang0876c412020-06-23 15:06:58 -0400917
Tianjie Xu9afb2212020-05-10 21:48:15 +0000918 def __init__(self, input_file, name, placeholder_values=None):
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000919 self.input_file = input_file
920 self.partition = name
921 self.props_allow_override = [props.format(name) for props in [
Tianjie Xu9afb2212020-05-10 21:48:15 +0000922 'ro.product.{}.brand', 'ro.product.{}.name', 'ro.product.{}.device']]
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000923 self.build_props = {}
Tianjie Xu9afb2212020-05-10 21:48:15 +0000924 self.prop_overrides = set()
925 self.placeholder_values = {}
926 if placeholder_values:
927 self.placeholder_values = copy.deepcopy(placeholder_values)
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000928
929 @staticmethod
930 def FromDictionary(name, build_props):
931 """Constructs an instance from a build prop dictionary."""
932
933 props = PartitionBuildProps("unknown", name)
934 props.build_props = build_props.copy()
935 return props
936
937 @staticmethod
jiajia tangf3f842b2021-03-17 21:49:44 +0800938 def FromInputFile(input_file, name, placeholder_values=None, ramdisk_format=RamdiskFormat.LZ4):
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000939 """Loads the build.prop file and builds the attributes."""
Yifan Hong10482a22021-01-07 14:38:41 -0800940
Devin Mooreafdd7c72021-12-13 22:04:08 +0000941 if name in ("boot", "init_boot"):
Kelvin Zhang563750f2021-04-28 12:46:17 -0400942 data = PartitionBuildProps._ReadBootPropFile(
Devin Mooreafdd7c72021-12-13 22:04:08 +0000943 input_file, name, ramdisk_format=ramdisk_format)
Yifan Hong10482a22021-01-07 14:38:41 -0800944 else:
945 data = PartitionBuildProps._ReadPartitionPropFile(input_file, name)
946
947 props = PartitionBuildProps(input_file, name, placeholder_values)
948 props._LoadBuildProp(data)
949 return props
950
951 @staticmethod
Devin Mooreafdd7c72021-12-13 22:04:08 +0000952 def _ReadBootPropFile(input_file, partition_name, ramdisk_format):
Yifan Hong10482a22021-01-07 14:38:41 -0800953 """
954 Read build.prop for boot image from input_file.
955 Return empty string if not found.
956 """
Devin Mooreafdd7c72021-12-13 22:04:08 +0000957 image_path = 'IMAGES/' + partition_name + '.img'
Yifan Hong10482a22021-01-07 14:38:41 -0800958 try:
Devin Mooreafdd7c72021-12-13 22:04:08 +0000959 boot_img = ExtractFromInputFile(input_file, image_path)
Yifan Hong10482a22021-01-07 14:38:41 -0800960 except KeyError:
Devin Mooreafdd7c72021-12-13 22:04:08 +0000961 logger.warning('Failed to read %s', image_path)
Yifan Hong10482a22021-01-07 14:38:41 -0800962 return ''
jiajia tangf3f842b2021-03-17 21:49:44 +0800963 prop_file = GetBootImageBuildProp(boot_img, ramdisk_format=ramdisk_format)
Yifan Hong10482a22021-01-07 14:38:41 -0800964 if prop_file is None:
965 return ''
Kelvin Zhang645dcb82021-02-09 17:52:50 -0500966 with open(prop_file, "r") as f:
967 return f.read()
Yifan Hong10482a22021-01-07 14:38:41 -0800968
969 @staticmethod
970 def _ReadPartitionPropFile(input_file, name):
971 """
972 Read build.prop for name from input_file.
973 Return empty string if not found.
974 """
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000975 data = ''
976 for prop_file in ['{}/etc/build.prop'.format(name.upper()),
977 '{}/build.prop'.format(name.upper())]:
978 try:
979 data = ReadFromInputFile(input_file, prop_file)
980 break
981 except KeyError:
982 logger.warning('Failed to read %s', prop_file)
Kelvin Zhang4fc3aa02021-11-16 18:58:58 -0800983 if data == '':
984 logger.warning("Failed to read build.prop for partition {}".format(name))
Yifan Hong10482a22021-01-07 14:38:41 -0800985 return data
Tianjie Xu0fde41e2020-05-09 05:24:18 +0000986
Yifan Hong125d0b62020-09-24 17:07:03 -0700987 @staticmethod
988 def FromBuildPropFile(name, build_prop_file):
989 """Constructs an instance from a build prop file."""
990
991 props = PartitionBuildProps("unknown", name)
992 with open(build_prop_file) as f:
993 props._LoadBuildProp(f.read())
994 return props
995
Tianjie Xu9afb2212020-05-10 21:48:15 +0000996 def _LoadBuildProp(self, data):
997 for line in data.split('\n'):
998 line = line.strip()
999 if not line or line.startswith("#"):
1000 continue
1001 if line.startswith("import"):
1002 overrides = self._ImportParser(line)
1003 duplicates = self.prop_overrides.intersection(overrides.keys())
1004 if duplicates:
1005 raise ValueError('prop {} is overridden multiple times'.format(
1006 ','.join(duplicates)))
1007 self.prop_overrides = self.prop_overrides.union(overrides.keys())
1008 self.build_props.update(overrides)
1009 elif "=" in line:
1010 name, value = line.split("=", 1)
1011 if name in self.prop_overrides:
1012 raise ValueError('prop {} is set again after overridden by import '
1013 'statement'.format(name))
1014 self.build_props[name] = value
1015
1016 def _ImportParser(self, line):
1017 """Parses the build prop in a given import statement."""
1018
1019 tokens = line.split()
Kelvin Zhang0876c412020-06-23 15:06:58 -04001020 if tokens[0] != 'import' or (len(tokens) != 2 and len(tokens) != 3):
Tianjie Xu9afb2212020-05-10 21:48:15 +00001021 raise ValueError('Unrecognized import statement {}'.format(line))
Hongguang Chenb4702b72020-05-13 18:05:20 -07001022
1023 if len(tokens) == 3:
1024 logger.info("Import %s from %s, skip", tokens[2], tokens[1])
1025 return {}
1026
Tianjie Xu9afb2212020-05-10 21:48:15 +00001027 import_path = tokens[1]
1028 if not re.match(r'^/{}/.*\.prop$'.format(self.partition), import_path):
Kelvin Zhang42ab8282022-02-17 13:07:55 -08001029 logger.warn('Unrecognized import path {}'.format(line))
1030 return {}
Tianjie Xu9afb2212020-05-10 21:48:15 +00001031
1032 # We only recognize a subset of import statement that the init process
1033 # supports. And we can loose the restriction based on how the dynamic
1034 # fingerprint is used in practice. The placeholder format should be
1035 # ${placeholder}, and its value should be provided by the caller through
1036 # the placeholder_values.
1037 for prop, value in self.placeholder_values.items():
1038 prop_place_holder = '${{{}}}'.format(prop)
1039 if prop_place_holder in import_path:
1040 import_path = import_path.replace(prop_place_holder, value)
1041 if '$' in import_path:
1042 logger.info('Unresolved place holder in import path %s', import_path)
1043 return {}
1044
1045 import_path = import_path.replace('/{}'.format(self.partition),
1046 self.partition.upper())
1047 logger.info('Parsing build props override from %s', import_path)
1048
1049 lines = ReadFromInputFile(self.input_file, import_path).split('\n')
1050 d = LoadDictionaryFromLines(lines)
1051 return {key: val for key, val in d.items()
1052 if key in self.props_allow_override}
1053
Tianjie Xu0fde41e2020-05-09 05:24:18 +00001054 def GetProp(self, prop):
1055 return self.build_props.get(prop)
1056
1057
Tianjie Xucfa86222016-03-07 16:31:19 -08001058def LoadRecoveryFSTab(read_helper, fstab_version, recovery_fstab_path,
1059 system_root_image=False):
Doug Zongker9ce0fb62010-09-20 18:04:41 -07001060 class Partition(object):
Yifan Hong65afc072020-04-17 10:08:10 -07001061 def __init__(self, mount_point, fs_type, device, length, context, slotselect):
Dan Albert8b72aef2015-03-23 19:13:21 -07001062 self.mount_point = mount_point
1063 self.fs_type = fs_type
1064 self.device = device
1065 self.length = length
Tao Bao548eb762015-06-10 12:32:41 -07001066 self.context = context
Yifan Hong65afc072020-04-17 10:08:10 -07001067 self.slotselect = slotselect
Doug Zongker9ce0fb62010-09-20 18:04:41 -07001068
1069 try:
Tianjie Xucfa86222016-03-07 16:31:19 -08001070 data = read_helper(recovery_fstab_path)
Doug Zongker9ce0fb62010-09-20 18:04:41 -07001071 except KeyError:
Tao Bao32fcdab2018-10-12 10:30:39 -07001072 logger.warning("Failed to find %s", recovery_fstab_path)
Jeff Davidson033fbe22011-10-26 18:08:09 -07001073 data = ""
Doug Zongker9ce0fb62010-09-20 18:04:41 -07001074
Tao Baod1de6f32017-03-01 16:38:48 -08001075 assert fstab_version == 2
1076
1077 d = {}
1078 for line in data.split("\n"):
1079 line = line.strip()
1080 if not line or line.startswith("#"):
1081 continue
1082
1083 # <src> <mnt_point> <type> <mnt_flags and options> <fs_mgr_flags>
1084 pieces = line.split()
1085 if len(pieces) != 5:
1086 raise ValueError("malformed recovery.fstab line: \"%s\"" % (line,))
1087
1088 # Ignore entries that are managed by vold.
1089 options = pieces[4]
1090 if "voldmanaged=" in options:
1091 continue
1092
1093 # It's a good line, parse it.
1094 length = 0
Yifan Hong65afc072020-04-17 10:08:10 -07001095 slotselect = False
Tao Baod1de6f32017-03-01 16:38:48 -08001096 options = options.split(",")
1097 for i in options:
1098 if i.startswith("length="):
1099 length = int(i[7:])
Yifan Hong65afc072020-04-17 10:08:10 -07001100 elif i == "slotselect":
1101 slotselect = True
Doug Zongker086cbb02011-02-17 15:54:20 -08001102 else:
Tao Baod1de6f32017-03-01 16:38:48 -08001103 # Ignore all unknown options in the unified fstab.
Dan Albert8b72aef2015-03-23 19:13:21 -07001104 continue
Ken Sumrall3b07cf12013-02-19 17:35:29 -08001105
Tao Baod1de6f32017-03-01 16:38:48 -08001106 mount_flags = pieces[3]
1107 # Honor the SELinux context if present.
1108 context = None
1109 for i in mount_flags.split(","):
1110 if i.startswith("context="):
1111 context = i
Doug Zongker086cbb02011-02-17 15:54:20 -08001112
Tao Baod1de6f32017-03-01 16:38:48 -08001113 mount_point = pieces[1]
1114 d[mount_point] = Partition(mount_point=mount_point, fs_type=pieces[2],
Yifan Hong65afc072020-04-17 10:08:10 -07001115 device=pieces[0], length=length, context=context,
1116 slotselect=slotselect)
Ken Sumrall3b07cf12013-02-19 17:35:29 -08001117
Daniel Rosenberge6853b02015-06-05 17:59:27 -07001118 # / is used for the system mount point when the root directory is included in
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001119 # system. Other areas assume system is always at "/system" so point /system
1120 # at /.
Daniel Rosenberge6853b02015-06-05 17:59:27 -07001121 if system_root_image:
Tao Baoda30cfa2017-12-01 16:19:46 -08001122 assert '/system' not in d and '/' in d
Daniel Rosenberge6853b02015-06-05 17:59:27 -07001123 d["/system"] = d["/"]
Doug Zongker9ce0fb62010-09-20 18:04:41 -07001124 return d
1125
1126
Tao Bao765668f2019-10-04 22:03:00 -07001127def _FindAndLoadRecoveryFstab(info_dict, input_file, read_helper):
1128 """Finds the path to recovery fstab and loads its contents."""
1129 # recovery fstab is only meaningful when installing an update via recovery
1130 # (i.e. non-A/B OTA). Skip loading fstab if device used A/B OTA.
Yifan Hong65afc072020-04-17 10:08:10 -07001131 if info_dict.get('ab_update') == 'true' and \
1132 info_dict.get("allow_non_ab") != "true":
Tao Bao765668f2019-10-04 22:03:00 -07001133 return None
1134
1135 # We changed recovery.fstab path in Q, from ../RAMDISK/etc/recovery.fstab to
1136 # ../RAMDISK/system/etc/recovery.fstab. This function has to handle both
1137 # cases, since it may load the info_dict from an old build (e.g. when
1138 # generating incremental OTAs from that build).
1139 system_root_image = info_dict.get('system_root_image') == 'true'
1140 if info_dict.get('no_recovery') != 'true':
1141 recovery_fstab_path = 'RECOVERY/RAMDISK/system/etc/recovery.fstab'
1142 if isinstance(input_file, zipfile.ZipFile):
1143 if recovery_fstab_path not in input_file.namelist():
1144 recovery_fstab_path = 'RECOVERY/RAMDISK/etc/recovery.fstab'
1145 else:
1146 path = os.path.join(input_file, *recovery_fstab_path.split('/'))
1147 if not os.path.exists(path):
1148 recovery_fstab_path = 'RECOVERY/RAMDISK/etc/recovery.fstab'
1149 return LoadRecoveryFSTab(
1150 read_helper, info_dict['fstab_version'], recovery_fstab_path,
1151 system_root_image)
1152
1153 if info_dict.get('recovery_as_boot') == 'true':
1154 recovery_fstab_path = 'BOOT/RAMDISK/system/etc/recovery.fstab'
1155 if isinstance(input_file, zipfile.ZipFile):
1156 if recovery_fstab_path not in input_file.namelist():
1157 recovery_fstab_path = 'BOOT/RAMDISK/etc/recovery.fstab'
1158 else:
1159 path = os.path.join(input_file, *recovery_fstab_path.split('/'))
1160 if not os.path.exists(path):
1161 recovery_fstab_path = 'BOOT/RAMDISK/etc/recovery.fstab'
1162 return LoadRecoveryFSTab(
1163 read_helper, info_dict['fstab_version'], recovery_fstab_path,
1164 system_root_image)
1165
1166 return None
1167
1168
Doug Zongker37974732010-09-16 17:44:38 -07001169def DumpInfoDict(d):
1170 for k, v in sorted(d.items()):
Tao Bao32fcdab2018-10-12 10:30:39 -07001171 logger.info("%-25s = (%s) %s", k, type(v).__name__, v)
Doug Zongkerc19a8d52010-07-01 15:30:11 -07001172
Dan Albert8b72aef2015-03-23 19:13:21 -07001173
Daniel Norman55417142019-11-25 16:04:36 -08001174def MergeDynamicPartitionInfoDicts(framework_dict, vendor_dict):
Daniel Normanbfc51ef2019-07-24 14:34:54 -07001175 """Merges dynamic partition info variables.
1176
1177 Args:
1178 framework_dict: The dictionary of dynamic partition info variables from the
1179 partial framework target files.
1180 vendor_dict: The dictionary of dynamic partition info variables from the
1181 partial vendor target files.
Daniel Normanbfc51ef2019-07-24 14:34:54 -07001182
1183 Returns:
1184 The merged dynamic partition info dictionary.
1185 """
Daniel Normanb0c75912020-09-24 14:30:21 -07001186
1187 def uniq_concat(a, b):
jiajia tange5ddfcd2022-06-21 10:36:12 +08001188 combined = set(a.split())
1189 combined.update(set(b.split()))
Daniel Normanb0c75912020-09-24 14:30:21 -07001190 combined = [item.strip() for item in combined if item.strip()]
1191 return " ".join(sorted(combined))
1192
1193 if (framework_dict.get("use_dynamic_partitions") !=
Kelvin Zhang6a683ce2022-05-02 12:19:45 -07001194 "true") or (vendor_dict.get("use_dynamic_partitions") != "true"):
Daniel Normanb0c75912020-09-24 14:30:21 -07001195 raise ValueError("Both dictionaries must have use_dynamic_partitions=true")
1196
1197 merged_dict = {"use_dynamic_partitions": "true"}
Kelvin Zhang6a683ce2022-05-02 12:19:45 -07001198 # For keys-value pairs that are the same, copy to merged dict
1199 for key in vendor_dict.keys():
1200 if key in framework_dict and framework_dict[key] == vendor_dict[key]:
1201 merged_dict[key] = vendor_dict[key]
Daniel Normanb0c75912020-09-24 14:30:21 -07001202
1203 merged_dict["dynamic_partition_list"] = uniq_concat(
1204 framework_dict.get("dynamic_partition_list", ""),
1205 vendor_dict.get("dynamic_partition_list", ""))
1206
1207 # Super block devices are defined by the vendor dict.
1208 if "super_block_devices" in vendor_dict:
1209 merged_dict["super_block_devices"] = vendor_dict["super_block_devices"]
jiajia tange5ddfcd2022-06-21 10:36:12 +08001210 for block_device in merged_dict["super_block_devices"].split():
Daniel Normanb0c75912020-09-24 14:30:21 -07001211 key = "super_%s_device_size" % block_device
1212 if key not in vendor_dict:
1213 raise ValueError("Vendor dict does not contain required key %s." % key)
1214 merged_dict[key] = vendor_dict[key]
1215
Daniel Normanbfc51ef2019-07-24 14:34:54 -07001216 # Partition groups and group sizes are defined by the vendor dict because
1217 # these values may vary for each board that uses a shared system image.
1218 merged_dict["super_partition_groups"] = vendor_dict["super_partition_groups"]
jiajia tange5ddfcd2022-06-21 10:36:12 +08001219 for partition_group in merged_dict["super_partition_groups"].split():
Daniel Normanbfc51ef2019-07-24 14:34:54 -07001220 # Set the partition group's size using the value from the vendor dict.
Daniel Norman55417142019-11-25 16:04:36 -08001221 key = "super_%s_group_size" % partition_group
Daniel Normanbfc51ef2019-07-24 14:34:54 -07001222 if key not in vendor_dict:
1223 raise ValueError("Vendor dict does not contain required key %s." % key)
1224 merged_dict[key] = vendor_dict[key]
1225
1226 # Set the partition group's partition list using a concatenation of the
1227 # framework and vendor partition lists.
Daniel Norman55417142019-11-25 16:04:36 -08001228 key = "super_%s_partition_list" % partition_group
Daniel Normanb0c75912020-09-24 14:30:21 -07001229 merged_dict[key] = uniq_concat(
1230 framework_dict.get(key, ""), vendor_dict.get(key, ""))
P Adarsh Reddy7e9b5c42019-12-20 15:07:24 +05301231
Daniel Normanb0c75912020-09-24 14:30:21 -07001232 # Various other flags should be copied from the vendor dict, if defined.
1233 for key in ("virtual_ab", "virtual_ab_retrofit", "lpmake",
1234 "super_metadata_device", "super_partition_error_limit",
1235 "super_partition_size"):
1236 if key in vendor_dict.keys():
1237 merged_dict[key] = vendor_dict[key]
1238
Daniel Normanbfc51ef2019-07-24 14:34:54 -07001239 return merged_dict
1240
1241
Daniel Norman21c34f72020-11-11 17:25:50 -08001242def PartitionMapFromTargetFiles(target_files_dir):
1243 """Builds a map from partition -> path within an extracted target files directory."""
1244 # Keep possible_subdirs in sync with build/make/core/board_config.mk.
1245 possible_subdirs = {
1246 "system": ["SYSTEM"],
1247 "vendor": ["VENDOR", "SYSTEM/vendor"],
1248 "product": ["PRODUCT", "SYSTEM/product"],
1249 "system_ext": ["SYSTEM_EXT", "SYSTEM/system_ext"],
1250 "odm": ["ODM", "VENDOR/odm", "SYSTEM/vendor/odm"],
1251 "vendor_dlkm": [
1252 "VENDOR_DLKM", "VENDOR/vendor_dlkm", "SYSTEM/vendor/vendor_dlkm"
1253 ],
1254 "odm_dlkm": ["ODM_DLKM", "VENDOR/odm_dlkm", "SYSTEM/vendor/odm_dlkm"],
Ramji Jiyani13a41372022-01-27 07:05:08 +00001255 "system_dlkm": ["SYSTEM_DLKM", "SYSTEM/system_dlkm"],
Daniel Norman21c34f72020-11-11 17:25:50 -08001256 }
1257 partition_map = {}
1258 for partition, subdirs in possible_subdirs.items():
1259 for subdir in subdirs:
1260 if os.path.exists(os.path.join(target_files_dir, subdir)):
1261 partition_map[partition] = subdir
1262 break
1263 return partition_map
1264
1265
Daniel Normand3351562020-10-29 12:33:11 -07001266def SharedUidPartitionViolations(uid_dict, partition_groups):
1267 """Checks for APK sharedUserIds that cross partition group boundaries.
1268
1269 This uses a single or merged build's shareduid_violation_modules.json
1270 output file, as generated by find_shareduid_violation.py or
1271 core/tasks/find-shareduid-violation.mk.
1272
1273 An error is defined as a sharedUserId that is found in a set of partitions
1274 that span more than one partition group.
1275
1276 Args:
1277 uid_dict: A dictionary created by using the standard json module to read a
1278 complete shareduid_violation_modules.json file.
1279 partition_groups: A list of groups, where each group is a list of
1280 partitions.
1281
1282 Returns:
1283 A list of error messages.
1284 """
1285 errors = []
1286 for uid, partitions in uid_dict.items():
1287 found_in_groups = [
1288 group for group in partition_groups
1289 if set(partitions.keys()) & set(group)
1290 ]
1291 if len(found_in_groups) > 1:
1292 errors.append(
1293 "APK sharedUserId \"%s\" found across partition groups in partitions \"%s\""
1294 % (uid, ",".join(sorted(partitions.keys()))))
1295 return errors
1296
1297
Daniel Norman21c34f72020-11-11 17:25:50 -08001298def RunHostInitVerifier(product_out, partition_map):
1299 """Runs host_init_verifier on the init rc files within partitions.
1300
1301 host_init_verifier searches the etc/init path within each partition.
1302
1303 Args:
1304 product_out: PRODUCT_OUT directory, containing partition directories.
1305 partition_map: A map of partition name -> relative path within product_out.
1306 """
1307 allowed_partitions = ("system", "system_ext", "product", "vendor", "odm")
1308 cmd = ["host_init_verifier"]
1309 for partition, path in partition_map.items():
1310 if partition not in allowed_partitions:
1311 raise ExternalError("Unable to call host_init_verifier for partition %s" %
1312 partition)
1313 cmd.extend(["--out_%s" % partition, os.path.join(product_out, path)])
1314 # Add --property-contexts if the file exists on the partition.
1315 property_contexts = "%s_property_contexts" % (
1316 "plat" if partition == "system" else partition)
1317 property_contexts_path = os.path.join(product_out, path, "etc", "selinux",
1318 property_contexts)
1319 if os.path.exists(property_contexts_path):
1320 cmd.append("--property-contexts=%s" % property_contexts_path)
1321 # Add the passwd file if the file exists on the partition.
1322 passwd_path = os.path.join(product_out, path, "etc", "passwd")
1323 if os.path.exists(passwd_path):
1324 cmd.extend(["-p", passwd_path])
1325 return RunAndCheckOutput(cmd)
1326
1327
Bowgo Tsai3e599ea2017-05-26 18:30:04 +08001328def AppendAVBSigningArgs(cmd, partition):
1329 """Append signing arguments for avbtool."""
