blob: 58f0e853affc056e098e42d4fae0727a8e10003e [file] [log] [blame]
Doug Zongkereef39442009-04-02 12:14:19 -07001#!/usr/bin/env python
2#
3# Copyright (C) 2008 The Android Open Source Project
4#
5# Licensed under the Apache License, Version 2.0 (the "License");
6# you may not use this file except in compliance with the License.
7# You may obtain a copy of the License at
8#
9# http://www.apache.org/licenses/LICENSE-2.0
10#
11# Unless required by applicable law or agreed to in writing, software
12# distributed under the License is distributed on an "AS IS" BASIS,
13# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14# See the License for the specific language governing permissions and
15# limitations under the License.
16
17"""
Tao Bao30df8b42018-04-23 15:32:53 -070018Given a target-files zipfile, produces an OTA package that installs that build.
19An incremental OTA is produced if -i is given, otherwise a full OTA is produced.
Doug Zongkereef39442009-04-02 12:14:19 -070020
Tao Bao30df8b42018-04-23 15:32:53 -070021Usage: ota_from_target_files [options] input_target_files output_ota_package
Doug Zongkereef39442009-04-02 12:14:19 -070022
Tao Bao30df8b42018-04-23 15:32:53 -070023Common options that apply to both of non-A/B and A/B OTAs
24
25 --downgrade
26 Intentionally generate an incremental OTA that updates from a newer build
Tao Baofaa8e0b2018-04-12 14:31:43 -070027 to an older one (e.g. downgrading from P preview back to O MR1).
28 "ota-downgrade=yes" will be set in the package metadata file. A data wipe
29 will always be enforced when using this flag, so "ota-wipe=yes" will also
30 be included in the metadata file. The update-binary in the source build
31 will be used in the OTA package, unless --binary flag is specified. Please
32 also check the comment for --override_timestamp below.
Tao Bao30df8b42018-04-23 15:32:53 -070033
34 -i (--incremental_from) <file>
35 Generate an incremental OTA using the given target-files zip as the
36 starting build.
37
38 -k (--package_key) <key>
39 Key to use to sign the package (default is the value of
40 default_system_dev_certificate from the input target-files's
Tao Bao59cf0c52019-06-25 10:04:24 -070041 META/misc_info.txt, or "build/make/target/product/security/testkey" if
42 that value is not specified).
Doug Zongkerafb32ea2011-09-22 10:28:04 -070043
44 For incremental OTAs, the default value is based on the source
45 target-file, not the target build.
Doug Zongkereef39442009-04-02 12:14:19 -070046
Tao Bao30df8b42018-04-23 15:32:53 -070047 --override_timestamp
48 Intentionally generate an incremental OTA that updates from a newer build
Tao Baofaa8e0b2018-04-12 14:31:43 -070049 to an older one (based on timestamp comparison), by setting the downgrade
50 flag in the package metadata. This differs from --downgrade flag, as we
51 don't enforce a data wipe with this flag. Because we know for sure this is
52 NOT an actual downgrade case, but two builds happen to be cut in a reverse
53 order (e.g. from two branches). A legit use case is that we cut a new
54 build C (after having A and B), but want to enfore an update path of A ->
55 C -> B. Specifying --downgrade may not help since that would enforce a
56 data wipe for C -> B update.
57
58 We used to set a fake timestamp in the package metadata for this flow. But
59 now we consolidate the two cases (i.e. an actual downgrade, or a downgrade
60 based on timestamp) with the same "ota-downgrade=yes" flag, with the
61 difference being whether "ota-wipe=yes" is set.
Doug Zongkereef39442009-04-02 12:14:19 -070062
Tao Bao30df8b42018-04-23 15:32:53 -070063 --wipe_user_data
64 Generate an OTA package that will wipe the user data partition when
65 installed.
66
Yifan Hong50e79542018-11-08 17:44:12 -080067 --retrofit_dynamic_partitions
68 Generates an OTA package that updates a device to support dynamic
69 partitions (default False). This flag is implied when generating
70 an incremental OTA where the base build does not support dynamic
71 partitions but the target build does. For A/B, when this flag is set,
72 --skip_postinstall is implied.
73
xunchangabfa2652019-02-19 16:27:10 -080074 --skip_compatibility_check
Yifan Hong9276cf02019-08-21 16:37:04 -070075 Skip checking compatibility of the input target files package.
xunchangabfa2652019-02-19 16:27:10 -080076
xunchang1cfe2512019-02-19 14:14:48 -080077 --output_metadata_path
78 Write a copy of the metadata to a separate file. Therefore, users can
79 read the post build fingerprint without extracting the OTA package.
80
Yifan Hong65afc072020-04-17 10:08:10 -070081 --force_non_ab
82 This flag can only be set on an A/B device that also supports non-A/B
83 updates. Implies --two_step.
84 If set, generate that non-A/B update package.
85 If not set, generates A/B package for A/B device and non-A/B package for
86 non-A/B device.
87
Hongguang Chen49ab1b902020-10-19 14:15:43 -070088 -o (--oem_settings) <main_file[,additional_files...]>
89 Comma separated list of files used to specify the expected OEM-specific
90 properties on the OEM partition of the intended device. Multiple expected
91 values can be used by providing multiple files. Only the first dict will
92 be used to compute fingerprint, while the rest will be used to assert
93 OEM-specific properties.
94
Tao Bao30df8b42018-04-23 15:32:53 -070095Non-A/B OTA specific options
96
97 -b (--binary) <file>
98 Use the given binary as the update-binary in the output package, instead
99 of the binary in the build's target_files. Use for development only.
100
101 --block
102 Generate a block-based OTA for non-A/B device. We have deprecated the
103 support for file-based OTA since O. Block-based OTA will be used by
104 default for all non-A/B devices. Keeping this flag here to not break
105 existing callers.
106
107 -e (--extra_script) <file>
108 Insert the contents of file at the end of the update script.
Tao Bao43078aa2015-04-21 14:32:35 -0700109
leozwangaa6c1a12015-08-14 10:57:58 -0700110 --full_bootloader
111 Similar to --full_radio. When generating an incremental OTA, always
112 include a full copy of bootloader image.
113
Tao Bao30df8b42018-04-23 15:32:53 -0700114 --full_radio
115 When generating an incremental OTA, always include a full copy of radio
116 image. This option is only meaningful when -i is specified, because a full
117 radio is always included in a full OTA if applicable.
Michael Runge63f01de2014-10-28 19:24:19 -0700118
Tao Bao30df8b42018-04-23 15:32:53 -0700119 --log_diff <file>
120 Generate a log file that shows the differences in the source and target
121 builds for an incremental package. This option is only meaningful when -i
122 is specified.
123
Tao Bao8608cde2016-02-25 19:49:55 -0800124 --oem_no_mount
Tao Bao30df8b42018-04-23 15:32:53 -0700125 For devices with OEM-specific properties but without an OEM partition, do
126 not mount the OEM partition in the updater-script. This should be very
127 rarely used, since it's expected to have a dedicated OEM partition for
128 OEM-specific properties. Only meaningful when -o is specified.
Tao Bao8608cde2016-02-25 19:49:55 -0800129
Tao Bao30df8b42018-04-23 15:32:53 -0700130 --stash_threshold <float>
131 Specify the threshold that will be used to compute the maximum allowed
132 stash size (defaults to 0.8).
Doug Zongkerdbfaae52009-04-21 17:12:54 -0700133
Tao Bao30df8b42018-04-23 15:32:53 -0700134 -t (--worker_threads) <int>
135 Specify the number of worker-threads that will be used when generating
136 patches for incremental updates (defaults to 3).
Tao Bao3e6161a2017-02-28 11:48:48 -0800137
Tao Bao30df8b42018-04-23 15:32:53 -0700138 --verify
139 Verify the checksums of the updated system and vendor (if any) partitions.
140 Non-A/B incremental OTAs only.
Doug Zongker1c390a22009-05-14 19:06:36 -0700141
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800142 -2 (--two_step)
Tao Bao30df8b42018-04-23 15:32:53 -0700143 Generate a 'two-step' OTA package, where recovery is updated first, so
144 that any changes made to the system partition are done using the new
145 recovery (new kernel, etc.).
146
147A/B OTA specific options
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800148
Tianjie Xu1b079832019-08-28 12:19:23 -0700149 --disable_fec_computation
150 Disable the on device FEC data computation for incremental updates.
151
Tao Baof7140c02018-01-30 17:09:24 -0800152 --include_secondary
153 Additionally include the payload for secondary slot images (default:
154 False). Only meaningful when generating A/B OTAs.
155
156 By default, an A/B OTA package doesn't contain the images for the
157 secondary slot (e.g. system_other.img). Specifying this flag allows
158 generating a separate payload that will install secondary slot images.
159
160 Such a package needs to be applied in a two-stage manner, with a reboot
161 in-between. During the first stage, the updater applies the primary
162 payload only. Upon finishing, it reboots the device into the newly updated
163 slot. It then continues to install the secondary payload to the inactive
164 slot, but without switching the active slot at the end (needs the matching
165 support in update_engine, i.e. SWITCH_SLOT_ON_REBOOT flag).
166
167 Due to the special install procedure, the secondary payload will be always
168 generated as a full payload.
169
Tao Baodea0f8b2016-06-20 17:55:06 -0700170 --payload_signer <signer>
171 Specify the signer when signing the payload and metadata for A/B OTAs.
172 By default (i.e. without this flag), it calls 'openssl pkeyutl' to sign
173 with the package private key. If the private key cannot be accessed
174 directly, a payload signer that knows how to do that should be specified.
175 The signer will be supplied with "-inkey <path_to_key>",
176 "-in <input_file>" and "-out <output_file>" parameters.
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700177
178 --payload_signer_args <args>
179 Specify the arguments needed for payload signer.
Tao Bao15a146a2018-02-21 16:06:59 -0800180
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700181 --payload_signer_maximum_signature_size <signature_size>
182 The maximum signature size (in bytes) that would be generated by the given
183 payload signer. Only meaningful when custom payload signer is specified
184 via '--payload_signer'.
185 If the signer uses a RSA key, this should be the number of bytes to
186 represent the modulus. If it uses an EC key, this is the size of a
187 DER-encoded ECDSA signature.
188
xunchang376cc7c2019-04-08 23:04:58 -0700189 --payload_signer_key_size <key_size>
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700190 Deprecated. Use the '--payload_signer_maximum_signature_size' instead.
xunchang376cc7c2019-04-08 23:04:58 -0700191
Tianjied6867162020-05-10 14:30:13 -0700192 --boot_variable_file <path>
193 A file that contains the possible values of ro.boot.* properties. It's
194 used to calculate the possible runtime fingerprints when some
195 ro.product.* properties are overridden by the 'import' statement.
196 The file expects one property per line, and each line has the following
197 format: 'prop_name=value1,value2'. e.g. 'ro.boot.product.sku=std,pro'
198
Tao Bao15a146a2018-02-21 16:06:59 -0800199 --skip_postinstall
200 Skip the postinstall hooks when generating an A/B OTA package (default:
201 False). Note that this discards ALL the hooks, including non-optional
202 ones. Should only be used if caller knows it's safe to do so (e.g. all the
203 postinstall work is to dexopt apps and a data wipe will happen immediately
204 after). Only meaningful when generating A/B OTAs.
Yifan Hong38ab4d82020-06-18 15:19:56 -0700205
206 --partial "<PARTITION> [<PARTITION>[...]]"
207 Generate partial updates, overriding ab_partitions list with the given
208 list.
Hongguang Chen49ab1b902020-10-19 14:15:43 -0700209
210 --custom_image <custom_partition=custom_image>
211 Use the specified custom_image to update custom_partition when generating
212 an A/B OTA package. e.g. "--custom_image oem=oem.img --custom_image
213 cus=cus_test.img"
David Anderson45b42302021-03-11 12:58:32 -0800214
215 --disable_vabc
216 Disable Virtual A/B Compression, for builds that have compression enabled
217 by default.
