blob: 1fc6878d3ba0ac376e092406a778eb0c0f47d02b [file] [log] [blame]
Doug Zongkereef39442009-04-02 12:14:19 -07001#!/usr/bin/env python
2#
3# Copyright (C) 2008 The Android Open Source Project
4#
5# Licensed under the Apache License, Version 2.0 (the "License");
6# you may not use this file except in compliance with the License.
7# You may obtain a copy of the License at
8#
9# http://www.apache.org/licenses/LICENSE-2.0
10#
11# Unless required by applicable law or agreed to in writing, software
12# distributed under the License is distributed on an "AS IS" BASIS,
13# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14# See the License for the specific language governing permissions and
15# limitations under the License.
16
17"""
Tao Bao30df8b42018-04-23 15:32:53 -070018Given a target-files zipfile, produces an OTA package that installs that build.
19An incremental OTA is produced if -i is given, otherwise a full OTA is produced.
Doug Zongkereef39442009-04-02 12:14:19 -070020
Tao Bao30df8b42018-04-23 15:32:53 -070021Usage: ota_from_target_files [options] input_target_files output_ota_package
Doug Zongkereef39442009-04-02 12:14:19 -070022
Tao Bao30df8b42018-04-23 15:32:53 -070023Common options that apply to both of non-A/B and A/B OTAs
24
25 --downgrade
26 Intentionally generate an incremental OTA that updates from a newer build
Tao Baofaa8e0b2018-04-12 14:31:43 -070027 to an older one (e.g. downgrading from P preview back to O MR1).
28 "ota-downgrade=yes" will be set in the package metadata file. A data wipe
29 will always be enforced when using this flag, so "ota-wipe=yes" will also
30 be included in the metadata file. The update-binary in the source build
31 will be used in the OTA package, unless --binary flag is specified. Please
32 also check the comment for --override_timestamp below.
Tao Bao30df8b42018-04-23 15:32:53 -070033
34 -i (--incremental_from) <file>
35 Generate an incremental OTA using the given target-files zip as the
36 starting build.
37
38 -k (--package_key) <key>
39 Key to use to sign the package (default is the value of
40 default_system_dev_certificate from the input target-files's
Tao Bao59cf0c52019-06-25 10:04:24 -070041 META/misc_info.txt, or "build/make/target/product/security/testkey" if
42 that value is not specified).
Doug Zongkerafb32ea2011-09-22 10:28:04 -070043
44 For incremental OTAs, the default value is based on the source
45 target-file, not the target build.
Doug Zongkereef39442009-04-02 12:14:19 -070046
Tao Bao30df8b42018-04-23 15:32:53 -070047 --override_timestamp
48 Intentionally generate an incremental OTA that updates from a newer build
Tao Baofaa8e0b2018-04-12 14:31:43 -070049 to an older one (based on timestamp comparison), by setting the downgrade
50 flag in the package metadata. This differs from --downgrade flag, as we
51 don't enforce a data wipe with this flag. Because we know for sure this is
52 NOT an actual downgrade case, but two builds happen to be cut in a reverse
53 order (e.g. from two branches). A legit use case is that we cut a new
54 build C (after having A and B), but want to enfore an update path of A ->
55 C -> B. Specifying --downgrade may not help since that would enforce a
56 data wipe for C -> B update.
57
58 We used to set a fake timestamp in the package metadata for this flow. But
59 now we consolidate the two cases (i.e. an actual downgrade, or a downgrade
60 based on timestamp) with the same "ota-downgrade=yes" flag, with the
61 difference being whether "ota-wipe=yes" is set.
Doug Zongkereef39442009-04-02 12:14:19 -070062
Tao Bao30df8b42018-04-23 15:32:53 -070063 --wipe_user_data
64 Generate an OTA package that will wipe the user data partition when
65 installed.
66
Yifan Hong50e79542018-11-08 17:44:12 -080067 --retrofit_dynamic_partitions
68 Generates an OTA package that updates a device to support dynamic
69 partitions (default False). This flag is implied when generating
70 an incremental OTA where the base build does not support dynamic
71 partitions but the target build does. For A/B, when this flag is set,
72 --skip_postinstall is implied.
73
xunchangabfa2652019-02-19 16:27:10 -080074 --skip_compatibility_check
Yifan Hong9276cf02019-08-21 16:37:04 -070075 Skip checking compatibility of the input target files package.
xunchangabfa2652019-02-19 16:27:10 -080076
xunchang1cfe2512019-02-19 14:14:48 -080077 --output_metadata_path
78 Write a copy of the metadata to a separate file. Therefore, users can
79 read the post build fingerprint without extracting the OTA package.
80
Yifan Hong65afc072020-04-17 10:08:10 -070081 --force_non_ab
82 This flag can only be set on an A/B device that also supports non-A/B
83 updates. Implies --two_step.
84 If set, generate that non-A/B update package.
85 If not set, generates A/B package for A/B device and non-A/B package for
86 non-A/B device.
87
Hongguang Chen49ab1b902020-10-19 14:15:43 -070088 -o (--oem_settings) <main_file[,additional_files...]>
89 Comma separated list of files used to specify the expected OEM-specific
90 properties on the OEM partition of the intended device. Multiple expected
91 values can be used by providing multiple files. Only the first dict will
92 be used to compute fingerprint, while the rest will be used to assert
93 OEM-specific properties.
94
Tao Bao30df8b42018-04-23 15:32:53 -070095Non-A/B OTA specific options
96
97 -b (--binary) <file>
98 Use the given binary as the update-binary in the output package, instead
99 of the binary in the build's target_files. Use for development only.
100
101 --block
102 Generate a block-based OTA for non-A/B device. We have deprecated the
103 support for file-based OTA since O. Block-based OTA will be used by
104 default for all non-A/B devices. Keeping this flag here to not break
105 existing callers.
106
107 -e (--extra_script) <file>
108 Insert the contents of file at the end of the update script.
Tao Bao43078aa2015-04-21 14:32:35 -0700109
leozwangaa6c1a12015-08-14 10:57:58 -0700110 --full_bootloader
111 Similar to --full_radio. When generating an incremental OTA, always
112 include a full copy of bootloader image.
113
Tao Bao30df8b42018-04-23 15:32:53 -0700114 --full_radio
115 When generating an incremental OTA, always include a full copy of radio
116 image. This option is only meaningful when -i is specified, because a full
117 radio is always included in a full OTA if applicable.
Michael Runge63f01de2014-10-28 19:24:19 -0700118
Tao Bao30df8b42018-04-23 15:32:53 -0700119 --log_diff <file>
120 Generate a log file that shows the differences in the source and target
121 builds for an incremental package. This option is only meaningful when -i
122 is specified.
123
Tao Bao8608cde2016-02-25 19:49:55 -0800124 --oem_no_mount
Tao Bao30df8b42018-04-23 15:32:53 -0700125 For devices with OEM-specific properties but without an OEM partition, do
126 not mount the OEM partition in the updater-script. This should be very
127 rarely used, since it's expected to have a dedicated OEM partition for
128 OEM-specific properties. Only meaningful when -o is specified.
Tao Bao8608cde2016-02-25 19:49:55 -0800129
Tao Bao30df8b42018-04-23 15:32:53 -0700130 --stash_threshold <float>
131 Specify the threshold that will be used to compute the maximum allowed
132 stash size (defaults to 0.8).
Doug Zongkerdbfaae52009-04-21 17:12:54 -0700133
Tao Bao30df8b42018-04-23 15:32:53 -0700134 -t (--worker_threads) <int>
135 Specify the number of worker-threads that will be used when generating
136 patches for incremental updates (defaults to 3).
Tao Bao3e6161a2017-02-28 11:48:48 -0800137
Tao Bao30df8b42018-04-23 15:32:53 -0700138 --verify
139 Verify the checksums of the updated system and vendor (if any) partitions.
140 Non-A/B incremental OTAs only.
Doug Zongker1c390a22009-05-14 19:06:36 -0700141
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800142 -2 (--two_step)
Tao Bao30df8b42018-04-23 15:32:53 -0700143 Generate a 'two-step' OTA package, where recovery is updated first, so
144 that any changes made to the system partition are done using the new
145 recovery (new kernel, etc.).