1330 # e.g., "--key path/to/signing_key --algorithm SHA256_RSA4096"
1331 key_path = OPTIONS.info_dict.get("avb_" + partition + "_key_path")
Daniel Mentz25478182019-08-21 18:09:46 -07001332 if key_path and not os.path.exists(key_path) and OPTIONS.search_path:
1333 new_key_path = os.path.join(OPTIONS.search_path, key_path)
1334 if os.path.exists(new_key_path):
1335 key_path = new_key_path
Bowgo Tsai3e599ea2017-05-26 18:30:04 +08001336 algorithm = OPTIONS.info_dict.get("avb_" + partition + "_algorithm")
1337 if key_path and algorithm:
1338 cmd.extend(["--key", key_path, "--algorithm", algorithm])
Tao Bao2b6dfd62017-09-27 17:17:43 -07001339 avb_salt = OPTIONS.info_dict.get("avb_salt")
1340 # make_vbmeta_image doesn't like "--salt" (and it's not needed).
Tao Bao744c4c72018-08-20 21:09:07 -07001341 if avb_salt and not partition.startswith("vbmeta"):
Tao Bao2b6dfd62017-09-27 17:17:43 -07001342 cmd.extend(["--salt", avb_salt])
Bowgo Tsai3e599ea2017-05-26 18:30:04 +08001343
1344
Tao Bao765668f2019-10-04 22:03:00 -07001345def GetAvbPartitionArg(partition, image, info_dict=None):
Daniel Norman276f0622019-07-26 14:13:51 -07001346 """Returns the VBMeta arguments for partition.
1347
1348 It sets up the VBMeta argument by including the partition descriptor from the
1349 given 'image', or by configuring the partition as a chained partition.
1350
1351 Args:
1352 partition: The name of the partition (e.g. "system").
1353 image: The path to the partition image.
1354 info_dict: A dict returned by common.LoadInfoDict(). Will use
1355 OPTIONS.info_dict if None has been given.
1356
1357 Returns:
1358 A list of VBMeta arguments.
1359 """
1360 if info_dict is None:
1361 info_dict = OPTIONS.info_dict
1362
1363 # Check if chain partition is used.
1364 key_path = info_dict.get("avb_" + partition + "_key_path")
cfig1aeef722019-09-20 22:45:06 +08001365 if not key_path:
1366 return ["--include_descriptors_from_image", image]
1367
1368 # For a non-A/B device, we don't chain /recovery nor include its descriptor
1369 # into vbmeta.img. The recovery image will be configured on an independent
1370 # boot chain, to be verified with AVB_SLOT_VERIFY_FLAGS_NO_VBMETA_PARTITION.
1371 # See details at
1372 # https://android.googlesource.com/platform/external/avb/+/master/README.md#booting-into-recovery.
Tao Bao3612c882019-10-14 17:49:31 -07001373 if info_dict.get("ab_update") != "true" and partition == "recovery":
cfig1aeef722019-09-20 22:45:06 +08001374 return []
1375
1376 # Otherwise chain the partition into vbmeta.
1377 chained_partition_arg = GetAvbChainedPartitionArg(partition, info_dict)
1378 return ["--chain_partition", chained_partition_arg]
Daniel Norman276f0622019-07-26 14:13:51 -07001379
1380
Tao Bao02a08592018-07-22 12:40:45 -07001381def GetAvbChainedPartitionArg(partition, info_dict, key=None):
1382 """Constructs and returns the arg to build or verify a chained partition.
1383
1384 Args:
1385 partition: The partition name.
1386 info_dict: The info dict to look up the key info and rollback index
1387 location.
1388 key: The key to be used for building or verifying the partition. Defaults to
1389 the key listed in info_dict.
1390
1391 Returns:
1392 A string of form "partition:rollback_index_location:key" that can be used to
1393 build or verify vbmeta image.
Tao Bao02a08592018-07-22 12:40:45 -07001394 """
1395 if key is None:
1396 key = info_dict["avb_" + partition + "_key_path"]
Daniel Mentz25478182019-08-21 18:09:46 -07001397 if key and not os.path.exists(key) and OPTIONS.search_path:
1398 new_key_path = os.path.join(OPTIONS.search_path, key)
1399 if os.path.exists(new_key_path):
1400 key = new_key_path
Tao Bao1ac886e2019-06-26 11:58:22 -07001401 pubkey_path = ExtractAvbPublicKey(info_dict["avb_avbtool"], key)
Tao Bao02a08592018-07-22 12:40:45 -07001402 rollback_index_location = info_dict[
1403 "avb_" + partition + "_rollback_index_location"]
1404 return "{}:{}:{}".format(partition, rollback_index_location, pubkey_path)
1405
1406
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001407def _HasGkiCertificationArgs():
1408 return ("gki_signing_key_path" in OPTIONS.info_dict and
1409 "gki_signing_algorithm" in OPTIONS.info_dict)
Bowgo Tsai27c39b02021-03-12 21:40:32 +08001410
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001411
Yi-Yo Chiang24da1a42022-02-22 19:51:15 +08001412def _GenerateGkiCertificate(image, image_name):
Bowgo Tsai27c39b02021-03-12 21:40:32 +08001413 key_path = OPTIONS.info_dict.get("gki_signing_key_path")
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001414 algorithm = OPTIONS.info_dict.get("gki_signing_algorithm")
Bowgo Tsai27c39b02021-03-12 21:40:32 +08001415
1416 if not os.path.exists(key_path) and OPTIONS.search_path:
1417 new_key_path = os.path.join(OPTIONS.search_path, key_path)
1418 if os.path.exists(new_key_path):
1419 key_path = new_key_path
1420
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001421 # Checks key_path exists, before processing --gki_signing_* args.
Bowgo Tsai27c39b02021-03-12 21:40:32 +08001422 if not os.path.exists(key_path):
Kelvin Zhang563750f2021-04-28 12:46:17 -04001423 raise ExternalError(
1424 'gki_signing_key_path: "{}" not found'.format(key_path))
Bowgo Tsai27c39b02021-03-12 21:40:32 +08001425
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001426 output_certificate = tempfile.NamedTemporaryFile()
1427 cmd = [
1428 "generate_gki_certificate",
1429 "--name", image_name,
1430 "--algorithm", algorithm,
1431 "--key", key_path,
1432 "--output", output_certificate.name,
1433 image,
1434 ]
Bowgo Tsai27c39b02021-03-12 21:40:32 +08001435
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001436 signature_args = OPTIONS.info_dict.get("gki_signing_signature_args", "")
1437 signature_args = signature_args.strip()
1438 if signature_args:
1439 cmd.extend(["--additional_avb_args", signature_args])
1440
Yi-Yo Chiang24da1a42022-02-22 19:51:15 +08001441 args = OPTIONS.info_dict.get("avb_boot_add_hash_footer_args", "")
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001442 args = args.strip()
1443 if args:
1444 cmd.extend(["--additional_avb_args", args])
1445
1446 RunAndCheckOutput(cmd)
1447
1448 output_certificate.seek(os.SEEK_SET, 0)
1449 data = output_certificate.read()
1450 output_certificate.close()
1451 return data
Bowgo Tsai27c39b02021-03-12 21:40:32 +08001452
1453
Daniel Norman276f0622019-07-26 14:13:51 -07001454def BuildVBMeta(image_path, partitions, name, needed_partitions):
1455 """Creates a VBMeta image.
1456
1457 It generates the requested VBMeta image. The requested image could be for
1458 top-level or chained VBMeta image, which is determined based on the name.
1459
1460 Args:
1461 image_path: The output path for the new VBMeta image.
1462 partitions: A dict that's keyed by partition names with image paths as
Hongguang Chenf23364d2020-04-27 18:36:36 -07001463 values. Only valid partition names are accepted, as partitions listed
1464 in common.AVB_PARTITIONS and custom partitions listed in
1465 OPTIONS.info_dict.get("avb_custom_images_partition_list")
Daniel Norman276f0622019-07-26 14:13:51 -07001466 name: Name of the VBMeta partition, e.g. 'vbmeta', 'vbmeta_system'.
1467 needed_partitions: Partitions whose descriptors should be included into the
1468 generated VBMeta image.
1469
1470 Raises:
1471 AssertionError: On invalid input args.
1472 """
1473 avbtool = OPTIONS.info_dict["avb_avbtool"]
1474 cmd = [avbtool, "make_vbmeta_image", "--output", image_path]
1475 AppendAVBSigningArgs(cmd, name)
1476
Hongguang Chenf23364d2020-04-27 18:36:36 -07001477 custom_partitions = OPTIONS.info_dict.get(
1478 "avb_custom_images_partition_list", "").strip().split()
1479
Daniel Norman276f0622019-07-26 14:13:51 -07001480 for partition, path in partitions.items():
1481 if partition not in needed_partitions:
1482 continue
1483 assert (partition in AVB_PARTITIONS or
Hongguang Chenf23364d2020-04-27 18:36:36 -07001484 partition in AVB_VBMETA_PARTITIONS or
1485 partition in custom_partitions), \
Daniel Norman276f0622019-07-26 14:13:51 -07001486 'Unknown partition: {}'.format(partition)
1487 assert os.path.exists(path), \
1488 'Failed to find {} for {}'.format(path, partition)
1489 cmd.extend(GetAvbPartitionArg(partition, path))
1490
1491 args = OPTIONS.info_dict.get("avb_{}_args".format(name))
1492 if args and args.strip():
1493 split_args = shlex.split(args)
1494 for index, arg in enumerate(split_args[:-1]):
Ivan Lozanob021b2a2020-07-28 09:31:06 -04001495 # Check that the image file exists. Some images might be defined
Daniel Norman276f0622019-07-26 14:13:51 -07001496 # as a path relative to source tree, which may not be available at the
1497 # same location when running this script (we have the input target_files
1498 # zip only). For such cases, we additionally scan other locations (e.g.
1499 # IMAGES/, RADIO/, etc) before bailing out.
1500 if arg == '--include_descriptors_from_image':
Tianjie Xueaed60c2020-03-12 00:33:28 -07001501 chained_image = split_args[index + 1]
1502 if os.path.exists(chained_image):
Daniel Norman276f0622019-07-26 14:13:51 -07001503 continue
1504 found = False
1505 for dir_name in ['IMAGES', 'RADIO', 'PREBUILT_IMAGES']:
1506 alt_path = os.path.join(
Tianjie Xueaed60c2020-03-12 00:33:28 -07001507 OPTIONS.input_tmp, dir_name, os.path.basename(chained_image))
Daniel Norman276f0622019-07-26 14:13:51 -07001508 if os.path.exists(alt_path):
1509 split_args[index + 1] = alt_path
1510 found = True
1511 break
Tianjie Xueaed60c2020-03-12 00:33:28 -07001512 assert found, 'Failed to find {}'.format(chained_image)
Daniel Norman276f0622019-07-26 14:13:51 -07001513 cmd.extend(split_args)
1514
1515 RunAndCheckOutput(cmd)
1516
1517
jiajia tang836f76b2021-04-02 14:48:26 +08001518def _MakeRamdisk(sourcedir, fs_config_file=None,
1519 ramdisk_format=RamdiskFormat.GZ):
Steve Mucklee1b10862019-07-10 10:49:37 -07001520 ramdisk_img = tempfile.NamedTemporaryFile()
1521
1522 if fs_config_file is not None and os.access(fs_config_file, os.F_OK):
1523 cmd = ["mkbootfs", "-f", fs_config_file,
1524 os.path.join(sourcedir, "RAMDISK")]
1525 else:
1526 cmd = ["mkbootfs", os.path.join(sourcedir, "RAMDISK")]
1527 p1 = Run(cmd, stdout=subprocess.PIPE)
jiajia tang836f76b2021-04-02 14:48:26 +08001528 if ramdisk_format == RamdiskFormat.LZ4:
Kelvin Zhangcff4d762020-07-29 16:37:51 -04001529 p2 = Run(["lz4", "-l", "-12", "--favor-decSpeed"], stdin=p1.stdout,
J. Avila98cd4cc2020-06-10 20:09:10 +00001530 stdout=ramdisk_img.file.fileno())
jiajia tang836f76b2021-04-02 14:48:26 +08001531 elif ramdisk_format == RamdiskFormat.GZ:
J. Avila98cd4cc2020-06-10 20:09:10 +00001532 p2 = Run(["minigzip"], stdin=p1.stdout, stdout=ramdisk_img.file.fileno())
jiajia tang836f76b2021-04-02 14:48:26 +08001533 else:
1534 raise ValueError("Only support lz4 or minigzip ramdisk format.")
Steve Mucklee1b10862019-07-10 10:49:37 -07001535
1536 p2.wait()
1537 p1.wait()
1538 assert p1.returncode == 0, "mkbootfs of %s ramdisk failed" % (sourcedir,)
J. Avila98cd4cc2020-06-10 20:09:10 +00001539 assert p2.returncode == 0, "compression of %s ramdisk failed" % (sourcedir,)
Steve Mucklee1b10862019-07-10 10:49:37 -07001540
1541 return ramdisk_img
1542
1543
Steve Muckle9793cf62020-04-08 18:27:00 -07001544def _BuildBootableImage(image_name, sourcedir, fs_config_file, info_dict=None,
Tao Baod42e97e2016-11-30 12:11:57 -08001545 has_ramdisk=False, two_step_image=False):
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001546 """Build a bootable image from the specified sourcedir.
Doug Zongkere1c31ba2009-06-23 17:40:35 -07001547
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001548 Take a kernel, cmdline, and optionally a ramdisk directory from the input (in
Tao Baod42e97e2016-11-30 12:11:57 -08001549 'sourcedir'), and turn them into a boot image. 'two_step_image' indicates if
1550 we are building a two-step special image (i.e. building a recovery image to
1551 be loaded into /boot in two-step OTAs).
1552
1553 Return the image data, or None if sourcedir does not appear to contains files
1554 for building the requested image.
1555 """
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001556
Yifan Hong63c5ca12020-10-08 11:54:02 -07001557 if info_dict is None:
1558 info_dict = OPTIONS.info_dict
1559
Steve Muckle9793cf62020-04-08 18:27:00 -07001560 # "boot" or "recovery", without extension.
1561 partition_name = os.path.basename(sourcedir).lower()
1562
Yifan Hong63c5ca12020-10-08 11:54:02 -07001563 kernel = None
Steve Muckle9793cf62020-04-08 18:27:00 -07001564 if partition_name == "recovery":
Yifan Hong63c5ca12020-10-08 11:54:02 -07001565 if info_dict.get("exclude_kernel_from_recovery_image") == "true":
1566 logger.info("Excluded kernel binary from recovery image.")
1567 else:
1568 kernel = "kernel"
Devin Mooreafdd7c72021-12-13 22:04:08 +00001569 elif partition_name == "init_boot":
1570 pass
Steve Muckle9793cf62020-04-08 18:27:00 -07001571 else:
1572 kernel = image_name.replace("boot", "kernel")
Kelvin Zhang0876c412020-06-23 15:06:58 -04001573 kernel = kernel.replace(".img", "")
Yifan Hong63c5ca12020-10-08 11:54:02 -07001574 if kernel and not os.access(os.path.join(sourcedir, kernel), os.F_OK):
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001575 return None
1576
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001577 kernel_path = os.path.join(sourcedir, kernel) if kernel else None
1578
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001579 if has_ramdisk and not os.access(os.path.join(sourcedir, "RAMDISK"), os.F_OK):
Doug Zongkere1c31ba2009-06-23 17:40:35 -07001580 return None
Doug Zongkereef39442009-04-02 12:14:19 -07001581
Doug Zongkereef39442009-04-02 12:14:19 -07001582 img = tempfile.NamedTemporaryFile()
1583
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001584 if has_ramdisk:
TJ Rhoades6f488e92022-05-01 22:16:22 -07001585 ramdisk_format = GetRamdiskFormat(info_dict)
jiajia tang836f76b2021-04-02 14:48:26 +08001586 ramdisk_img = _MakeRamdisk(sourcedir, fs_config_file,
1587 ramdisk_format=ramdisk_format)
Doug Zongkereef39442009-04-02 12:14:19 -07001588
Bjorn Andersson612e2cd2012-11-25 16:53:44 -08001589 # use MKBOOTIMG from environ, or "mkbootimg" if empty or not set
1590 mkbootimg = os.getenv('MKBOOTIMG') or "mkbootimg"
1591
Yifan Hong63c5ca12020-10-08 11:54:02 -07001592 cmd = [mkbootimg]
Yi-Yo Chiang36054e22022-01-08 22:29:30 +08001593 if kernel_path is not None:
1594 cmd.extend(["--kernel", kernel_path])
Doug Zongker38a649f2009-06-17 09:07:09 -07001595
Benoit Fradina45a8682014-07-14 21:00:43 +02001596 fn = os.path.join(sourcedir, "second")
1597 if os.access(fn, os.F_OK):
1598 cmd.append("--second")
1599 cmd.append(fn)
1600
Hridya Valsaraju9683b2f2019-01-22 18:08:59 -08001601 fn = os.path.join(sourcedir, "dtb")
1602 if os.access(fn, os.F_OK):
1603 cmd.append("--dtb")
1604 cmd.append(fn)
1605
Doug Zongker171f1cd2009-06-15 22:36:37 -07001606 fn = os.path.join(sourcedir, "cmdline")
1607 if os.access(fn, os.F_OK):
Doug Zongker38a649f2009-06-17 09:07:09 -07001608 cmd.append("--cmdline")
1609 cmd.append(open(fn).read().rstrip("\n"))
1610
1611 fn = os.path.join(sourcedir, "base")
1612 if os.access(fn, os.F_OK):
1613 cmd.append("--base")
1614 cmd.append(open(fn).read().rstrip("\n"))
1615
Ying Wang4de6b5b2010-08-25 14:29:34 -07001616 fn = os.path.join(sourcedir, "pagesize")
1617 if os.access(fn, os.F_OK):
1618 cmd.append("--pagesize")
1619 cmd.append(open(fn).read().rstrip("\n"))
1620
Steve Mucklef84668e2020-03-16 19:13:46 -07001621 if partition_name == "recovery":
1622 args = info_dict.get("recovery_mkbootimg_args")
P.Adarsh Reddyd8e24ee2020-05-04 19:40:16 +05301623 if not args:
1624 # Fall back to "mkbootimg_args" for recovery image
1625 # in case "recovery_mkbootimg_args" is not set.
1626 args = info_dict.get("mkbootimg_args")
Devin Mooreafdd7c72021-12-13 22:04:08 +00001627 elif partition_name == "init_boot":
1628 args = info_dict.get("mkbootimg_init_args")
Steve Mucklef84668e2020-03-16 19:13:46 -07001629 else:
1630 args = info_dict.get("mkbootimg_args")
Doug Zongkerd5131602012-08-02 14:46:42 -07001631 if args and args.strip():
Jianxun Zhang09849492013-04-17 15:19:19 -07001632 cmd.extend(shlex.split(args))
Doug Zongkerd5131602012-08-02 14:46:42 -07001633
Yi-Yo Chiang24da1a42022-02-22 19:51:15 +08001634 args = info_dict.get("mkbootimg_version_args")
1635 if args and args.strip():
1636 cmd.extend(shlex.split(args))
Sami Tolvanen3303d902016-03-15 16:49:30 +00001637
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001638 if has_ramdisk:
1639 cmd.extend(["--ramdisk", ramdisk_img.name])
1640
Tao Baod95e9fd2015-03-29 23:07:41 -07001641 img_unsigned = None
Tao Bao76def242017-11-21 09:25:31 -08001642 if info_dict.get("vboot"):
Tao Baod95e9fd2015-03-29 23:07:41 -07001643 img_unsigned = tempfile.NamedTemporaryFile()
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001644 cmd.extend(["--output", img_unsigned.name])
Tao Baod95e9fd2015-03-29 23:07:41 -07001645 else:
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001646 cmd.extend(["--output", img.name])
Doug Zongker38a649f2009-06-17 09:07:09 -07001647
Chen, ZhiminX752439b2018-09-23 22:10:47 +08001648 if partition_name == "recovery":
1649 if info_dict.get("include_recovery_dtbo") == "true":
1650 fn = os.path.join(sourcedir, "recovery_dtbo")
1651 cmd.extend(["--recovery_dtbo", fn])
1652 if info_dict.get("include_recovery_acpio") == "true":
1653 fn = os.path.join(sourcedir, "recovery_acpio")
1654 cmd.extend(["--recovery_acpio", fn])
Hridya Valsarajue74a38b2018-03-21 12:15:11 -07001655
Tao Bao986ee862018-10-04 15:46:16 -07001656 RunAndCheckOutput(cmd)
Doug Zongkereef39442009-04-02 12:14:19 -07001657
Yi-Yo Chiang24da1a42022-02-22 19:51:15 +08001658 if _HasGkiCertificationArgs():
1659 if not os.path.exists(img.name):
1660 raise ValueError("Cannot find GKI boot.img")
1661 if kernel_path is None or not os.path.exists(kernel_path):
1662 raise ValueError("Cannot find GKI kernel.img")
1663
1664 # Certify GKI images.
1665 boot_signature_bytes = b''
1666 boot_signature_bytes += _GenerateGkiCertificate(img.name, "boot")
1667 boot_signature_bytes += _GenerateGkiCertificate(
1668 kernel_path, "generic_kernel")
1669
1670 BOOT_SIGNATURE_SIZE = 16 * 1024
1671 if len(boot_signature_bytes) > BOOT_SIGNATURE_SIZE:
1672 raise ValueError(
1673 f"GKI boot_signature size must be <= {BOOT_SIGNATURE_SIZE}")
1674 boot_signature_bytes += (
1675 b'\0' * (BOOT_SIGNATURE_SIZE - len(boot_signature_bytes)))
1676 assert len(boot_signature_bytes) == BOOT_SIGNATURE_SIZE
1677
1678 with open(img.name, 'ab') as f:
1679 f.write(boot_signature_bytes)
1680
Tao Bao76def242017-11-21 09:25:31 -08001681 if (info_dict.get("boot_signer") == "true" and
Kelvin Zhang563750f2021-04-28 12:46:17 -04001682 info_dict.get("verity_key")):
Tao Baod42e97e2016-11-30 12:11:57 -08001683 # Hard-code the path as "/boot" for two-step special recovery image (which
1684 # will be loaded into /boot during the two-step OTA).
1685 if two_step_image:
1686 path = "/boot"
1687 else:
Tao Baobf70c312017-07-11 17:27:55 -07001688 path = "/" + partition_name
Baligh Uddin601ddea2015-06-09 15:48:14 -07001689 cmd = [OPTIONS.boot_signer_path]
1690 cmd.extend(OPTIONS.boot_signer_args)
1691 cmd.extend([path, img.name,
1692 info_dict["verity_key"] + ".pk8",
1693 info_dict["verity_key"] + ".x509.pem", img.name])
Tao Bao986ee862018-10-04 15:46:16 -07001694 RunAndCheckOutput(cmd)
Geremy Condra95ebe7a2014-08-19 17:27:56 -07001695
Tao Baod95e9fd2015-03-29 23:07:41 -07001696 # Sign the image if vboot is non-empty.
Tao Bao76def242017-11-21 09:25:31 -08001697 elif info_dict.get("vboot"):
Tao Baobf70c312017-07-11 17:27:55 -07001698 path = "/" + partition_name
Tao Baod95e9fd2015-03-29 23:07:41 -07001699 img_keyblock = tempfile.NamedTemporaryFile()
Tao Bao4f104d12017-02-17 23:21:31 -08001700 # We have switched from the prebuilt futility binary to using the tool
1701 # (futility-host) built from the source. Override the setting in the old
1702 # TF.zip.