Kelvin Zhang2a3e5b12021-05-04 18:20:34 -0400218
219 --vabc_downgrade
220 Don't disable Virtual A/B Compression for downgrading OTAs.
221 For VABC downgrades, we must finish merging before doing data wipe, and
222 since data wipe is required for downgrading OTA, this might cause long
223 wait time in recovery.
Kelvin Zhang1250bca2021-08-27 15:10:27 -0700224
225 --enable_vabc_xor
226 Enable the VABC xor feature. Will reduce space requirements for OTA
227
Tianjiee7ab38d2021-09-08 19:09:38 -0700228 --force_minor_version
229 Override the update_engine minor version for delta generation.
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -0700230
231 --compressor_types
232 A colon ':' separated list of compressors. Allowed values are bz2 and brotli.
Kelvin Zhang410bb382022-01-06 09:15:54 -0800233
234 --enable_zucchini
235 Whether to enable to zucchini feature. Will generate smaller OTA but uses more memory.
Doug Zongkereef39442009-04-02 12:14:19 -0700236"""
237
Tao Bao89fbb0f2017-01-10 10:47:58 -0800238from __future__ import print_function
239
Tao Bao32fcdab2018-10-12 10:30:39 -0700240import logging
Doug Zongkerfc44a512014-08-26 13:10:25 -0700241import multiprocessing
Kelvin Zhang65029a22020-11-03 10:07:51 -0500242import os
Tao Bao2dd1c482017-02-03 16:49:39 -0800243import os.path
Kelvin Zhang65029a22020-11-03 10:07:51 -0500244import re
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700245import shlex
Tao Bao15a146a2018-02-21 16:06:59 -0800246import shutil
Tao Bao85f16982018-03-08 16:28:33 -0800247import struct
Kelvin Zhang65029a22020-11-03 10:07:51 -0500248import subprocess
Tao Bao481bab82017-12-21 11:23:09 -0800249import sys
Doug Zongkereef39442009-04-02 12:14:19 -0700250import zipfile
251
Kelvin Zhang766eea72021-06-03 09:36:08 -0400252import care_map_pb2
Doug Zongkereef39442009-04-02 12:14:19 -0700253import common
Kelvin Zhang2e417382020-08-20 11:33:11 -0400254import ota_utils
Kelvin Zhang22c687c2021-01-21 10:51:57 -0500255from ota_utils import (UNZIP_PATTERN, FinalizeMetadata, GetPackageMetadata,
Kelvin Zhang25ab9982021-06-22 09:51:34 -0400256 PropertyFiles, SECURITY_PATCH_LEVEL_PROP_NAME, GetZipEntryOffset)
Kelvin Zhang26390482021-11-02 14:31:10 -0700257from common import IsSparseImage
Kelvin Zhang0876c412020-06-23 15:06:58 -0400258import target_files_diff
Kelvin Zhangcff4d762020-07-29 16:37:51 -0400259from check_target_files_vintf import CheckVintfIfTrebleEnabled
260from non_ab_ota import GenerateNonAbOtaPackage
Kelvin Zhang0876c412020-06-23 15:06:58 -0400261
Tao Bao481bab82017-12-21 11:23:09 -0800262if sys.hexversion < 0x02070000:
263 print("Python 2.7 or newer is required.", file=sys.stderr)
264 sys.exit(1)
265
Tao Bao32fcdab2018-10-12 10:30:39 -0700266logger = logging.getLogger(__name__)
Tao Bao481bab82017-12-21 11:23:09 -0800267
Kelvin Zhang2e417382020-08-20 11:33:11 -0400268OPTIONS = ota_utils.OPTIONS
Michael Runge63f01de2014-10-28 19:24:19 -0700269OPTIONS.verify = False
Doug Zongkereef39442009-04-02 12:14:19 -0700270OPTIONS.patch_threshold = 0.95
Doug Zongkerdbfaae52009-04-21 17:12:54 -0700271OPTIONS.wipe_user_data = False
Doug Zongker1c390a22009-05-14 19:06:36 -0700272OPTIONS.extra_script = None
Doug Zongkerfc44a512014-08-26 13:10:25 -0700273OPTIONS.worker_threads = multiprocessing.cpu_count() // 2
274if OPTIONS.worker_threads == 0:
275 OPTIONS.worker_threads = 1
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800276OPTIONS.two_step = False
Tao Baof7140c02018-01-30 17:09:24 -0800277OPTIONS.include_secondary = False
Tao Bao457cbf62017-03-06 09:56:01 -0800278OPTIONS.block_based = True
Doug Zongker25568482014-03-03 10:21:27 -0800279OPTIONS.updater_binary = None
Tianjie Xu9afb2212020-05-10 21:48:15 +0000280OPTIONS.oem_dicts = None
Michael Runge6e836112014-04-15 17:40:21 -0700281OPTIONS.oem_source = None
Tao Bao8608cde2016-02-25 19:49:55 -0800282OPTIONS.oem_no_mount = False
Tao Bao43078aa2015-04-21 14:32:35 -0700283OPTIONS.full_radio = False
leozwangaa6c1a12015-08-14 10:57:58 -0700284OPTIONS.full_bootloader = False
Tao Baod47d8e12015-05-21 14:09:49 -0700285# Stash size cannot exceed cache_size * threshold.
286OPTIONS.cache_size = None
287OPTIONS.stash_threshold = 0.8
Tao Baod62c6032015-11-30 09:40:20 -0800288OPTIONS.log_diff = None
Tao Baodea0f8b2016-06-20 17:55:06 -0700289OPTIONS.payload_signer = None
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700290OPTIONS.payload_signer_args = []
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700291OPTIONS.payload_signer_maximum_signature_size = None
Tao Bao5f8ff932017-03-21 22:35:00 -0700292OPTIONS.extracted_input = None
Tao Bao15a146a2018-02-21 16:06:59 -0800293OPTIONS.skip_postinstall = False
xunchangabfa2652019-02-19 16:27:10 -0800294OPTIONS.skip_compatibility_check = False
Tianjie Xu1b079832019-08-28 12:19:23 -0700295OPTIONS.disable_fec_computation = False
Kelvin Zhangcaf7bbc2020-11-20 14:09:42 -0500296OPTIONS.disable_verity_computation = False
Yifan Hong38ab4d82020-06-18 15:19:56 -0700297OPTIONS.partial = None
Hongguang Chen49ab1b902020-10-19 14:15:43 -0700298OPTIONS.custom_images = {}
Kelvin Zhangbbfa1822021-02-03 17:19:44 -0500299OPTIONS.disable_vabc = False
Kelvin Zhang80ff4662021-02-08 19:57:57 -0500300OPTIONS.spl_downgrade = False
Kelvin Zhang2a3e5b12021-05-04 18:20:34 -0400301OPTIONS.vabc_downgrade = False
Kelvin Zhang1250bca2021-08-27 15:10:27 -0700302OPTIONS.enable_vabc_xor = True
Tianjiee7ab38d2021-09-08 19:09:38 -0700303OPTIONS.force_minor_version = None
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -0700304OPTIONS.compressor_types = None
Kelvin Zhang410bb382022-01-06 09:15:54 -0800305OPTIONS.enable_zucchini = None
Tao Bao8dcf7382015-05-21 14:09:49 -0700306
Tao Bao15a146a2018-02-21 16:06:59 -0800307POSTINSTALL_CONFIG = 'META/postinstall_config.txt'
Yifan Hong50e79542018-11-08 17:44:12 -0800308DYNAMIC_PARTITION_INFO = 'META/dynamic_partitions_info.txt'
Yifan Hongb433eba2019-03-06 12:42:53 -0800309AB_PARTITIONS = 'META/ab_partitions.txt'
Kelvin Zhangcff4d762020-07-29 16:37:51 -0400310
Tao Baof0c4aa22018-04-30 20:29:30 -0700311# Files to be unzipped for target diffing purpose.
312TARGET_DIFFING_UNZIP_PATTERN = ['BOOT', 'RECOVERY', 'SYSTEM/*', 'VENDOR/*',
Yifan Hongcfb917a2020-05-07 14:58:20 -0700313 'PRODUCT/*', 'SYSTEM_EXT/*', 'ODM/*',
Yifan Hongf496f1b2020-07-15 16:52:59 -0700314 'VENDOR_DLKM/*', 'ODM_DLKM/*']
Yifan Hongb433eba2019-03-06 12:42:53 -0800315RETROFIT_DAP_UNZIP_PATTERN = ['OTA/super_*.img', AB_PARTITIONS]
Tao Bao3e759462019-09-17 22:43:11 -0700316
317# Images to be excluded from secondary payload. We essentially only keep
318# 'system_other' and bootloader partitions.
319SECONDARY_PAYLOAD_SKIPPED_IMAGES = [
Yifan Hongc08cbf02020-09-15 19:07:39 +0000320 'boot', 'dtbo', 'modem', 'odm', 'odm_dlkm', 'product', 'radio', 'recovery',
Tianjiec3850642020-05-13 14:47:31 -0700321 'system_ext', 'vbmeta', 'vbmeta_system', 'vbmeta_vendor', 'vendor',
Yifan Hongf496f1b2020-07-15 16:52:59 -0700322 'vendor_boot']
Tao Bao6b0b2f92017-03-05 11:38:11 -0800323
Kelvin Zhang05ff7052021-02-10 09:13:26 -0500324
Tao Baofabe0832018-01-17 15:52:28 -0800325class PayloadSigner(object):
326 """A class that wraps the payload signing works.
327
328 When generating a Payload, hashes of the payload and metadata files will be
329 signed with the device key, either by calling an external payload signer or
330 by calling openssl with the package key. This class provides a unified
331 interface, so that callers can just call PayloadSigner.Sign().
332
333 If an external payload signer has been specified (OPTIONS.payload_signer), it
334 calls the signer with the provided args (OPTIONS.payload_signer_args). Note
335 that the signing key should be provided as part of the payload_signer_args.
336 Otherwise without an external signer, it uses the package key
337 (OPTIONS.package_key) and calls openssl for the signing works.
338 """
339
340 def __init__(self):
341 if OPTIONS.payload_signer is None:
342 # Prepare the payload signing key.
343 private_key = OPTIONS.package_key + OPTIONS.private_key_suffix
344 pw = OPTIONS.key_passwords[OPTIONS.package_key]
345
346 cmd = ["openssl", "pkcs8", "-in", private_key, "-inform", "DER"]
347 cmd.extend(["-passin", "pass:" + pw] if pw else ["-nocrypt"])
348 signing_key = common.MakeTempFile(prefix="key-", suffix=".key")
349 cmd.extend(["-out", signing_key])
Tao Baobec89c12018-10-15 11:53:28 -0700350 common.RunAndCheckOutput(cmd, verbose=False)
Tao Baofabe0832018-01-17 15:52:28 -0800351
352 self.signer = "openssl"
353 self.signer_args = ["pkeyutl", "-sign", "-inkey", signing_key,
354 "-pkeyopt", "digest:sha256"]
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700355 self.maximum_signature_size = self._GetMaximumSignatureSizeInBytes(
356 signing_key)
Tao Baofabe0832018-01-17 15:52:28 -0800357 else:
358 self.signer = OPTIONS.payload_signer
359 self.signer_args = OPTIONS.payload_signer_args
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700360 if OPTIONS.payload_signer_maximum_signature_size:
361 self.maximum_signature_size = int(
362 OPTIONS.payload_signer_maximum_signature_size)
xunchang376cc7c2019-04-08 23:04:58 -0700363 else:
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700364 # The legacy config uses RSA2048 keys.
365 logger.warning("The maximum signature size for payload signer is not"
366 " set, default to 256 bytes.")
367 self.maximum_signature_size = 256
xunchang376cc7c2019-04-08 23:04:58 -0700368
369 @staticmethod
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700370 def _GetMaximumSignatureSizeInBytes(signing_key):
371 out_signature_size_file = common.MakeTempFile("signature_size")
372 cmd = ["delta_generator", "--out_maximum_signature_size_file={}".format(
373 out_signature_size_file), "--private_key={}".format(signing_key)]
374 common.RunAndCheckOutput(cmd)
375 with open(out_signature_size_file) as f:
376 signature_size = f.read().rstrip()
Luca Stefani88e1a142020-03-27 14:05:12 +0100377 logger.info("%s outputs the maximum signature size: %s", cmd[0],
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700378 signature_size)
379 return int(signature_size)
Tao Baofabe0832018-01-17 15:52:28 -0800380
381 def Sign(self, in_file):
382 """Signs the given input file. Returns the output filename."""