146
147A/B OTA specific options
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800148
Tianjie Xu1b079832019-08-28 12:19:23 -0700149 --disable_fec_computation
150 Disable the on device FEC data computation for incremental updates.
151
Tao Baof7140c02018-01-30 17:09:24 -0800152 --include_secondary
153 Additionally include the payload for secondary slot images (default:
154 False). Only meaningful when generating A/B OTAs.
155
156 By default, an A/B OTA package doesn't contain the images for the
157 secondary slot (e.g. system_other.img). Specifying this flag allows
158 generating a separate payload that will install secondary slot images.
159
160 Such a package needs to be applied in a two-stage manner, with a reboot
161 in-between. During the first stage, the updater applies the primary
162 payload only. Upon finishing, it reboots the device into the newly updated
163 slot. It then continues to install the secondary payload to the inactive
164 slot, but without switching the active slot at the end (needs the matching
165 support in update_engine, i.e. SWITCH_SLOT_ON_REBOOT flag).
166
167 Due to the special install procedure, the secondary payload will be always
168 generated as a full payload.
169
Tao Baodea0f8b2016-06-20 17:55:06 -0700170 --payload_signer <signer>
171 Specify the signer when signing the payload and metadata for A/B OTAs.
172 By default (i.e. without this flag), it calls 'openssl pkeyutl' to sign
173 with the package private key. If the private key cannot be accessed
174 directly, a payload signer that knows how to do that should be specified.
175 The signer will be supplied with "-inkey <path_to_key>",
176 "-in <input_file>" and "-out <output_file>" parameters.
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700177
178 --payload_signer_args <args>
179 Specify the arguments needed for payload signer.
Tao Bao15a146a2018-02-21 16:06:59 -0800180
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700181 --payload_signer_maximum_signature_size <signature_size>
182 The maximum signature size (in bytes) that would be generated by the given
183 payload signer. Only meaningful when custom payload signer is specified
184 via '--payload_signer'.
185 If the signer uses a RSA key, this should be the number of bytes to
186 represent the modulus. If it uses an EC key, this is the size of a
187 DER-encoded ECDSA signature.
188
xunchang376cc7c2019-04-08 23:04:58 -0700189 --payload_signer_key_size <key_size>
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700190 Deprecated. Use the '--payload_signer_maximum_signature_size' instead.
xunchang376cc7c2019-04-08 23:04:58 -0700191
Tianjied6867162020-05-10 14:30:13 -0700192 --boot_variable_file <path>
193 A file that contains the possible values of ro.boot.* properties. It's
194 used to calculate the possible runtime fingerprints when some
195 ro.product.* properties are overridden by the 'import' statement.
196 The file expects one property per line, and each line has the following
197 format: 'prop_name=value1,value2'. e.g. 'ro.boot.product.sku=std,pro'
198
Tao Bao15a146a2018-02-21 16:06:59 -0800199 --skip_postinstall
200 Skip the postinstall hooks when generating an A/B OTA package (default:
201 False). Note that this discards ALL the hooks, including non-optional
202 ones. Should only be used if caller knows it's safe to do so (e.g. all the
203 postinstall work is to dexopt apps and a data wipe will happen immediately
204 after). Only meaningful when generating A/B OTAs.
Yifan Hong38ab4d82020-06-18 15:19:56 -0700205
206 --partial "<PARTITION> [<PARTITION>[...]]"
207 Generate partial updates, overriding ab_partitions list with the given
208 list.
Hongguang Chen49ab1b902020-10-19 14:15:43 -0700209
210 --custom_image <custom_partition=custom_image>
211 Use the specified custom_image to update custom_partition when generating
212 an A/B OTA package. e.g. "--custom_image oem=oem.img --custom_image
213 cus=cus_test.img"
David Anderson45b42302021-03-11 12:58:32 -0800214
215 --disable_vabc
216 Disable Virtual A/B Compression, for builds that have compression enabled
217 by default.
Kelvin Zhang2a3e5b12021-05-04 18:20:34 -0400218
219 --vabc_downgrade
220 Don't disable Virtual A/B Compression for downgrading OTAs.
221 For VABC downgrades, we must finish merging before doing data wipe, and
222 since data wipe is required for downgrading OTA, this might cause long
223 wait time in recovery.
Kelvin Zhang1250bca2021-08-27 15:10:27 -0700224
225 --enable_vabc_xor
226 Enable the VABC xor feature. Will reduce space requirements for OTA
227
Tianjiee7ab38d2021-09-08 19:09:38 -0700228 --force_minor_version
229 Override the update_engine minor version for delta generation.
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -0700230
231 --compressor_types
232 A colon ':' separated list of compressors. Allowed values are bz2 and brotli.
Doug Zongkereef39442009-04-02 12:14:19 -0700233"""
234
Tao Bao89fbb0f2017-01-10 10:47:58 -0800235from __future__ import print_function
236
Tao Bao32fcdab2018-10-12 10:30:39 -0700237import logging
Doug Zongkerfc44a512014-08-26 13:10:25 -0700238import multiprocessing
Kelvin Zhang65029a22020-11-03 10:07:51 -0500239import os
Tao Bao2dd1c482017-02-03 16:49:39 -0800240import os.path
Kelvin Zhang65029a22020-11-03 10:07:51 -0500241import re
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700242import shlex
Tao Bao15a146a2018-02-21 16:06:59 -0800243import shutil
Tao Bao85f16982018-03-08 16:28:33 -0800244import struct
Kelvin Zhang65029a22020-11-03 10:07:51 -0500245import subprocess
Tao Bao481bab82017-12-21 11:23:09 -0800246import sys
Doug Zongkereef39442009-04-02 12:14:19 -0700247import zipfile
248
Kelvin Zhang766eea72021-06-03 09:36:08 -0400249import care_map_pb2
Doug Zongkereef39442009-04-02 12:14:19 -0700250import common
Kelvin Zhang2e417382020-08-20 11:33:11 -0400251import ota_utils
Kelvin Zhang22c687c2021-01-21 10:51:57 -0500252from ota_utils import (UNZIP_PATTERN, FinalizeMetadata, GetPackageMetadata,
Kelvin Zhang25ab9982021-06-22 09:51:34 -0400253 PropertyFiles, SECURITY_PATCH_LEVEL_PROP_NAME, GetZipEntryOffset)
Kelvin Zhang0876c412020-06-23 15:06:58 -0400254import target_files_diff
Kelvin Zhangcff4d762020-07-29 16:37:51 -0400255from check_target_files_vintf import CheckVintfIfTrebleEnabled
256from non_ab_ota import GenerateNonAbOtaPackage
Kelvin Zhang0876c412020-06-23 15:06:58 -0400257
Tao Bao481bab82017-12-21 11:23:09 -0800258if sys.hexversion < 0x02070000:
259 print("Python 2.7 or newer is required.", file=sys.stderr)
260 sys.exit(1)
261
Tao Bao32fcdab2018-10-12 10:30:39 -0700262logger = logging.getLogger(__name__)
Tao Bao481bab82017-12-21 11:23:09 -0800263
Kelvin Zhang2e417382020-08-20 11:33:11 -0400264OPTIONS = ota_utils.OPTIONS
Michael Runge63f01de2014-10-28 19:24:19 -0700265OPTIONS.verify = False
Doug Zongkereef39442009-04-02 12:14:19 -0700266OPTIONS.patch_threshold = 0.95
Doug Zongkerdbfaae52009-04-21 17:12:54 -0700267OPTIONS.wipe_user_data = False
Doug Zongker1c390a22009-05-14 19:06:36 -0700268OPTIONS.extra_script = None
Doug Zongkerfc44a512014-08-26 13:10:25 -0700269OPTIONS.worker_threads = multiprocessing.cpu_count() // 2
270if OPTIONS.worker_threads == 0:
271 OPTIONS.worker_threads = 1
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800272OPTIONS.two_step = False
Tao Baof7140c02018-01-30 17:09:24 -0800273OPTIONS.include_secondary = False
Tao Bao457cbf62017-03-06 09:56:01 -0800274OPTIONS.block_based = True
Doug Zongker25568482014-03-03 10:21:27 -0800275OPTIONS.updater_binary = None
Tianjie Xu9afb2212020-05-10 21:48:15 +0000276OPTIONS.oem_dicts = None
Michael Runge6e836112014-04-15 17:40:21 -0700277OPTIONS.oem_source = None
Tao Bao8608cde2016-02-25 19:49:55 -0800278OPTIONS.oem_no_mount = False
Tao Bao43078aa2015-04-21 14:32:35 -0700279OPTIONS.full_radio = False
leozwangaa6c1a12015-08-14 10:57:58 -0700280OPTIONS.full_bootloader = False
Tao Baod47d8e12015-05-21 14:09:49 -0700281# Stash size cannot exceed cache_size * threshold.