1703 futility = info_dict["futility"]
1704 if futility.startswith("prebuilts/"):
1705 futility = "futility-host"
1706 cmd = [info_dict["vboot_signer_cmd"], futility,
Tao Baod95e9fd2015-03-29 23:07:41 -07001707 img_unsigned.name, info_dict["vboot_key"] + ".vbpubk",
Furquan Shaikh852b8de2015-08-10 11:43:45 -07001708 info_dict["vboot_key"] + ".vbprivk",
1709 info_dict["vboot_subkey"] + ".vbprivk",
1710 img_keyblock.name,
Tao Baod95e9fd2015-03-29 23:07:41 -07001711 img.name]
Tao Bao986ee862018-10-04 15:46:16 -07001712 RunAndCheckOutput(cmd)
Tao Baod95e9fd2015-03-29 23:07:41 -07001713
Tao Baof3282b42015-04-01 11:21:55 -07001714 # Clean up the temp files.
1715 img_unsigned.close()
1716 img_keyblock.close()
1717
David Zeuthen8fecb282017-12-01 16:24:01 -05001718 # AVB: if enabled, calculate and add hash to boot.img or recovery.img.
Bowgo Tsai3e599ea2017-05-26 18:30:04 +08001719 if info_dict.get("avb_enable") == "true":
Tao Baof88e0ce2019-03-18 14:01:38 -07001720 avbtool = info_dict["avb_avbtool"]
Steve Muckle903a1ca2020-05-07 17:32:10 -07001721 if partition_name == "recovery":
1722 part_size = info_dict["recovery_size"]
1723 else:
Kelvin Zhang0876c412020-06-23 15:06:58 -04001724 part_size = info_dict[image_name.replace(".img", "_size")]
David Zeuthen2ce63ed2016-09-15 13:43:54 -04001725 cmd = [avbtool, "add_hash_footer", "--image", img.name,
Tao Baobf70c312017-07-11 17:27:55 -07001726 "--partition_size", str(part_size), "--partition_name",
1727 partition_name]
1728 AppendAVBSigningArgs(cmd, partition_name)
David Zeuthen8fecb282017-12-01 16:24:01 -05001729 args = info_dict.get("avb_" + partition_name + "_add_hash_footer_args")
David Zeuthen2ce63ed2016-09-15 13:43:54 -04001730 if args and args.strip():
1731 cmd.extend(shlex.split(args))
Tao Bao986ee862018-10-04 15:46:16 -07001732 RunAndCheckOutput(cmd)
David Zeuthend995f4b2016-01-29 16:59:17 -05001733
1734 img.seek(os.SEEK_SET, 0)
1735 data = img.read()
1736
1737 if has_ramdisk:
1738 ramdisk_img.close()
1739 img.close()
1740
1741 return data
1742
1743
Bowgo Tsaicf9ead82021-05-20 00:14:42 +08001744def _SignBootableImage(image_path, prebuilt_name, partition_name,
1745 info_dict=None):
1746 """Performs AVB signing for a prebuilt boot.img.
1747
1748 Args:
1749 image_path: The full path of the image, e.g., /path/to/boot.img.
1750 prebuilt_name: The prebuilt image name, e.g., boot.img, boot-5.4-gz.img,
Bowgo Tsai88fc2bd2022-01-05 20:19:25 +08001751 boot-5.10.img, recovery.img or init_boot.img.
1752 partition_name: The partition name, e.g., 'boot', 'init_boot' or 'recovery'.
Bowgo Tsaicf9ead82021-05-20 00:14:42 +08001753 info_dict: The information dict read from misc_info.txt.
1754 """
1755 if info_dict is None:
1756 info_dict = OPTIONS.info_dict
1757
1758 # AVB: if enabled, calculate and add hash to boot.img or recovery.img.
1759 if info_dict.get("avb_enable") == "true":
1760 avbtool = info_dict["avb_avbtool"]
1761 if partition_name == "recovery":
1762 part_size = info_dict["recovery_size"]
1763 else:
1764 part_size = info_dict[prebuilt_name.replace(".img", "_size")]
1765
1766 cmd = [avbtool, "add_hash_footer", "--image", image_path,
1767 "--partition_size", str(part_size), "--partition_name",
1768 partition_name]
1769 AppendAVBSigningArgs(cmd, partition_name)
1770 args = info_dict.get("avb_" + partition_name + "_add_hash_footer_args")
1771 if args and args.strip():
1772 cmd.extend(shlex.split(args))
1773 RunAndCheckOutput(cmd)
1774
1775
Bowgo Tsai88fc2bd2022-01-05 20:19:25 +08001776def HasRamdisk(partition_name, info_dict=None):
1777 """Returns true/false to see if a bootable image should have a ramdisk.
1778
1779 Args:
1780 partition_name: The partition name, e.g., 'boot', 'init_boot' or 'recovery'.
1781 info_dict: The information dict read from misc_info.txt.
1782 """
1783 if info_dict is None:
1784 info_dict = OPTIONS.info_dict
1785
1786 if partition_name != "boot":
1787 return True # init_boot.img or recovery.img has a ramdisk.
1788
1789 if info_dict.get("recovery_as_boot") == "true":
1790 return True # the recovery-as-boot boot.img has a RECOVERY ramdisk.
1791
Bowgo Tsai85578e02022-04-19 10:50:59 +08001792 if info_dict.get("gki_boot_image_without_ramdisk") == "true":
1793 return False # A GKI boot.img has no ramdisk since Android-13.
1794
Bowgo Tsai88fc2bd2022-01-05 20:19:25 +08001795 if info_dict.get("system_root_image") == "true":
1796 # The ramdisk content is merged into the system.img, so there is NO
1797 # ramdisk in the boot.img or boot-<kernel version>.img.
1798 return False
1799
1800 if info_dict.get("init_boot") == "true":
1801 # The ramdisk is moved to the init_boot.img, so there is NO
1802 # ramdisk in the boot.img or boot-<kernel version>.img.
1803 return False
1804
1805 return True
1806
1807
Doug Zongkerd5131602012-08-02 14:46:42 -07001808def GetBootableImage(name, prebuilt_name, unpack_dir, tree_subdir,
Tao Baod42e97e2016-11-30 12:11:57 -08001809 info_dict=None, two_step_image=False):
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001810 """Return a File object with the desired bootable image.
1811
1812 Look for it in 'unpack_dir'/BOOTABLE_IMAGES under the name 'prebuilt_name',
1813 otherwise look for it under 'unpack_dir'/IMAGES, otherwise construct it from
1814 the source files in 'unpack_dir'/'tree_subdir'."""
Doug Zongkereef39442009-04-02 12:14:19 -07001815
Bowgo Tsaicf9ead82021-05-20 00:14:42 +08001816 if info_dict is None:
1817 info_dict = OPTIONS.info_dict
1818
Doug Zongker55d93282011-01-25 17:03:34 -08001819 prebuilt_path = os.path.join(unpack_dir, "BOOTABLE_IMAGES", prebuilt_name)
1820 if os.path.exists(prebuilt_path):
Tao Bao32fcdab2018-10-12 10:30:39 -07001821 logger.info("using prebuilt %s from BOOTABLE_IMAGES...", prebuilt_name)
Doug Zongker55d93282011-01-25 17:03:34 -08001822 return File.FromLocalFile(name, prebuilt_path)
Doug Zongker6f1d0312014-08-22 08:07:12 -07001823
1824 prebuilt_path = os.path.join(unpack_dir, "IMAGES", prebuilt_name)
1825 if os.path.exists(prebuilt_path):
Tao Bao32fcdab2018-10-12 10:30:39 -07001826 logger.info("using prebuilt %s from IMAGES...", prebuilt_name)
Doug Zongker6f1d0312014-08-22 08:07:12 -07001827 return File.FromLocalFile(name, prebuilt_path)
1828
Bowgo Tsai88fc2bd2022-01-05 20:19:25 +08001829 partition_name = tree_subdir.lower()
Bowgo Tsaicf9ead82021-05-20 00:14:42 +08001830 prebuilt_path = os.path.join(unpack_dir, "PREBUILT_IMAGES", prebuilt_name)
1831 if os.path.exists(prebuilt_path):
1832 logger.info("Re-signing prebuilt %s from PREBUILT_IMAGES...", prebuilt_name)
1833 signed_img = MakeTempFile()
1834 shutil.copy(prebuilt_path, signed_img)
Bowgo Tsaicf9ead82021-05-20 00:14:42 +08001835 _SignBootableImage(signed_img, prebuilt_name, partition_name, info_dict)
1836 return File.FromLocalFile(name, signed_img)
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001837
Bowgo Tsaicf9ead82021-05-20 00:14:42 +08001838 logger.info("building image from target_files %s...", tree_subdir)
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001839
Bowgo Tsai88fc2bd2022-01-05 20:19:25 +08001840 has_ramdisk = HasRamdisk(partition_name, info_dict)
Tao Bao7a5bf8a2015-07-21 18:01:20 -07001841
Doug Zongker6f1d0312014-08-22 08:07:12 -07001842 fs_config = "META/" + tree_subdir.lower() + "_filesystem_config.txt"
Steve Muckle9793cf62020-04-08 18:27:00 -07001843 data = _BuildBootableImage(prebuilt_name, os.path.join(unpack_dir, tree_subdir),
David Zeuthen2ce63ed2016-09-15 13:43:54 -04001844 os.path.join(unpack_dir, fs_config),
Tao Baod42e97e2016-11-30 12:11:57 -08001845 info_dict, has_ramdisk, two_step_image)
Doug Zongker6f1d0312014-08-22 08:07:12 -07001846 if data:
1847 return File(name, data)
1848 return None
Doug Zongker55d93282011-01-25 17:03:34 -08001849
Doug Zongkereef39442009-04-02 12:14:19 -07001850
Lucas Wei03230252022-04-18 16:00:40 +08001851def _BuildVendorBootImage(sourcedir, partition_name, info_dict=None):
Steve Mucklee1b10862019-07-10 10:49:37 -07001852 """Build a vendor boot image from the specified sourcedir.
1853
1854 Take a ramdisk, dtb, and vendor_cmdline from the input (in 'sourcedir'), and
1855 turn them into a vendor boot image.
1856
1857 Return the image data, or None if sourcedir does not appear to contains files
1858 for building the requested image.
1859 """
1860
1861 if info_dict is None:
1862 info_dict = OPTIONS.info_dict
1863
1864 img = tempfile.NamedTemporaryFile()
1865
TJ Rhoades6f488e92022-05-01 22:16:22 -07001866 ramdisk_format = GetRamdiskFormat(info_dict)
jiajia tang836f76b2021-04-02 14:48:26 +08001867 ramdisk_img = _MakeRamdisk(sourcedir, ramdisk_format=ramdisk_format)
Steve Mucklee1b10862019-07-10 10:49:37 -07001868
1869 # use MKBOOTIMG from environ, or "mkbootimg" if empty or not set
1870 mkbootimg = os.getenv('MKBOOTIMG') or "mkbootimg"
1871
1872 cmd = [mkbootimg]
1873
1874 fn = os.path.join(sourcedir, "dtb")
1875 if os.access(fn, os.F_OK):
Lucas Wei03230252022-04-18 16:00:40 +08001876 has_vendor_kernel_boot = (info_dict.get("vendor_kernel_boot", "").lower() == "true")
1877
1878 # Pack dtb into vendor_kernel_boot if building vendor_kernel_boot.
1879 # Otherwise pack dtb into vendor_boot.
1880 if not has_vendor_kernel_boot or partition_name == "vendor_kernel_boot":
1881 cmd.append("--dtb")
1882 cmd.append(fn)
Steve Mucklee1b10862019-07-10 10:49:37 -07001883
1884 fn = os.path.join(sourcedir, "vendor_cmdline")
1885 if os.access(fn, os.F_OK):
1886 cmd.append("--vendor_cmdline")
1887 cmd.append(open(fn).read().rstrip("\n"))
1888
1889 fn = os.path.join(sourcedir, "base")
1890 if os.access(fn, os.F_OK):
1891 cmd.append("--base")
1892 cmd.append(open(fn).read().rstrip("\n"))
1893
1894 fn = os.path.join(sourcedir, "pagesize")
1895 if os.access(fn, os.F_OK):
1896 cmd.append("--pagesize")
1897 cmd.append(open(fn).read().rstrip("\n"))
1898
1899 args = info_dict.get("mkbootimg_args")
1900 if args and args.strip():
1901 cmd.extend(shlex.split(args))
1902
1903 args = info_dict.get("mkbootimg_version_args")
1904 if args and args.strip():
1905 cmd.extend(shlex.split(args))
1906
1907 cmd.extend(["--vendor_ramdisk", ramdisk_img.name])
1908 cmd.extend(["--vendor_boot", img.name])
1909
Devin Moore50509012021-01-13 10:45:04 -08001910 fn = os.path.join(sourcedir, "vendor_bootconfig")
1911 if os.access(fn, os.F_OK):
1912 cmd.append("--vendor_bootconfig")
1913 cmd.append(fn)
1914
Yo Chiangd21e7dc2020-12-10 18:42:47 +08001915 ramdisk_fragment_imgs = []
1916 fn = os.path.join(sourcedir, "vendor_ramdisk_fragments")
1917 if os.access(fn, os.F_OK):
1918 ramdisk_fragments = shlex.split(open(fn).read().rstrip("\n"))
1919 for ramdisk_fragment in ramdisk_fragments:
Kelvin Zhang563750f2021-04-28 12:46:17 -04001920 fn = os.path.join(sourcedir, "RAMDISK_FRAGMENTS",
1921 ramdisk_fragment, "mkbootimg_args")
Yo Chiangd21e7dc2020-12-10 18:42:47 +08001922 cmd.extend(shlex.split(open(fn).read().rstrip("\n")))
Kelvin Zhang563750f2021-04-28 12:46:17 -04001923 fn = os.path.join(sourcedir, "RAMDISK_FRAGMENTS",
1924 ramdisk_fragment, "prebuilt_ramdisk")
Yo Chiangd21e7dc2020-12-10 18:42:47 +08001925 # Use prebuilt image if found, else create ramdisk from supplied files.
1926 if os.access(fn, os.F_OK):
1927 ramdisk_fragment_pathname = fn
1928 else:
Kelvin Zhang563750f2021-04-28 12:46:17 -04001929 ramdisk_fragment_root = os.path.join(
1930 sourcedir, "RAMDISK_FRAGMENTS", ramdisk_fragment)
jiajia tang836f76b2021-04-02 14:48:26 +08001931 ramdisk_fragment_img = _MakeRamdisk(ramdisk_fragment_root,
1932 ramdisk_format=ramdisk_format)
Yo Chiangd21e7dc2020-12-10 18:42:47 +08001933 ramdisk_fragment_imgs.append(ramdisk_fragment_img)
1934 ramdisk_fragment_pathname = ramdisk_fragment_img.name
1935 cmd.extend(["--vendor_ramdisk_fragment", ramdisk_fragment_pathname])
1936
Steve Mucklee1b10862019-07-10 10:49:37 -07001937 RunAndCheckOutput(cmd)
1938
1939 # AVB: if enabled, calculate and add hash.
1940 if info_dict.get("avb_enable") == "true":
1941 avbtool = info_dict["avb_avbtool"]
Lucas Wei03230252022-04-18 16:00:40 +08001942 part_size = info_dict[f'{partition_name}_size']
Steve Mucklee1b10862019-07-10 10:49:37 -07001943 cmd = [avbtool, "add_hash_footer", "--image", img.name,
Lucas Wei03230252022-04-18 16:00:40 +08001944 "--partition_size", str(part_size), "--partition_name", partition_name]
1945 AppendAVBSigningArgs(cmd, partition_name)
1946 args = info_dict.get(f'avb_{partition_name}_add_hash_footer_args')
Steve Mucklee1b10862019-07-10 10:49:37 -07001947 if args and args.strip():
1948 cmd.extend(shlex.split(args))
1949 RunAndCheckOutput(cmd)
1950
1951 img.seek(os.SEEK_SET, 0)
1952 data = img.read()
1953
Yo Chiangd21e7dc2020-12-10 18:42:47 +08001954 for f in ramdisk_fragment_imgs:
1955 f.close()
Steve Mucklee1b10862019-07-10 10:49:37 -07001956 ramdisk_img.close()
1957 img.close()
1958
1959 return data
1960
1961
1962def GetVendorBootImage(name, prebuilt_name, unpack_dir, tree_subdir,
1963 info_dict=None):
1964 """Return a File object with the desired vendor boot image.
1965
1966 Look for it under 'unpack_dir'/IMAGES, otherwise construct it from
1967 the source files in 'unpack_dir'/'tree_subdir'."""
1968
1969 prebuilt_path = os.path.join(unpack_dir, "IMAGES", prebuilt_name)
1970 if os.path.exists(prebuilt_path):
1971 logger.info("using prebuilt %s from IMAGES...", prebuilt_name)
1972 return File.FromLocalFile(name, prebuilt_path)
1973
1974 logger.info("building image from target_files %s...", tree_subdir)
1975
1976 if info_dict is None:
1977 info_dict = OPTIONS.info_dict
1978
Kelvin Zhang0876c412020-06-23 15:06:58 -04001979 data = _BuildVendorBootImage(
Lucas Wei03230252022-04-18 16:00:40 +08001980 os.path.join(unpack_dir, tree_subdir), "vendor_boot", info_dict)
1981 if data:
1982 return File(name, data)
1983 return None
1984
1985
1986def GetVendorKernelBootImage(name, prebuilt_name, unpack_dir, tree_subdir,
1987 info_dict=None):
1988 """Return a File object with the desired vendor kernel boot image.
1989
1990 Look for it under 'unpack_dir'/IMAGES, otherwise construct it from
1991 the source files in 'unpack_dir'/'tree_subdir'."""
1992
1993 prebuilt_path = os.path.join(unpack_dir, "IMAGES", prebuilt_name)
1994 if os.path.exists(prebuilt_path):
1995 logger.info("using prebuilt %s from IMAGES...", prebuilt_name)
1996 return File.FromLocalFile(name, prebuilt_path)
1997
1998 logger.info("building image from target_files %s...", tree_subdir)
1999
2000 if info_dict is None:
2001 info_dict = OPTIONS.info_dict
2002
2003 data = _BuildVendorBootImage(
2004 os.path.join(unpack_dir, tree_subdir), "vendor_kernel_boot", info_dict)
Steve Mucklee1b10862019-07-10 10:49:37 -07002005 if data:
2006 return File(name, data)
2007 return None
2008
2009
Narayan Kamatha07bf042017-08-14 14:49:21 +01002010def Gunzip(in_filename, out_filename):
Tao Bao76def242017-11-21 09:25:31 -08002011 """Gunzips the given gzip compressed file to a given output file."""
2012 with gzip.open(in_filename, "rb") as in_file, \
Kelvin Zhang0876c412020-06-23 15:06:58 -04002013 open(out_filename, "wb") as out_file:
Narayan Kamatha07bf042017-08-14 14:49:21 +01002014 shutil.copyfileobj(in_file, out_file)
2015
2016
Tao Bao0ff15de2019-03-20 11:26:06 -07002017def UnzipToDir(filename, dirname, patterns=None):
Bill Peckham8ff3fbd2019-02-22 10:57:43 -08002018 """Unzips the archive to the given directory.
2019
2020 Args:
2021 filename: The name of the zip file to unzip.
Bill Peckham8ff3fbd2019-02-22 10:57:43 -08002022 dirname: Where the unziped files will land.
Tao Bao0ff15de2019-03-20 11:26:06 -07002023 patterns: Files to unzip from the archive. If omitted, will unzip the entire
2024 archvie. Non-matching patterns will be filtered out. If there's no match
2025 after the filtering, no file will be unzipped.
Bill Peckham8ff3fbd2019-02-22 10:57:43 -08002026 """
Bill Peckham8ff3fbd2019-02-22 10:57:43 -08002027 cmd = ["unzip", "-o", "-q", filename, "-d", dirname]
Tao Bao0ff15de2019-03-20 11:26:06 -07002028 if patterns is not None:
2029 # Filter out non-matching patterns. unzip will complain otherwise.
Kelvin Zhang928c2342020-09-22 16:15:57 -04002030 with zipfile.ZipFile(filename, allowZip64=True) as input_zip:
Tao Bao0ff15de2019-03-20 11:26:06 -07002031 names = input_zip.namelist()
2032 filtered = [
2033 pattern for pattern in patterns if fnmatch.filter(names, pattern)]
2034
2035 # There isn't any matching files. Don't unzip anything.
2036 if not filtered:
2037 return
2038 cmd.extend(filtered)
2039
Bill Peckham8ff3fbd2019-02-22 10:57:43 -08002040 RunAndCheckOutput(cmd)
2041
2042
Daniel Norman78554ea2021-09-14 10:29:38 -07002043def UnzipTemp(filename, patterns=None):
Tao Bao1c830bf2017-12-25 10:43:47 -08002044 """Unzips the given archive into a temporary directory and returns the name.
Doug Zongker55d93282011-01-25 17:03:34 -08002045
Bill Peckham8ff3fbd2019-02-22 10:57:43 -08002046 Args:
2047 filename: If filename is of the form "foo.zip+bar.zip", unzip foo.zip into
2048 a temp dir, then unzip bar.zip into that_dir/BOOTABLE_IMAGES.
2049
Daniel Norman78554ea2021-09-14 10:29:38 -07002050 patterns: Files to unzip from the archive. If omitted, will unzip the entire
Bill Peckham8ff3fbd2019-02-22 10:57:43 -08002051 archvie.
Doug Zongker55d93282011-01-25 17:03:34 -08002052
Tao Bao1c830bf2017-12-25 10:43:47 -08002053 Returns:
Tao Baodba59ee2018-01-09 13:21:02 -08002054 The name of the temporary directory.
Doug Zongker55d93282011-01-25 17:03:34 -08002055 """
Doug Zongkereef39442009-04-02 12:14:19 -07002056
Tao Bao1c830bf2017-12-25 10:43:47 -08002057 tmp = MakeTempDir(prefix="targetfiles-")
Doug Zongker55d93282011-01-25 17:03:34 -08002058 m = re.match(r"^(.*[.]zip)\+(.*[.]zip)$", filename, re.IGNORECASE)
2059 if m:
Daniel Norman78554ea2021-09-14 10:29:38 -07002060 UnzipToDir(m.group(1), tmp, patterns)
2061 UnzipToDir(m.group(2), os.path.join(tmp, "BOOTABLE_IMAGES"), patterns)
Doug Zongker55d93282011-01-25 17:03:34 -08002062 filename = m.group(1)
2063 else:
Daniel Norman78554ea2021-09-14 10:29:38 -07002064 UnzipToDir(filename, tmp, patterns)
Doug Zongker55d93282011-01-25 17:03:34 -08002065
Tao Baodba59ee2018-01-09 13:21:02 -08002066 return tmp
Doug Zongkereef39442009-04-02 12:14:19 -07002067
2068
Yifan Hong8a66a712019-04-04 15:37:57 -07002069def GetUserImage(which, tmpdir, input_zip,
2070 info_dict=None,
2071 allow_shared_blocks=None,
2072 hashtree_info_generator=None,
2073 reset_file_map=False):
2074 """Returns an Image object suitable for passing to BlockImageDiff.
2075
2076 This function loads the specified image from the given path. If the specified
2077 image is sparse, it also performs additional processing for OTA purpose. For
2078 example, it always adds block 0 to clobbered blocks list. It also detects
2079 files that cannot be reconstructed from the block list, for whom we should
2080 avoid applying imgdiff.