383 out_file = common.MakeTempFile(prefix="signed-", suffix=".bin")
384 cmd = [self.signer] + self.signer_args + ['-in', in_file, '-out', out_file]
Tao Bao718faed2019-08-02 13:24:19 -0700385 common.RunAndCheckOutput(cmd)
Tao Baofabe0832018-01-17 15:52:28 -0800386 return out_file
387
388
Tao Bao40b18822018-01-30 18:19:04 -0800389class Payload(object):
390 """Manages the creation and the signing of an A/B OTA Payload."""
391
392 PAYLOAD_BIN = 'payload.bin'
393 PAYLOAD_PROPERTIES_TXT = 'payload_properties.txt'
Tao Baof7140c02018-01-30 17:09:24 -0800394 SECONDARY_PAYLOAD_BIN = 'secondary/payload.bin'
395 SECONDARY_PAYLOAD_PROPERTIES_TXT = 'secondary/payload_properties.txt'
Tao Bao40b18822018-01-30 18:19:04 -0800396
Tao Bao667ff572018-02-10 00:02:40 -0800397 def __init__(self, secondary=False):
398 """Initializes a Payload instance.
399
400 Args:
401 secondary: Whether it's generating a secondary payload (default: False).
402 """
Tao Bao40b18822018-01-30 18:19:04 -0800403 self.payload_file = None
404 self.payload_properties = None
Tao Bao667ff572018-02-10 00:02:40 -0800405 self.secondary = secondary
Tao Bao40b18822018-01-30 18:19:04 -0800406
Tao Baof0c4aa22018-04-30 20:29:30 -0700407 def _Run(self, cmd): # pylint: disable=no-self-use
Tao Bao718faed2019-08-02 13:24:19 -0700408 # Don't pipe (buffer) the output if verbose is set. Let
409 # brillo_update_payload write to stdout/stderr directly, so its progress can
410 # be monitored.
411 if OPTIONS.verbose:
412 common.RunAndCheckOutput(cmd, stdout=None, stderr=None)
413 else:
414 common.RunAndCheckOutput(cmd)
415
Tao Bao40b18822018-01-30 18:19:04 -0800416 def Generate(self, target_file, source_file=None, additional_args=None):
417 """Generates a payload from the given target-files zip(s).
418
419 Args:
420 target_file: The filename of the target build target-files zip.
421 source_file: The filename of the source build target-files zip; or None if
422 generating a full OTA.
423 additional_args: A list of additional args that should be passed to
424 brillo_update_payload script; or None.
425 """
426 if additional_args is None:
427 additional_args = []
428
429 payload_file = common.MakeTempFile(prefix="payload-", suffix=".bin")
430 cmd = ["brillo_update_payload", "generate",
431 "--payload", payload_file,
432 "--target_image", target_file]
433 if source_file is not None:
434 cmd.extend(["--source_image", source_file])
Tianjie Xu1b079832019-08-28 12:19:23 -0700435 if OPTIONS.disable_fec_computation:
436 cmd.extend(["--disable_fec_computation", "true"])
Kelvin Zhangcaf7bbc2020-11-20 14:09:42 -0500437 if OPTIONS.disable_verity_computation:
438 cmd.extend(["--disable_verity_computation", "true"])
Tao Bao40b18822018-01-30 18:19:04 -0800439 cmd.extend(additional_args)
Tao Bao718faed2019-08-02 13:24:19 -0700440 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800441
442 self.payload_file = payload_file
443 self.payload_properties = None
444
445 def Sign(self, payload_signer):
446 """Generates and signs the hashes of the payload and metadata.
447
448 Args:
449 payload_signer: A PayloadSigner() instance that serves the signing work.
450
451 Raises:
452 AssertionError: On any failure when calling brillo_update_payload script.
453 """
454 assert isinstance(payload_signer, PayloadSigner)
455
456 # 1. Generate hashes of the payload and metadata files.
457 payload_sig_file = common.MakeTempFile(prefix="sig-", suffix=".bin")
458 metadata_sig_file = common.MakeTempFile(prefix="sig-", suffix=".bin")
459 cmd = ["brillo_update_payload", "hash",
460 "--unsigned_payload", self.payload_file,
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700461 "--signature_size", str(payload_signer.maximum_signature_size),
Tao Bao40b18822018-01-30 18:19:04 -0800462 "--metadata_hash_file", metadata_sig_file,
463 "--payload_hash_file", payload_sig_file]
Tao Bao718faed2019-08-02 13:24:19 -0700464 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800465
466 # 2. Sign the hashes.
467 signed_payload_sig_file = payload_signer.Sign(payload_sig_file)
468 signed_metadata_sig_file = payload_signer.Sign(metadata_sig_file)
469
470 # 3. Insert the signatures back into the payload file.
471 signed_payload_file = common.MakeTempFile(prefix="signed-payload-",
472 suffix=".bin")
473 cmd = ["brillo_update_payload", "sign",
474 "--unsigned_payload", self.payload_file,
475 "--payload", signed_payload_file,
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700476 "--signature_size", str(payload_signer.maximum_signature_size),
Tao Bao40b18822018-01-30 18:19:04 -0800477 "--metadata_signature_file", signed_metadata_sig_file,
478 "--payload_signature_file", signed_payload_sig_file]
Tao Bao718faed2019-08-02 13:24:19 -0700479 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800480
481 # 4. Dump the signed payload properties.
482 properties_file = common.MakeTempFile(prefix="payload-properties-",
483 suffix=".txt")
484 cmd = ["brillo_update_payload", "properties",
485 "--payload", signed_payload_file,
486 "--properties_file", properties_file]
Tao Bao718faed2019-08-02 13:24:19 -0700487 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800488
Tao Bao667ff572018-02-10 00:02:40 -0800489 if self.secondary:
490 with open(properties_file, "a") as f:
491 f.write("SWITCH_SLOT_ON_REBOOT=0\n")
492
Tao Bao40b18822018-01-30 18:19:04 -0800493 if OPTIONS.wipe_user_data:
494 with open(properties_file, "a") as f:
495 f.write("POWERWASH=1\n")
496
497 self.payload_file = signed_payload_file
498 self.payload_properties = properties_file
499
Tao Bao667ff572018-02-10 00:02:40 -0800500 def WriteToZip(self, output_zip):
Tao Bao40b18822018-01-30 18:19:04 -0800501 """Writes the payload to the given zip.
502
503 Args:
504 output_zip: The output ZipFile instance.
505 """
506 assert self.payload_file is not None
507 assert self.payload_properties is not None
508
Tao Bao667ff572018-02-10 00:02:40 -0800509 if self.secondary:
Tao Baof7140c02018-01-30 17:09:24 -0800510 payload_arcname = Payload.SECONDARY_PAYLOAD_BIN
511 payload_properties_arcname = Payload.SECONDARY_PAYLOAD_PROPERTIES_TXT
512 else:
513 payload_arcname = Payload.PAYLOAD_BIN
514 payload_properties_arcname = Payload.PAYLOAD_PROPERTIES_TXT
515
Tao Bao40b18822018-01-30 18:19:04 -0800516 # Add the signed payload file and properties into the zip. In order to
517 # support streaming, we pack them as ZIP_STORED. So these entries can be
518 # read directly with the offset and length pairs.
Tao Baof7140c02018-01-30 17:09:24 -0800519 common.ZipWrite(output_zip, self.payload_file, arcname=payload_arcname,
Tao Bao40b18822018-01-30 18:19:04 -0800520 compress_type=zipfile.ZIP_STORED)
521 common.ZipWrite(output_zip, self.payload_properties,
Tao Baof7140c02018-01-30 17:09:24 -0800522 arcname=payload_properties_arcname,
Tao Bao40b18822018-01-30 18:19:04 -0800523 compress_type=zipfile.ZIP_STORED)
524
525
Tao Bao481bab82017-12-21 11:23:09 -0800526def _LoadOemDicts(oem_source):
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800527 """Returns the list of loaded OEM properties dict."""
Tao Bao481bab82017-12-21 11:23:09 -0800528 if not oem_source:
529 return None
530
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800531 oem_dicts = []
Tao Bao481bab82017-12-21 11:23:09 -0800532 for oem_file in oem_source:
533 with open(oem_file) as fp:
534 oem_dicts.append(common.LoadDictionaryFromLines(fp.readlines()))
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800535 return oem_dicts
Doug Zongkereef39442009-04-02 12:14:19 -0700536
Doug Zongkereef39442009-04-02 12:14:19 -0700537
Tao Baod3fc38a2018-03-08 16:09:01 -0800538class StreamingPropertyFiles(PropertyFiles):
539 """A subclass for computing the property-files for streaming A/B OTAs."""
540
541 def __init__(self):
542 super(StreamingPropertyFiles, self).__init__()
543 self.name = 'ota-streaming-property-files'
544 self.required = (
545 # payload.bin and payload_properties.txt must exist.
546 'payload.bin',
547 'payload_properties.txt',
548 )
549 self.optional = (
Tianjied868c122021-06-07 16:11:47 -0700550 # apex_info.pb isn't directly used in the update flow
551 'apex_info.pb',
Tianjie Xu4c05f4a2018-09-14 16:24:41 -0700552 # care_map is available only if dm-verity is enabled.
553 'care_map.pb',
Tao Baod3fc38a2018-03-08 16:09:01 -0800554 'care_map.txt',
555 # compatibility.zip is available only if target supports Treble.
556 'compatibility.zip',
557 )
558
559
Tao Bao85f16982018-03-08 16:28:33 -0800560class AbOtaPropertyFiles(StreamingPropertyFiles):
561 """The property-files for A/B OTA that includes payload_metadata.bin info.
562
563 Since P, we expose one more token (aka property-file), in addition to the ones
564 for streaming A/B OTA, for a virtual entry of 'payload_metadata.bin'.
565 'payload_metadata.bin' is the header part of a payload ('payload.bin'), which
566 doesn't exist as a separate ZIP entry, but can be used to verify if the
567 payload can be applied on the given device.
568
569 For backward compatibility, we keep both of the 'ota-streaming-property-files'
570 and the newly added 'ota-property-files' in P. The new token will only be
571 available in 'ota-property-files'.
572 """
573
574 def __init__(self):
575 super(AbOtaPropertyFiles, self).__init__()
576 self.name = 'ota-property-files'
577
578 def _GetPrecomputed(self, input_zip):
579 offset, size = self._GetPayloadMetadataOffsetAndSize(input_zip)
580 return ['payload_metadata.bin:{}:{}'.format(offset, size)]
581
582 @staticmethod
583 def _GetPayloadMetadataOffsetAndSize(input_zip):
584 """Computes the offset and size of the payload metadata for a given package.
585
586 (From system/update_engine/update_metadata.proto)
587 A delta update file contains all the deltas needed to update a system from
588 one specific version to another specific version. The update format is
589 represented by this struct pseudocode:
590
591 struct delta_update_file {
592 char magic[4] = "CrAU";
593 uint64 file_format_version;
594 uint64 manifest_size; // Size of protobuf DeltaArchiveManifest
595
596 // Only present if format_version > 1:
597 uint32 metadata_signature_size;
598
599 // The Bzip2 compressed DeltaArchiveManifest
600 char manifest[metadata_signature_size];
601
602 // The signature of the metadata (from the beginning of the payload up to
603 // this location, not including the signature itself). This is a
604 // serialized Signatures message.
605 char medatada_signature_message[metadata_signature_size];
606
607 // Data blobs for files, no specific format. The specific offset
608 // and length of each data blob is recorded in the DeltaArchiveManifest.
609 struct {
610 char data[];
611 } blobs[];
612
613 // These two are not signed:
614 uint64 payload_signatures_message_size;
615 char payload_signatures_message[];
616 };
617
618 'payload-metadata.bin' contains all the bytes from the beginning of the
619 payload, till the end of 'medatada_signature_message'.