282OPTIONS.cache_size = None
283OPTIONS.stash_threshold = 0.8
Tao Baod62c6032015-11-30 09:40:20 -0800284OPTIONS.log_diff = None
Tao Baodea0f8b2016-06-20 17:55:06 -0700285OPTIONS.payload_signer = None
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700286OPTIONS.payload_signer_args = []
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700287OPTIONS.payload_signer_maximum_signature_size = None
Tao Bao5f8ff932017-03-21 22:35:00 -0700288OPTIONS.extracted_input = None
Tao Bao15a146a2018-02-21 16:06:59 -0800289OPTIONS.skip_postinstall = False
xunchangabfa2652019-02-19 16:27:10 -0800290OPTIONS.skip_compatibility_check = False
Tianjie Xu1b079832019-08-28 12:19:23 -0700291OPTIONS.disable_fec_computation = False
Kelvin Zhangcaf7bbc2020-11-20 14:09:42 -0500292OPTIONS.disable_verity_computation = False
Yifan Hong38ab4d82020-06-18 15:19:56 -0700293OPTIONS.partial = None
Hongguang Chen49ab1b902020-10-19 14:15:43 -0700294OPTIONS.custom_images = {}
Kelvin Zhangbbfa1822021-02-03 17:19:44 -0500295OPTIONS.disable_vabc = False
Kelvin Zhang80ff4662021-02-08 19:57:57 -0500296OPTIONS.spl_downgrade = False
Kelvin Zhang2a3e5b12021-05-04 18:20:34 -0400297OPTIONS.vabc_downgrade = False
Kelvin Zhang1250bca2021-08-27 15:10:27 -0700298OPTIONS.enable_vabc_xor = True
Tianjiee7ab38d2021-09-08 19:09:38 -0700299OPTIONS.force_minor_version = None
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -0700300OPTIONS.compressor_types = None
Tao Bao8dcf7382015-05-21 14:09:49 -0700301
Tao Bao15a146a2018-02-21 16:06:59 -0800302POSTINSTALL_CONFIG = 'META/postinstall_config.txt'
Yifan Hong50e79542018-11-08 17:44:12 -0800303DYNAMIC_PARTITION_INFO = 'META/dynamic_partitions_info.txt'
Yifan Hongb433eba2019-03-06 12:42:53 -0800304AB_PARTITIONS = 'META/ab_partitions.txt'
Kelvin Zhangcff4d762020-07-29 16:37:51 -0400305
Tao Baof0c4aa22018-04-30 20:29:30 -0700306# Files to be unzipped for target diffing purpose.
307TARGET_DIFFING_UNZIP_PATTERN = ['BOOT', 'RECOVERY', 'SYSTEM/*', 'VENDOR/*',
Yifan Hongcfb917a2020-05-07 14:58:20 -0700308 'PRODUCT/*', 'SYSTEM_EXT/*', 'ODM/*',
Yifan Hongf496f1b2020-07-15 16:52:59 -0700309 'VENDOR_DLKM/*', 'ODM_DLKM/*']
Yifan Hongb433eba2019-03-06 12:42:53 -0800310RETROFIT_DAP_UNZIP_PATTERN = ['OTA/super_*.img', AB_PARTITIONS]
Tao Bao3e759462019-09-17 22:43:11 -0700311
312# Images to be excluded from secondary payload. We essentially only keep
313# 'system_other' and bootloader partitions.
314SECONDARY_PAYLOAD_SKIPPED_IMAGES = [
Yifan Hongc08cbf02020-09-15 19:07:39 +0000315 'boot', 'dtbo', 'modem', 'odm', 'odm_dlkm', 'product', 'radio', 'recovery',
Tianjiec3850642020-05-13 14:47:31 -0700316 'system_ext', 'vbmeta', 'vbmeta_system', 'vbmeta_vendor', 'vendor',
Yifan Hongf496f1b2020-07-15 16:52:59 -0700317 'vendor_boot']
Tao Bao6b0b2f92017-03-05 11:38:11 -0800318
Kelvin Zhang05ff7052021-02-10 09:13:26 -0500319
Tao Baofabe0832018-01-17 15:52:28 -0800320class PayloadSigner(object):
321 """A class that wraps the payload signing works.
322
323 When generating a Payload, hashes of the payload and metadata files will be
324 signed with the device key, either by calling an external payload signer or
325 by calling openssl with the package key. This class provides a unified
326 interface, so that callers can just call PayloadSigner.Sign().
327
328 If an external payload signer has been specified (OPTIONS.payload_signer), it
329 calls the signer with the provided args (OPTIONS.payload_signer_args). Note
330 that the signing key should be provided as part of the payload_signer_args.
331 Otherwise without an external signer, it uses the package key
332 (OPTIONS.package_key) and calls openssl for the signing works.
333 """
334
335 def __init__(self):
336 if OPTIONS.payload_signer is None:
337 # Prepare the payload signing key.
338 private_key = OPTIONS.package_key + OPTIONS.private_key_suffix
339 pw = OPTIONS.key_passwords[OPTIONS.package_key]
340
341 cmd = ["openssl", "pkcs8", "-in", private_key, "-inform", "DER"]
342 cmd.extend(["-passin", "pass:" + pw] if pw else ["-nocrypt"])
343 signing_key = common.MakeTempFile(prefix="key-", suffix=".key")
344 cmd.extend(["-out", signing_key])
Tao Baobec89c12018-10-15 11:53:28 -0700345 common.RunAndCheckOutput(cmd, verbose=False)
Tao Baofabe0832018-01-17 15:52:28 -0800346
347 self.signer = "openssl"
348 self.signer_args = ["pkeyutl", "-sign", "-inkey", signing_key,
349 "-pkeyopt", "digest:sha256"]
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700350 self.maximum_signature_size = self._GetMaximumSignatureSizeInBytes(
351 signing_key)
Tao Baofabe0832018-01-17 15:52:28 -0800352 else:
353 self.signer = OPTIONS.payload_signer
354 self.signer_args = OPTIONS.payload_signer_args
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700355 if OPTIONS.payload_signer_maximum_signature_size:
356 self.maximum_signature_size = int(
357 OPTIONS.payload_signer_maximum_signature_size)
xunchang376cc7c2019-04-08 23:04:58 -0700358 else:
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700359 # The legacy config uses RSA2048 keys.
360 logger.warning("The maximum signature size for payload signer is not"
361 " set, default to 256 bytes.")
362 self.maximum_signature_size = 256
xunchang376cc7c2019-04-08 23:04:58 -0700363
364 @staticmethod
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700365 def _GetMaximumSignatureSizeInBytes(signing_key):
366 out_signature_size_file = common.MakeTempFile("signature_size")
367 cmd = ["delta_generator", "--out_maximum_signature_size_file={}".format(
368 out_signature_size_file), "--private_key={}".format(signing_key)]
369 common.RunAndCheckOutput(cmd)
370 with open(out_signature_size_file) as f:
371 signature_size = f.read().rstrip()
Luca Stefani88e1a142020-03-27 14:05:12 +0100372 logger.info("%s outputs the maximum signature size: %s", cmd[0],
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700373 signature_size)
374 return int(signature_size)
Tao Baofabe0832018-01-17 15:52:28 -0800375
376 def Sign(self, in_file):
377 """Signs the given input file. Returns the output filename."""
378 out_file = common.MakeTempFile(prefix="signed-", suffix=".bin")
379 cmd = [self.signer] + self.signer_args + ['-in', in_file, '-out', out_file]
Tao Bao718faed2019-08-02 13:24:19 -0700380 common.RunAndCheckOutput(cmd)
Tao Baofabe0832018-01-17 15:52:28 -0800381 return out_file
382
383
Tao Bao40b18822018-01-30 18:19:04 -0800384class Payload(object):
385 """Manages the creation and the signing of an A/B OTA Payload."""