2081
2082 Args:
2083 which: The partition name.
2084 tmpdir: The directory that contains the prebuilt image and block map file.
2085 input_zip: The target-files ZIP archive.
2086 info_dict: The dict to be looked up for relevant info.
2087 allow_shared_blocks: If image is sparse, whether having shared blocks is
2088 allowed. If none, it is looked up from info_dict.
2089 hashtree_info_generator: If present and image is sparse, generates the
2090 hashtree_info for this sparse image.
2091 reset_file_map: If true and image is sparse, reset file map before returning
2092 the image.
2093 Returns:
2094 A Image object. If it is a sparse image and reset_file_map is False, the
2095 image will have file_map info loaded.
2096 """
Tao Baoc1a1ec32019-06-18 16:29:37 -07002097 if info_dict is None:
Yifan Hong8a66a712019-04-04 15:37:57 -07002098 info_dict = LoadInfoDict(input_zip)
2099
2100 is_sparse = info_dict.get("extfs_sparse_flag")
David Anderson9e95a022021-08-31 21:32:45 -07002101 if info_dict.get(which + "_disable_sparse"):
2102 is_sparse = False
Yifan Hong8a66a712019-04-04 15:37:57 -07002103
2104 # When target uses 'BOARD_EXT4_SHARE_DUP_BLOCKS := true', images may contain
2105 # shared blocks (i.e. some blocks will show up in multiple files' block
2106 # list). We can only allocate such shared blocks to the first "owner", and
2107 # disable imgdiff for all later occurrences.
2108 if allow_shared_blocks is None:
2109 allow_shared_blocks = info_dict.get("ext4_share_dup_blocks") == "true"
2110
2111 if is_sparse:
2112 img = GetSparseImage(which, tmpdir, input_zip, allow_shared_blocks,
2113 hashtree_info_generator)
2114 if reset_file_map:
2115 img.ResetFileMap()
2116 return img
Kelvin Zhang0876c412020-06-23 15:06:58 -04002117 return GetNonSparseImage(which, tmpdir, hashtree_info_generator)
Yifan Hong8a66a712019-04-04 15:37:57 -07002118
2119
2120def GetNonSparseImage(which, tmpdir, hashtree_info_generator=None):
2121 """Returns a Image object suitable for passing to BlockImageDiff.
2122
2123 This function loads the specified non-sparse image from the given path.
2124
2125 Args:
2126 which: The partition name.
2127 tmpdir: The directory that contains the prebuilt image and block map file.
2128 Returns:
2129 A Image object.
2130 """
2131 path = os.path.join(tmpdir, "IMAGES", which + ".img")
2132 mappath = os.path.join(tmpdir, "IMAGES", which + ".map")
2133
2134 # The image and map files must have been created prior to calling
2135 # ota_from_target_files.py (since LMP).
2136 assert os.path.exists(path) and os.path.exists(mappath)
2137
Tianjie Xu41976c72019-07-03 13:57:01 -07002138 return images.FileImage(path, hashtree_info_generator=hashtree_info_generator)
2139
Yifan Hong8a66a712019-04-04 15:37:57 -07002140
Tianjie Xu67c7cbb2018-08-30 00:32:07 -07002141def GetSparseImage(which, tmpdir, input_zip, allow_shared_blocks,
2142 hashtree_info_generator=None):
Tao Baoc765cca2018-01-31 17:32:40 -08002143 """Returns a SparseImage object suitable for passing to BlockImageDiff.
2144
2145 This function loads the specified sparse image from the given path, and
2146 performs additional processing for OTA purpose. For example, it always adds
2147 block 0 to clobbered blocks list. It also detects files that cannot be
2148 reconstructed from the block list, for whom we should avoid applying imgdiff.
2149
2150 Args:
Tao Baob2de7d92019-04-10 10:01:47 -07002151 which: The partition name, e.g. "system", "vendor".
Tao Baoc765cca2018-01-31 17:32:40 -08002152 tmpdir: The directory that contains the prebuilt image and block map file.
2153 input_zip: The target-files ZIP archive.
Tao Baoe709b092018-02-07 12:40:00 -08002154 allow_shared_blocks: Whether having shared blocks is allowed.
Tianjie Xu67c7cbb2018-08-30 00:32:07 -07002155 hashtree_info_generator: If present, generates the hashtree_info for this
2156 sparse image.
Tao Baoc765cca2018-01-31 17:32:40 -08002157 Returns:
2158 A SparseImage object, with file_map info loaded.
2159 """
Tao Baoc765cca2018-01-31 17:32:40 -08002160 path = os.path.join(tmpdir, "IMAGES", which + ".img")
2161 mappath = os.path.join(tmpdir, "IMAGES", which + ".map")
2162
2163 # The image and map files must have been created prior to calling
2164 # ota_from_target_files.py (since LMP).
2165 assert os.path.exists(path) and os.path.exists(mappath)
2166
2167 # In ext4 filesystems, block 0 might be changed even being mounted R/O. We add
2168 # it to clobbered_blocks so that it will be written to the target
2169 # unconditionally. Note that they are still part of care_map. (Bug: 20939131)
2170 clobbered_blocks = "0"
2171
Tianjie Xu67c7cbb2018-08-30 00:32:07 -07002172 image = sparse_img.SparseImage(
2173 path, mappath, clobbered_blocks, allow_shared_blocks=allow_shared_blocks,
2174 hashtree_info_generator=hashtree_info_generator)
Tao Baoc765cca2018-01-31 17:32:40 -08002175
2176 # block.map may contain less blocks, because mke2fs may skip allocating blocks
2177 # if they contain all zeros. We can't reconstruct such a file from its block
2178 # list. Tag such entries accordingly. (Bug: 65213616)
2179 for entry in image.file_map:
Tao Baoc765cca2018-01-31 17:32:40 -08002180 # Skip artificial names, such as "__ZERO", "__NONZERO-1".
Tao Baod3554e62018-07-10 15:31:22 -07002181 if not entry.startswith('/'):
Tao Baoc765cca2018-01-31 17:32:40 -08002182 continue
2183
Tom Cherryd14b8952018-08-09 14:26:00 -07002184 # "/system/framework/am.jar" => "SYSTEM/framework/am.jar". Note that the
2185 # filename listed in system.map may contain an additional leading slash
2186 # (i.e. "//system/framework/am.jar"). Using lstrip to get consistent
2187 # results.
wangshumin71af07a2021-02-24 11:08:47 +08002188 # And handle another special case, where files not under /system
Tom Cherryd14b8952018-08-09 14:26:00 -07002189 # (e.g. "/sbin/charger") are packed under ROOT/ in a target_files.zip.
wangshumin71af07a2021-02-24 11:08:47 +08002190 arcname = entry.lstrip('/')
2191 if which == 'system' and not arcname.startswith('system'):
Tao Baod3554e62018-07-10 15:31:22 -07002192 arcname = 'ROOT/' + arcname
wangshumin71af07a2021-02-24 11:08:47 +08002193 else:
2194 arcname = arcname.replace(which, which.upper(), 1)
Tao Baod3554e62018-07-10 15:31:22 -07002195
2196 assert arcname in input_zip.namelist(), \
2197 "Failed to find the ZIP entry for {}".format(entry)
2198
Tao Baoc765cca2018-01-31 17:32:40 -08002199 info = input_zip.getinfo(arcname)
2200 ranges = image.file_map[entry]
Tao Baoe709b092018-02-07 12:40:00 -08002201
2202 # If a RangeSet has been tagged as using shared blocks while loading the
Tao Bao2a20f342018-12-03 15:08:23 -08002203 # image, check the original block list to determine its completeness. Note
2204 # that the 'incomplete' flag would be tagged to the original RangeSet only.
Tao Baoe709b092018-02-07 12:40:00 -08002205 if ranges.extra.get('uses_shared_blocks'):
Tao Bao2a20f342018-12-03 15:08:23 -08002206 ranges = ranges.extra['uses_shared_blocks']
Tao Baoe709b092018-02-07 12:40:00 -08002207
Tao Baoc765cca2018-01-31 17:32:40 -08002208 if RoundUpTo4K(info.file_size) > ranges.size() * 4096:
2209 ranges.extra['incomplete'] = True
2210
2211 return image
2212
2213
Doug Zongkereef39442009-04-02 12:14:19 -07002214def GetKeyPasswords(keylist):
2215 """Given a list of keys, prompt the user to enter passwords for
2216 those which require them. Return a {key: password} dict. password
2217 will be None if the key has no password."""
2218
Doug Zongker8ce7c252009-05-22 13:34:54 -07002219 no_passwords = []
2220 need_passwords = []
T.R. Fullhart37e10522013-03-18 10:31:26 -07002221 key_passwords = {}
Doug Zongkereef39442009-04-02 12:14:19 -07002222 devnull = open("/dev/null", "w+b")
Cole Faustb820bcd2021-10-28 13:59:48 -07002223
2224 # sorted() can't compare strings to None, so convert Nones to strings
2225 for k in sorted(keylist, key=lambda x: x if x is not None else ""):
Doug Zongkerf6a53aa2009-12-15 15:06:55 -08002226 # We don't need a password for things that aren't really keys.
Jooyung Han8caba5e2021-10-27 03:58:09 +09002227 if k in SPECIAL_CERT_STRINGS or k is None:
Doug Zongker8ce7c252009-05-22 13:34:54 -07002228 no_passwords.append(k)
Doug Zongker43874f82009-04-14 14:05:15 -07002229 continue
2230
T.R. Fullhart37e10522013-03-18 10:31:26 -07002231 p = Run(["openssl", "pkcs8", "-in", k+OPTIONS.private_key_suffix,
Doug Zongker602a84e2009-06-18 08:35:12 -07002232 "-inform", "DER", "-nocrypt"],
2233 stdin=devnull.fileno(),
2234 stdout=devnull.fileno(),
2235 stderr=subprocess.STDOUT)
Doug Zongkereef39442009-04-02 12:14:19 -07002236 p.communicate()
2237 if p.returncode == 0:
T.R. Fullhart37e10522013-03-18 10:31:26 -07002238 # Definitely an unencrypted key.
Doug Zongker8ce7c252009-05-22 13:34:54 -07002239 no_passwords.append(k)
Doug Zongkereef39442009-04-02 12:14:19 -07002240 else:
T.R. Fullhart37e10522013-03-18 10:31:26 -07002241 p = Run(["openssl", "pkcs8", "-in", k+OPTIONS.private_key_suffix,
2242 "-inform", "DER", "-passin", "pass:"],
2243 stdin=devnull.fileno(),
2244 stdout=devnull.fileno(),
2245 stderr=subprocess.PIPE)
Dan Albert8b72aef2015-03-23 19:13:21 -07002246 _, stderr = p.communicate()
T.R. Fullhart37e10522013-03-18 10:31:26 -07002247 if p.returncode == 0:
2248 # Encrypted key with empty string as password.
2249 key_passwords[k] = ''
2250 elif stderr.startswith('Error decrypting key'):
2251 # Definitely encrypted key.
2252 # It would have said "Error reading key" if it didn't parse correctly.
2253 need_passwords.append(k)
2254 else:
2255 # Potentially, a type of key that openssl doesn't understand.
2256 # We'll let the routines in signapk.jar handle it.
2257 no_passwords.append(k)
Doug Zongkereef39442009-04-02 12:14:19 -07002258 devnull.close()
Doug Zongker8ce7c252009-05-22 13:34:54 -07002259
T.R. Fullhart37e10522013-03-18 10:31:26 -07002260 key_passwords.update(PasswordManager().GetPasswords(need_passwords))
Tao Bao76def242017-11-21 09:25:31 -08002261 key_passwords.update(dict.fromkeys(no_passwords))
Doug Zongkereef39442009-04-02 12:14:19 -07002262 return key_passwords
2263
2264
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002265def GetMinSdkVersion(apk_name):
Tao Baof47bf0f2018-03-21 23:28:51 -07002266 """Gets the minSdkVersion declared in the APK.
2267
Martin Stjernholm58472e82022-01-07 22:08:47 +00002268 It calls OPTIONS.aapt2_path to query the embedded minSdkVersion from the given
2269 APK file. This can be both a decimal number (API Level) or a codename.
Tao Baof47bf0f2018-03-21 23:28:51 -07002270
2271 Args:
2272 apk_name: The APK filename.
2273
2274 Returns:
2275 The parsed SDK version string.
2276
2277 Raises:
2278 ExternalError: On failing to obtain the min SDK version.
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002279 """
Tao Baof47bf0f2018-03-21 23:28:51 -07002280 proc = Run(
Martin Stjernholm58472e82022-01-07 22:08:47 +00002281 [OPTIONS.aapt2_path, "dump", "badging", apk_name], stdout=subprocess.PIPE,
Tao Baof47bf0f2018-03-21 23:28:51 -07002282 stderr=subprocess.PIPE)
2283 stdoutdata, stderrdata = proc.communicate()
2284 if proc.returncode != 0:
2285 raise ExternalError(
Kelvin Zhang21118bb2022-02-12 09:40:35 -08002286 "Failed to obtain minSdkVersion for {}: aapt2 return code {}:\n{}\n{}".format(
2287 apk_name, proc.returncode, stdoutdata, stderrdata))
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002288
Tao Baof47bf0f2018-03-21 23:28:51 -07002289 for line in stdoutdata.split("\n"):
2290 # Looking for lines such as sdkVersion:'23' or sdkVersion:'M'.
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002291 m = re.match(r'sdkVersion:\'([^\']*)\'', line)
2292 if m:
2293 return m.group(1)
changho.shin0f125362019-07-08 10:59:00 +09002294 raise ExternalError("No minSdkVersion returned by aapt2")
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002295
2296
2297def GetMinSdkVersionInt(apk_name, codename_to_api_level_map):
Tao Baof47bf0f2018-03-21 23:28:51 -07002298 """Returns the minSdkVersion declared in the APK as a number (API Level).
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002299
Tao Baof47bf0f2018-03-21 23:28:51 -07002300 If minSdkVersion is set to a codename, it is translated to a number using the
2301 provided map.
2302
2303 Args:
2304 apk_name: The APK filename.
2305
2306 Returns:
2307 The parsed SDK version number.
2308
2309 Raises:
2310 ExternalError: On failing to get the min SDK version number.
2311 """
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002312 version = GetMinSdkVersion(apk_name)
2313 try:
2314 return int(version)
2315 except ValueError:
2316 # Not a decimal number. Codename?
2317 if version in codename_to_api_level_map:
2318 return codename_to_api_level_map[version]
Kelvin Zhang0876c412020-06-23 15:06:58 -04002319 raise ExternalError(
2320 "Unknown minSdkVersion: '{}'. Known codenames: {}".format(
2321 version, codename_to_api_level_map))
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002322
2323
2324def SignFile(input_name, output_name, key, password, min_api_level=None,
Tao Baoffc9a302019-03-22 23:16:58 -07002325 codename_to_api_level_map=None, whole_file=False,
2326 extra_signapk_args=None):
Doug Zongkereef39442009-04-02 12:14:19 -07002327 """Sign the input_name zip/jar/apk, producing output_name. Use the
2328 given key and password (the latter may be None if the key does not
2329 have a password.
2330
Doug Zongker951495f2009-08-14 12:44:19 -07002331 If whole_file is true, use the "-w" option to SignApk to embed a
2332 signature that covers the whole file in the archive comment of the
2333 zip file.
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002334
2335 min_api_level is the API Level (int) of the oldest platform this file may end
2336 up on. If not specified for an APK, the API Level is obtained by interpreting
2337 the minSdkVersion attribute of the APK's AndroidManifest.xml.
2338
2339 codename_to_api_level_map is needed to translate the codename which may be
2340 encountered as the APK's minSdkVersion.
Tao Baoffc9a302019-03-22 23:16:58 -07002341
2342 Caller may optionally specify extra args to be passed to SignApk, which
2343 defaults to OPTIONS.extra_signapk_args if omitted.
Doug Zongkereef39442009-04-02 12:14:19 -07002344 """
Tao Bao76def242017-11-21 09:25:31 -08002345 if codename_to_api_level_map is None:
2346 codename_to_api_level_map = {}
Tao Baoffc9a302019-03-22 23:16:58 -07002347 if extra_signapk_args is None:
2348 extra_signapk_args = OPTIONS.extra_signapk_args
Doug Zongker951495f2009-08-14 12:44:19 -07002349
Alex Klyubin9667b182015-12-10 13:38:50 -08002350 java_library_path = os.path.join(
2351 OPTIONS.search_path, OPTIONS.signapk_shared_library_path)
2352
Tao Baoe95540e2016-11-08 12:08:53 -08002353 cmd = ([OPTIONS.java_path] + OPTIONS.java_args +
2354 ["-Djava.library.path=" + java_library_path,
2355 "-jar", os.path.join(OPTIONS.search_path, OPTIONS.signapk_path)] +
Tao Baoffc9a302019-03-22 23:16:58 -07002356 extra_signapk_args)
Doug Zongker951495f2009-08-14 12:44:19 -07002357 if whole_file:
2358 cmd.append("-w")
Alex Klyubin2cfd1d12016-01-13 10:32:47 -08002359
2360 min_sdk_version = min_api_level
2361 if min_sdk_version is None:
2362 if not whole_file:
2363 min_sdk_version = GetMinSdkVersionInt(
2364 input_name, codename_to_api_level_map)
2365 if min_sdk_version is not None:
2366 cmd.extend(["--min-sdk-version", str(min_sdk_version)])
2367
T.R. Fullhart37e10522013-03-18 10:31:26 -07002368 cmd.extend([key + OPTIONS.public_key_suffix,
2369 key + OPTIONS.private_key_suffix,
Alex Klyubineb756d72015-12-04 09:21:08 -08002370 input_name, output_name])
Doug Zongker951495f2009-08-14 12:44:19 -07002371
Tao Bao73dd4f42018-10-04 16:25:33 -07002372 proc = Run(cmd, stdin=subprocess.PIPE)
Doug Zongkereef39442009-04-02 12:14:19 -07002373 if password is not None:
2374 password += "\n"
Tao Bao73dd4f42018-10-04 16:25:33 -07002375 stdoutdata, _ = proc.communicate(password)
2376 if proc.returncode != 0:
Tao Bao80921982018-03-21 21:02:19 -07002377 raise ExternalError(
2378 "Failed to run signapk.jar: return code {}:\n{}".format(
Tao Bao73dd4f42018-10-04 16:25:33 -07002379 proc.returncode, stdoutdata))
Doug Zongkereef39442009-04-02 12:14:19 -07002380
Melisa Carranza Zunigae0a977a2022-06-16 18:44:27 +02002381def SignSePolicy(sepolicy, key, password):
2382 """Sign the sepolicy zip, producing an fsverity .fsv_sig and
2383 an RSA .sig signature files.
2384 """
2385
2386 if OPTIONS.sign_sepolicy_path is None:
2387 return False
2388
2389 java_library_path = os.path.join(
2390 OPTIONS.search_path, OPTIONS.signapk_shared_library_path)
2391
2392 cmd = ([OPTIONS.java_path] + OPTIONS.java_args +
2393 ["-Djava.library.path=" + java_library_path,
2394 "-jar", os.path.join(OPTIONS.search_path, OPTIONS.sign_sepolicy_path)] +
2395 OPTIONS.extra_sign_sepolicy_args)
2396
2397 cmd.extend([key + OPTIONS.public_key_suffix,
2398 key + OPTIONS.private_key_suffix,
2399 sepolicy])
2400
2401 proc = Run(cmd, stdin=subprocess.PIPE)
2402 if password is not None:
2403 password += "\n"
2404 stdoutdata, _ = proc.communicate(password)
2405 if proc.returncode != 0:
2406 raise ExternalError(
2407 "Failed to run sign sepolicy: return code {}:\n{}".format(
2408 proc.returncode, stdoutdata))
2409 return True
Doug Zongkereef39442009-04-02 12:14:19 -07002410
Doug Zongker37974732010-09-16 17:44:38 -07002411def CheckSize(data, target, info_dict):
Tao Bao9dd909e2017-11-14 11:27:32 -08002412 """Checks the data string passed against the max size limit.
Doug Zongkerc77a9ad2010-09-16 11:28:43 -07002413
Tao Bao9dd909e2017-11-14 11:27:32 -08002414 For non-AVB images, raise exception if the data is too big. Print a warning
2415 if the data is nearing the maximum size.
2416
2417 For AVB images, the actual image size should be identical to the limit.
2418
2419 Args:
2420 data: A string that contains all the data for the partition.
2421 target: The partition name. The ".img" suffix is optional.
2422 info_dict: The dict to be looked up for relevant info.
2423 """
Dan Albert8b72aef2015-03-23 19:13:21 -07002424 if target.endswith(".img"):
2425 target = target[:-4]
Doug Zongker9ce0fb62010-09-20 18:04:41 -07002426 mount_point = "/" + target
2427
Ying Wangf8824af2014-06-03 14:07:27 -07002428 fs_type = None
2429 limit = None
Doug Zongker9ce0fb62010-09-20 18:04:41 -07002430 if info_dict["fstab"]:
Dan Albert8b72aef2015-03-23 19:13:21 -07002431 if mount_point == "/userdata":
2432 mount_point = "/data"
Doug Zongker9ce0fb62010-09-20 18:04:41 -07002433 p = info_dict["fstab"][mount_point]
2434 fs_type = p.fs_type
Andrew Boie0f9aec82012-02-14 09:32:52 -08002435 device = p.device
2436 if "/" in device:
2437 device = device[device.rfind("/")+1:]
Tao Bao76def242017-11-21 09:25:31 -08002438 limit = info_dict.get(device + "_size")
Dan Albert8b72aef2015-03-23 19:13:21 -07002439 if not fs_type or not limit:
2440 return
Doug Zongkereef39442009-04-02 12:14:19 -07002441
Andrew Boie0f9aec82012-02-14 09:32:52 -08002442 size = len(data)
Tao Bao9dd909e2017-11-14 11:27:32 -08002443 # target could be 'userdata' or 'cache'. They should follow the non-AVB image
2444 # path.
2445 if info_dict.get("avb_enable") == "true" and target in AVB_PARTITIONS:
2446 if size != limit:
2447 raise ExternalError(
2448 "Mismatching image size for %s: expected %d actual %d" % (
2449 target, limit, size))
2450 else:
2451 pct = float(size) * 100.0 / limit
2452 msg = "%s size (%d) is %.2f%% of limit (%d)" % (target, size, pct, limit)
2453 if pct >= 99.0:
2454 raise ExternalError(msg)
Kelvin Zhang0876c412020-06-23 15:06:58 -04002455
2456 if pct >= 95.0:
Tao Bao32fcdab2018-10-12 10:30:39 -07002457 logger.warning("\n WARNING: %s\n", msg)
2458 else:
2459 logger.info(" %s", msg)
Doug Zongkereef39442009-04-02 12:14:19 -07002460
2461
Doug Zongkerf6a53aa2009-12-15 15:06:55 -08002462def ReadApkCerts(tf_zip):
Tao Bao818ddf52018-01-05 11:17:34 -08002463 """Parses the APK certs info from a given target-files zip.
2464
2465 Given a target-files ZipFile, parses the META/apkcerts.txt entry and returns a
2466 tuple with the following elements: (1) a dictionary that maps packages to
2467 certs (based on the "certificate" and "private_key" attributes in the file;
2468 (2) a string representing the extension of compressed APKs in the target files
2469 (e.g ".gz", ".bro").
2470
2471 Args:
2472 tf_zip: The input target_files ZipFile (already open).