620 """
621 payload_info = input_zip.getinfo('payload.bin')
Kelvin Zhang25ab9982021-06-22 09:51:34 -0400622 (payload_offset, payload_size) = GetZipEntryOffset(input_zip, payload_info)
Tao Bao85f16982018-03-08 16:28:33 -0800623
Kelvin Zhang25ab9982021-06-22 09:51:34 -0400624 # Read the underlying raw zipfile at specified offset
625 payload_fp = input_zip.fp
626 payload_fp.seek(payload_offset)
627 header_bin = payload_fp.read(24)
Tao Bao85f16982018-03-08 16:28:33 -0800628
629 # network byte order (big-endian)
630 header = struct.unpack("!IQQL", header_bin)
631
632 # 'CrAU'
633 magic = header[0]
Kelvin Zhang25ab9982021-06-22 09:51:34 -0400634 assert magic == 0x43724155, "Invalid magic: {:x}, computed offset {}" \
635 .format(magic, payload_offset)
Tao Bao85f16982018-03-08 16:28:33 -0800636
637 manifest_size = header[2]
638 metadata_signature_size = header[3]
639 metadata_total = 24 + manifest_size + metadata_signature_size
640 assert metadata_total < payload_size
641
642 return (payload_offset, metadata_total)
643
644
Yifan Hong38ab4d82020-06-18 15:19:56 -0700645def UpdatesInfoForSpecialUpdates(content, partitions_filter,
646 delete_keys=None):
647 """ Updates info file for secondary payload generation, partial update, etc.
648
649 Scan each line in the info file, and remove the unwanted partitions from
650 the dynamic partition list in the related properties. e.g.
651 "super_google_dynamic_partitions_partition_list=system vendor product"
652 will become "super_google_dynamic_partitions_partition_list=system".
653
654 Args:
655 content: The content of the input info file. e.g. misc_info.txt.
656 partitions_filter: A function to filter the desired partitions from a given
657 list
658 delete_keys: A list of keys to delete in the info file
659
660 Returns:
661 A string of the updated info content.
662 """
663
664 output_list = []
665 # The suffix in partition_list variables that follows the name of the
666 # partition group.
667 list_suffix = 'partition_list'
668 for line in content.splitlines():
669 if line.startswith('#') or '=' not in line:
670 output_list.append(line)
671 continue
672 key, value = line.strip().split('=', 1)
673
674 if delete_keys and key in delete_keys:
675 pass
676 elif key.endswith(list_suffix):
677 partitions = value.split()
678 # TODO for partial update, partitions in the same group must be all
679 # updated or all omitted
680 partitions = filter(partitions_filter, partitions)
681 output_list.append('{}={}'.format(key, ' '.join(partitions)))
682 else:
683 output_list.append(line)
684 return '\n'.join(output_list)
685
686
Tao Bao15a146a2018-02-21 16:06:59 -0800687def GetTargetFilesZipForSecondaryImages(input_file, skip_postinstall=False):
Tao Baof7140c02018-01-30 17:09:24 -0800688 """Returns a target-files.zip file for generating secondary payload.
689
690 Although the original target-files.zip already contains secondary slot
691 images (i.e. IMAGES/system_other.img), we need to rename the files to the
692 ones without _other suffix. Note that we cannot instead modify the names in
693 META/ab_partitions.txt, because there are no matching partitions on device.
694
695 For the partitions that don't have secondary images, the ones for primary
696 slot will be used. This is to ensure that we always have valid boot, vbmeta,
697 bootloader images in the inactive slot.
698
699 Args:
700 input_file: The input target-files.zip file.
Tao Bao15a146a2018-02-21 16:06:59 -0800701 skip_postinstall: Whether to skip copying the postinstall config file.
Tao Baof7140c02018-01-30 17:09:24 -0800702
703 Returns:
704 The filename of the target-files.zip for generating secondary payload.
705 """
Tianjie Xu1c808002019-09-11 00:29:26 -0700706
707 def GetInfoForSecondaryImages(info_file):
Yifan Hong38ab4d82020-06-18 15:19:56 -0700708 """Updates info file for secondary payload generation."""
Tianjie Xu1c808002019-09-11 00:29:26 -0700709 with open(info_file) as f:
Yifan Hong38ab4d82020-06-18 15:19:56 -0700710 content = f.read()
711 # Remove virtual_ab flag from secondary payload so that OTA client
712 # don't use snapshots for secondary update
713 delete_keys = ['virtual_ab', "virtual_ab_retrofit"]
714 return UpdatesInfoForSpecialUpdates(
715 content, lambda p: p not in SECONDARY_PAYLOAD_SKIPPED_IMAGES,
716 delete_keys)
Tianjie Xu1c808002019-09-11 00:29:26 -0700717
Tao Baof7140c02018-01-30 17:09:24 -0800718 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
719 target_zip = zipfile.ZipFile(target_file, 'w', allowZip64=True)
720
Kelvin Zhang928c2342020-09-22 16:15:57 -0400721 with zipfile.ZipFile(input_file, 'r', allowZip64=True) as input_zip:
Tao Baodba59ee2018-01-09 13:21:02 -0800722 infolist = input_zip.infolist()
Tao Bao12489802018-07-12 14:47:38 -0700723
Tao Bao0ff15de2019-03-20 11:26:06 -0700724 input_tmp = common.UnzipTemp(input_file, UNZIP_PATTERN)
Tao Baodba59ee2018-01-09 13:21:02 -0800725 for info in infolist:
Tao Baof7140c02018-01-30 17:09:24 -0800726 unzipped_file = os.path.join(input_tmp, *info.filename.split('/'))
727 if info.filename == 'IMAGES/system_other.img':
728 common.ZipWrite(target_zip, unzipped_file, arcname='IMAGES/system.img')
729
730 # Primary images and friends need to be skipped explicitly.
731 elif info.filename in ('IMAGES/system.img',
732 'IMAGES/system.map'):
733 pass
Tao Bao3e759462019-09-17 22:43:11 -0700734
735 # Copy images that are not in SECONDARY_PAYLOAD_SKIPPED_IMAGES.
736 elif info.filename.startswith(('IMAGES/', 'RADIO/')):
737 image_name = os.path.basename(info.filename)
738 if image_name not in ['{}.img'.format(partition) for partition in
739 SECONDARY_PAYLOAD_SKIPPED_IMAGES]:
740 common.ZipWrite(target_zip, unzipped_file, arcname=info.filename)
Tao Baof7140c02018-01-30 17:09:24 -0800741
Tao Bao15a146a2018-02-21 16:06:59 -0800742 # Skip copying the postinstall config if requested.
743 elif skip_postinstall and info.filename == POSTINSTALL_CONFIG:
744 pass
745
Tianjie Xu1c808002019-09-11 00:29:26 -0700746 elif info.filename.startswith('META/'):
747 # Remove the unnecessary partitions for secondary images from the
748 # ab_partitions file.
749 if info.filename == AB_PARTITIONS:
750 with open(unzipped_file) as f:
751 partition_list = f.read().splitlines()
752 partition_list = [partition for partition in partition_list if partition
Tao Bao3e759462019-09-17 22:43:11 -0700753 and partition not in SECONDARY_PAYLOAD_SKIPPED_IMAGES]
Kelvin Zhang0876c412020-06-23 15:06:58 -0400754 common.ZipWriteStr(target_zip, info.filename,
755 '\n'.join(partition_list))
Tianjie Xu1c808002019-09-11 00:29:26 -0700756 # Remove the unnecessary partitions from the dynamic partitions list.
757 elif (info.filename == 'META/misc_info.txt' or
758 info.filename == DYNAMIC_PARTITION_INFO):
759 modified_info = GetInfoForSecondaryImages(unzipped_file)
760 common.ZipWriteStr(target_zip, info.filename, modified_info)
761 else:
762 common.ZipWrite(target_zip, unzipped_file, arcname=info.filename)
Tao Baof7140c02018-01-30 17:09:24 -0800763
Tao Baof7140c02018-01-30 17:09:24 -0800764 common.ZipClose(target_zip)
765
766 return target_file
767
768
Tao Bao15a146a2018-02-21 16:06:59 -0800769def GetTargetFilesZipWithoutPostinstallConfig(input_file):
770 """Returns a target-files.zip that's not containing postinstall_config.txt.
771
772 This allows brillo_update_payload script to skip writing all the postinstall
773 hooks in the generated payload. The input target-files.zip file will be
774 duplicated, with 'META/postinstall_config.txt' skipped. If input_file doesn't
775 contain the postinstall_config.txt entry, the input file will be returned.
776
777 Args:
778 input_file: The input target-files.zip filename.
779
780 Returns:
781 The filename of target-files.zip that doesn't contain postinstall config.
782 """
783 # We should only make a copy if postinstall_config entry exists.
Kelvin Zhang928c2342020-09-22 16:15:57 -0400784 with zipfile.ZipFile(input_file, 'r', allowZip64=True) as input_zip:
Tao Bao15a146a2018-02-21 16:06:59 -0800785 if POSTINSTALL_CONFIG not in input_zip.namelist():
786 return input_file
787
788 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
789 shutil.copyfile(input_file, target_file)
790 common.ZipDelete(target_file, POSTINSTALL_CONFIG)
791 return target_file
792
Kelvin Zhang06400172021-03-05 15:42:03 -0500793
Kelvin Zhanga59bb272020-10-30 12:52:25 -0400794def ParseInfoDict(target_file_path):
795 with zipfile.ZipFile(target_file_path, 'r', allowZip64=True) as zfp:
796 return common.LoadInfoDict(zfp)
Tao Bao15a146a2018-02-21 16:06:59 -0800797
Kelvin Zhang06400172021-03-05 15:42:03 -0500798
Yifan Hong38ab4d82020-06-18 15:19:56 -0700799def GetTargetFilesZipForPartialUpdates(input_file, ab_partitions):
800 """Returns a target-files.zip for partial ota update package generation.
801
802 This function modifies ab_partitions list with the desired partitions before
803 calling the brillo_update_payload script. It also cleans up the reference to
804 the excluded partitions in the info file, e.g misc_info.txt.
805
806 Args:
807 input_file: The input target-files.zip filename.
808 ab_partitions: A list of partitions to include in the partial update
809
810 Returns:
811 The filename of target-files.zip used for partial ota update.
812 """
813
814 def AddImageForPartition(partition_name):
815 """Add the archive name for a given partition to the copy list."""
816 for prefix in ['IMAGES', 'RADIO']:
817 image_path = '{}/{}.img'.format(prefix, partition_name)
818 if image_path in namelist:
819 copy_entries.append(image_path)
820 map_path = '{}/{}.map'.format(prefix, partition_name)
821 if map_path in namelist:
822 copy_entries.append(map_path)
823 return
824
825 raise ValueError("Cannot find {} in input zipfile".format(partition_name))
826
827 with zipfile.ZipFile(input_file, allowZip64=True) as input_zip:
Kelvin Zhanga59bb272020-10-30 12:52:25 -0400828 original_ab_partitions = input_zip.read(
829 AB_PARTITIONS).decode().splitlines()
Yifan Hong38ab4d82020-06-18 15:19:56 -0700830 namelist = input_zip.namelist()
831
832 unrecognized_partitions = [partition for partition in ab_partitions if
833 partition not in original_ab_partitions]
834 if unrecognized_partitions:
835 raise ValueError("Unrecognized partitions when generating partial updates",
836 unrecognized_partitions)
837
838 logger.info("Generating partial updates for %s", ab_partitions)
839
840 copy_entries = ['META/update_engine_config.txt']
841 for partition_name in ab_partitions:
842 AddImageForPartition(partition_name)
843
844 # Use zip2zip to avoid extracting the zipfile.