386
387 PAYLOAD_BIN = 'payload.bin'
388 PAYLOAD_PROPERTIES_TXT = 'payload_properties.txt'
Tao Baof7140c02018-01-30 17:09:24 -0800389 SECONDARY_PAYLOAD_BIN = 'secondary/payload.bin'
390 SECONDARY_PAYLOAD_PROPERTIES_TXT = 'secondary/payload_properties.txt'
Tao Bao40b18822018-01-30 18:19:04 -0800391
Tao Bao667ff572018-02-10 00:02:40 -0800392 def __init__(self, secondary=False):
393 """Initializes a Payload instance.
394
395 Args:
396 secondary: Whether it's generating a secondary payload (default: False).
397 """
Tao Bao40b18822018-01-30 18:19:04 -0800398 self.payload_file = None
399 self.payload_properties = None
Tao Bao667ff572018-02-10 00:02:40 -0800400 self.secondary = secondary
Tao Bao40b18822018-01-30 18:19:04 -0800401
Tao Baof0c4aa22018-04-30 20:29:30 -0700402 def _Run(self, cmd): # pylint: disable=no-self-use
Tao Bao718faed2019-08-02 13:24:19 -0700403 # Don't pipe (buffer) the output if verbose is set. Let
404 # brillo_update_payload write to stdout/stderr directly, so its progress can
405 # be monitored.
406 if OPTIONS.verbose:
407 common.RunAndCheckOutput(cmd, stdout=None, stderr=None)
408 else:
409 common.RunAndCheckOutput(cmd)
410
Tao Bao40b18822018-01-30 18:19:04 -0800411 def Generate(self, target_file, source_file=None, additional_args=None):
412 """Generates a payload from the given target-files zip(s).
413
414 Args:
415 target_file: The filename of the target build target-files zip.
416 source_file: The filename of the source build target-files zip; or None if
417 generating a full OTA.
418 additional_args: A list of additional args that should be passed to
419 brillo_update_payload script; or None.
420 """
421 if additional_args is None:
422 additional_args = []
423
424 payload_file = common.MakeTempFile(prefix="payload-", suffix=".bin")
425 cmd = ["brillo_update_payload", "generate",
426 "--payload", payload_file,
427 "--target_image", target_file]
428 if source_file is not None:
429 cmd.extend(["--source_image", source_file])
Tianjie Xu1b079832019-08-28 12:19:23 -0700430 if OPTIONS.disable_fec_computation:
431 cmd.extend(["--disable_fec_computation", "true"])
Kelvin Zhangcaf7bbc2020-11-20 14:09:42 -0500432 if OPTIONS.disable_verity_computation:
433 cmd.extend(["--disable_verity_computation", "true"])
Tao Bao40b18822018-01-30 18:19:04 -0800434 cmd.extend(additional_args)
Tao Bao718faed2019-08-02 13:24:19 -0700435 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800436
437 self.payload_file = payload_file
438 self.payload_properties = None
439
440 def Sign(self, payload_signer):
441 """Generates and signs the hashes of the payload and metadata.
442
443 Args:
444 payload_signer: A PayloadSigner() instance that serves the signing work.
445
446 Raises:
447 AssertionError: On any failure when calling brillo_update_payload script.
448 """
449 assert isinstance(payload_signer, PayloadSigner)
450
451 # 1. Generate hashes of the payload and metadata files.
452 payload_sig_file = common.MakeTempFile(prefix="sig-", suffix=".bin")
453 metadata_sig_file = common.MakeTempFile(prefix="sig-", suffix=".bin")
454 cmd = ["brillo_update_payload", "hash",
455 "--unsigned_payload", self.payload_file,
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700456 "--signature_size", str(payload_signer.maximum_signature_size),
Tao Bao40b18822018-01-30 18:19:04 -0800457 "--metadata_hash_file", metadata_sig_file,
458 "--payload_hash_file", payload_sig_file]
Tao Bao718faed2019-08-02 13:24:19 -0700459 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800460
461 # 2. Sign the hashes.
462 signed_payload_sig_file = payload_signer.Sign(payload_sig_file)
463 signed_metadata_sig_file = payload_signer.Sign(metadata_sig_file)
464
465 # 3. Insert the signatures back into the payload file.
466 signed_payload_file = common.MakeTempFile(prefix="signed-payload-",
467 suffix=".bin")
468 cmd = ["brillo_update_payload", "sign",
469 "--unsigned_payload", self.payload_file,
470 "--payload", signed_payload_file,
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700471 "--signature_size", str(payload_signer.maximum_signature_size),
Tao Bao40b18822018-01-30 18:19:04 -0800472 "--metadata_signature_file", signed_metadata_sig_file,
473 "--payload_signature_file", signed_payload_sig_file]
Tao Bao718faed2019-08-02 13:24:19 -0700474 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800475
476 # 4. Dump the signed payload properties.
477 properties_file = common.MakeTempFile(prefix="payload-properties-",
478 suffix=".txt")
479 cmd = ["brillo_update_payload", "properties",
480 "--payload", signed_payload_file,
481 "--properties_file", properties_file]
Tao Bao718faed2019-08-02 13:24:19 -0700482 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800483
Tao Bao667ff572018-02-10 00:02:40 -0800484 if self.secondary:
485 with open(properties_file, "a") as f:
486 f.write("SWITCH_SLOT_ON_REBOOT=0\n")
487
Tao Bao40b18822018-01-30 18:19:04 -0800488 if OPTIONS.wipe_user_data:
489 with open(properties_file, "a") as f:
490 f.write("POWERWASH=1\n")
491
492 self.payload_file = signed_payload_file
493 self.payload_properties = properties_file
494
Tao Bao667ff572018-02-10 00:02:40 -0800495 def WriteToZip(self, output_zip):
Tao Bao40b18822018-01-30 18:19:04 -0800496 """Writes the payload to the given zip.
497
498 Args:
499 output_zip: The output ZipFile instance.
500 """
501 assert self.payload_file is not None
502 assert self.payload_properties is not None
503
Tao Bao667ff572018-02-10 00:02:40 -0800504 if self.secondary:
Tao Baof7140c02018-01-30 17:09:24 -0800505 payload_arcname = Payload.SECONDARY_PAYLOAD_BIN
506 payload_properties_arcname = Payload.SECONDARY_PAYLOAD_PROPERTIES_TXT
507 else:
508 payload_arcname = Payload.PAYLOAD_BIN
509 payload_properties_arcname = Payload.PAYLOAD_PROPERTIES_TXT
510
Tao Bao40b18822018-01-30 18:19:04 -0800511 # Add the signed payload file and properties into the zip. In order to
512 # support streaming, we pack them as ZIP_STORED. So these entries can be
513 # read directly with the offset and length pairs.
Tao Baof7140c02018-01-30 17:09:24 -0800514 common.ZipWrite(output_zip, self.payload_file, arcname=payload_arcname,
Tao Bao40b18822018-01-30 18:19:04 -0800515 compress_type=zipfile.ZIP_STORED)
516 common.ZipWrite(output_zip, self.payload_properties,
Tao Baof7140c02018-01-30 17:09:24 -0800517 arcname=payload_properties_arcname,
Tao Bao40b18822018-01-30 18:19:04 -0800518 compress_type=zipfile.ZIP_STORED)
519
520
Tao Bao481bab82017-12-21 11:23:09 -0800521def _LoadOemDicts(oem_source):
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800522 """Returns the list of loaded OEM properties dict."""
Tao Bao481bab82017-12-21 11:23:09 -0800523 if not oem_source:
524 return None
525
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800526 oem_dicts = []
Tao Bao481bab82017-12-21 11:23:09 -0800527 for oem_file in oem_source:
528 with open(oem_file) as fp:
529 oem_dicts.append(common.LoadDictionaryFromLines(fp.readlines()))
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800530 return oem_dicts
Doug Zongkereef39442009-04-02 12:14:19 -0700531
Doug Zongkereef39442009-04-02 12:14:19 -0700532
Tao Baod3fc38a2018-03-08 16:09:01 -0800533class StreamingPropertyFiles(PropertyFiles):
534 """A subclass for computing the property-files for streaming A/B OTAs."""