2473
2474 Returns:
2475 (certmap, ext): certmap is a dictionary that maps packages to certs; ext is
2476 the extension string of compressed APKs (e.g. ".gz"), or None if there's
2477 no compressed APKs.
2478 """
Doug Zongkerf6a53aa2009-12-15 15:06:55 -08002479 certmap = {}
Narayan Kamatha07bf042017-08-14 14:49:21 +01002480 compressed_extension = None
2481
Tao Bao0f990332017-09-08 19:02:54 -07002482 # META/apkcerts.txt contains the info for _all_ the packages known at build
2483 # time. Filter out the ones that are not installed.
2484 installed_files = set()
2485 for name in tf_zip.namelist():
2486 basename = os.path.basename(name)
2487 if basename:
2488 installed_files.add(basename)
2489
Tao Baoda30cfa2017-12-01 16:19:46 -08002490 for line in tf_zip.read('META/apkcerts.txt').decode().split('\n'):
Doug Zongkerf6a53aa2009-12-15 15:06:55 -08002491 line = line.strip()
Dan Albert8b72aef2015-03-23 19:13:21 -07002492 if not line:
2493 continue
Tao Bao818ddf52018-01-05 11:17:34 -08002494 m = re.match(
2495 r'^name="(?P<NAME>.*)"\s+certificate="(?P<CERT>.*)"\s+'
Bill Peckham5c7b0342020-04-03 15:36:23 -07002496 r'private_key="(?P<PRIVKEY>.*?)"(\s+compressed="(?P<COMPRESSED>.*?)")?'
2497 r'(\s+partition="(?P<PARTITION>.*?)")?$',
Tao Bao818ddf52018-01-05 11:17:34 -08002498 line)
2499 if not m:
2500 continue
Narayan Kamatha07bf042017-08-14 14:49:21 +01002501
Tao Bao818ddf52018-01-05 11:17:34 -08002502 matches = m.groupdict()
2503 cert = matches["CERT"]
2504 privkey = matches["PRIVKEY"]
2505 name = matches["NAME"]
2506 this_compressed_extension = matches["COMPRESSED"]
2507
2508 public_key_suffix_len = len(OPTIONS.public_key_suffix)
2509 private_key_suffix_len = len(OPTIONS.private_key_suffix)
2510 if cert in SPECIAL_CERT_STRINGS and not privkey:
2511 certmap[name] = cert
2512 elif (cert.endswith(OPTIONS.public_key_suffix) and
2513 privkey.endswith(OPTIONS.private_key_suffix) and
2514 cert[:-public_key_suffix_len] == privkey[:-private_key_suffix_len]):
2515 certmap[name] = cert[:-public_key_suffix_len]
2516 else:
2517 raise ValueError("Failed to parse line from apkcerts.txt:\n" + line)
2518
2519 if not this_compressed_extension:
2520 continue
2521
2522 # Only count the installed files.
2523 filename = name + '.' + this_compressed_extension
2524 if filename not in installed_files:
2525 continue
2526
2527 # Make sure that all the values in the compression map have the same
2528 # extension. We don't support multiple compression methods in the same
2529 # system image.
2530 if compressed_extension:
2531 if this_compressed_extension != compressed_extension:
2532 raise ValueError(
2533 "Multiple compressed extensions: {} vs {}".format(
2534 compressed_extension, this_compressed_extension))
2535 else:
2536 compressed_extension = this_compressed_extension
2537
2538 return (certmap,
2539 ("." + compressed_extension) if compressed_extension else None)
Doug Zongkerf6a53aa2009-12-15 15:06:55 -08002540
2541
Doug Zongkereef39442009-04-02 12:14:19 -07002542COMMON_DOCSTRING = """
Tao Bao30df8b42018-04-23 15:32:53 -07002543Global options
2544
2545 -p (--path) <dir>
2546 Prepend <dir>/bin to the list of places to search for binaries run by this
2547 script, and expect to find jars in <dir>/framework.
Doug Zongkereef39442009-04-02 12:14:19 -07002548
Doug Zongker05d3dea2009-06-22 11:32:31 -07002549 -s (--device_specific) <file>
Tao Bao30df8b42018-04-23 15:32:53 -07002550 Path to the Python module containing device-specific releasetools code.
Doug Zongker05d3dea2009-06-22 11:32:31 -07002551
Tao Bao30df8b42018-04-23 15:32:53 -07002552 -x (--extra) <key=value>
2553 Add a key/value pair to the 'extras' dict, which device-specific extension
2554 code may look at.
Doug Zongker8bec09e2009-11-30 15:37:14 -08002555
Doug Zongkereef39442009-04-02 12:14:19 -07002556 -v (--verbose)
2557 Show command lines being executed.
2558
2559 -h (--help)
2560 Display this usage message and exit.
Yifan Hong30910932019-10-25 20:36:55 -07002561
2562 --logfile <file>
2563 Put verbose logs to specified file (regardless of --verbose option.)
Doug Zongkereef39442009-04-02 12:14:19 -07002564"""
2565
Kelvin Zhang0876c412020-06-23 15:06:58 -04002566
Doug Zongkereef39442009-04-02 12:14:19 -07002567def Usage(docstring):
Tao Bao89fbb0f2017-01-10 10:47:58 -08002568 print(docstring.rstrip("\n"))
2569 print(COMMON_DOCSTRING)
Doug Zongkereef39442009-04-02 12:14:19 -07002570
2571
2572def ParseOptions(argv,
2573 docstring,
2574 extra_opts="", extra_long_opts=(),
2575 extra_option_handler=None):
2576 """Parse the options in argv and return any arguments that aren't
2577 flags. docstring is the calling module's docstring, to be displayed
2578 for errors and -h. extra_opts and extra_long_opts are for flags
2579 defined by the caller, which are processed by passing them to
2580 extra_option_handler."""
2581
2582 try:
2583 opts, args = getopt.getopt(
Doug Zongker8bec09e2009-11-30 15:37:14 -08002584 argv, "hvp:s:x:" + extra_opts,
Alex Klyubin9667b182015-12-10 13:38:50 -08002585 ["help", "verbose", "path=", "signapk_path=",
Melisa Carranza Zunigae0a977a2022-06-16 18:44:27 +02002586 "signapk_shared_library_path=", "extra_signapk_args=",
2587 "sign_sepolicy_path=", "extra_sign_sepolicy_args=", "aapt2_path=",
Tianjie Xu88a759d2020-01-23 10:47:54 -08002588 "java_path=", "java_args=", "android_jar_path=", "public_key_suffix=",
Baligh Uddin601ddea2015-06-09 15:48:14 -07002589 "private_key_suffix=", "boot_signer_path=", "boot_signer_args=",
2590 "verity_signer_path=", "verity_signer_args=", "device_specific=",
Jan Monsche147d482021-06-23 12:30:35 +02002591 "extra=", "logfile="] + list(extra_long_opts))
Dan Albert8b72aef2015-03-23 19:13:21 -07002592 except getopt.GetoptError as err:
Doug Zongkereef39442009-04-02 12:14:19 -07002593 Usage(docstring)
Tao Bao89fbb0f2017-01-10 10:47:58 -08002594 print("**", str(err), "**")
Doug Zongkereef39442009-04-02 12:14:19 -07002595 sys.exit(2)
2596
Doug Zongkereef39442009-04-02 12:14:19 -07002597 for o, a in opts:
2598 if o in ("-h", "--help"):
2599 Usage(docstring)
2600 sys.exit()
2601 elif o in ("-v", "--verbose"):
2602 OPTIONS.verbose = True
2603 elif o in ("-p", "--path"):
Doug Zongker602a84e2009-06-18 08:35:12 -07002604 OPTIONS.search_path = a
T.R. Fullhart37e10522013-03-18 10:31:26 -07002605 elif o in ("--signapk_path",):
2606 OPTIONS.signapk_path = a
Alex Klyubin9667b182015-12-10 13:38:50 -08002607 elif o in ("--signapk_shared_library_path",):
2608 OPTIONS.signapk_shared_library_path = a
T.R. Fullhart37e10522013-03-18 10:31:26 -07002609 elif o in ("--extra_signapk_args",):
2610 OPTIONS.extra_signapk_args = shlex.split(a)
Melisa Carranza Zunigae0a977a2022-06-16 18:44:27 +02002611 elif o in ("--sign_sepolicy_path",):
2612 OPTIONS.sign_sepolicy_path = a
2613 elif o in ("--extra_sign_sepolicy_args",):
2614 OPTIONS.extra_sign_sepolicy_args = shlex.split(a)
Martin Stjernholm58472e82022-01-07 22:08:47 +00002615 elif o in ("--aapt2_path",):
2616 OPTIONS.aapt2_path = a
T.R. Fullhart37e10522013-03-18 10:31:26 -07002617 elif o in ("--java_path",):
2618 OPTIONS.java_path = a
Baligh Uddin339ee492014-09-05 11:18:07 -07002619 elif o in ("--java_args",):
Tao Baoe95540e2016-11-08 12:08:53 -08002620 OPTIONS.java_args = shlex.split(a)
Tianjie Xu88a759d2020-01-23 10:47:54 -08002621 elif o in ("--android_jar_path",):
2622 OPTIONS.android_jar_path = a
T.R. Fullhart37e10522013-03-18 10:31:26 -07002623 elif o in ("--public_key_suffix",):
2624 OPTIONS.public_key_suffix = a
2625 elif o in ("--private_key_suffix",):
2626 OPTIONS.private_key_suffix = a
Baligh Uddine2048682014-11-20 09:52:05 -08002627 elif o in ("--boot_signer_path",):
hungweichen49447912022-08-19 06:04:06 +00002628 raise ValueError("--boot_signer_path is no longer supported, please switch to AVB")
Baligh Uddin601ddea2015-06-09 15:48:14 -07002629 elif o in ("--boot_signer_args",):
hungweichen49447912022-08-19 06:04:06 +00002630 raise ValueError("--boot_signer_args is no longer supported, please switch to AVB")
Baligh Uddin601ddea2015-06-09 15:48:14 -07002631 elif o in ("--verity_signer_path",):
hungweichen49447912022-08-19 06:04:06 +00002632 raise ValueError("--verity_signer_path is no longer supported, please switch to AVB")
Baligh Uddin601ddea2015-06-09 15:48:14 -07002633 elif o in ("--verity_signer_args",):
hungweichen49447912022-08-19 06:04:06 +00002634 raise ValueError("--verity_signer_args is no longer supported, please switch to AVB")
Doug Zongker05d3dea2009-06-22 11:32:31 -07002635 elif o in ("-s", "--device_specific"):
2636 OPTIONS.device_specific = a
Doug Zongker5ecba702009-12-03 16:36:20 -08002637 elif o in ("-x", "--extra"):
Doug Zongker8bec09e2009-11-30 15:37:14 -08002638 key, value = a.split("=", 1)
2639 OPTIONS.extras[key] = value
Yifan Hong30910932019-10-25 20:36:55 -07002640 elif o in ("--logfile",):
2641 OPTIONS.logfile = a
Doug Zongkereef39442009-04-02 12:14:19 -07002642 else:
2643 if extra_option_handler is None or not extra_option_handler(o, a):
2644 assert False, "unknown option \"%s\"" % (o,)
2645
Doug Zongker85448772014-09-09 14:59:20 -07002646 if OPTIONS.search_path:
2647 os.environ["PATH"] = (os.path.join(OPTIONS.search_path, "bin") +
2648 os.pathsep + os.environ["PATH"])
Doug Zongkereef39442009-04-02 12:14:19 -07002649
2650 return args
2651
2652
Tao Bao4c851b12016-09-19 13:54:38 -07002653def MakeTempFile(prefix='tmp', suffix=''):
Doug Zongkerfc44a512014-08-26 13:10:25 -07002654 """Make a temp file and add it to the list of things to be deleted
2655 when Cleanup() is called. Return the filename."""
2656 fd, fn = tempfile.mkstemp(prefix=prefix, suffix=suffix)
2657 os.close(fd)
2658 OPTIONS.tempfiles.append(fn)
2659 return fn
2660
2661
Tao Bao1c830bf2017-12-25 10:43:47 -08002662def MakeTempDir(prefix='tmp', suffix=''):
2663 """Makes a temporary dir that will be cleaned up with a call to Cleanup().
2664
2665 Returns:
2666 The absolute pathname of the new directory.
2667 """
2668 dir_name = tempfile.mkdtemp(suffix=suffix, prefix=prefix)
2669 OPTIONS.tempfiles.append(dir_name)
2670 return dir_name
2671
2672
Doug Zongkereef39442009-04-02 12:14:19 -07002673def Cleanup():
2674 for i in OPTIONS.tempfiles:
2675 if os.path.isdir(i):
Tao Bao1c830bf2017-12-25 10:43:47 -08002676 shutil.rmtree(i, ignore_errors=True)
Doug Zongkereef39442009-04-02 12:14:19 -07002677 else:
2678 os.remove(i)
Tao Bao1c830bf2017-12-25 10:43:47 -08002679 del OPTIONS.tempfiles[:]
Doug Zongker8ce7c252009-05-22 13:34:54 -07002680
2681
2682class PasswordManager(object):
2683 def __init__(self):
Tao Bao76def242017-11-21 09:25:31 -08002684 self.editor = os.getenv("EDITOR")
2685 self.pwfile = os.getenv("ANDROID_PW_FILE")
Doug Zongker8ce7c252009-05-22 13:34:54 -07002686
2687 def GetPasswords(self, items):
2688 """Get passwords corresponding to each string in 'items',
2689 returning a dict. (The dict may have keys in addition to the
2690 values in 'items'.)
2691
2692 Uses the passwords in $ANDROID_PW_FILE if available, letting the
2693 user edit that file to add more needed passwords. If no editor is
2694 available, or $ANDROID_PW_FILE isn't define, prompts the user
2695 interactively in the ordinary way.
2696 """
2697
2698 current = self.ReadFile()
2699
2700 first = True
2701 while True:
2702 missing = []
2703 for i in items:
2704 if i not in current or not current[i]:
2705 missing.append(i)
2706 # Are all the passwords already in the file?
Dan Albert8b72aef2015-03-23 19:13:21 -07002707 if not missing:
2708 return current
Doug Zongker8ce7c252009-05-22 13:34:54 -07002709
2710 for i in missing:
2711 current[i] = ""
2712
2713 if not first:
Tao Bao89fbb0f2017-01-10 10:47:58 -08002714 print("key file %s still missing some passwords." % (self.pwfile,))
Tao Baoda30cfa2017-12-01 16:19:46 -08002715 if sys.version_info[0] >= 3:
2716 raw_input = input # pylint: disable=redefined-builtin
Doug Zongker8ce7c252009-05-22 13:34:54 -07002717 answer = raw_input("try to edit again? [y]> ").strip()
2718 if answer and answer[0] not in 'yY':
2719 raise RuntimeError("key passwords unavailable")
2720 first = False
2721
2722 current = self.UpdateAndReadFile(current)
2723
Kelvin Zhang0876c412020-06-23 15:06:58 -04002724 def PromptResult(self, current): # pylint: disable=no-self-use
Doug Zongker8ce7c252009-05-22 13:34:54 -07002725 """Prompt the user to enter a value (password) for each key in
2726 'current' whose value is fales. Returns a new dict with all the
2727 values.
2728 """
2729 result = {}
Tao Bao38884282019-07-10 22:20:56 -07002730 for k, v in sorted(current.items()):
Doug Zongker8ce7c252009-05-22 13:34:54 -07002731 if v:
2732 result[k] = v
2733 else:
2734 while True:
Dan Albert8b72aef2015-03-23 19:13:21 -07002735 result[k] = getpass.getpass(
2736 "Enter password for %s key> " % k).strip()
2737 if result[k]:
2738 break
Doug Zongker8ce7c252009-05-22 13:34:54 -07002739 return result
2740
2741 def UpdateAndReadFile(self, current):
2742 if not self.editor or not self.pwfile:
2743 return self.PromptResult(current)
2744
2745 f = open(self.pwfile, "w")
Dan Albert8b72aef2015-03-23 19:13:21 -07002746 os.chmod(self.pwfile, 0o600)
Doug Zongker8ce7c252009-05-22 13:34:54 -07002747 f.write("# Enter key passwords between the [[[ ]]] brackets.\n")
2748 f.write("# (Additional spaces are harmless.)\n\n")
2749
2750 first_line = None
Tao Bao38884282019-07-10 22:20:56 -07002751 sorted_list = sorted([(not v, k, v) for (k, v) in current.items()])
Dan Albert8b72aef2015-03-23 19:13:21 -07002752 for i, (_, k, v) in enumerate(sorted_list):
Doug Zongker8ce7c252009-05-22 13:34:54 -07002753 f.write("[[[ %s ]]] %s\n" % (v, k))
2754 if not v and first_line is None:
2755 # position cursor on first line with no password.
2756 first_line = i + 4
2757 f.close()
2758
Tao Bao986ee862018-10-04 15:46:16 -07002759 RunAndCheckOutput([self.editor, "+%d" % (first_line,), self.pwfile])
Doug Zongker8ce7c252009-05-22 13:34:54 -07002760
2761 return self.ReadFile()
2762
2763 def ReadFile(self):
2764 result = {}
Dan Albert8b72aef2015-03-23 19:13:21 -07002765 if self.pwfile is None:
2766 return result
Doug Zongker8ce7c252009-05-22 13:34:54 -07002767 try:
2768 f = open(self.pwfile, "r")
2769 for line in f:
2770 line = line.strip()
Dan Albert8b72aef2015-03-23 19:13:21 -07002771 if not line or line[0] == '#':
2772 continue
Doug Zongker8ce7c252009-05-22 13:34:54 -07002773 m = re.match(r"^\[\[\[\s*(.*?)\s*\]\]\]\s*(\S+)$", line)
2774 if not m:
Tao Bao32fcdab2018-10-12 10:30:39 -07002775 logger.warning("Failed to parse password file: %s", line)
Doug Zongker8ce7c252009-05-22 13:34:54 -07002776 else:
2777 result[m.group(2)] = m.group(1)
2778 f.close()
Dan Albert8b72aef2015-03-23 19:13:21 -07002779 except IOError as e:
Doug Zongker8ce7c252009-05-22 13:34:54 -07002780 if e.errno != errno.ENOENT:
Tao Bao32fcdab2018-10-12 10:30:39 -07002781 logger.exception("Error reading password file:")
Doug Zongker8ce7c252009-05-22 13:34:54 -07002782 return result
Doug Zongker048e7ca2009-06-15 14:31:53 -07002783
2784
Dan Albert8e0178d2015-01-27 15:53:15 -08002785def ZipWrite(zip_file, filename, arcname=None, perms=0o644,
2786 compress_type=None):
Dan Albert8e0178d2015-01-27 15:53:15 -08002787
2788 # http://b/18015246
2789 # Python 2.7's zipfile implementation wrongly thinks that zip64 is required
2790 # for files larger than 2GiB. We can work around this by adjusting their
2791 # limit. Note that `zipfile.writestr()` will not work for strings larger than
2792 # 2GiB. The Python interpreter sometimes rejects strings that large (though
2793 # it isn't clear to me exactly what circumstances cause this).
2794 # `zipfile.write()` must be used directly to work around this.
2795 #
2796 # This mess can be avoided if we port to python3.
2797 saved_zip64_limit = zipfile.ZIP64_LIMIT
2798 zipfile.ZIP64_LIMIT = (1 << 32) - 1
2799
2800 if compress_type is None:
2801 compress_type = zip_file.compression
2802 if arcname is None:
2803 arcname = filename
2804
2805 saved_stat = os.stat(filename)
2806
2807 try:
2808 # `zipfile.write()` doesn't allow us to pass ZipInfo, so just modify the
2809 # file to be zipped and reset it when we're done.
2810 os.chmod(filename, perms)
2811
2812 # Use a fixed timestamp so the output is repeatable.
Bryan Henrye6d547d2018-07-31 18:32:00 -07002813 # Note: Use of fromtimestamp rather than utcfromtimestamp here is
2814 # intentional. zip stores datetimes in local time without a time zone
2815 # attached, so we need "epoch" but in the local time zone to get 2009/01/01
2816 # in the zip archive.
2817 local_epoch = datetime.datetime.fromtimestamp(0)
2818 timestamp = (datetime.datetime(2009, 1, 1) - local_epoch).total_seconds()
Dan Albert8e0178d2015-01-27 15:53:15 -08002819 os.utime(filename, (timestamp, timestamp))
2820
2821 zip_file.write(filename, arcname=arcname, compress_type=compress_type)
2822 finally:
2823 os.chmod(filename, saved_stat.st_mode)
2824 os.utime(filename, (saved_stat.st_atime, saved_stat.st_mtime))
2825 zipfile.ZIP64_LIMIT = saved_zip64_limit
2826
2827
Tao Bao58c1b962015-05-20 09:32:18 -07002828def ZipWriteStr(zip_file, zinfo_or_arcname, data, perms=None,
Tao Baof3282b42015-04-01 11:21:55 -07002829 compress_type=None):
2830 """Wrap zipfile.writestr() function to work around the zip64 limit.
2831
2832 Even with the ZIP64_LIMIT workaround, it won't allow writing a string
2833 longer than 2GiB. It gives 'OverflowError: size does not fit in an int'
2834 when calling crc32(bytes).
2835
2836 But it still works fine to write a shorter string into a large zip file.
2837 We should use ZipWrite() whenever possible, and only use ZipWriteStr()
2838 when we know the string won't be too long.
2839 """
2840
2841 saved_zip64_limit = zipfile.ZIP64_LIMIT
2842 zipfile.ZIP64_LIMIT = (1 << 32) - 1
2843
2844 if not isinstance(zinfo_or_arcname, zipfile.ZipInfo):
2845 zinfo = zipfile.ZipInfo(filename=zinfo_or_arcname)
Dan Albert8b72aef2015-03-23 19:13:21 -07002846 zinfo.compress_type = zip_file.compression
Tao Bao58c1b962015-05-20 09:32:18 -07002847 if perms is None:
Tao Bao2a410582015-07-10 17:18:23 -07002848 perms = 0o100644
Geremy Condra36bd3652014-02-06 19:45:10 -08002849 else:
Tao Baof3282b42015-04-01 11:21:55 -07002850 zinfo = zinfo_or_arcname
Tao Baoc1a1ec32019-06-18 16:29:37 -07002851 # Python 2 and 3 behave differently when calling ZipFile.writestr() with
2852 # zinfo.external_attr being 0. Python 3 uses `0o600 << 16` as the value for
2853 # such a case (since
2854 # https://github.com/python/cpython/commit/18ee29d0b870caddc0806916ca2c823254f1a1f9),
2855 # which seems to make more sense. Otherwise the entry will have 0o000 as the
2856 # permission bits. We follow the logic in Python 3 to get consistent
2857 # behavior between using the two versions.
2858 if not zinfo.external_attr:
2859 zinfo.external_attr = 0o600 << 16
Tao Baof3282b42015-04-01 11:21:55 -07002860
2861 # If compress_type is given, it overrides the value in zinfo.
2862 if compress_type is not None:
2863 zinfo.compress_type = compress_type
2864
Tao Bao58c1b962015-05-20 09:32:18 -07002865 # If perms is given, it has a priority.
2866 if perms is not None:
Tao Bao2a410582015-07-10 17:18:23 -07002867 # If perms doesn't set the file type, mark it as a regular file.
2868 if perms & 0o770000 == 0:
2869 perms |= 0o100000
Tao Bao58c1b962015-05-20 09:32:18 -07002870 zinfo.external_attr = perms << 16
2871
Tao Baof3282b42015-04-01 11:21:55 -07002872 # Use a fixed timestamp so the output is repeatable.