845 partial_target_file = common.MakeTempFile(suffix='.zip')
846 cmd = ['zip2zip', '-i', input_file, '-o', partial_target_file]
847 cmd.extend(['{}:{}'.format(name, name) for name in copy_entries])
848 common.RunAndCheckOutput(cmd)
849
850 partial_target_zip = zipfile.ZipFile(partial_target_file, 'a',
851 allowZip64=True)
852 with zipfile.ZipFile(input_file, allowZip64=True) as input_zip:
853 common.ZipWriteStr(partial_target_zip, 'META/ab_partitions.txt',
854 '\n'.join(ab_partitions))
Kelvin Zhang766eea72021-06-03 09:36:08 -0400855 CARE_MAP_ENTRY = "META/care_map.pb"
856 if CARE_MAP_ENTRY in input_zip.namelist():
857 caremap = care_map_pb2.CareMap()
858 caremap.ParseFromString(input_zip.read(CARE_MAP_ENTRY))
859 filtered = [
860 part for part in caremap.partitions if part.name in ab_partitions]
861 del caremap.partitions[:]
862 caremap.partitions.extend(filtered)
863 common.ZipWriteStr(partial_target_zip, CARE_MAP_ENTRY,
864 caremap.SerializeToString())
865
Yifan Hong38ab4d82020-06-18 15:19:56 -0700866 for info_file in ['META/misc_info.txt', DYNAMIC_PARTITION_INFO]:
867 if info_file not in input_zip.namelist():
868 logger.warning('Cannot find %s in input zipfile', info_file)
869 continue
870 content = input_zip.read(info_file).decode()
871 modified_info = UpdatesInfoForSpecialUpdates(
872 content, lambda p: p in ab_partitions)
873 common.ZipWriteStr(partial_target_zip, info_file, modified_info)
874
Kelvin Zhang766eea72021-06-03 09:36:08 -0400875 # TODO(xunchang) handle META/postinstall_config.txt'
876
Yifan Hong38ab4d82020-06-18 15:19:56 -0700877 common.ZipClose(partial_target_zip)
878
879 return partial_target_file
880
881
Yifan Hong50e79542018-11-08 17:44:12 -0800882def GetTargetFilesZipForRetrofitDynamicPartitions(input_file,
Yifan Hongb433eba2019-03-06 12:42:53 -0800883 super_block_devices,
884 dynamic_partition_list):
Yifan Hong50e79542018-11-08 17:44:12 -0800885 """Returns a target-files.zip for retrofitting dynamic partitions.
886
887 This allows brillo_update_payload to generate an OTA based on the exact
888 bits on the block devices. Postinstall is disabled.
889
890 Args:
891 input_file: The input target-files.zip filename.
892 super_block_devices: The list of super block devices
Yifan Hongb433eba2019-03-06 12:42:53 -0800893 dynamic_partition_list: The list of dynamic partitions
Yifan Hong50e79542018-11-08 17:44:12 -0800894
895 Returns:
896 The filename of target-files.zip with *.img replaced with super_*.img for
897 each block device in super_block_devices.
898 """
899 assert super_block_devices, "No super_block_devices are specified."
900
901 replace = {'OTA/super_{}.img'.format(dev): 'IMAGES/{}.img'.format(dev)
Tao Bao03fecb62018-11-28 10:59:23 -0800902 for dev in super_block_devices}
Yifan Hong50e79542018-11-08 17:44:12 -0800903
904 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
905 shutil.copyfile(input_file, target_file)
906
Kelvin Zhang928c2342020-09-22 16:15:57 -0400907 with zipfile.ZipFile(input_file, allowZip64=True) as input_zip:
Yifan Hong50e79542018-11-08 17:44:12 -0800908 namelist = input_zip.namelist()
909
Yifan Hongb433eba2019-03-06 12:42:53 -0800910 input_tmp = common.UnzipTemp(input_file, RETROFIT_DAP_UNZIP_PATTERN)
911
912 # Remove partitions from META/ab_partitions.txt that is in
913 # dynamic_partition_list but not in super_block_devices so that
914 # brillo_update_payload won't generate update for those logical partitions.
915 ab_partitions_file = os.path.join(input_tmp, *AB_PARTITIONS.split('/'))
916 with open(ab_partitions_file) as f:
917 ab_partitions_lines = f.readlines()
918 ab_partitions = [line.strip() for line in ab_partitions_lines]
919 # Assert that all super_block_devices are in ab_partitions
920 super_device_not_updated = [partition for partition in super_block_devices
921 if partition not in ab_partitions]
922 assert not super_device_not_updated, \
923 "{} is in super_block_devices but not in {}".format(
924 super_device_not_updated, AB_PARTITIONS)
925 # ab_partitions -= (dynamic_partition_list - super_block_devices)
Kelvin Zhang0876c412020-06-23 15:06:58 -0400926 new_ab_partitions = common.MakeTempFile(
927 prefix="ab_partitions", suffix=".txt")
Yifan Hongb433eba2019-03-06 12:42:53 -0800928 with open(new_ab_partitions, 'w') as f:
929 for partition in ab_partitions:
930 if (partition in dynamic_partition_list and
Kelvin Zhang06400172021-03-05 15:42:03 -0500931 partition not in super_block_devices):
Tao Bao59cf0c52019-06-25 10:04:24 -0700932 logger.info("Dropping %s from ab_partitions.txt", partition)
933 continue
Yifan Hongb433eba2019-03-06 12:42:53 -0800934 f.write(partition + "\n")
935 to_delete = [AB_PARTITIONS]
936
Yifan Hong50e79542018-11-08 17:44:12 -0800937 # Always skip postinstall for a retrofit update.
Yifan Hongb433eba2019-03-06 12:42:53 -0800938 to_delete += [POSTINSTALL_CONFIG]
Yifan Hong50e79542018-11-08 17:44:12 -0800939
940 # Delete dynamic_partitions_info.txt so that brillo_update_payload thinks this
941 # is a regular update on devices without dynamic partitions support.
942 to_delete += [DYNAMIC_PARTITION_INFO]
943
Tao Bao03fecb62018-11-28 10:59:23 -0800944 # Remove the existing partition images as well as the map files.
Tao Bao59cf0c52019-06-25 10:04:24 -0700945 to_delete += list(replace.values())
Tao Bao03fecb62018-11-28 10:59:23 -0800946 to_delete += ['IMAGES/{}.map'.format(dev) for dev in super_block_devices]
Yifan Hong50e79542018-11-08 17:44:12 -0800947
948 common.ZipDelete(target_file, to_delete)
949
Yifan Hong50e79542018-11-08 17:44:12 -0800950 target_zip = zipfile.ZipFile(target_file, 'a', allowZip64=True)
951
952 # Write super_{foo}.img as {foo}.img.
953 for src, dst in replace.items():
954 assert src in namelist, \
Tao Bao59cf0c52019-06-25 10:04:24 -0700955 'Missing {} in {}; {} cannot be written'.format(src, input_file, dst)
Yifan Hong50e79542018-11-08 17:44:12 -0800956 unzipped_file = os.path.join(input_tmp, *src.split('/'))
957 common.ZipWrite(target_zip, unzipped_file, arcname=dst)
958
Yifan Hongb433eba2019-03-06 12:42:53 -0800959 # Write new ab_partitions.txt file
960 common.ZipWrite(target_zip, new_ab_partitions, arcname=AB_PARTITIONS)
961
Yifan Hong50e79542018-11-08 17:44:12 -0800962 common.ZipClose(target_zip)
963
964 return target_file
965
Kelvin Zhanga59bb272020-10-30 12:52:25 -0400966
Hongguang Chen49ab1b902020-10-19 14:15:43 -0700967def GetTargetFilesZipForCustomImagesUpdates(input_file, custom_images):
968 """Returns a target-files.zip for custom partitions update.
969
970 This function modifies ab_partitions list with the desired custom partitions
971 and puts the custom images into the target target-files.zip.
972
973 Args:
974 input_file: The input target-files.zip filename.
975 custom_images: A map of custom partitions and custom images.
976
977 Returns:
978 The filename of a target-files.zip which has renamed the custom images in
979 the IMAGS/ to their partition names.
980 """
981 # Use zip2zip to avoid extracting the zipfile.
982 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
983 cmd = ['zip2zip', '-i', input_file, '-o', target_file]
984
985 with zipfile.ZipFile(input_file, allowZip64=True) as input_zip:
986 namelist = input_zip.namelist()
987
988 # Write {custom_image}.img as {custom_partition}.img.
989 for custom_partition, custom_image in custom_images.items():
990 default_custom_image = '{}.img'.format(custom_partition)
991 if default_custom_image != custom_image:
992 logger.info("Update custom partition '%s' with '%s'",
993 custom_partition, custom_image)
994 # Default custom image need to be deleted first.
995 namelist.remove('IMAGES/{}'.format(default_custom_image))
996 # IMAGES/{custom_image}.img:IMAGES/{custom_partition}.img.
997 cmd.extend(['IMAGES/{}:IMAGES/{}'.format(custom_image,
998 default_custom_image)])
999
1000 cmd.extend(['{}:{}'.format(name, name) for name in namelist])
1001 common.RunAndCheckOutput(cmd)
1002
1003 return target_file
Yifan Hong50e79542018-11-08 17:44:12 -08001004
Kelvin Zhang06400172021-03-05 15:42:03 -05001005
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001006def GeneratePartitionTimestampFlags(partition_state):
1007 partition_timestamps = [
1008 part.partition_name + ":" + part.version
1009 for part in partition_state]
1010 return ["--partition_timestamps", ",".join(partition_timestamps)]
1011
Kelvin Zhang06400172021-03-05 15:42:03 -05001012
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001013def GeneratePartitionTimestampFlagsDowngrade(
Kelvin Zhang06400172021-03-05 15:42:03 -05001014 pre_partition_state, post_partition_state):
Kelvin Zhang80195722020-11-04 14:38:34 -05001015 assert pre_partition_state is not None
1016 partition_timestamps = {}
1017 for part in pre_partition_state:
1018 partition_timestamps[part.partition_name] = part.version
1019 for part in post_partition_state:
1020 partition_timestamps[part.partition_name] = \
Kelvin Zhang06400172021-03-05 15:42:03 -05001021 max(part.version, partition_timestamps[part.partition_name])
Kelvin Zhang80195722020-11-04 14:38:34 -05001022 return [
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001023 "--partition_timestamps",
Kelvin Zhang06400172021-03-05 15:42:03 -05001024 ",".join([key + ":" + val for (key, val)
1025 in partition_timestamps.items()])
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001026 ]
Kelvin Zhang80195722020-11-04 14:38:34 -05001027
Kelvin Zhang06400172021-03-05 15:42:03 -05001028
Kelvin Zhang65029a22020-11-03 10:07:51 -05001029def SupportsMainlineGkiUpdates(target_file):
1030 """Return True if the build supports MainlineGKIUpdates.
1031
1032 This function scans the product.img file in IMAGES/ directory for
1033 pattern |*/apex/com.android.gki.*.apex|. If there are files
1034 matching this pattern, conclude that build supports mainline
1035 GKI and return True
1036
1037 Args:
1038 target_file: Path to a target_file.zip, or an extracted directory
1039 Return:
1040 True if thisb uild supports Mainline GKI Updates.
1041 """
1042 if target_file is None:
1043 return False
1044 if os.path.isfile(target_file):
1045 target_file = common.UnzipTemp(target_file, ["IMAGES/product.img"])
1046 if not os.path.isdir(target_file):
1047 assert os.path.isdir(target_file), \
1048 "{} must be a path to zip archive or dir containing extracted"\
1049 " target_files".format(target_file)
1050 image_file = os.path.join(target_file, "IMAGES", "product.img")
1051
1052 if not os.path.isfile(image_file):
1053 return False
1054
1055 if IsSparseImage(image_file):
1056 # Unsparse the image
1057 tmp_img = common.MakeTempFile(suffix=".img")
1058 subprocess.check_output(["simg2img", image_file, tmp_img])
1059 image_file = tmp_img
1060
1061 cmd = ["debugfs_static", "-R", "ls -p /apex", image_file]
1062 output = subprocess.check_output(cmd).decode()
1063
1064 pattern = re.compile(r"com\.android\.gki\..*\.apex")
1065 return pattern.search(output) is not None
1066
Kelvin Zhang06400172021-03-05 15:42:03 -05001067
Tao Baof0c4aa22018-04-30 20:29:30 -07001068def GenerateAbOtaPackage(target_file, output_file, source_file=None):
Tao Baofe5b69a2018-03-02 09:47:43 -08001069 """Generates an Android OTA package that has A/B update payload."""