535
536 def __init__(self):
537 super(StreamingPropertyFiles, self).__init__()
538 self.name = 'ota-streaming-property-files'
539 self.required = (
540 # payload.bin and payload_properties.txt must exist.
541 'payload.bin',
542 'payload_properties.txt',
543 )
544 self.optional = (
Tianjied868c122021-06-07 16:11:47 -0700545 # apex_info.pb isn't directly used in the update flow
546 'apex_info.pb',
Tianjie Xu4c05f4a2018-09-14 16:24:41 -0700547 # care_map is available only if dm-verity is enabled.
548 'care_map.pb',
Tao Baod3fc38a2018-03-08 16:09:01 -0800549 'care_map.txt',
550 # compatibility.zip is available only if target supports Treble.
551 'compatibility.zip',
552 )
553
554
Tao Bao85f16982018-03-08 16:28:33 -0800555class AbOtaPropertyFiles(StreamingPropertyFiles):
556 """The property-files for A/B OTA that includes payload_metadata.bin info.
557
558 Since P, we expose one more token (aka property-file), in addition to the ones
559 for streaming A/B OTA, for a virtual entry of 'payload_metadata.bin'.
560 'payload_metadata.bin' is the header part of a payload ('payload.bin'), which
561 doesn't exist as a separate ZIP entry, but can be used to verify if the
562 payload can be applied on the given device.
563
564 For backward compatibility, we keep both of the 'ota-streaming-property-files'
565 and the newly added 'ota-property-files' in P. The new token will only be
566 available in 'ota-property-files'.
567 """
568
569 def __init__(self):
570 super(AbOtaPropertyFiles, self).__init__()
571 self.name = 'ota-property-files'
572
573 def _GetPrecomputed(self, input_zip):
574 offset, size = self._GetPayloadMetadataOffsetAndSize(input_zip)
575 return ['payload_metadata.bin:{}:{}'.format(offset, size)]
576
577 @staticmethod
578 def _GetPayloadMetadataOffsetAndSize(input_zip):
579 """Computes the offset and size of the payload metadata for a given package.
580
581 (From system/update_engine/update_metadata.proto)
582 A delta update file contains all the deltas needed to update a system from
583 one specific version to another specific version. The update format is
584 represented by this struct pseudocode:
585
586 struct delta_update_file {
587 char magic[4] = "CrAU";
588 uint64 file_format_version;
589 uint64 manifest_size; // Size of protobuf DeltaArchiveManifest
590
591 // Only present if format_version > 1:
592 uint32 metadata_signature_size;
593
594 // The Bzip2 compressed DeltaArchiveManifest
595 char manifest[metadata_signature_size];
596
597 // The signature of the metadata (from the beginning of the payload up to
598 // this location, not including the signature itself). This is a
599 // serialized Signatures message.
600 char medatada_signature_message[metadata_signature_size];
601
602 // Data blobs for files, no specific format. The specific offset
603 // and length of each data blob is recorded in the DeltaArchiveManifest.
604 struct {
605 char data[];
606 } blobs[];
607
608 // These two are not signed:
609 uint64 payload_signatures_message_size;
610 char payload_signatures_message[];
611 };
612
613 'payload-metadata.bin' contains all the bytes from the beginning of the
614 payload, till the end of 'medatada_signature_message'.
615 """
616 payload_info = input_zip.getinfo('payload.bin')
Kelvin Zhang25ab9982021-06-22 09:51:34 -0400617 (payload_offset, payload_size) = GetZipEntryOffset(input_zip, payload_info)
Tao Bao85f16982018-03-08 16:28:33 -0800618
Kelvin Zhang25ab9982021-06-22 09:51:34 -0400619 # Read the underlying raw zipfile at specified offset
620 payload_fp = input_zip.fp
621 payload_fp.seek(payload_offset)
622 header_bin = payload_fp.read(24)
Tao Bao85f16982018-03-08 16:28:33 -0800623
624 # network byte order (big-endian)
625 header = struct.unpack("!IQQL", header_bin)
626
627 # 'CrAU'
628 magic = header[0]
Kelvin Zhang25ab9982021-06-22 09:51:34 -0400629 assert magic == 0x43724155, "Invalid magic: {:x}, computed offset {}" \
630 .format(magic, payload_offset)
Tao Bao85f16982018-03-08 16:28:33 -0800631
632 manifest_size = header[2]
633 metadata_signature_size = header[3]
634 metadata_total = 24 + manifest_size + metadata_signature_size
635 assert metadata_total < payload_size
636
637 return (payload_offset, metadata_total)
638
639
Yifan Hong38ab4d82020-06-18 15:19:56 -0700640def UpdatesInfoForSpecialUpdates(content, partitions_filter,
641 delete_keys=None):
642 """ Updates info file for secondary payload generation, partial update, etc.
643
644 Scan each line in the info file, and remove the unwanted partitions from
645 the dynamic partition list in the related properties. e.g.
646 "super_google_dynamic_partitions_partition_list=system vendor product"
647 will become "super_google_dynamic_partitions_partition_list=system".
648
649 Args:
650 content: The content of the input info file. e.g. misc_info.txt.
651 partitions_filter: A function to filter the desired partitions from a given
652 list
653 delete_keys: A list of keys to delete in the info file
654
655 Returns:
656 A string of the updated info content.
657 """
658
659 output_list = []
660 # The suffix in partition_list variables that follows the name of the
661 # partition group.
662 list_suffix = 'partition_list'
663 for line in content.splitlines():
664 if line.startswith('#') or '=' not in line:
665 output_list.append(line)
666 continue
667 key, value = line.strip().split('=', 1)
668
669 if delete_keys and key in delete_keys:
670 pass
671 elif key.endswith(list_suffix):
672 partitions = value.split()
673 # TODO for partial update, partitions in the same group must be all
674 # updated or all omitted
675 partitions = filter(partitions_filter, partitions)
676 output_list.append('{}={}'.format(key, ' '.join(partitions)))
677 else:
678 output_list.append(line)
679 return '\n'.join(output_list)
680
681
Tao Bao15a146a2018-02-21 16:06:59 -0800682def GetTargetFilesZipForSecondaryImages(input_file, skip_postinstall=False):
Tao Baof7140c02018-01-30 17:09:24 -0800683 """Returns a target-files.zip file for generating secondary payload.
684
685 Although the original target-files.zip already contains secondary slot
686 images (i.e. IMAGES/system_other.img), we need to rename the files to the
687 ones without _other suffix. Note that we cannot instead modify the names in
688 META/ab_partitions.txt, because there are no matching partitions on device.
689
690 For the partitions that don't have secondary images, the ones for primary
691 slot will be used. This is to ensure that we always have valid boot, vbmeta,
692 bootloader images in the inactive slot.
693
694 Args:
695 input_file: The input target-files.zip file.
Tao Bao15a146a2018-02-21 16:06:59 -0800696 skip_postinstall: Whether to skip copying the postinstall config file.
Tao Baof7140c02018-01-30 17:09:24 -0800697
698 Returns:
699 The filename of the target-files.zip for generating secondary payload.
700 """
Tianjie Xu1c808002019-09-11 00:29:26 -0700701
702 def GetInfoForSecondaryImages(info_file):
Yifan Hong38ab4d82020-06-18 15:19:56 -0700703 """Updates info file for secondary payload generation."""
Tianjie Xu1c808002019-09-11 00:29:26 -0700704 with open(info_file) as f:
Yifan Hong38ab4d82020-06-18 15:19:56 -0700705 content = f.read()
706 # Remove virtual_ab flag from secondary payload so that OTA client
707 # don't use snapshots for secondary update
708 delete_keys = ['virtual_ab', "virtual_ab_retrofit"]
709 return UpdatesInfoForSpecialUpdates(
710 content, lambda p: p not in SECONDARY_PAYLOAD_SKIPPED_IMAGES,
711 delete_keys)
Tianjie Xu1c808002019-09-11 00:29:26 -0700712
Tao Baof7140c02018-01-30 17:09:24 -0800713 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
714 target_zip = zipfile.ZipFile(target_file, 'w', allowZip64=True)
715
Kelvin Zhang928c2342020-09-22 16:15:57 -0400716 with zipfile.ZipFile(input_file, 'r', allowZip64=True) as input_zip:
Tao Baodba59ee2018-01-09 13:21:02 -0800717 infolist = input_zip.infolist()
Tao Bao12489802018-07-12 14:47:38 -0700718
Tao Bao0ff15de2019-03-20 11:26:06 -0700719 input_tmp = common.UnzipTemp(input_file, UNZIP_PATTERN)
Tao Baodba59ee2018-01-09 13:21:02 -0800720 for info in infolist:
Tao Baof7140c02018-01-30 17:09:24 -0800721 unzipped_file = os.path.join(input_tmp, *info.filename.split('/'))
722 if info.filename == 'IMAGES/system_other.img':
723 common.ZipWrite(target_zip, unzipped_file, arcname='IMAGES/system.img')
724
725 # Primary images and friends need to be skipped explicitly.