Tao Baof3282b42015-04-01 11:21:55 -07002873 zinfo.date_time = (2009, 1, 1, 0, 0, 0)
2874
Dan Albert8b72aef2015-03-23 19:13:21 -07002875 zip_file.writestr(zinfo, data)
Tao Baof3282b42015-04-01 11:21:55 -07002876 zipfile.ZIP64_LIMIT = saved_zip64_limit
2877
2878
Tao Bao89d7ab22017-12-14 17:05:33 -08002879def ZipDelete(zip_filename, entries):
2880 """Deletes entries from a ZIP file.
2881
2882 Since deleting entries from a ZIP file is not supported, it shells out to
2883 'zip -d'.
2884
2885 Args:
2886 zip_filename: The name of the ZIP file.
2887 entries: The name of the entry, or the list of names to be deleted.
2888
2889 Raises:
2890 AssertionError: In case of non-zero return from 'zip'.
2891 """
Tao Baoc1a1ec32019-06-18 16:29:37 -07002892 if isinstance(entries, str):
Tao Bao89d7ab22017-12-14 17:05:33 -08002893 entries = [entries]
Kelvin Zhang70876142022-02-09 16:05:29 -08002894 # If list is empty, nothing to do
2895 if not entries:
2896 return
Tao Bao89d7ab22017-12-14 17:05:33 -08002897 cmd = ["zip", "-d", zip_filename] + entries
Tao Bao986ee862018-10-04 15:46:16 -07002898 RunAndCheckOutput(cmd)
Tao Bao89d7ab22017-12-14 17:05:33 -08002899
2900
Tao Baof3282b42015-04-01 11:21:55 -07002901def ZipClose(zip_file):
2902 # http://b/18015246
2903 # zipfile also refers to ZIP64_LIMIT during close() when it writes out the
2904 # central directory.
2905 saved_zip64_limit = zipfile.ZIP64_LIMIT
2906 zipfile.ZIP64_LIMIT = (1 << 32) - 1
2907
2908 zip_file.close()
2909
2910 zipfile.ZIP64_LIMIT = saved_zip64_limit
Doug Zongker05d3dea2009-06-22 11:32:31 -07002911
2912
2913class DeviceSpecificParams(object):
2914 module = None
Kelvin Zhang0876c412020-06-23 15:06:58 -04002915
Doug Zongker05d3dea2009-06-22 11:32:31 -07002916 def __init__(self, **kwargs):
2917 """Keyword arguments to the constructor become attributes of this
2918 object, which is passed to all functions in the device-specific
2919 module."""
Tao Bao38884282019-07-10 22:20:56 -07002920 for k, v in kwargs.items():
Doug Zongker05d3dea2009-06-22 11:32:31 -07002921 setattr(self, k, v)
Doug Zongker8bec09e2009-11-30 15:37:14 -08002922 self.extras = OPTIONS.extras
Doug Zongker05d3dea2009-06-22 11:32:31 -07002923
2924 if self.module is None:
2925 path = OPTIONS.device_specific
Dan Albert8b72aef2015-03-23 19:13:21 -07002926 if not path:
2927 return
Doug Zongker8e2f2b92009-06-24 14:34:57 -07002928 try:
2929 if os.path.isdir(path):
2930 info = imp.find_module("releasetools", [path])
2931 else:
2932 d, f = os.path.split(path)
2933 b, x = os.path.splitext(f)
2934 if x == ".py":
2935 f = b
2936 info = imp.find_module(f, [d])
Tao Bao32fcdab2018-10-12 10:30:39 -07002937 logger.info("loaded device-specific extensions from %s", path)
Doug Zongker8e2f2b92009-06-24 14:34:57 -07002938 self.module = imp.load_module("device_specific", *info)
2939 except ImportError:
Tao Bao32fcdab2018-10-12 10:30:39 -07002940 logger.info("unable to load device-specific module; assuming none")
Doug Zongker05d3dea2009-06-22 11:32:31 -07002941
2942 def _DoCall(self, function_name, *args, **kwargs):
2943 """Call the named function in the device-specific module, passing
2944 the given args and kwargs. The first argument to the call will be
2945 the DeviceSpecific object itself. If there is no module, or the
2946 module does not define the function, return the value of the
2947 'default' kwarg (which itself defaults to None)."""
2948 if self.module is None or not hasattr(self.module, function_name):
Tao Bao76def242017-11-21 09:25:31 -08002949 return kwargs.get("default")
Doug Zongker05d3dea2009-06-22 11:32:31 -07002950 return getattr(self.module, function_name)(*((self,) + args), **kwargs)
2951
2952 def FullOTA_Assertions(self):
2953 """Called after emitting the block of assertions at the top of a
2954 full OTA package. Implementations can add whatever additional
2955 assertions they like."""
2956 return self._DoCall("FullOTA_Assertions")
2957
Doug Zongkere5ff5902012-01-17 10:55:37 -08002958 def FullOTA_InstallBegin(self):
2959 """Called at the start of full OTA installation."""
2960 return self._DoCall("FullOTA_InstallBegin")
2961
Yifan Hong10c530d2018-12-27 17:34:18 -08002962 def FullOTA_GetBlockDifferences(self):
2963 """Called during full OTA installation and verification.
2964 Implementation should return a list of BlockDifference objects describing
2965 the update on each additional partitions.
2966 """
2967 return self._DoCall("FullOTA_GetBlockDifferences")
2968
Doug Zongker05d3dea2009-06-22 11:32:31 -07002969 def FullOTA_InstallEnd(self):
2970 """Called at the end of full OTA installation; typically this is
2971 used to install the image for the device's baseband processor."""
2972 return self._DoCall("FullOTA_InstallEnd")
2973
2974 def IncrementalOTA_Assertions(self):
2975 """Called after emitting the block of assertions at the top of an
2976 incremental OTA package. Implementations can add whatever
2977 additional assertions they like."""
2978 return self._DoCall("IncrementalOTA_Assertions")
2979
Doug Zongkere5ff5902012-01-17 10:55:37 -08002980 def IncrementalOTA_VerifyBegin(self):
2981 """Called at the start of the verification phase of incremental
2982 OTA installation; additional checks can be placed here to abort
2983 the script before any changes are made."""
2984 return self._DoCall("IncrementalOTA_VerifyBegin")
2985
Doug Zongker05d3dea2009-06-22 11:32:31 -07002986 def IncrementalOTA_VerifyEnd(self):
2987 """Called at the end of the verification phase of incremental OTA
2988 installation; additional checks can be placed here to abort the
2989 script before any changes are made."""
2990 return self._DoCall("IncrementalOTA_VerifyEnd")
2991
Doug Zongkere5ff5902012-01-17 10:55:37 -08002992 def IncrementalOTA_InstallBegin(self):
2993 """Called at the start of incremental OTA installation (after
2994 verification is complete)."""
2995 return self._DoCall("IncrementalOTA_InstallBegin")
2996
Yifan Hong10c530d2018-12-27 17:34:18 -08002997 def IncrementalOTA_GetBlockDifferences(self):
2998 """Called during incremental OTA installation and verification.
2999 Implementation should return a list of BlockDifference objects describing
3000 the update on each additional partitions.
3001 """
3002 return self._DoCall("IncrementalOTA_GetBlockDifferences")
3003
Doug Zongker05d3dea2009-06-22 11:32:31 -07003004 def IncrementalOTA_InstallEnd(self):
3005 """Called at the end of incremental OTA installation; typically
3006 this is used to install the image for the device's baseband
3007 processor."""
3008 return self._DoCall("IncrementalOTA_InstallEnd")
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003009
Tao Bao9bc6bb22015-11-09 16:58:28 -08003010 def VerifyOTA_Assertions(self):
3011 return self._DoCall("VerifyOTA_Assertions")
3012
Tao Bao76def242017-11-21 09:25:31 -08003013
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003014class File(object):
Tao Bao76def242017-11-21 09:25:31 -08003015 def __init__(self, name, data, compress_size=None):
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003016 self.name = name
3017 self.data = data
3018 self.size = len(data)
YOUNG HO CHAccc5c402016-10-13 13:40:46 +09003019 self.compress_size = compress_size or self.size
Doug Zongker55d93282011-01-25 17:03:34 -08003020 self.sha1 = sha1(data).hexdigest()
3021
3022 @classmethod
3023 def FromLocalFile(cls, name, diskname):
3024 f = open(diskname, "rb")
3025 data = f.read()
3026 f.close()
3027 return File(name, data)
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003028
3029 def WriteToTemp(self):
3030 t = tempfile.NamedTemporaryFile()
3031 t.write(self.data)
3032 t.flush()
3033 return t
3034
Dan Willemsen2ee00d52017-03-05 19:51:56 -08003035 def WriteToDir(self, d):
3036 with open(os.path.join(d, self.name), "wb") as fp:
3037 fp.write(self.data)
3038
Geremy Condra36bd3652014-02-06 19:45:10 -08003039 def AddToZip(self, z, compression=None):
Tao Baof3282b42015-04-01 11:21:55 -07003040 ZipWriteStr(z, self.name, self.data, compress_type=compression)
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003041
Tao Bao76def242017-11-21 09:25:31 -08003042
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003043DIFF_PROGRAM_BY_EXT = {
Kelvin Zhang0876c412020-06-23 15:06:58 -04003044 ".gz": "imgdiff",
3045 ".zip": ["imgdiff", "-z"],
3046 ".jar": ["imgdiff", "-z"],
3047 ".apk": ["imgdiff", "-z"],
3048 ".img": "imgdiff",
3049}
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003050
Tao Bao76def242017-11-21 09:25:31 -08003051
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003052class Difference(object):
Doug Zongker24cd2802012-08-14 16:36:15 -07003053 def __init__(self, tf, sf, diff_program=None):
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003054 self.tf = tf
3055 self.sf = sf
3056 self.patch = None
Doug Zongker24cd2802012-08-14 16:36:15 -07003057 self.diff_program = diff_program
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003058
3059 def ComputePatch(self):
3060 """Compute the patch (as a string of data) needed to turn sf into
3061 tf. Returns the same tuple as GetPatch()."""
3062
3063 tf = self.tf
3064 sf = self.sf
3065
Doug Zongker24cd2802012-08-14 16:36:15 -07003066 if self.diff_program:
3067 diff_program = self.diff_program
3068 else:
3069 ext = os.path.splitext(tf.name)[1]
3070 diff_program = DIFF_PROGRAM_BY_EXT.get(ext, "bsdiff")
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003071
3072 ttemp = tf.WriteToTemp()
3073 stemp = sf.WriteToTemp()
3074
3075 ext = os.path.splitext(tf.name)[1]
3076
3077 try:
3078 ptemp = tempfile.NamedTemporaryFile()
3079 if isinstance(diff_program, list):
3080 cmd = copy.copy(diff_program)
3081 else:
3082 cmd = [diff_program]
3083 cmd.append(stemp.name)
3084 cmd.append(ttemp.name)
3085 cmd.append(ptemp.name)
3086 p = Run(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE)
Doug Zongkerf8340082014-08-05 10:39:37 -07003087 err = []
Kelvin Zhang0876c412020-06-23 15:06:58 -04003088
Doug Zongkerf8340082014-08-05 10:39:37 -07003089 def run():
3090 _, e = p.communicate()
Dan Albert8b72aef2015-03-23 19:13:21 -07003091 if e:
3092 err.append(e)
Doug Zongkerf8340082014-08-05 10:39:37 -07003093 th = threading.Thread(target=run)
3094 th.start()
3095 th.join(timeout=300) # 5 mins
3096 if th.is_alive():
Tao Bao32fcdab2018-10-12 10:30:39 -07003097 logger.warning("diff command timed out")
Doug Zongkerf8340082014-08-05 10:39:37 -07003098 p.terminate()
3099 th.join(5)
3100 if th.is_alive():
3101 p.kill()
3102 th.join()
3103
Tianjie Xua2a9f992018-01-05 15:15:54 -08003104 if p.returncode != 0:
Yifan Honga4140d22021-08-04 18:09:03 -07003105 logger.warning("Failure running %s:\n%s\n", cmd, "".join(err))
Doug Zongkerf8340082014-08-05 10:39:37 -07003106 self.patch = None
3107 return None, None, None
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003108 diff = ptemp.read()
3109 finally:
3110 ptemp.close()
3111 stemp.close()
3112 ttemp.close()
3113
3114 self.patch = diff
3115 return self.tf, self.sf, self.patch
3116
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003117 def GetPatch(self):
Tao Bao76def242017-11-21 09:25:31 -08003118 """Returns a tuple of (target_file, source_file, patch_data).
3119
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003120 patch_data may be None if ComputePatch hasn't been called, or if
Tao Bao76def242017-11-21 09:25:31 -08003121 computing the patch failed.
3122 """
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003123 return self.tf, self.sf, self.patch
3124
3125
3126def ComputeDifferences(diffs):
3127 """Call ComputePatch on all the Difference objects in 'diffs'."""
Tao Bao32fcdab2018-10-12 10:30:39 -07003128 logger.info("%d diffs to compute", len(diffs))
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003129
3130 # Do the largest files first, to try and reduce the long-pole effect.
3131 by_size = [(i.tf.size, i) for i in diffs]
3132 by_size.sort(reverse=True)
3133 by_size = [i[1] for i in by_size]
3134
3135 lock = threading.Lock()
3136 diff_iter = iter(by_size) # accessed under lock
3137
3138 def worker():
3139 try:
3140 lock.acquire()
3141 for d in diff_iter:
3142 lock.release()
3143 start = time.time()
3144 d.ComputePatch()
3145 dur = time.time() - start
3146 lock.acquire()
3147
3148 tf, sf, patch = d.GetPatch()
3149 if sf.name == tf.name:
3150 name = tf.name
3151 else:
3152 name = "%s (%s)" % (tf.name, sf.name)
3153 if patch is None:
Tao Bao32fcdab2018-10-12 10:30:39 -07003154 logger.error("patching failed! %40s", name)
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003155 else:
Tao Bao32fcdab2018-10-12 10:30:39 -07003156 logger.info(
3157 "%8.2f sec %8d / %8d bytes (%6.2f%%) %s", dur, len(patch),
3158 tf.size, 100.0 * len(patch) / tf.size, name)
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003159 lock.release()
Tao Bao32fcdab2018-10-12 10:30:39 -07003160 except Exception:
3161 logger.exception("Failed to compute diff from worker")
Doug Zongkerea5d7a92010-09-12 15:26:16 -07003162 raise
3163
3164 # start worker threads; wait for them all to finish.
3165 threads = [threading.Thread(target=worker)
3166 for i in range(OPTIONS.worker_threads)]
3167 for th in threads:
3168 th.start()
3169 while threads:
3170 threads.pop().join()
Doug Zongker96a57e72010-09-26 14:57:41 -07003171
3172
Dan Albert8b72aef2015-03-23 19:13:21 -07003173class BlockDifference(object):
3174 def __init__(self, partition, tgt, src=None, check_first_block=False,
Tao Bao293fd132016-06-11 12:19:23 -07003175 version=None, disable_imgdiff=False):
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003176 self.tgt = tgt
3177 self.src = src
3178 self.partition = partition
Doug Zongkerb34fcce2014-09-11 09:34:56 -07003179 self.check_first_block = check_first_block
Tao Bao293fd132016-06-11 12:19:23 -07003180 self.disable_imgdiff = disable_imgdiff
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003181
Tao Baodd2a5892015-03-12 12:32:37 -07003182 if version is None:
Tao Bao0582cb62017-12-21 11:47:01 -08003183 version = max(
3184 int(i) for i in
3185 OPTIONS.info_dict.get("blockimgdiff_versions", "1").split(","))
Tao Bao8fad03e2017-03-01 14:36:26 -08003186 assert version >= 3
Tao Baodd2a5892015-03-12 12:32:37 -07003187 self.version = version
Doug Zongker62338182014-09-08 08:29:55 -07003188
Tianjie Xu41976c72019-07-03 13:57:01 -07003189 b = BlockImageDiff(tgt, src, threads=OPTIONS.worker_threads,
3190 version=self.version,
3191 disable_imgdiff=self.disable_imgdiff)
Tao Bao04bce3a2018-02-28 11:11:00 -08003192 self.path = os.path.join(MakeTempDir(), partition)
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003193 b.Compute(self.path)
Tao Baod8d14be2016-02-04 14:26:02 -08003194 self._required_cache = b.max_stashed_size
Tao Baod522bdc2016-04-12 15:53:16 -07003195 self.touched_src_ranges = b.touched_src_ranges
3196 self.touched_src_sha1 = b.touched_src_sha1
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003197
Yifan Hong10c530d2018-12-27 17:34:18 -08003198 # On devices with dynamic partitions, for new partitions,
3199 # src is None but OPTIONS.source_info_dict is not.
3200 if OPTIONS.source_info_dict is None:
3201 is_dynamic_build = OPTIONS.info_dict.get(
3202 "use_dynamic_partitions") == "true"
Yifan Hongbb2658d2019-01-25 12:30:58 -08003203 is_dynamic_source = False
Tao Baoaac4ad52015-10-16 15:26:34 -07003204 else:
Yifan Hong10c530d2018-12-27 17:34:18 -08003205 is_dynamic_build = OPTIONS.source_info_dict.get(
3206 "use_dynamic_partitions") == "true"
Yifan Hongbb2658d2019-01-25 12:30:58 -08003207 is_dynamic_source = partition in shlex.split(
3208 OPTIONS.source_info_dict.get("dynamic_partition_list", "").strip())
Yifan Hong10c530d2018-12-27 17:34:18 -08003209
Yifan Hongbb2658d2019-01-25 12:30:58 -08003210 is_dynamic_target = partition in shlex.split(
Yifan Hong10c530d2018-12-27 17:34:18 -08003211 OPTIONS.info_dict.get("dynamic_partition_list", "").strip())
3212
Yifan Hongbb2658d2019-01-25 12:30:58 -08003213 # For dynamic partitions builds, check partition list in both source
3214 # and target build because new partitions may be added, and existing
3215 # partitions may be removed.
3216 is_dynamic = is_dynamic_build and (is_dynamic_source or is_dynamic_target)
3217
Yifan Hong10c530d2018-12-27 17:34:18 -08003218 if is_dynamic:
3219 self.device = 'map_partition("%s")' % partition
3220 else:
3221 if OPTIONS.source_info_dict is None:
Yifan Hongbdb32012020-05-07 12:38:53 -07003222 _, device_expr = GetTypeAndDeviceExpr("/" + partition,
3223 OPTIONS.info_dict)
Yifan Hong10c530d2018-12-27 17:34:18 -08003224 else:
Yifan Hongbdb32012020-05-07 12:38:53 -07003225 _, device_expr = GetTypeAndDeviceExpr("/" + partition,
3226 OPTIONS.source_info_dict)
3227 self.device = device_expr
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003228
Tao Baod8d14be2016-02-04 14:26:02 -08003229 @property
3230 def required_cache(self):
3231 return self._required_cache
3232
Tao Bao76def242017-11-21 09:25:31 -08003233 def WriteScript(self, script, output_zip, progress=None,
3234 write_verify_script=False):
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003235 if not self.src:
3236 # write the output unconditionally
Jesse Zhao75bcea02015-01-06 10:59:53 -08003237 script.Print("Patching %s image unconditionally..." % (self.partition,))
3238 else:
3239 script.Print("Patching %s image after verification." % (self.partition,))
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003240
Dan Albert8b72aef2015-03-23 19:13:21 -07003241 if progress:
3242 script.ShowProgress(progress, 0)
Jesse Zhao75bcea02015-01-06 10:59:53 -08003243 self._WriteUpdate(script, output_zip)
Tao Bao76def242017-11-21 09:25:31 -08003244
3245 if write_verify_script:
Yifan Hong10c530d2018-12-27 17:34:18 -08003246 self.WritePostInstallVerifyScript(script)
Jesse Zhao75bcea02015-01-06 10:59:53 -08003247
Tao Bao9bc6bb22015-11-09 16:58:28 -08003248 def WriteStrictVerifyScript(self, script):
3249 """Verify all the blocks in the care_map, including clobbered blocks.
3250
3251 This differs from the WriteVerifyScript() function: a) it prints different
3252 error messages; b) it doesn't allow half-way updated images to pass the
3253 verification."""
3254
3255 partition = self.partition
3256 script.Print("Verifying %s..." % (partition,))
3257 ranges = self.tgt.care_map
3258 ranges_str = ranges.to_string_raw()
Tao Bao76def242017-11-21 09:25:31 -08003259 script.AppendExtra(
Yifan Hong10c530d2018-12-27 17:34:18 -08003260 'range_sha1(%s, "%s") == "%s" && ui_print(" Verified.") || '
3261 'ui_print("%s has unexpected contents.");' % (
Tao Bao76def242017-11-21 09:25:31 -08003262 self.device, ranges_str,
3263 self.tgt.TotalSha1(include_clobbered_blocks=True),
Yifan Hong10c530d2018-12-27 17:34:18 -08003264 self.partition))
Tao Bao9bc6bb22015-11-09 16:58:28 -08003265 script.AppendExtra("")
3266
Tao Baod522bdc2016-04-12 15:53:16 -07003267 def WriteVerifyScript(self, script, touched_blocks_only=False):
Sami Tolvanendd67a292014-12-09 16:40:34 +00003268 partition = self.partition
Tao Baof9efe282016-04-14 15:58:05 -07003269
3270 # full OTA
Jesse Zhao75bcea02015-01-06 10:59:53 -08003271 if not self.src:
Sami Tolvanendd67a292014-12-09 16:40:34 +00003272 script.Print("Image %s will be patched unconditionally." % (partition,))
Tao Baof9efe282016-04-14 15:58:05 -07003273
3274 # incremental OTA
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003275 else:
Tao Bao8fad03e2017-03-01 14:36:26 -08003276 if touched_blocks_only:
Tao Baod522bdc2016-04-12 15:53:16 -07003277 ranges = self.touched_src_ranges
3278 expected_sha1 = self.touched_src_sha1
3279 else:
3280 ranges = self.src.care_map.subtract(self.src.clobbered_blocks)
3281 expected_sha1 = self.src.TotalSha1()
Tao Baof9efe282016-04-14 15:58:05 -07003282
3283 # No blocks to be checked, skipping.
3284 if not ranges:
3285 return
3286
Tao Bao5ece99d2015-05-12 11:42:31 -07003287 ranges_str = ranges.to_string_raw()
Tao Bao76def242017-11-21 09:25:31 -08003288 script.AppendExtra(
Yifan Hong10c530d2018-12-27 17:34:18 -08003289 'if (range_sha1(%s, "%s") == "%s" || block_image_verify(%s, '
Tao Bao76def242017-11-21 09:25:31 -08003290 'package_extract_file("%s.transfer.list"), "%s.new.dat", '
3291 '"%s.patch.dat")) then' % (
3292 self.device, ranges_str, expected_sha1,
3293 self.device, partition, partition, partition))
Tao Baodd2a5892015-03-12 12:32:37 -07003294 script.Print('Verified %s image...' % (partition,))
Dan Albert8b72aef2015-03-23 19:13:21 -07003295 script.AppendExtra('else')
Sami Tolvanendd67a292014-12-09 16:40:34 +00003296
Tianjie Xufc3422a2015-12-15 11:53:59 -08003297 if self.version >= 4:
3298
3299 # Bug: 21124327
3300 # When generating incrementals for the system and vendor partitions in
3301 # version 4 or newer, explicitly check the first block (which contains
3302 # the superblock) of the partition to see if it's what we expect. If
3303 # this check fails, give an explicit log message about the partition
3304 # having been remounted R/W (the most likely explanation).