Tao Baodea0f8b2016-06-20 17:55:06 -07001070 # Stage the output zip package for package signing.
Tao Bao491d7e22018-02-21 13:17:22 -08001071 if not OPTIONS.no_signing:
1072 staging_file = common.MakeTempFile(suffix='.zip')
1073 else:
1074 staging_file = output_file
Tao Baoa652c002018-03-01 19:31:38 -08001075 output_zip = zipfile.ZipFile(staging_file, "w",
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001076 compression=zipfile.ZIP_DEFLATED,
1077 allowZip64=True)
Tao Baoc098e9e2016-01-07 13:03:56 -08001078
Tao Bao481bab82017-12-21 11:23:09 -08001079 if source_file is not None:
Kelvin Zhang39aea442020-08-17 11:04:25 -04001080 assert "ab_partitions" in OPTIONS.source_info_dict, \
1081 "META/ab_partitions.txt is required for ab_update."
1082 assert "ab_partitions" in OPTIONS.target_info_dict, \
1083 "META/ab_partitions.txt is required for ab_update."
Tao Bao1c320f82019-10-04 23:25:12 -07001084 target_info = common.BuildInfo(OPTIONS.target_info_dict, OPTIONS.oem_dicts)
1085 source_info = common.BuildInfo(OPTIONS.source_info_dict, OPTIONS.oem_dicts)
Kelvin Zhang563750f2021-04-28 12:46:17 -04001086 # If source supports VABC, delta_generator/update_engine will attempt to
1087 # use VABC. This dangerous, as the target build won't have snapuserd to
1088 # serve I/O request when device boots. Therefore, disable VABC if source
1089 # build doesn't supports it.
1090 if not source_info.is_vabc or not target_info.is_vabc:
Kelvin Zhang10eac082021-06-10 14:32:19 -04001091 logger.info("Either source or target does not support VABC, disabling.")
Kelvin Zhang563750f2021-04-28 12:46:17 -04001092 OPTIONS.disable_vabc = True
Kelvin Zhang563750f2021-04-28 12:46:17 -04001093
Tao Bao481bab82017-12-21 11:23:09 -08001094 else:
Kelvin Zhang39aea442020-08-17 11:04:25 -04001095 assert "ab_partitions" in OPTIONS.info_dict, \
1096 "META/ab_partitions.txt is required for ab_update."
Tao Bao1c320f82019-10-04 23:25:12 -07001097 target_info = common.BuildInfo(OPTIONS.info_dict, OPTIONS.oem_dicts)
Tao Bao481bab82017-12-21 11:23:09 -08001098 source_info = None
Tao Baoc098e9e2016-01-07 13:03:56 -08001099
Kelvin Zhang10eac082021-06-10 14:32:19 -04001100 if target_info.vendor_suppressed_vabc:
1101 logger.info("Vendor suppressed VABC. Disabling")
1102 OPTIONS.disable_vabc = True
Kelvin Zhangad427382021-08-12 16:19:09 -07001103 if not target_info.is_vabc_xor or OPTIONS.disable_vabc:
1104 logger.info("VABC XOR Not supported, disabling")
1105 OPTIONS.enable_vabc_xor = False
Yifan Hong38ab4d82020-06-18 15:19:56 -07001106 additional_args = []
1107
Hongguang Chen49ab1b902020-10-19 14:15:43 -07001108 # Prepare custom images.
1109 if OPTIONS.custom_images:
1110 target_file = GetTargetFilesZipForCustomImagesUpdates(
1111 target_file, OPTIONS.custom_images)
1112
Yifan Hong50e79542018-11-08 17:44:12 -08001113 if OPTIONS.retrofit_dynamic_partitions:
1114 target_file = GetTargetFilesZipForRetrofitDynamicPartitions(
Yifan Hongb433eba2019-03-06 12:42:53 -08001115 target_file, target_info.get("super_block_devices").strip().split(),
1116 target_info.get("dynamic_partition_list").strip().split())
Yifan Hong38ab4d82020-06-18 15:19:56 -07001117 elif OPTIONS.partial:
1118 target_file = GetTargetFilesZipForPartialUpdates(target_file,
1119 OPTIONS.partial)
1120 additional_args += ["--is_partial_update", "true"]
Yifan Hong50e79542018-11-08 17:44:12 -08001121 elif OPTIONS.skip_postinstall:
Tao Bao15a146a2018-02-21 16:06:59 -08001122 target_file = GetTargetFilesZipWithoutPostinstallConfig(target_file)
Kelvin Zhang39aea442020-08-17 11:04:25 -04001123 # Target_file may have been modified, reparse ab_partitions
1124 with zipfile.ZipFile(target_file, allowZip64=True) as zfp:
1125 target_info.info_dict['ab_partitions'] = zfp.read(
Kelvin Zhang31233e52020-11-03 13:42:46 -05001126 AB_PARTITIONS).decode().strip().split("\n")
Tao Bao15a146a2018-02-21 16:06:59 -08001127
Kelvin Zhang414ca422021-08-27 15:12:08 -07001128 CheckVintfIfTrebleEnabled(target_file, target_info)
1129
Kelvin Zhang39aea442020-08-17 11:04:25 -04001130 # Metadata to comply with Android OTA package format.
1131 metadata = GetPackageMetadata(target_info, source_info)
Tao Bao40b18822018-01-30 18:19:04 -08001132 # Generate payload.
1133 payload = Payload()
1134
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001135 partition_timestamps_flags = []
Tao Bao40b18822018-01-30 18:19:04 -08001136 # Enforce a max timestamp this payload can be applied on top of.
Tao Baoff1b86e2017-10-03 14:17:57 -07001137 if OPTIONS.downgrade:
Tao Bao2a12ed72018-01-22 11:35:00 -08001138 max_timestamp = source_info.GetBuildProp("ro.build.date.utc")
Kelvin Zhang80195722020-11-04 14:38:34 -05001139 partition_timestamps_flags = GeneratePartitionTimestampFlagsDowngrade(
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001140 metadata.precondition.partition_state,
1141 metadata.postcondition.partition_state
1142 )
Tao Baoff1b86e2017-10-03 14:17:57 -07001143 else:
Tianjiea2076132020-08-19 17:25:32 -07001144 max_timestamp = str(metadata.postcondition.timestamp)
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001145 partition_timestamps_flags = GeneratePartitionTimestampFlags(
1146 metadata.postcondition.partition_state)
Tao Baoc098e9e2016-01-07 13:03:56 -08001147
Kelvin Zhang410bb382022-01-06 09:15:54 -08001148 # Auto-check for compatibility only if --enable_zucchini omitted. Otherwise
1149 # let user override zucchini settings. This is useful for testing.
1150 if OPTIONS.enable_zucchini is None:
1151 if not ota_utils.IsZucchiniCompatible(source_file, target_file):
1152 additional_args += ["--enable_zucchini", "false"]
1153 else:
1154 additional_args += ["--enable_zucchini", str(OPTIONS.enable_zucchini).lower()]
1155
Kelvin Zhangbbfa1822021-02-03 17:19:44 -05001156 if OPTIONS.disable_vabc:
1157 additional_args += ["--disable_vabc", "true"]
Kelvin Zhangf66caee2021-07-12 09:44:20 -04001158 if OPTIONS.enable_vabc_xor:
1159 additional_args += ["--enable_vabc_xor", "true"]
Tianjiee7ab38d2021-09-08 19:09:38 -07001160 if OPTIONS.force_minor_version:
1161 additional_args += ["--force_minor_version", OPTIONS.force_minor_version]
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -07001162 if OPTIONS.compressor_types:
1163 additional_args += ["--compressor_types", OPTIONS.compressor_types]
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001164 additional_args += ["--max_timestamp", max_timestamp]
1165
Kelvin Zhang65029a22020-11-03 10:07:51 -05001166 if SupportsMainlineGkiUpdates(source_file):
Kelvin Zhang06400172021-03-05 15:42:03 -05001167 logger.warning(
1168 "Detected build with mainline GKI, include full boot image.")
Kelvin Zhang65029a22020-11-03 10:07:51 -05001169 additional_args.extend(["--full_boot", "true"])
1170
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001171 payload.Generate(
1172 target_file,
1173 source_file,
1174 additional_args + partition_timestamps_flags
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001175 )
Tao Baoc098e9e2016-01-07 13:03:56 -08001176
Tao Bao40b18822018-01-30 18:19:04 -08001177 # Sign the payload.
Tao Baof7140c02018-01-30 17:09:24 -08001178 payload_signer = PayloadSigner()
1179 payload.Sign(payload_signer)
Tao Baoc098e9e2016-01-07 13:03:56 -08001180
Tao Bao40b18822018-01-30 18:19:04 -08001181 # Write the payload into output zip.
1182 payload.WriteToZip(output_zip)
Tao Baoc098e9e2016-01-07 13:03:56 -08001183
Tao Baof7140c02018-01-30 17:09:24 -08001184 # Generate and include the secondary payload that installs secondary images
1185 # (e.g. system_other.img).
1186 if OPTIONS.include_secondary:
1187 # We always include a full payload for the secondary slot, even when
1188 # building an incremental OTA. See the comments for "--include_secondary".
Tao Bao15a146a2018-02-21 16:06:59 -08001189 secondary_target_file = GetTargetFilesZipForSecondaryImages(
1190 target_file, OPTIONS.skip_postinstall)
Tao Bao667ff572018-02-10 00:02:40 -08001191 secondary_payload = Payload(secondary=True)
Tao Baodb1fe412018-02-09 23:15:05 -08001192 secondary_payload.Generate(secondary_target_file,
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001193 additional_args=["--max_timestamp",
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001194 max_timestamp])
Tao Baof7140c02018-01-30 17:09:24 -08001195 secondary_payload.Sign(payload_signer)
Tao Bao667ff572018-02-10 00:02:40 -08001196 secondary_payload.WriteToZip(output_zip)
Tao Baof7140c02018-01-30 17:09:24 -08001197
Tianjie Xucfa86222016-03-07 16:31:19 -08001198 # If dm-verity is supported for the device, copy contents of care_map
1199 # into A/B OTA package.
Kelvin Zhang928c2342020-09-22 16:15:57 -04001200 target_zip = zipfile.ZipFile(target_file, "r", allowZip64=True)
Tao Bao481bab82017-12-21 11:23:09 -08001201 if (target_info.get("verity") == "true" or
Kelvin Zhang06400172021-03-05 15:42:03 -05001202 target_info.get("avb_enable") == "true"):
Tianjie Xu4c05f4a2018-09-14 16:24:41 -07001203 care_map_list = [x for x in ["care_map.pb", "care_map.txt"] if
1204 "META/" + x in target_zip.namelist()]
1205
1206 # Adds care_map if either the protobuf format or the plain text one exists.
1207 if care_map_list:
1208 care_map_name = care_map_list[0]
1209 care_map_data = target_zip.read("META/" + care_map_name)
1210 # In order to support streaming, care_map needs to be packed as
Tao Bao40b18822018-01-30 18:19:04 -08001211 # ZIP_STORED.
Tianjie Xu4c05f4a2018-09-14 16:24:41 -07001212 common.ZipWriteStr(output_zip, care_map_name, care_map_data,
Tao Bao481bab82017-12-21 11:23:09 -08001213 compress_type=zipfile.ZIP_STORED)
Tianjie Xucfa86222016-03-07 16:31:19 -08001214 else:
Tao Bao32fcdab2018-10-12 10:30:39 -07001215 logger.warning("Cannot find care map file in target_file package")
Tao Bao21803d32017-04-19 10:16:09 -07001216
Tianjiea5fca032021-06-01 22:06:28 -07001217 # Add the source apex version for incremental ota updates, and write the
1218 # result apex info to the ota package.