726 elif info.filename in ('IMAGES/system.img',
727 'IMAGES/system.map'):
728 pass
Tao Bao3e759462019-09-17 22:43:11 -0700729
730 # Copy images that are not in SECONDARY_PAYLOAD_SKIPPED_IMAGES.
731 elif info.filename.startswith(('IMAGES/', 'RADIO/')):
732 image_name = os.path.basename(info.filename)
733 if image_name not in ['{}.img'.format(partition) for partition in
734 SECONDARY_PAYLOAD_SKIPPED_IMAGES]:
735 common.ZipWrite(target_zip, unzipped_file, arcname=info.filename)
Tao Baof7140c02018-01-30 17:09:24 -0800736
Tao Bao15a146a2018-02-21 16:06:59 -0800737 # Skip copying the postinstall config if requested.
738 elif skip_postinstall and info.filename == POSTINSTALL_CONFIG:
739 pass
740
Tianjie Xu1c808002019-09-11 00:29:26 -0700741 elif info.filename.startswith('META/'):
742 # Remove the unnecessary partitions for secondary images from the
743 # ab_partitions file.
744 if info.filename == AB_PARTITIONS:
745 with open(unzipped_file) as f:
746 partition_list = f.read().splitlines()
747 partition_list = [partition for partition in partition_list if partition
Tao Bao3e759462019-09-17 22:43:11 -0700748 and partition not in SECONDARY_PAYLOAD_SKIPPED_IMAGES]
Kelvin Zhang0876c412020-06-23 15:06:58 -0400749 common.ZipWriteStr(target_zip, info.filename,
750 '\n'.join(partition_list))
Tianjie Xu1c808002019-09-11 00:29:26 -0700751 # Remove the unnecessary partitions from the dynamic partitions list.
752 elif (info.filename == 'META/misc_info.txt' or
753 info.filename == DYNAMIC_PARTITION_INFO):
754 modified_info = GetInfoForSecondaryImages(unzipped_file)
755 common.ZipWriteStr(target_zip, info.filename, modified_info)
756 else:
757 common.ZipWrite(target_zip, unzipped_file, arcname=info.filename)
Tao Baof7140c02018-01-30 17:09:24 -0800758
Tao Baof7140c02018-01-30 17:09:24 -0800759 common.ZipClose(target_zip)
760
761 return target_file
762
763
Tao Bao15a146a2018-02-21 16:06:59 -0800764def GetTargetFilesZipWithoutPostinstallConfig(input_file):
765 """Returns a target-files.zip that's not containing postinstall_config.txt.
766
767 This allows brillo_update_payload script to skip writing all the postinstall
768 hooks in the generated payload. The input target-files.zip file will be
769 duplicated, with 'META/postinstall_config.txt' skipped. If input_file doesn't
770 contain the postinstall_config.txt entry, the input file will be returned.
771
772 Args:
773 input_file: The input target-files.zip filename.
774
775 Returns:
776 The filename of target-files.zip that doesn't contain postinstall config.
777 """
778 # We should only make a copy if postinstall_config entry exists.
Kelvin Zhang928c2342020-09-22 16:15:57 -0400779 with zipfile.ZipFile(input_file, 'r', allowZip64=True) as input_zip:
Tao Bao15a146a2018-02-21 16:06:59 -0800780 if POSTINSTALL_CONFIG not in input_zip.namelist():
781 return input_file
782
783 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
784 shutil.copyfile(input_file, target_file)
785 common.ZipDelete(target_file, POSTINSTALL_CONFIG)
786 return target_file
787
Kelvin Zhang06400172021-03-05 15:42:03 -0500788
Kelvin Zhanga59bb272020-10-30 12:52:25 -0400789def ParseInfoDict(target_file_path):
790 with zipfile.ZipFile(target_file_path, 'r', allowZip64=True) as zfp:
791 return common.LoadInfoDict(zfp)
Tao Bao15a146a2018-02-21 16:06:59 -0800792
Kelvin Zhang06400172021-03-05 15:42:03 -0500793
Yifan Hong38ab4d82020-06-18 15:19:56 -0700794def GetTargetFilesZipForPartialUpdates(input_file, ab_partitions):
795 """Returns a target-files.zip for partial ota update package generation.
796
797 This function modifies ab_partitions list with the desired partitions before
798 calling the brillo_update_payload script. It also cleans up the reference to
799 the excluded partitions in the info file, e.g misc_info.txt.
800
801 Args:
802 input_file: The input target-files.zip filename.
803 ab_partitions: A list of partitions to include in the partial update
804
805 Returns:
806 The filename of target-files.zip used for partial ota update.
807 """
808
809 def AddImageForPartition(partition_name):
810 """Add the archive name for a given partition to the copy list."""
811 for prefix in ['IMAGES', 'RADIO']:
812 image_path = '{}/{}.img'.format(prefix, partition_name)
813 if image_path in namelist:
814 copy_entries.append(image_path)
815 map_path = '{}/{}.map'.format(prefix, partition_name)
816 if map_path in namelist:
817 copy_entries.append(map_path)
818 return
819
820 raise ValueError("Cannot find {} in input zipfile".format(partition_name))
821
822 with zipfile.ZipFile(input_file, allowZip64=True) as input_zip:
Kelvin Zhanga59bb272020-10-30 12:52:25 -0400823 original_ab_partitions = input_zip.read(
824 AB_PARTITIONS).decode().splitlines()
Yifan Hong38ab4d82020-06-18 15:19:56 -0700825 namelist = input_zip.namelist()
826
827 unrecognized_partitions = [partition for partition in ab_partitions if
828 partition not in original_ab_partitions]
829 if unrecognized_partitions:
830 raise ValueError("Unrecognized partitions when generating partial updates",
831 unrecognized_partitions)
832
833 logger.info("Generating partial updates for %s", ab_partitions)
834
835 copy_entries = ['META/update_engine_config.txt']
836 for partition_name in ab_partitions:
837 AddImageForPartition(partition_name)
838
839 # Use zip2zip to avoid extracting the zipfile.
840 partial_target_file = common.MakeTempFile(suffix='.zip')
841 cmd = ['zip2zip', '-i', input_file, '-o', partial_target_file]
842 cmd.extend(['{}:{}'.format(name, name) for name in copy_entries])
843 common.RunAndCheckOutput(cmd)
844
845 partial_target_zip = zipfile.ZipFile(partial_target_file, 'a',
846 allowZip64=True)
847 with zipfile.ZipFile(input_file, allowZip64=True) as input_zip:
848 common.ZipWriteStr(partial_target_zip, 'META/ab_partitions.txt',
849 '\n'.join(ab_partitions))
Kelvin Zhang766eea72021-06-03 09:36:08 -0400850 CARE_MAP_ENTRY = "META/care_map.pb"
851 if CARE_MAP_ENTRY in input_zip.namelist():
852 caremap = care_map_pb2.CareMap()
853 caremap.ParseFromString(input_zip.read(CARE_MAP_ENTRY))
854 filtered = [
855 part for part in caremap.partitions if part.name in ab_partitions]
856 del caremap.partitions[:]
857 caremap.partitions.extend(filtered)
858 common.ZipWriteStr(partial_target_zip, CARE_MAP_ENTRY,
859 caremap.SerializeToString())
860
Yifan Hong38ab4d82020-06-18 15:19:56 -0700861 for info_file in ['META/misc_info.txt', DYNAMIC_PARTITION_INFO]:
862 if info_file not in input_zip.namelist():
863 logger.warning('Cannot find %s in input zipfile', info_file)
864 continue
865 content = input_zip.read(info_file).decode()
866 modified_info = UpdatesInfoForSpecialUpdates(
867 content, lambda p: p in ab_partitions)
868 common.ZipWriteStr(partial_target_zip, info_file, modified_info)
869
Kelvin Zhang766eea72021-06-03 09:36:08 -0400870 # TODO(xunchang) handle META/postinstall_config.txt'
871
Yifan Hong38ab4d82020-06-18 15:19:56 -0700872 common.ZipClose(partial_target_zip)
873
874 return partial_target_file
875
876
Yifan Hong50e79542018-11-08 17:44:12 -0800877def GetTargetFilesZipForRetrofitDynamicPartitions(input_file,
Yifan Hongb433eba2019-03-06 12:42:53 -0800878 super_block_devices,
879 dynamic_partition_list):
Yifan Hong50e79542018-11-08 17:44:12 -0800880 """Returns a target-files.zip for retrofitting dynamic partitions.