3305 if self.check_first_block:
Yifan Hong10c530d2018-12-27 17:34:18 -08003306 script.AppendExtra('check_first_block(%s);' % (self.device,))
Tianjie Xufc3422a2015-12-15 11:53:59 -08003307
3308 # If version >= 4, try block recovery before abort update
Tianjie Xu209db462016-05-24 17:34:52 -07003309 if partition == "system":
3310 code = ErrorCode.SYSTEM_RECOVER_FAILURE
3311 else:
3312 code = ErrorCode.VENDOR_RECOVER_FAILURE
Tianjie Xufc3422a2015-12-15 11:53:59 -08003313 script.AppendExtra((
Yifan Hong10c530d2018-12-27 17:34:18 -08003314 'ifelse (block_image_recover({device}, "{ranges}") && '
3315 'block_image_verify({device}, '
Tianjie Xufc3422a2015-12-15 11:53:59 -08003316 'package_extract_file("{partition}.transfer.list"), '
3317 '"{partition}.new.dat", "{partition}.patch.dat"), '
3318 'ui_print("{partition} recovered successfully."), '
Tianjie Xu209db462016-05-24 17:34:52 -07003319 'abort("E{code}: {partition} partition fails to recover"));\n'
Tianjie Xufc3422a2015-12-15 11:53:59 -08003320 'endif;').format(device=self.device, ranges=ranges_str,
Tianjie Xu209db462016-05-24 17:34:52 -07003321 partition=partition, code=code))
Doug Zongkerb34fcce2014-09-11 09:34:56 -07003322
Tao Baodd2a5892015-03-12 12:32:37 -07003323 # Abort the OTA update. Note that the incremental OTA cannot be applied
3324 # even if it may match the checksum of the target partition.
3325 # a) If version < 3, operations like move and erase will make changes
3326 # unconditionally and damage the partition.
3327 # b) If version >= 3, it won't even reach here.
Tianjie Xufc3422a2015-12-15 11:53:59 -08003328 else:
Tianjie Xu209db462016-05-24 17:34:52 -07003329 if partition == "system":
3330 code = ErrorCode.SYSTEM_VERIFICATION_FAILURE
3331 else:
3332 code = ErrorCode.VENDOR_VERIFICATION_FAILURE
3333 script.AppendExtra((
3334 'abort("E%d: %s partition has unexpected contents");\n'
3335 'endif;') % (code, partition))
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003336
Yifan Hong10c530d2018-12-27 17:34:18 -08003337 def WritePostInstallVerifyScript(self, script):
Tao Bao5fcaaef2015-06-01 13:40:49 -07003338 partition = self.partition
3339 script.Print('Verifying the updated %s image...' % (partition,))
3340 # Unlike pre-install verification, clobbered_blocks should not be ignored.
3341 ranges = self.tgt.care_map
3342 ranges_str = ranges.to_string_raw()
Tao Bao76def242017-11-21 09:25:31 -08003343 script.AppendExtra(
Yifan Hong10c530d2018-12-27 17:34:18 -08003344 'if range_sha1(%s, "%s") == "%s" then' % (
Tao Bao76def242017-11-21 09:25:31 -08003345 self.device, ranges_str,
3346 self.tgt.TotalSha1(include_clobbered_blocks=True)))
Tao Baoe9b61912015-07-09 17:37:49 -07003347
3348 # Bug: 20881595
3349 # Verify that extended blocks are really zeroed out.
3350 if self.tgt.extended:
3351 ranges_str = self.tgt.extended.to_string_raw()
Tao Bao76def242017-11-21 09:25:31 -08003352 script.AppendExtra(
Yifan Hong10c530d2018-12-27 17:34:18 -08003353 'if range_sha1(%s, "%s") == "%s" then' % (
Tao Bao76def242017-11-21 09:25:31 -08003354 self.device, ranges_str,
3355 self._HashZeroBlocks(self.tgt.extended.size())))
Tao Baoe9b61912015-07-09 17:37:49 -07003356 script.Print('Verified the updated %s image.' % (partition,))
Tianjie Xu209db462016-05-24 17:34:52 -07003357 if partition == "system":
3358 code = ErrorCode.SYSTEM_NONZERO_CONTENTS
3359 else:
3360 code = ErrorCode.VENDOR_NONZERO_CONTENTS
Tao Baoe9b61912015-07-09 17:37:49 -07003361 script.AppendExtra(
3362 'else\n'
Tianjie Xu209db462016-05-24 17:34:52 -07003363 ' abort("E%d: %s partition has unexpected non-zero contents after '
3364 'OTA update");\n'
3365 'endif;' % (code, partition))
Tao Baoe9b61912015-07-09 17:37:49 -07003366 else:
3367 script.Print('Verified the updated %s image.' % (partition,))
3368
Tianjie Xu209db462016-05-24 17:34:52 -07003369 if partition == "system":
3370 code = ErrorCode.SYSTEM_UNEXPECTED_CONTENTS
3371 else:
3372 code = ErrorCode.VENDOR_UNEXPECTED_CONTENTS
3373
Tao Bao5fcaaef2015-06-01 13:40:49 -07003374 script.AppendExtra(
3375 'else\n'
Tianjie Xu209db462016-05-24 17:34:52 -07003376 ' abort("E%d: %s partition has unexpected contents after OTA '
3377 'update");\n'
3378 'endif;' % (code, partition))
Tao Bao5fcaaef2015-06-01 13:40:49 -07003379
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003380 def _WriteUpdate(self, script, output_zip):
Dan Albert8e0178d2015-01-27 15:53:15 -08003381 ZipWrite(output_zip,
3382 '{}.transfer.list'.format(self.path),
3383 '{}.transfer.list'.format(self.partition))
Tianjie Xub0a29ad2017-07-06 15:13:59 -07003384
Tao Bao76def242017-11-21 09:25:31 -08003385 # For full OTA, compress the new.dat with brotli with quality 6 to reduce
3386 # its size. Quailty 9 almost triples the compression time but doesn't
3387 # further reduce the size too much. For a typical 1.8G system.new.dat
Tianjie Xub0a29ad2017-07-06 15:13:59 -07003388 # zip | brotli(quality 6) | brotli(quality 9)
3389 # compressed_size: 942M | 869M (~8% reduced) | 854M
3390 # compression_time: 75s | 265s | 719s
3391 # decompression_time: 15s | 25s | 25s
3392
3393 if not self.src:
Alex Deymob10e07a2017-11-09 23:53:42 +01003394 brotli_cmd = ['brotli', '--quality=6',
3395 '--output={}.new.dat.br'.format(self.path),
3396 '{}.new.dat'.format(self.path)]
Tianjie Xub0a29ad2017-07-06 15:13:59 -07003397 print("Compressing {}.new.dat with brotli".format(self.partition))
Tao Bao986ee862018-10-04 15:46:16 -07003398 RunAndCheckOutput(brotli_cmd)
Tianjie Xub0a29ad2017-07-06 15:13:59 -07003399
3400 new_data_name = '{}.new.dat.br'.format(self.partition)
3401 ZipWrite(output_zip,
3402 '{}.new.dat.br'.format(self.path),
3403 new_data_name,
3404 compress_type=zipfile.ZIP_STORED)
3405 else:
3406 new_data_name = '{}.new.dat'.format(self.partition)
3407 ZipWrite(output_zip, '{}.new.dat'.format(self.path), new_data_name)
3408
Dan Albert8e0178d2015-01-27 15:53:15 -08003409 ZipWrite(output_zip,
3410 '{}.patch.dat'.format(self.path),
3411 '{}.patch.dat'.format(self.partition),
3412 compress_type=zipfile.ZIP_STORED)
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003413
Tianjie Xu209db462016-05-24 17:34:52 -07003414 if self.partition == "system":
3415 code = ErrorCode.SYSTEM_UPDATE_FAILURE
3416 else:
3417 code = ErrorCode.VENDOR_UPDATE_FAILURE
3418
Yifan Hong10c530d2018-12-27 17:34:18 -08003419 call = ('block_image_update({device}, '
Dan Albert8e0178d2015-01-27 15:53:15 -08003420 'package_extract_file("{partition}.transfer.list"), '
Tianjie Xub0a29ad2017-07-06 15:13:59 -07003421 '"{new_data_name}", "{partition}.patch.dat") ||\n'
Tianjie Xu209db462016-05-24 17:34:52 -07003422 ' abort("E{code}: Failed to update {partition} image.");'.format(
Tianjie Xub0a29ad2017-07-06 15:13:59 -07003423 device=self.device, partition=self.partition,
3424 new_data_name=new_data_name, code=code))
Dan Albert8b72aef2015-03-23 19:13:21 -07003425 script.AppendExtra(script.WordWrap(call))
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003426
Kelvin Zhang0876c412020-06-23 15:06:58 -04003427 def _HashBlocks(self, source, ranges): # pylint: disable=no-self-use
Sami Tolvanendd67a292014-12-09 16:40:34 +00003428 data = source.ReadRangeSet(ranges)
3429 ctx = sha1()
3430
3431 for p in data:
3432 ctx.update(p)
3433
3434 return ctx.hexdigest()
3435
Kelvin Zhang0876c412020-06-23 15:06:58 -04003436 def _HashZeroBlocks(self, num_blocks): # pylint: disable=no-self-use
Tao Baoe9b61912015-07-09 17:37:49 -07003437 """Return the hash value for all zero blocks."""
3438 zero_block = '\x00' * 4096
3439 ctx = sha1()
3440 for _ in range(num_blocks):
3441 ctx.update(zero_block)
3442
3443 return ctx.hexdigest()
3444
Doug Zongkerab7ca1d2014-08-26 10:40:28 -07003445
Tianjie Xu41976c72019-07-03 13:57:01 -07003446# Expose these two classes to support vendor-specific scripts
3447DataImage = images.DataImage
3448EmptyImage = images.EmptyImage
3449
Tao Bao76def242017-11-21 09:25:31 -08003450
Doug Zongker96a57e72010-09-26 14:57:41 -07003451# map recovery.fstab's fs_types to mount/format "partition types"
Dan Albert8b72aef2015-03-23 19:13:21 -07003452PARTITION_TYPES = {
Dan Albert8b72aef2015-03-23 19:13:21 -07003453 "ext4": "EMMC",
3454 "emmc": "EMMC",
Mohamad Ayyash95e74c12015-05-01 15:39:36 -07003455 "f2fs": "EMMC",
3456 "squashfs": "EMMC"
Dan Albert8b72aef2015-03-23 19:13:21 -07003457}
Doug Zongker96a57e72010-09-26 14:57:41 -07003458
Kelvin Zhang0876c412020-06-23 15:06:58 -04003459
Yifan Hongbdb32012020-05-07 12:38:53 -07003460def GetTypeAndDevice(mount_point, info, check_no_slot=True):
3461 """
3462 Use GetTypeAndDeviceExpr whenever possible. This function is kept for
3463 backwards compatibility. It aborts if the fstab entry has slotselect option
3464 (unless check_no_slot is explicitly set to False).
3465 """
Doug Zongker96a57e72010-09-26 14:57:41 -07003466 fstab = info["fstab"]
3467 if fstab:
Yifan Hongbdb32012020-05-07 12:38:53 -07003468 if check_no_slot:
3469 assert not fstab[mount_point].slotselect, \
Kelvin Zhang0876c412020-06-23 15:06:58 -04003470 "Use GetTypeAndDeviceExpr instead"
Dan Albert8b72aef2015-03-23 19:13:21 -07003471 return (PARTITION_TYPES[fstab[mount_point].fs_type],
3472 fstab[mount_point].device)
Kelvin Zhang0876c412020-06-23 15:06:58 -04003473 raise KeyError
Baligh Uddinbeb6afd2013-11-13 00:22:34 +00003474
3475
Yifan Hongbdb32012020-05-07 12:38:53 -07003476def GetTypeAndDeviceExpr(mount_point, info):
3477 """
3478 Return the filesystem of the partition, and an edify expression that evaluates
3479 to the device at runtime.
3480 """
3481 fstab = info["fstab"]
3482 if fstab:
3483 p = fstab[mount_point]
3484 device_expr = '"%s"' % fstab[mount_point].device
3485 if p.slotselect:
3486 device_expr = 'add_slot_suffix(%s)' % device_expr
3487 return (PARTITION_TYPES[fstab[mount_point].fs_type], device_expr)
Kelvin Zhang0876c412020-06-23 15:06:58 -04003488 raise KeyError
Yifan Hongbdb32012020-05-07 12:38:53 -07003489
3490
3491def GetEntryForDevice(fstab, device):
3492 """
3493 Returns:
3494 The first entry in fstab whose device is the given value.
3495 """
3496 if not fstab:
3497 return None
3498 for mount_point in fstab:
3499 if fstab[mount_point].device == device:
3500 return fstab[mount_point]
3501 return None
3502
Kelvin Zhang0876c412020-06-23 15:06:58 -04003503
Baligh Uddinbeb6afd2013-11-13 00:22:34 +00003504def ParseCertificate(data):
Tao Bao17e4e612018-02-16 17:12:54 -08003505 """Parses and converts a PEM-encoded certificate into DER-encoded.
3506
3507 This gives the same result as `openssl x509 -in <filename> -outform DER`.
3508
3509 Returns:
Tao Baoda30cfa2017-12-01 16:19:46 -08003510 The decoded certificate bytes.
Tao Bao17e4e612018-02-16 17:12:54 -08003511 """
3512 cert_buffer = []
Baligh Uddinbeb6afd2013-11-13 00:22:34 +00003513 save = False
3514 for line in data.split("\n"):
3515 if "--END CERTIFICATE--" in line:
3516 break
3517 if save:
Tao Bao17e4e612018-02-16 17:12:54 -08003518 cert_buffer.append(line)
Baligh Uddinbeb6afd2013-11-13 00:22:34 +00003519 if "--BEGIN CERTIFICATE--" in line:
3520 save = True
Tao Baoda30cfa2017-12-01 16:19:46 -08003521 cert = base64.b64decode("".join(cert_buffer))
Baligh Uddinbeb6afd2013-11-13 00:22:34 +00003522 return cert
Doug Zongkerc9253822014-02-04 12:17:58 -08003523
Tao Bao04e1f012018-02-04 12:13:35 -08003524
3525def ExtractPublicKey(cert):
3526 """Extracts the public key (PEM-encoded) from the given certificate file.
3527
3528 Args:
3529 cert: The certificate filename.
3530
3531 Returns:
3532 The public key string.
3533
3534 Raises:
3535 AssertionError: On non-zero return from 'openssl'.
3536 """
3537 # The behavior with '-out' is different between openssl 1.1 and openssl 1.0.
3538 # While openssl 1.1 writes the key into the given filename followed by '-out',
3539 # openssl 1.0 (both of 1.0.1 and 1.0.2) doesn't. So we collect the output from
3540 # stdout instead.
3541 cmd = ['openssl', 'x509', '-pubkey', '-noout', '-in', cert]
3542 proc = Run(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE)
3543 pubkey, stderrdata = proc.communicate()
3544 assert proc.returncode == 0, \
3545 'Failed to dump public key from certificate: %s\n%s' % (cert, stderrdata)
3546 return pubkey
3547
3548
Tao Bao1ac886e2019-06-26 11:58:22 -07003549def ExtractAvbPublicKey(avbtool, key):
Tao Bao2cc0ca12019-03-15 10:44:43 -07003550 """Extracts the AVB public key from the given public or private key.
3551
3552 Args:
Tao Bao1ac886e2019-06-26 11:58:22 -07003553 avbtool: The AVB tool to use.
Tao Bao2cc0ca12019-03-15 10:44:43 -07003554 key: The input key file, which should be PEM-encoded public or private key.
3555
3556 Returns:
3557 The path to the extracted AVB public key file.
3558 """
3559 output = MakeTempFile(prefix='avb-', suffix='.avbpubkey')
3560 RunAndCheckOutput(
Tao Bao1ac886e2019-06-26 11:58:22 -07003561 [avbtool, 'extract_public_key', "--key", key, "--output", output])
Tao Bao2cc0ca12019-03-15 10:44:43 -07003562 return output
3563
3564
Doug Zongker412c02f2014-02-13 10:58:24 -08003565def MakeRecoveryPatch(input_dir, output_sink, recovery_img, boot_img,
3566 info_dict=None):
Tao Bao6d5d6232018-03-09 17:04:42 -08003567 """Generates the recovery-from-boot patch and writes the script to output.
Doug Zongkerc9253822014-02-04 12:17:58 -08003568
Tao Bao6d5d6232018-03-09 17:04:42 -08003569 Most of the space in the boot and recovery images is just the kernel, which is
3570 identical for the two, so the resulting patch should be efficient. Add it to
3571 the output zip, along with a shell script that is run from init.rc on first
3572 boot to actually do the patching and install the new recovery image.
3573
3574 Args:
3575 input_dir: The top-level input directory of the target-files.zip.
3576 output_sink: The callback function that writes the result.
3577 recovery_img: File object for the recovery image.
3578 boot_img: File objects for the boot image.
3579 info_dict: A dict returned by common.LoadInfoDict() on the input
3580 target_files. Will use OPTIONS.info_dict if None has been given.
Doug Zongkerc9253822014-02-04 12:17:58 -08003581 """
Doug Zongker412c02f2014-02-13 10:58:24 -08003582 if info_dict is None:
3583 info_dict = OPTIONS.info_dict
3584
Tao Bao6d5d6232018-03-09 17:04:42 -08003585 full_recovery_image = info_dict.get("full_recovery_image") == "true"
Bill Peckhame868aec2019-09-17 17:06:47 -07003586 board_uses_vendorimage = info_dict.get("board_uses_vendorimage") == "true"
3587
3588 if board_uses_vendorimage:
3589 # In this case, the output sink is rooted at VENDOR
3590 recovery_img_path = "etc/recovery.img"
3591 recovery_resource_dat_path = "VENDOR/etc/recovery-resource.dat"
3592 sh_dir = "bin"
3593 else:
3594 # In this case the output sink is rooted at SYSTEM
3595 recovery_img_path = "vendor/etc/recovery.img"
3596 recovery_resource_dat_path = "SYSTEM/vendor/etc/recovery-resource.dat"
3597 sh_dir = "vendor/bin"
Doug Zongkerc9253822014-02-04 12:17:58 -08003598
Tao Baof2cffbd2015-07-22 12:33:18 -07003599 if full_recovery_image:
Bill Peckhame868aec2019-09-17 17:06:47 -07003600 output_sink(recovery_img_path, recovery_img.data)
Tao Baof2cffbd2015-07-22 12:33:18 -07003601
3602 else:
Tao Bao6d5d6232018-03-09 17:04:42 -08003603 system_root_image = info_dict.get("system_root_image") == "true"
Bill Peckhame868aec2019-09-17 17:06:47 -07003604 path = os.path.join(input_dir, recovery_resource_dat_path)
Tao Bao6d5d6232018-03-09 17:04:42 -08003605 # With system-root-image, boot and recovery images will have mismatching
3606 # entries (only recovery has the ramdisk entry) (Bug: 72731506). Use bsdiff
3607 # to handle such a case.
3608 if system_root_image:
3609 diff_program = ["bsdiff"]
Tao Baof2cffbd2015-07-22 12:33:18 -07003610 bonus_args = ""
Tao Bao6d5d6232018-03-09 17:04:42 -08003611 assert not os.path.exists(path)
3612 else:
3613 diff_program = ["imgdiff"]
3614 if os.path.exists(path):
3615 diff_program.append("-b")
3616 diff_program.append(path)
Bill Peckhame868aec2019-09-17 17:06:47 -07003617 bonus_args = "--bonus /vendor/etc/recovery-resource.dat"
Tao Bao6d5d6232018-03-09 17:04:42 -08003618 else:
3619 bonus_args = ""
Tao Baof2cffbd2015-07-22 12:33:18 -07003620
3621 d = Difference(recovery_img, boot_img, diff_program=diff_program)
3622 _, _, patch = d.ComputePatch()
3623 output_sink("recovery-from-boot.p", patch)
Doug Zongkerc9253822014-02-04 12:17:58 -08003624
Dan Albertebb19aa2015-03-27 19:11:53 -07003625 try:
Tao Bao6f0b2192015-10-13 16:37:12 -07003626 # The following GetTypeAndDevice()s need to use the path in the target
3627 # info_dict instead of source_info_dict.
Yifan Hongbdb32012020-05-07 12:38:53 -07003628 boot_type, boot_device = GetTypeAndDevice("/boot", info_dict,
3629 check_no_slot=False)
3630 recovery_type, recovery_device = GetTypeAndDevice("/recovery", info_dict,
3631 check_no_slot=False)
Dan Albertebb19aa2015-03-27 19:11:53 -07003632 except KeyError:
Ying Wanga961a092014-07-29 11:42:37 -07003633 return
Doug Zongkerc9253822014-02-04 12:17:58 -08003634
Tao Baof2cffbd2015-07-22 12:33:18 -07003635 if full_recovery_image:
Bill Peckhame868aec2019-09-17 17:06:47 -07003636
3637 # Note that we use /vendor to refer to the recovery resources. This will
3638 # work for a separate vendor partition mounted at /vendor or a
3639 # /system/vendor subdirectory on the system partition, for which init will
3640 # create a symlink from /vendor to /system/vendor.
3641
3642 sh = """#!/vendor/bin/sh
Tao Bao4948aed2018-07-13 16:11:16 -07003643if ! applypatch --check %(type)s:%(device)s:%(size)d:%(sha1)s; then
3644 applypatch \\
Bill Peckhame868aec2019-09-17 17:06:47 -07003645 --flash /vendor/etc/recovery.img \\
Tao Bao4948aed2018-07-13 16:11:16 -07003646 --target %(type)s:%(device)s:%(size)d:%(sha1)s && \\
3647 log -t recovery "Installing new recovery image: succeeded" || \\
3648 log -t recovery "Installing new recovery image: failed"
Tao Baof2cffbd2015-07-22 12:33:18 -07003649else
3650 log -t recovery "Recovery image already installed"
3651fi
3652""" % {'type': recovery_type,
3653 'device': recovery_device,
3654 'sha1': recovery_img.sha1,
3655 'size': recovery_img.size}
3656 else:
Bill Peckhame868aec2019-09-17 17:06:47 -07003657 sh = """#!/vendor/bin/sh
Tao Bao4948aed2018-07-13 16:11:16 -07003658if ! applypatch --check %(recovery_type)s:%(recovery_device)s:%(recovery_size)d:%(recovery_sha1)s; then
3659 applypatch %(bonus_args)s \\
Bill Peckhame868aec2019-09-17 17:06:47 -07003660 --patch /vendor/recovery-from-boot.p \\
Tao Bao4948aed2018-07-13 16:11:16 -07003661 --source %(boot_type)s:%(boot_device)s:%(boot_size)d:%(boot_sha1)s \\
3662 --target %(recovery_type)s:%(recovery_device)s:%(recovery_size)d:%(recovery_sha1)s && \\
3663 log -t recovery "Installing new recovery image: succeeded" || \\
3664 log -t recovery "Installing new recovery image: failed"
Doug Zongkerc9253822014-02-04 12:17:58 -08003665else
3666 log -t recovery "Recovery image already installed"
3667fi
Dan Albert8b72aef2015-03-23 19:13:21 -07003668""" % {'boot_size': boot_img.size,
3669 'boot_sha1': boot_img.sha1,
3670 'recovery_size': recovery_img.size,
3671 'recovery_sha1': recovery_img.sha1,
3672 'boot_type': boot_type,
Yifan Hongbdb32012020-05-07 12:38:53 -07003673 'boot_device': boot_device + '$(getprop ro.boot.slot_suffix)',
Tianjiee3c31ea2020-05-19 13:44:26 -07003674 'recovery_type': recovery_type,
3675 'recovery_device': recovery_device + '$(getprop ro.boot.slot_suffix)',
Dan Albert8b72aef2015-03-23 19:13:21 -07003676 'bonus_args': bonus_args}
Doug Zongkerc9253822014-02-04 12:17:58 -08003677
Bill Peckhame868aec2019-09-17 17:06:47 -07003678 # The install script location moved from /system/etc to /system/bin in the L
3679 # release. In the R release it is in VENDOR/bin or SYSTEM/vendor/bin.