1219 ota_apex_info = ota_utils.ConstructOtaApexInfo(target_zip, source_file)
1220 if ota_apex_info is not None:
1221 common.ZipWriteStr(output_zip, "apex_info.pb", ota_apex_info,
1222 compress_type=zipfile.ZIP_STORED)
Kelvin Zhang7bd09912021-01-21 10:33:13 -05001223
Tao Bao21803d32017-04-19 10:16:09 -07001224 common.ZipClose(target_zip)
Tianjie Xucfa86222016-03-07 16:31:19 -08001225
Tao Baofe5b69a2018-03-02 09:47:43 -08001226 # We haven't written the metadata entry yet, which will be handled in
1227 # FinalizeMetadata().
Tao Baoc96316c2017-01-24 22:10:49 -08001228 common.ZipClose(output_zip)
1229
Tao Bao85f16982018-03-08 16:28:33 -08001230 # AbOtaPropertyFiles intends to replace StreamingPropertyFiles, as it covers
1231 # all the info of the latter. However, system updaters and OTA servers need to
1232 # take time to switch to the new flag. We keep both of the flags for
1233 # P-timeframe, and will remove StreamingPropertyFiles in later release.
Tao Baod3fc38a2018-03-08 16:09:01 -08001234 needed_property_files = (
Tao Bao85f16982018-03-08 16:28:33 -08001235 AbOtaPropertyFiles(),
Tao Baod3fc38a2018-03-08 16:09:01 -08001236 StreamingPropertyFiles(),
1237 )
1238 FinalizeMetadata(metadata, staging_file, output_file, needed_property_files)
Tao Baoc96316c2017-01-24 22:10:49 -08001239
Tao Baoc098e9e2016-01-07 13:03:56 -08001240
Doug Zongkereef39442009-04-02 12:14:19 -07001241def main(argv):
1242
1243 def option_handler(o, a):
Tao Bao4b76a0e2017-10-31 12:13:33 -07001244 if o in ("-k", "--package_key"):
Doug Zongkereef39442009-04-02 12:14:19 -07001245 OPTIONS.package_key = a
Doug Zongkereef39442009-04-02 12:14:19 -07001246 elif o in ("-i", "--incremental_from"):
1247 OPTIONS.incremental_source = a
Tao Bao43078aa2015-04-21 14:32:35 -07001248 elif o == "--full_radio":
1249 OPTIONS.full_radio = True
leozwangaa6c1a12015-08-14 10:57:58 -07001250 elif o == "--full_bootloader":
1251 OPTIONS.full_bootloader = True
Tao Bao337633f2017-12-06 15:20:19 -08001252 elif o == "--wipe_user_data":
Doug Zongkerdbfaae52009-04-21 17:12:54 -07001253 OPTIONS.wipe_user_data = True
Tao Bao5d182562016-02-23 11:38:39 -08001254 elif o == "--downgrade":
1255 OPTIONS.downgrade = True
1256 OPTIONS.wipe_user_data = True
Tao Bao3e6161a2017-02-28 11:48:48 -08001257 elif o == "--override_timestamp":
Tao Baofaa8e0b2018-04-12 14:31:43 -07001258 OPTIONS.downgrade = True
Michael Runge6e836112014-04-15 17:40:21 -07001259 elif o in ("-o", "--oem_settings"):
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -08001260 OPTIONS.oem_source = a.split(',')
Tao Bao8608cde2016-02-25 19:49:55 -08001261 elif o == "--oem_no_mount":
1262 OPTIONS.oem_no_mount = True
Doug Zongker1c390a22009-05-14 19:06:36 -07001263 elif o in ("-e", "--extra_script"):
1264 OPTIONS.extra_script = a
Martin Blumenstingl374e1142014-05-31 20:42:55 +02001265 elif o in ("-t", "--worker_threads"):
1266 if a.isdigit():
1267 OPTIONS.worker_threads = int(a)
1268 else:
1269 raise ValueError("Cannot parse value %r for option %r - only "
1270 "integers are allowed." % (a, o))
Doug Zongker9b23f2c2013-11-25 14:44:12 -08001271 elif o in ("-2", "--two_step"):
1272 OPTIONS.two_step = True
Tao Baof7140c02018-01-30 17:09:24 -08001273 elif o == "--include_secondary":
1274 OPTIONS.include_secondary = True
Doug Zongker26e66192014-02-20 13:22:07 -08001275 elif o == "--no_signing":
Takeshi Kanemotoe153b342013-11-14 17:20:50 +09001276 OPTIONS.no_signing = True
Dan Albert8b72aef2015-03-23 19:13:21 -07001277 elif o == "--verify":
Michael Runge63f01de2014-10-28 19:24:19 -07001278 OPTIONS.verify = True
Doug Zongker26e66192014-02-20 13:22:07 -08001279 elif o == "--block":
1280 OPTIONS.block_based = True
Doug Zongker25568482014-03-03 10:21:27 -08001281 elif o in ("-b", "--binary"):
1282 OPTIONS.updater_binary = a
Tao Bao8dcf7382015-05-21 14:09:49 -07001283 elif o == "--stash_threshold":
1284 try:
1285 OPTIONS.stash_threshold = float(a)
1286 except ValueError:
1287 raise ValueError("Cannot parse value %r for option %r - expecting "
1288 "a float" % (a, o))
Tao Baod62c6032015-11-30 09:40:20 -08001289 elif o == "--log_diff":
1290 OPTIONS.log_diff = a
Tao Baodea0f8b2016-06-20 17:55:06 -07001291 elif o == "--payload_signer":
1292 OPTIONS.payload_signer = a
Baligh Uddin2abbbd02016-06-22 12:14:16 -07001293 elif o == "--payload_signer_args":
1294 OPTIONS.payload_signer_args = shlex.split(a)
Tianjie Xu21e6deb2019-10-07 18:01:00 -07001295 elif o == "--payload_signer_maximum_signature_size":
1296 OPTIONS.payload_signer_maximum_signature_size = a
xunchang376cc7c2019-04-08 23:04:58 -07001297 elif o == "--payload_signer_key_size":
Tianjie Xu21e6deb2019-10-07 18:01:00 -07001298 # TODO(Xunchang) remove this option after cleaning up the callers.
1299 logger.warning("The option '--payload_signer_key_size' is deprecated."
1300 " Use '--payload_signer_maximum_signature_size' instead.")
1301 OPTIONS.payload_signer_maximum_signature_size = a
Dan Willemsencea5cd22017-03-21 14:44:27 -07001302 elif o == "--extracted_input_target_files":
1303 OPTIONS.extracted_input = a
Tao Bao15a146a2018-02-21 16:06:59 -08001304 elif o == "--skip_postinstall":
1305 OPTIONS.skip_postinstall = True
Yifan Hong50e79542018-11-08 17:44:12 -08001306 elif o == "--retrofit_dynamic_partitions":
1307 OPTIONS.retrofit_dynamic_partitions = True
xunchangabfa2652019-02-19 16:27:10 -08001308 elif o == "--skip_compatibility_check":
1309 OPTIONS.skip_compatibility_check = True
xunchang1cfe2512019-02-19 14:14:48 -08001310 elif o == "--output_metadata_path":
1311 OPTIONS.output_metadata_path = a
Tianjie Xu1b079832019-08-28 12:19:23 -07001312 elif o == "--disable_fec_computation":
1313 OPTIONS.disable_fec_computation = True
Kelvin Zhangcaf7bbc2020-11-20 14:09:42 -05001314 elif o == "--disable_verity_computation":
1315 OPTIONS.disable_verity_computation = True
Yifan Hong65afc072020-04-17 10:08:10 -07001316 elif o == "--force_non_ab":
1317 OPTIONS.force_non_ab = True
Tianjied6867162020-05-10 14:30:13 -07001318 elif o == "--boot_variable_file":
1319 OPTIONS.boot_variable_file = a
Yifan Hong38ab4d82020-06-18 15:19:56 -07001320 elif o == "--partial":
1321 partitions = a.split()
1322 if not partitions:
1323 raise ValueError("Cannot parse partitions in {}".format(a))
1324 OPTIONS.partial = partitions
Hongguang Chen49ab1b902020-10-19 14:15:43 -07001325 elif o == "--custom_image":
1326 custom_partition, custom_image = a.split("=")
1327 OPTIONS.custom_images[custom_partition] = custom_image
Kelvin Zhangbbfa1822021-02-03 17:19:44 -05001328 elif o == "--disable_vabc":
1329 OPTIONS.disable_vabc = True
Kelvin Zhang80ff4662021-02-08 19:57:57 -05001330 elif o == "--spl_downgrade":
1331 OPTIONS.spl_downgrade = True
Kelvin Zhang06400172021-03-05 15:42:03 -05001332 OPTIONS.wipe_user_data = True
Kelvin Zhang2a3e5b12021-05-04 18:20:34 -04001333 elif o == "--vabc_downgrade":
1334 OPTIONS.vabc_downgrade = True
Kelvin Zhangf66caee2021-07-12 09:44:20 -04001335 elif o == "--enable_vabc_xor":
Kelvin Zhang1250bca2021-08-27 15:10:27 -07001336 OPTIONS.enable_vabc_xor = a.lower() != "false"
Tianjiee7ab38d2021-09-08 19:09:38 -07001337 elif o == "--force_minor_version":
1338 OPTIONS.force_minor_version = a
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -07001339 elif o == "--compressor_types":
1340 OPTIONS.compressor_types = a
Kelvin Zhang410bb382022-01-06 09:15:54 -08001341 elif o == "--enable_zucchini":
1342 OPTIONS.enable_zucchini = a.lower() != "false"
Doug Zongkereef39442009-04-02 12:14:19 -07001343 else:
1344 return False
Doug Zongkerdbfaae52009-04-21 17:12:54 -07001345 return True
Doug Zongkereef39442009-04-02 12:14:19 -07001346
1347 args = common.ParseOptions(argv, __doc__,
Kelvin Zhang4b588cf2021-11-09 08:42:11 -08001348 extra_opts="b:k:i:d:e:t:2o:",
1349 extra_long_opts=[
1350 "package_key=",
1351 "incremental_from=",
1352 "full_radio",
1353 "full_bootloader",
1354 "wipe_user_data",
1355 "downgrade",
1356 "override_timestamp",
1357 "extra_script=",
1358 "worker_threads=",
1359 "two_step",
1360 "include_secondary",
1361 "no_signing",
1362 "block",
1363 "binary=",
1364 "oem_settings=",
1365 "oem_no_mount",
1366 "verify",
1367 "stash_threshold=",
1368 "log_diff=",
1369 "payload_signer=",
1370 "payload_signer_args=",
1371 "payload_signer_maximum_signature_size=",
1372 "payload_signer_key_size=",
1373 "extracted_input_target_files=",
1374 "skip_postinstall",
1375 "retrofit_dynamic_partitions",
1376 "skip_compatibility_check",
1377 "output_metadata_path=",
1378 "disable_fec_computation",
1379 "disable_verity_computation",
1380 "force_non_ab",
1381 "boot_variable_file=",
1382 "partial=",
1383 "custom_image=",
1384 "disable_vabc",
1385 "spl_downgrade",
1386 "vabc_downgrade",
1387 "enable_vabc_xor=",
1388 "force_minor_version=",
1389 "compressor_types=",
Kelvin Zhang410bb382022-01-06 09:15:54 -08001390 "enable_zucchin=",
Kelvin Zhang4b588cf2021-11-09 08:42:11 -08001391 ], extra_option_handler=option_handler)
Doug Zongkereef39442009-04-02 12:14:19 -07001392
1393 if len(args) != 2:
1394 common.Usage(__doc__)
1395 sys.exit(1)
1396
Tao Bao32fcdab2018-10-12 10:30:39 -07001397 common.InitLogging()
1398
Tao Bao2db13852018-01-08 22:28:57 -08001399 # Load the build info dicts from the zip directly or the extracted input
1400 # directory. We don't need to unzip the entire target-files zips, because they
1401 # won't be needed for A/B OTAs (brillo_update_payload does that on its own).