881
882 This allows brillo_update_payload to generate an OTA based on the exact
883 bits on the block devices. Postinstall is disabled.
884
885 Args:
886 input_file: The input target-files.zip filename.
887 super_block_devices: The list of super block devices
Yifan Hongb433eba2019-03-06 12:42:53 -0800888 dynamic_partition_list: The list of dynamic partitions
Yifan Hong50e79542018-11-08 17:44:12 -0800889
890 Returns:
891 The filename of target-files.zip with *.img replaced with super_*.img for
892 each block device in super_block_devices.
893 """
894 assert super_block_devices, "No super_block_devices are specified."
895
896 replace = {'OTA/super_{}.img'.format(dev): 'IMAGES/{}.img'.format(dev)
Tao Bao03fecb62018-11-28 10:59:23 -0800897 for dev in super_block_devices}
Yifan Hong50e79542018-11-08 17:44:12 -0800898
899 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
900 shutil.copyfile(input_file, target_file)
901
Kelvin Zhang928c2342020-09-22 16:15:57 -0400902 with zipfile.ZipFile(input_file, allowZip64=True) as input_zip:
Yifan Hong50e79542018-11-08 17:44:12 -0800903 namelist = input_zip.namelist()
904
Yifan Hongb433eba2019-03-06 12:42:53 -0800905 input_tmp = common.UnzipTemp(input_file, RETROFIT_DAP_UNZIP_PATTERN)
906
907 # Remove partitions from META/ab_partitions.txt that is in
908 # dynamic_partition_list but not in super_block_devices so that
909 # brillo_update_payload won't generate update for those logical partitions.
910 ab_partitions_file = os.path.join(input_tmp, *AB_PARTITIONS.split('/'))
911 with open(ab_partitions_file) as f:
912 ab_partitions_lines = f.readlines()
913 ab_partitions = [line.strip() for line in ab_partitions_lines]
914 # Assert that all super_block_devices are in ab_partitions
915 super_device_not_updated = [partition for partition in super_block_devices
916 if partition not in ab_partitions]
917 assert not super_device_not_updated, \
918 "{} is in super_block_devices but not in {}".format(
919 super_device_not_updated, AB_PARTITIONS)
920 # ab_partitions -= (dynamic_partition_list - super_block_devices)
Kelvin Zhang0876c412020-06-23 15:06:58 -0400921 new_ab_partitions = common.MakeTempFile(
922 prefix="ab_partitions", suffix=".txt")
Yifan Hongb433eba2019-03-06 12:42:53 -0800923 with open(new_ab_partitions, 'w') as f:
924 for partition in ab_partitions:
925 if (partition in dynamic_partition_list and
Kelvin Zhang06400172021-03-05 15:42:03 -0500926 partition not in super_block_devices):
Tao Bao59cf0c52019-06-25 10:04:24 -0700927 logger.info("Dropping %s from ab_partitions.txt", partition)
928 continue
Yifan Hongb433eba2019-03-06 12:42:53 -0800929 f.write(partition + "\n")
930 to_delete = [AB_PARTITIONS]
931
Yifan Hong50e79542018-11-08 17:44:12 -0800932 # Always skip postinstall for a retrofit update.
Yifan Hongb433eba2019-03-06 12:42:53 -0800933 to_delete += [POSTINSTALL_CONFIG]
Yifan Hong50e79542018-11-08 17:44:12 -0800934
935 # Delete dynamic_partitions_info.txt so that brillo_update_payload thinks this
936 # is a regular update on devices without dynamic partitions support.
937 to_delete += [DYNAMIC_PARTITION_INFO]
938
Tao Bao03fecb62018-11-28 10:59:23 -0800939 # Remove the existing partition images as well as the map files.
Tao Bao59cf0c52019-06-25 10:04:24 -0700940 to_delete += list(replace.values())
Tao Bao03fecb62018-11-28 10:59:23 -0800941 to_delete += ['IMAGES/{}.map'.format(dev) for dev in super_block_devices]
Yifan Hong50e79542018-11-08 17:44:12 -0800942
943 common.ZipDelete(target_file, to_delete)
944
Yifan Hong50e79542018-11-08 17:44:12 -0800945 target_zip = zipfile.ZipFile(target_file, 'a', allowZip64=True)
946
947 # Write super_{foo}.img as {foo}.img.
948 for src, dst in replace.items():
949 assert src in namelist, \
Tao Bao59cf0c52019-06-25 10:04:24 -0700950 'Missing {} in {}; {} cannot be written'.format(src, input_file, dst)
Yifan Hong50e79542018-11-08 17:44:12 -0800951 unzipped_file = os.path.join(input_tmp, *src.split('/'))
952 common.ZipWrite(target_zip, unzipped_file, arcname=dst)
953
Yifan Hongb433eba2019-03-06 12:42:53 -0800954 # Write new ab_partitions.txt file
955 common.ZipWrite(target_zip, new_ab_partitions, arcname=AB_PARTITIONS)
956
Yifan Hong50e79542018-11-08 17:44:12 -0800957 common.ZipClose(target_zip)
958
959 return target_file
960
Kelvin Zhanga59bb272020-10-30 12:52:25 -0400961
Hongguang Chen49ab1b902020-10-19 14:15:43 -0700962def GetTargetFilesZipForCustomImagesUpdates(input_file, custom_images):
963 """Returns a target-files.zip for custom partitions update.
964
965 This function modifies ab_partitions list with the desired custom partitions
966 and puts the custom images into the target target-files.zip.
967
968 Args:
969 input_file: The input target-files.zip filename.
970 custom_images: A map of custom partitions and custom images.
971
972 Returns:
973 The filename of a target-files.zip which has renamed the custom images in
974 the IMAGS/ to their partition names.
975 """
976 # Use zip2zip to avoid extracting the zipfile.
977 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
978 cmd = ['zip2zip', '-i', input_file, '-o', target_file]
979
980 with zipfile.ZipFile(input_file, allowZip64=True) as input_zip:
981 namelist = input_zip.namelist()
982
983 # Write {custom_image}.img as {custom_partition}.img.
984 for custom_partition, custom_image in custom_images.items():
985 default_custom_image = '{}.img'.format(custom_partition)
986 if default_custom_image != custom_image:
987 logger.info("Update custom partition '%s' with '%s'",
988 custom_partition, custom_image)
989 # Default custom image need to be deleted first.
990 namelist.remove('IMAGES/{}'.format(default_custom_image))
991 # IMAGES/{custom_image}.img:IMAGES/{custom_partition}.img.