3680 sh_location = os.path.join(sh_dir, "install-recovery.sh")
Tao Bao9f0c8df2015-07-07 18:31:47 -07003681
Tao Bao32fcdab2018-10-12 10:30:39 -07003682 logger.info("putting script in %s", sh_location)
Doug Zongkerc9253822014-02-04 12:17:58 -08003683
Tao Baoda30cfa2017-12-01 16:19:46 -08003684 output_sink(sh_location, sh.encode())
Yifan Hong10c530d2018-12-27 17:34:18 -08003685
3686
3687class DynamicPartitionUpdate(object):
3688 def __init__(self, src_group=None, tgt_group=None, progress=None,
3689 block_difference=None):
3690 self.src_group = src_group
3691 self.tgt_group = tgt_group
3692 self.progress = progress
3693 self.block_difference = block_difference
3694
3695 @property
3696 def src_size(self):
3697 if not self.block_difference:
3698 return 0
3699 return DynamicPartitionUpdate._GetSparseImageSize(self.block_difference.src)
3700
3701 @property
3702 def tgt_size(self):
3703 if not self.block_difference:
3704 return 0
3705 return DynamicPartitionUpdate._GetSparseImageSize(self.block_difference.tgt)
3706
3707 @staticmethod
3708 def _GetSparseImageSize(img):
3709 if not img:
3710 return 0
3711 return img.blocksize * img.total_blocks
3712
3713
3714class DynamicGroupUpdate(object):
3715 def __init__(self, src_size=None, tgt_size=None):
3716 # None: group does not exist. 0: no size limits.
3717 self.src_size = src_size
3718 self.tgt_size = tgt_size
3719
3720
3721class DynamicPartitionsDifference(object):
3722 def __init__(self, info_dict, block_diffs, progress_dict=None,
3723 source_info_dict=None):
3724 if progress_dict is None:
Tao Baof1113e92019-06-18 12:10:14 -07003725 progress_dict = {}
Yifan Hong10c530d2018-12-27 17:34:18 -08003726
3727 self._remove_all_before_apply = False
3728 if source_info_dict is None:
3729 self._remove_all_before_apply = True
Tao Baof1113e92019-06-18 12:10:14 -07003730 source_info_dict = {}
Yifan Hong10c530d2018-12-27 17:34:18 -08003731
Tao Baof1113e92019-06-18 12:10:14 -07003732 block_diff_dict = collections.OrderedDict(
3733 [(e.partition, e) for e in block_diffs])
3734
Yifan Hong10c530d2018-12-27 17:34:18 -08003735 assert len(block_diff_dict) == len(block_diffs), \
3736 "Duplicated BlockDifference object for {}".format(
3737 [partition for partition, count in
3738 collections.Counter(e.partition for e in block_diffs).items()
3739 if count > 1])
3740
Yifan Hong79997e52019-01-23 16:56:19 -08003741 self._partition_updates = collections.OrderedDict()
Yifan Hong10c530d2018-12-27 17:34:18 -08003742
3743 for p, block_diff in block_diff_dict.items():
3744 self._partition_updates[p] = DynamicPartitionUpdate()
3745 self._partition_updates[p].block_difference = block_diff
3746
3747 for p, progress in progress_dict.items():
3748 if p in self._partition_updates:
3749 self._partition_updates[p].progress = progress
3750
3751 tgt_groups = shlex.split(info_dict.get(
3752 "super_partition_groups", "").strip())
3753 src_groups = shlex.split(source_info_dict.get(
3754 "super_partition_groups", "").strip())
3755
3756 for g in tgt_groups:
3757 for p in shlex.split(info_dict.get(
Kelvin Zhang563750f2021-04-28 12:46:17 -04003758 "super_%s_partition_list" % g, "").strip()):
Yifan Hong10c530d2018-12-27 17:34:18 -08003759 assert p in self._partition_updates, \
3760 "{} is in target super_{}_partition_list but no BlockDifference " \
3761 "object is provided.".format(p, g)
3762 self._partition_updates[p].tgt_group = g
3763
3764 for g in src_groups:
3765 for p in shlex.split(source_info_dict.get(
Kelvin Zhang563750f2021-04-28 12:46:17 -04003766 "super_%s_partition_list" % g, "").strip()):
Yifan Hong10c530d2018-12-27 17:34:18 -08003767 assert p in self._partition_updates, \
3768 "{} is in source super_{}_partition_list but no BlockDifference " \
3769 "object is provided.".format(p, g)
3770 self._partition_updates[p].src_group = g
3771
Yifan Hong45433e42019-01-18 13:55:25 -08003772 target_dynamic_partitions = set(shlex.split(info_dict.get(
3773 "dynamic_partition_list", "").strip()))
3774 block_diffs_with_target = set(p for p, u in self._partition_updates.items()
3775 if u.tgt_size)
3776 assert block_diffs_with_target == target_dynamic_partitions, \
3777 "Target Dynamic partitions: {}, BlockDifference with target: {}".format(
3778 list(target_dynamic_partitions), list(block_diffs_with_target))
3779
3780 source_dynamic_partitions = set(shlex.split(source_info_dict.get(
3781 "dynamic_partition_list", "").strip()))
3782 block_diffs_with_source = set(p for p, u in self._partition_updates.items()
3783 if u.src_size)
3784 assert block_diffs_with_source == source_dynamic_partitions, \
3785 "Source Dynamic partitions: {}, BlockDifference with source: {}".format(
3786 list(source_dynamic_partitions), list(block_diffs_with_source))
3787
Yifan Hong10c530d2018-12-27 17:34:18 -08003788 if self._partition_updates:
3789 logger.info("Updating dynamic partitions %s",
3790 self._partition_updates.keys())
3791
Yifan Hong79997e52019-01-23 16:56:19 -08003792 self._group_updates = collections.OrderedDict()
Yifan Hong10c530d2018-12-27 17:34:18 -08003793
3794 for g in tgt_groups:
3795 self._group_updates[g] = DynamicGroupUpdate()
3796 self._group_updates[g].tgt_size = int(info_dict.get(
3797 "super_%s_group_size" % g, "0").strip())
3798
3799 for g in src_groups:
3800 if g not in self._group_updates:
3801 self._group_updates[g] = DynamicGroupUpdate()
3802 self._group_updates[g].src_size = int(source_info_dict.get(
3803 "super_%s_group_size" % g, "0").strip())
3804
3805 self._Compute()
3806
3807 def WriteScript(self, script, output_zip, write_verify_script=False):
3808 script.Comment('--- Start patching dynamic partitions ---')
3809 for p, u in self._partition_updates.items():
3810 if u.src_size and u.tgt_size and u.src_size > u.tgt_size:
3811 script.Comment('Patch partition %s' % p)
3812 u.block_difference.WriteScript(script, output_zip, progress=u.progress,
3813 write_verify_script=False)
3814
3815 op_list_path = MakeTempFile()
3816 with open(op_list_path, 'w') as f:
3817 for line in self._op_list:
3818 f.write('{}\n'.format(line))
3819
3820 ZipWrite(output_zip, op_list_path, "dynamic_partitions_op_list")
3821
3822 script.Comment('Update dynamic partition metadata')
3823 script.AppendExtra('assert(update_dynamic_partitions('
3824 'package_extract_file("dynamic_partitions_op_list")));')
3825
3826 if write_verify_script:
3827 for p, u in self._partition_updates.items():
3828 if u.src_size and u.tgt_size and u.src_size > u.tgt_size:
3829 u.block_difference.WritePostInstallVerifyScript(script)
Kelvin Zhang0876c412020-06-23 15:06:58 -04003830 script.AppendExtra('unmap_partition("%s");' % p) # ignore errors
Yifan Hong10c530d2018-12-27 17:34:18 -08003831
3832 for p, u in self._partition_updates.items():
3833 if u.tgt_size and u.src_size <= u.tgt_size:
3834 script.Comment('Patch partition %s' % p)
3835 u.block_difference.WriteScript(script, output_zip, progress=u.progress,
3836 write_verify_script=write_verify_script)
3837 if write_verify_script:
Kelvin Zhang0876c412020-06-23 15:06:58 -04003838 script.AppendExtra('unmap_partition("%s");' % p) # ignore errors
Yifan Hong10c530d2018-12-27 17:34:18 -08003839
3840 script.Comment('--- End patching dynamic partitions ---')
3841
3842 def _Compute(self):
3843 self._op_list = list()
3844
3845 def append(line):
3846 self._op_list.append(line)
3847
3848 def comment(line):
3849 self._op_list.append("# %s" % line)
3850
3851 if self._remove_all_before_apply:
3852 comment('Remove all existing dynamic partitions and groups before '
3853 'applying full OTA')
3854 append('remove_all_groups')
3855
3856 for p, u in self._partition_updates.items():
3857 if u.src_group and not u.tgt_group:
3858 append('remove %s' % p)
3859
3860 for p, u in self._partition_updates.items():
3861 if u.src_group and u.tgt_group and u.src_group != u.tgt_group:
3862 comment('Move partition %s from %s to default' % (p, u.src_group))
3863 append('move %s default' % p)
3864
3865 for p, u in self._partition_updates.items():
3866 if u.src_size and u.tgt_size and u.src_size > u.tgt_size:
3867 comment('Shrink partition %s from %d to %d' %
3868 (p, u.src_size, u.tgt_size))
3869 append('resize %s %s' % (p, u.tgt_size))
3870
3871 for g, u in self._group_updates.items():
3872 if u.src_size is not None and u.tgt_size is None:
3873 append('remove_group %s' % g)
3874 if (u.src_size is not None and u.tgt_size is not None and
Kelvin Zhang563750f2021-04-28 12:46:17 -04003875 u.src_size > u.tgt_size):
Yifan Hong10c530d2018-12-27 17:34:18 -08003876 comment('Shrink group %s from %d to %d' % (g, u.src_size, u.tgt_size))
3877 append('resize_group %s %d' % (g, u.tgt_size))
3878
3879 for g, u in self._group_updates.items():
3880 if u.src_size is None and u.tgt_size is not None:
3881 comment('Add group %s with maximum size %d' % (g, u.tgt_size))
3882 append('add_group %s %d' % (g, u.tgt_size))
3883 if (u.src_size is not None and u.tgt_size is not None and
Kelvin Zhang563750f2021-04-28 12:46:17 -04003884 u.src_size < u.tgt_size):
Yifan Hong10c530d2018-12-27 17:34:18 -08003885 comment('Grow group %s from %d to %d' % (g, u.src_size, u.tgt_size))
3886 append('resize_group %s %d' % (g, u.tgt_size))
3887
3888 for p, u in self._partition_updates.items():
3889 if u.tgt_group and not u.src_group:
3890 comment('Add partition %s to group %s' % (p, u.tgt_group))
3891 append('add %s %s' % (p, u.tgt_group))
3892
3893 for p, u in self._partition_updates.items():
3894 if u.tgt_size and u.src_size < u.tgt_size:
Kelvin Zhang0876c412020-06-23 15:06:58 -04003895 comment('Grow partition %s from %d to %d' %
3896 (p, u.src_size, u.tgt_size))
Yifan Hong10c530d2018-12-27 17:34:18 -08003897 append('resize %s %d' % (p, u.tgt_size))
3898
3899 for p, u in self._partition_updates.items():
3900 if u.src_group and u.tgt_group and u.src_group != u.tgt_group:
3901 comment('Move partition %s from default to %s' %
3902 (p, u.tgt_group))
3903 append('move %s %s' % (p, u.tgt_group))
Yifan Hongc65a0542021-01-07 14:21:01 -08003904
3905
jiajia tangf3f842b2021-03-17 21:49:44 +08003906def GetBootImageBuildProp(boot_img, ramdisk_format=RamdiskFormat.LZ4):
Yifan Hongc65a0542021-01-07 14:21:01 -08003907 """
Yifan Hong85ac5012021-01-07 14:43:46 -08003908 Get build.prop from ramdisk within the boot image
Yifan Hongc65a0542021-01-07 14:21:01 -08003909
3910 Args:
jiajia tangf3f842b2021-03-17 21:49:44 +08003911 boot_img: the boot image file. Ramdisk must be compressed with lz4 or minigzip format.
Yifan Hongc65a0542021-01-07 14:21:01 -08003912
3913 Return:
Yifan Hong85ac5012021-01-07 14:43:46 -08003914 An extracted file that stores properties in the boot image.
Yifan Hongc65a0542021-01-07 14:21:01 -08003915 """
Yifan Hongc65a0542021-01-07 14:21:01 -08003916 tmp_dir = MakeTempDir('boot_', suffix='.img')
3917 try:
Kelvin Zhang563750f2021-04-28 12:46:17 -04003918 RunAndCheckOutput(['unpack_bootimg', '--boot_img',
3919 boot_img, '--out', tmp_dir])
Yifan Hongc65a0542021-01-07 14:21:01 -08003920 ramdisk = os.path.join(tmp_dir, 'ramdisk')
3921 if not os.path.isfile(ramdisk):
3922 logger.warning('Unable to get boot image timestamp: no ramdisk in boot')
3923 return None
3924 uncompressed_ramdisk = os.path.join(tmp_dir, 'uncompressed_ramdisk')
jiajia tangf3f842b2021-03-17 21:49:44 +08003925 if ramdisk_format == RamdiskFormat.LZ4:
3926 RunAndCheckOutput(['lz4', '-d', ramdisk, uncompressed_ramdisk])
3927 elif ramdisk_format == RamdiskFormat.GZ:
3928 with open(ramdisk, 'rb') as input_stream:
3929 with open(uncompressed_ramdisk, 'wb') as output_stream:
Kelvin Zhang563750f2021-04-28 12:46:17 -04003930 p2 = Run(['minigzip', '-d'], stdin=input_stream.fileno(),
3931 stdout=output_stream.fileno())
jiajia tangf3f842b2021-03-17 21:49:44 +08003932 p2.wait()
3933 else:
3934 logger.error('Only support lz4 or minigzip ramdisk format.')
3935 return None
Yifan Hongc65a0542021-01-07 14:21:01 -08003936
3937 abs_uncompressed_ramdisk = os.path.abspath(uncompressed_ramdisk)
3938 extracted_ramdisk = MakeTempDir('extracted_ramdisk')
3939 # Use "toybox cpio" instead of "cpio" because the latter invokes cpio from
3940 # the host environment.
3941 RunAndCheckOutput(['toybox', 'cpio', '-F', abs_uncompressed_ramdisk, '-i'],
Kelvin Zhang563750f2021-04-28 12:46:17 -04003942 cwd=extracted_ramdisk)
Yifan Hongc65a0542021-01-07 14:21:01 -08003943
Yifan Hongc65a0542021-01-07 14:21:01 -08003944 for search_path in RAMDISK_BUILD_PROP_REL_PATHS:
3945 prop_file = os.path.join(extracted_ramdisk, search_path)
3946 if os.path.isfile(prop_file):
Yifan Hong7dc51172021-01-12 11:27:39 -08003947 return prop_file
Kelvin Zhang563750f2021-04-28 12:46:17 -04003948 logger.warning(
3949 'Unable to get boot image timestamp: no %s in ramdisk', search_path)
Yifan Hongc65a0542021-01-07 14:21:01 -08003950
Yifan Hong7dc51172021-01-12 11:27:39 -08003951 return None
Yifan Hongc65a0542021-01-07 14:21:01 -08003952
Yifan Hong85ac5012021-01-07 14:43:46 -08003953 except ExternalError as e:
3954 logger.warning('Unable to get boot image build props: %s', e)
3955 return None
3956
3957
3958def GetBootImageTimestamp(boot_img):
3959 """
3960 Get timestamp from ramdisk within the boot image
3961
3962 Args:
3963 boot_img: the boot image file. Ramdisk must be compressed with lz4 format.
3964
3965 Return:
3966 An integer that corresponds to the timestamp of the boot image, or None
3967 if file has unknown format. Raise exception if an unexpected error has
3968 occurred.
3969 """
3970 prop_file = GetBootImageBuildProp(boot_img)
3971 if not prop_file:
3972 return None
3973
3974 props = PartitionBuildProps.FromBuildPropFile('boot', prop_file)
3975 if props is None:
3976 return None
3977
3978 try:
Yifan Hongc65a0542021-01-07 14:21:01 -08003979 timestamp = props.GetProp('ro.bootimage.build.date.utc')
3980 if timestamp:
3981 return int(timestamp)
Kelvin Zhang563750f2021-04-28 12:46:17 -04003982 logger.warning(
3983 'Unable to get boot image timestamp: ro.bootimage.build.date.utc is undefined')
Yifan Hongc65a0542021-01-07 14:21:01 -08003984 return None
3985
3986 except ExternalError as e:
3987 logger.warning('Unable to get boot image timestamp: %s', e)
3988 return None
Kelvin Zhang27324132021-03-22 15:38:38 -04003989
3990
3991def GetCareMap(which, imgname):
3992 """Returns the care_map string for the given partition.
3993
3994 Args:
3995 which: The partition name, must be listed in PARTITIONS_WITH_CARE_MAP.
3996 imgname: The filename of the image.
3997
3998 Returns:
3999 (which, care_map_ranges): care_map_ranges is the raw string of the care_map
4000 RangeSet; or None.
4001 """
4002 assert which in PARTITIONS_WITH_CARE_MAP
4003
4004 # which + "_image_size" contains the size that the actual filesystem image
4005 # resides in, which is all that needs to be verified. The additional blocks in
4006 # the image file contain verity metadata, by reading which would trigger
4007 # invalid reads.
4008 image_size = OPTIONS.info_dict.get(which + "_image_size")
4009 if not image_size:
4010 return None
4011
David Anderson9e95a022021-08-31 21:32:45 -07004012 disable_sparse = OPTIONS.info_dict.get(which + "_disable_sparse")
4013
Kelvin Zhang27324132021-03-22 15:38:38 -04004014 image_blocks = int(image_size) // 4096 - 1
Kelvin Zhang98ef7bb2022-01-07 14:41:46 -08004015 # It's OK for image_blocks to be 0, because care map ranges are inclusive.
4016 # So 0-0 means "just block 0", which is valid.
4017 assert image_blocks >= 0, "blocks for {} must be non-negative, image size: {}".format(
4018 which, image_size)
Kelvin Zhang27324132021-03-22 15:38:38 -04004019
4020 # For sparse images, we will only check the blocks that are listed in the care
4021 # map, i.e. the ones with meaningful data.
David Anderson9e95a022021-08-31 21:32:45 -07004022 if "extfs_sparse_flag" in OPTIONS.info_dict and not disable_sparse:
Kelvin Zhang27324132021-03-22 15:38:38 -04004023 simg = sparse_img.SparseImage(imgname)
4024 care_map_ranges = simg.care_map.intersect(
4025 rangelib.RangeSet("0-{}".format(image_blocks)))
4026
4027 # Otherwise for non-sparse images, we read all the blocks in the filesystem
4028 # image.
4029 else:
4030 care_map_ranges = rangelib.RangeSet("0-{}".format(image_blocks))
4031
4032 return [which, care_map_ranges.to_string_raw()]
4033
4034
4035def AddCareMapForAbOta(output_file, ab_partitions, image_paths):
4036 """Generates and adds care_map.pb for a/b partition that has care_map.
4037
4038 Args:
4039 output_file: The output zip file (needs to be already open),
4040 or file path to write care_map.pb.
4041 ab_partitions: The list of A/B partitions.
4042 image_paths: A map from the partition name to the image path.
4043 """
4044 if not output_file:
4045 raise ExternalError('Expected output_file for AddCareMapForAbOta')
4046
4047 care_map_list = []
4048 for partition in ab_partitions:
4049 partition = partition.strip()
4050 if partition not in PARTITIONS_WITH_CARE_MAP:
4051 continue
4052
4053 verity_block_device = "{}_verity_block_device".format(partition)
4054 avb_hashtree_enable = "avb_{}_hashtree_enable".format(partition)
4055 if (verity_block_device in OPTIONS.info_dict or
4056 OPTIONS.info_dict.get(avb_hashtree_enable) == "true"):
4057 if partition not in image_paths:
4058 logger.warning('Potential partition with care_map missing from images: %s',
4059 partition)
4060 continue
4061 image_path = image_paths[partition]
4062 if not os.path.exists(image_path):
4063 raise ExternalError('Expected image at path {}'.format(image_path))
4064
4065 care_map = GetCareMap(partition, image_path)
4066 if not care_map:
4067 continue
4068 care_map_list += care_map
4069
4070 # adds fingerprint field to the care_map
4071 # TODO(xunchang) revisit the fingerprint calculation for care_map.
4072 partition_props = OPTIONS.info_dict.get(partition + ".build.prop")
4073 prop_name_list = ["ro.{}.build.fingerprint".format(partition),
4074 "ro.{}.build.thumbprint".format(partition)]
4075
4076 present_props = [x for x in prop_name_list if
4077 partition_props and partition_props.GetProp(x)]
4078 if not present_props:
4079 logger.warning(
4080 "fingerprint is not present for partition %s", partition)
4081 property_id, fingerprint = "unknown", "unknown"
4082 else:
4083 property_id = present_props[0]
4084 fingerprint = partition_props.GetProp(property_id)
4085 care_map_list += [property_id, fingerprint]
4086
4087 if not care_map_list:
4088 return
4089
4090 # Converts the list into proto buf message by calling care_map_generator; and
4091 # writes the result to a temp file.
4092 temp_care_map_text = MakeTempFile(prefix="caremap_text-",
4093 suffix=".txt")
4094 with open(temp_care_map_text, 'w') as text_file:
4095 text_file.write('\n'.join(care_map_list))
4096
4097 temp_care_map = MakeTempFile(prefix="caremap-", suffix=".pb")
4098 care_map_gen_cmd = ["care_map_generator", temp_care_map_text, temp_care_map]
4099 RunAndCheckOutput(care_map_gen_cmd)
4100
4101 if not isinstance(output_file, zipfile.ZipFile):
4102 shutil.copy(temp_care_map, output_file)
4103 return
4104 # output_file is a zip file
4105 care_map_path = "META/care_map.pb"
4106 if care_map_path in output_file.namelist():
4107 # Copy the temp file into the OPTIONS.input_tmp dir and update the
4108 # replace_updated_files_list used by add_img_to_target_files
4109 if not OPTIONS.replace_updated_files_list:
4110 OPTIONS.replace_updated_files_list = []
4111 shutil.copy(temp_care_map, os.path.join(OPTIONS.input_tmp, care_map_path))
4112 OPTIONS.replace_updated_files_list.append(care_map_path)
4113 else:
4114 ZipWrite(output_file, temp_care_map, arcname=care_map_path)
Kelvin Zhang26390482021-11-02 14:31:10 -07004115
4116
4117def IsSparseImage(filepath):
4118 with open(filepath, 'rb') as fp:
4119 # Magic for android sparse image format
4120 # https://source.android.com/devices/bootloader/images
4121 return fp.read(4) == b'\x3A\xFF\x26\xED'