1402 # When loading the info dicts, we don't need to provide the second parameter
1403 # to common.LoadInfoDict(). Specifying the second parameter allows replacing
1404 # some properties with their actual paths, such as 'selinux_fc',
1405 # 'ramdisk_dir', which won't be used during OTA generation.
Dan Willemsencea5cd22017-03-21 14:44:27 -07001406 if OPTIONS.extracted_input is not None:
Tao Bao2db13852018-01-08 22:28:57 -08001407 OPTIONS.info_dict = common.LoadInfoDict(OPTIONS.extracted_input)
Dan Willemsencea5cd22017-03-21 14:44:27 -07001408 else:
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001409 OPTIONS.info_dict = ParseInfoDict(args[0])
Kelvin Zhang80195722020-11-04 14:38:34 -05001410
Kelvin Zhang2a3e5b12021-05-04 18:20:34 -04001411 if OPTIONS.wipe_user_data:
1412 if not OPTIONS.vabc_downgrade:
1413 logger.info("Detected downgrade/datawipe OTA."
1414 "When wiping userdata, VABC OTA makes the user "
1415 "wait in recovery mode for merge to finish. Disable VABC by "
1416 "default. If you really want to do VABC downgrade, pass "
1417 "--vabc_downgrade")
1418 OPTIONS.disable_vabc = True
Kelvin Zhang80195722020-11-04 14:38:34 -05001419 # We should only allow downgrading incrementals (as opposed to full).
1420 # Otherwise the device may go back from arbitrary build with this full
1421 # OTA package.
Kelvin Zhang81641af2021-10-26 16:03:25 -07001422 if OPTIONS.incremental_source is None and OPTIONS.downgrade:
1423 raise ValueError("Cannot generate downgradable full OTAs")
Kelvin Zhang80195722020-11-04 14:38:34 -05001424
Yifan Hong38ab4d82020-06-18 15:19:56 -07001425 # TODO(xunchang) for retrofit and partial updates, maybe we should rebuild the
1426 # target-file and reload the info_dict. So the info will be consistent with
1427 # the modified target-file.
1428
Tao Bao32fcdab2018-10-12 10:30:39 -07001429 logger.info("--- target info ---")
1430 common.DumpInfoDict(OPTIONS.info_dict)
Tao Bao2db13852018-01-08 22:28:57 -08001431
1432 # Load the source build dict if applicable.
1433 if OPTIONS.incremental_source is not None:
1434 OPTIONS.target_info_dict = OPTIONS.info_dict
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001435 OPTIONS.source_info_dict = ParseInfoDict(OPTIONS.incremental_source)
Tao Bao2db13852018-01-08 22:28:57 -08001436
Tao Bao32fcdab2018-10-12 10:30:39 -07001437 logger.info("--- source info ---")
1438 common.DumpInfoDict(OPTIONS.source_info_dict)
Tao Bao2db13852018-01-08 22:28:57 -08001439
Kelvin Zhang83ea7832020-11-11 13:07:10 -05001440 if OPTIONS.partial:
1441 OPTIONS.info_dict['ab_partitions'] = \
Kelvin Zhang06400172021-03-05 15:42:03 -05001442 list(
1443 set(OPTIONS.info_dict['ab_partitions']) & set(OPTIONS.partial)
1444 )
Kelvin Zhang83ea7832020-11-11 13:07:10 -05001445 if OPTIONS.source_info_dict:
1446 OPTIONS.source_info_dict['ab_partitions'] = \
Kelvin Zhang06400172021-03-05 15:42:03 -05001447 list(
1448 set(OPTIONS.source_info_dict['ab_partitions']) &
1449 set(OPTIONS.partial)
1450 )
Kelvin Zhang83ea7832020-11-11 13:07:10 -05001451
Tao Bao2db13852018-01-08 22:28:57 -08001452 # Load OEM dicts if provided.
Tao Bao481bab82017-12-21 11:23:09 -08001453 OPTIONS.oem_dicts = _LoadOemDicts(OPTIONS.oem_source)
1454
Yifan Hong50e79542018-11-08 17:44:12 -08001455 # Assume retrofitting dynamic partitions when base build does not set
Yifan Hong50611032018-11-20 14:27:38 -08001456 # use_dynamic_partitions but target build does.
Yifan Hong50e79542018-11-08 17:44:12 -08001457 if (OPTIONS.source_info_dict and
Yifan Hong50611032018-11-20 14:27:38 -08001458 OPTIONS.source_info_dict.get("use_dynamic_partitions") != "true" and
Kelvin Zhang06400172021-03-05 15:42:03 -05001459 OPTIONS.target_info_dict.get("use_dynamic_partitions") == "true"):
Yifan Hong50e79542018-11-08 17:44:12 -08001460 if OPTIONS.target_info_dict.get("dynamic_partition_retrofit") != "true":
1461 raise common.ExternalError(
1462 "Expect to generate incremental OTA for retrofitting dynamic "
1463 "partitions, but dynamic_partition_retrofit is not set in target "
1464 "build.")
1465 logger.info("Implicitly generating retrofit incremental OTA.")
1466 OPTIONS.retrofit_dynamic_partitions = True
1467
1468 # Skip postinstall for retrofitting dynamic partitions.
1469 if OPTIONS.retrofit_dynamic_partitions:
1470 OPTIONS.skip_postinstall = True
1471
Tao Baoc098e9e2016-01-07 13:03:56 -08001472 ab_update = OPTIONS.info_dict.get("ab_update") == "true"
Yifan Hong65afc072020-04-17 10:08:10 -07001473 allow_non_ab = OPTIONS.info_dict.get("allow_non_ab") == "true"
1474 if OPTIONS.force_non_ab:
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001475 assert allow_non_ab,\
Kelvin Zhang06400172021-03-05 15:42:03 -05001476 "--force_non_ab only allowed on devices that supports non-A/B"
Yifan Hong65afc072020-04-17 10:08:10 -07001477 assert ab_update, "--force_non_ab only allowed on A/B devices"
1478
1479 generate_ab = not OPTIONS.force_non_ab and ab_update
Tao Baoc098e9e2016-01-07 13:03:56 -08001480
Christian Oderf63e2cd2017-05-01 22:30:15 +02001481 # Use the default key to sign the package if not specified with package_key.
1482 # package_keys are needed on ab_updates, so always define them if an
Yifan Hong65afc072020-04-17 10:08:10 -07001483 # A/B update is getting created.
1484 if not OPTIONS.no_signing or generate_ab:
Christian Oderf63e2cd2017-05-01 22:30:15 +02001485 if OPTIONS.package_key is None:
1486 OPTIONS.package_key = OPTIONS.info_dict.get(
1487 "default_system_dev_certificate",
Dan Willemsen0ab1be62019-04-09 21:35:37 -07001488 "build/make/target/product/security/testkey")
Christian Oderf63e2cd2017-05-01 22:30:15 +02001489 # Get signing keys
1490 OPTIONS.key_passwords = common.GetKeyPasswords([OPTIONS.package_key])
Kelvin Zhang4b588cf2021-11-09 08:42:11 -08001491
1492 # Only check for existence of key file if using the default signer.
1493 # Because the custom signer might not need the key file AT all.
1494 # b/191704641
Kelvin Zhang4fc3aa02021-11-16 18:58:58 -08001495 if not OPTIONS.payload_signer:
Kelvin Zhang4b588cf2021-11-09 08:42:11 -08001496 private_key_path = OPTIONS.package_key + OPTIONS.private_key_suffix
1497 if not os.path.exists(private_key_path):
1498 raise common.ExternalError(
1499 "Private key {} doesn't exist. Make sure you passed the"
1500 " correct key path through -k option".format(
1501 private_key_path)
1502 )
Kelvin Zhang4fc3aa02021-11-16 18:58:58 -08001503 signapk_abs_path = os.path.join(
1504 OPTIONS.search_path, OPTIONS.signapk_path)
1505 if not os.path.exists(signapk_abs_path):
1506 raise common.ExternalError(
1507 "Failed to find sign apk binary {} in search path {}. Make sure the correct search path is passed via -p".format(OPTIONS.signapk_path, OPTIONS.search_path))
Christian Oderf63e2cd2017-05-01 22:30:15 +02001508
Kelvin Zhang80ff4662021-02-08 19:57:57 -05001509 if OPTIONS.source_info_dict:
1510 source_build_prop = OPTIONS.source_info_dict["build.prop"]
1511 target_build_prop = OPTIONS.target_info_dict["build.prop"]
1512 source_spl = source_build_prop.GetProp(SECURITY_PATCH_LEVEL_PROP_NAME)
1513 target_spl = target_build_prop.GetProp(SECURITY_PATCH_LEVEL_PROP_NAME)
Kelvin Zhang05ff7052021-02-10 09:13:26 -05001514 is_spl_downgrade = target_spl < source_spl
Kelvin Zhang06400172021-03-05 15:42:03 -05001515 if is_spl_downgrade and not OPTIONS.spl_downgrade and not OPTIONS.downgrade:
Kelvin Zhang80ff4662021-02-08 19:57:57 -05001516 raise common.ExternalError(
Kelvin Zhang06400172021-03-05 15:42:03 -05001517 "Target security patch level {} is older than source SPL {} applying "
1518 "such OTA will likely cause device fail to boot. Pass --spl_downgrade "
1519 "to override this check. This script expects security patch level to "
1520 "be in format yyyy-mm-dd (e.x. 2021-02-05). It's possible to use "
1521 "separators other than -, so as long as it's used consistenly across "
1522 "all SPL dates".format(target_spl, source_spl))
Kelvin Zhang05ff7052021-02-10 09:13:26 -05001523 elif not is_spl_downgrade and OPTIONS.spl_downgrade:
1524 raise ValueError("--spl_downgrade specified but no actual SPL downgrade"
1525 " detected. Please only pass in this flag if you want a"
1526 " SPL downgrade. Target SPL: {} Source SPL: {}"
1527 .format(target_spl, source_spl))
Yifan Hong65afc072020-04-17 10:08:10 -07001528 if generate_ab:
Tao Baof0c4aa22018-04-30 20:29:30 -07001529 GenerateAbOtaPackage(
Tao Baoc098e9e2016-01-07 13:03:56 -08001530 target_file=args[0],
1531 output_file=args[1],
1532 source_file=OPTIONS.incremental_source)
1533
Dan Willemsencea5cd22017-03-21 14:44:27 -07001534 else:
Tao Baof0c4aa22018-04-30 20:29:30 -07001535 GenerateNonAbOtaPackage(
1536 target_file=args[0],
1537 output_file=args[1],
1538 source_file=OPTIONS.incremental_source)
Doug Zongkerfdd8e692009-08-03 17:27:48 -07001539
Tao Baof0c4aa22018-04-30 20:29:30 -07001540 # Post OTA generation works.
1541 if OPTIONS.incremental_source is not None and OPTIONS.log_diff:
1542 logger.info("Generating diff logs...")
1543 logger.info("Unzipping target-files for diffing...")
1544 target_dir = common.UnzipTemp(args[0], TARGET_DIFFING_UNZIP_PATTERN)
1545 source_dir = common.UnzipTemp(
1546 OPTIONS.incremental_source, TARGET_DIFFING_UNZIP_PATTERN)
Doug Zongkereb0a78a2014-01-27 10:01:06 -08001547
Tao Baof0c4aa22018-04-30 20:29:30 -07001548 with open(OPTIONS.log_diff, 'w') as out_file:
Tao Baof0c4aa22018-04-30 20:29:30 -07001549 target_files_diff.recursiveDiff(
1550 '', source_dir, target_dir, out_file)
Doug Zongker62d4f182014-08-04 16:06:43 -07001551
Tao Bao32fcdab2018-10-12 10:30:39 -07001552 logger.info("done.")
Doug Zongkereef39442009-04-02 12:14:19 -07001553
1554
1555if __name__ == '__main__':
1556 try:
Ying Wang7e6d4e42010-12-13 16:25:36 -08001557 common.CloseInheritedPipes()
Doug Zongkereef39442009-04-02 12:14:19 -07001558 main(sys.argv[1:])
Doug Zongkerfc44a512014-08-26 13:10:25 -07001559 finally:
1560 common.Cleanup()