992 cmd.extend(['IMAGES/{}:IMAGES/{}'.format(custom_image,
993 default_custom_image)])
994
995 cmd.extend(['{}:{}'.format(name, name) for name in namelist])
996 common.RunAndCheckOutput(cmd)
997
998 return target_file
Yifan Hong50e79542018-11-08 17:44:12 -0800999
Kelvin Zhang06400172021-03-05 15:42:03 -05001000
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001001def GeneratePartitionTimestampFlags(partition_state):
1002 partition_timestamps = [
1003 part.partition_name + ":" + part.version
1004 for part in partition_state]
1005 return ["--partition_timestamps", ",".join(partition_timestamps)]
1006
Kelvin Zhang06400172021-03-05 15:42:03 -05001007
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001008def GeneratePartitionTimestampFlagsDowngrade(
Kelvin Zhang06400172021-03-05 15:42:03 -05001009 pre_partition_state, post_partition_state):
Kelvin Zhang80195722020-11-04 14:38:34 -05001010 assert pre_partition_state is not None
1011 partition_timestamps = {}
1012 for part in pre_partition_state:
1013 partition_timestamps[part.partition_name] = part.version
1014 for part in post_partition_state:
1015 partition_timestamps[part.partition_name] = \
Kelvin Zhang06400172021-03-05 15:42:03 -05001016 max(part.version, partition_timestamps[part.partition_name])
Kelvin Zhang80195722020-11-04 14:38:34 -05001017 return [
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001018 "--partition_timestamps",
Kelvin Zhang06400172021-03-05 15:42:03 -05001019 ",".join([key + ":" + val for (key, val)
1020 in partition_timestamps.items()])
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001021 ]
Kelvin Zhang80195722020-11-04 14:38:34 -05001022
Kelvin Zhang06400172021-03-05 15:42:03 -05001023
Kelvin Zhang65029a22020-11-03 10:07:51 -05001024def IsSparseImage(filepath):
1025 with open(filepath, 'rb') as fp:
1026 # Magic for android sparse image format
1027 # https://source.android.com/devices/bootloader/images
1028 return fp.read(4) == b'\x3A\xFF\x26\xED'
1029
Kelvin Zhang06400172021-03-05 15:42:03 -05001030
Kelvin Zhang65029a22020-11-03 10:07:51 -05001031def SupportsMainlineGkiUpdates(target_file):
1032 """Return True if the build supports MainlineGKIUpdates.
1033
1034 This function scans the product.img file in IMAGES/ directory for
1035 pattern |*/apex/com.android.gki.*.apex|. If there are files
1036 matching this pattern, conclude that build supports mainline
1037 GKI and return True
1038
1039 Args:
1040 target_file: Path to a target_file.zip, or an extracted directory
1041 Return:
1042 True if thisb uild supports Mainline GKI Updates.
1043 """
1044 if target_file is None:
1045 return False
1046 if os.path.isfile(target_file):
1047 target_file = common.UnzipTemp(target_file, ["IMAGES/product.img"])
1048 if not os.path.isdir(target_file):
1049 assert os.path.isdir(target_file), \
1050 "{} must be a path to zip archive or dir containing extracted"\
1051 " target_files".format(target_file)
1052 image_file = os.path.join(target_file, "IMAGES", "product.img")
1053
1054 if not os.path.isfile(image_file):
1055 return False
1056
1057 if IsSparseImage(image_file):
1058 # Unsparse the image
1059 tmp_img = common.MakeTempFile(suffix=".img")
1060 subprocess.check_output(["simg2img", image_file, tmp_img])
1061 image_file = tmp_img
1062
1063 cmd = ["debugfs_static", "-R", "ls -p /apex", image_file]
1064 output = subprocess.check_output(cmd).decode()
1065
1066 pattern = re.compile(r"com\.android\.gki\..*\.apex")
1067 return pattern.search(output) is not None
1068
Kelvin Zhang06400172021-03-05 15:42:03 -05001069
Tao Baof0c4aa22018-04-30 20:29:30 -07001070def GenerateAbOtaPackage(target_file, output_file, source_file=None):
Tao Baofe5b69a2018-03-02 09:47:43 -08001071 """Generates an Android OTA package that has A/B update payload."""
Tao Baodea0f8b2016-06-20 17:55:06 -07001072 # Stage the output zip package for package signing.
Tao Bao491d7e22018-02-21 13:17:22 -08001073 if not OPTIONS.no_signing:
1074 staging_file = common.MakeTempFile(suffix='.zip')
1075 else:
1076 staging_file = output_file
Tao Baoa652c002018-03-01 19:31:38 -08001077 output_zip = zipfile.ZipFile(staging_file, "w",
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001078 compression=zipfile.ZIP_DEFLATED,
1079 allowZip64=True)
Tao Baoc098e9e2016-01-07 13:03:56 -08001080
Tao Bao481bab82017-12-21 11:23:09 -08001081 if source_file is not None:
Kelvin Zhang39aea442020-08-17 11:04:25 -04001082 assert "ab_partitions" in OPTIONS.source_info_dict, \
1083 "META/ab_partitions.txt is required for ab_update."
1084 assert "ab_partitions" in OPTIONS.target_info_dict, \
1085 "META/ab_partitions.txt is required for ab_update."
Tao Bao1c320f82019-10-04 23:25:12 -07001086 target_info = common.BuildInfo(OPTIONS.target_info_dict, OPTIONS.oem_dicts)
1087 source_info = common.BuildInfo(OPTIONS.source_info_dict, OPTIONS.oem_dicts)
Kelvin Zhang563750f2021-04-28 12:46:17 -04001088 # If source supports VABC, delta_generator/update_engine will attempt to
1089 # use VABC. This dangerous, as the target build won't have snapuserd to
1090 # serve I/O request when device boots. Therefore, disable VABC if source
1091 # build doesn't supports it.
1092 if not source_info.is_vabc or not target_info.is_vabc:
Kelvin Zhang10eac082021-06-10 14:32:19 -04001093 logger.info("Either source or target does not support VABC, disabling.")
Kelvin Zhang563750f2021-04-28 12:46:17 -04001094 OPTIONS.disable_vabc = True
Kelvin Zhang563750f2021-04-28 12:46:17 -04001095
Tao Bao481bab82017-12-21 11:23:09 -08001096 else:
Kelvin Zhang39aea442020-08-17 11:04:25 -04001097 assert "ab_partitions" in OPTIONS.info_dict, \
1098 "META/ab_partitions.txt is required for ab_update."
Tao Bao1c320f82019-10-04 23:25:12 -07001099 target_info = common.BuildInfo(OPTIONS.info_dict, OPTIONS.oem_dicts)
Tao Bao481bab82017-12-21 11:23:09 -08001100 source_info = None
Tao Baoc098e9e2016-01-07 13:03:56 -08001101
Kelvin Zhang10eac082021-06-10 14:32:19 -04001102 if target_info.vendor_suppressed_vabc:
1103 logger.info("Vendor suppressed VABC. Disabling")
1104 OPTIONS.disable_vabc = True
Kelvin Zhangad427382021-08-12 16:19:09 -07001105 if not target_info.is_vabc_xor or OPTIONS.disable_vabc:
1106 logger.info("VABC XOR Not supported, disabling")
1107 OPTIONS.enable_vabc_xor = False
Yifan Hong38ab4d82020-06-18 15:19:56 -07001108 additional_args = []
1109
Hongguang Chen49ab1b902020-10-19 14:15:43 -07001110 # Prepare custom images.
1111 if OPTIONS.custom_images:
1112 target_file = GetTargetFilesZipForCustomImagesUpdates(
1113 target_file, OPTIONS.custom_images)
1114
Yifan Hong50e79542018-11-08 17:44:12 -08001115 if OPTIONS.retrofit_dynamic_partitions:
1116 target_file = GetTargetFilesZipForRetrofitDynamicPartitions(
Yifan Hongb433eba2019-03-06 12:42:53 -08001117 target_file, target_info.get("super_block_devices").strip().split(),
1118 target_info.get("dynamic_partition_list").strip().split())
Yifan Hong38ab4d82020-06-18 15:19:56 -07001119 elif OPTIONS.partial:
1120 target_file = GetTargetFilesZipForPartialUpdates(target_file,
1121 OPTIONS.partial)
1122 additional_args += ["--is_partial_update", "true"]
Yifan Hong50e79542018-11-08 17:44:12 -08001123 elif OPTIONS.skip_postinstall:
Tao Bao15a146a2018-02-21 16:06:59 -08001124 target_file = GetTargetFilesZipWithoutPostinstallConfig(target_file)
Kelvin Zhang39aea442020-08-17 11:04:25 -04001125 # Target_file may have been modified, reparse ab_partitions
1126 with zipfile.ZipFile(target_file, allowZip64=True) as zfp:
1127 target_info.info_dict['ab_partitions'] = zfp.read(
Kelvin Zhang31233e52020-11-03 13:42:46 -05001128 AB_PARTITIONS).decode().strip().split("\n")
Tao Bao15a146a2018-02-21 16:06:59 -08001129
Kelvin Zhang414ca422021-08-27 15:12:08 -07001130 CheckVintfIfTrebleEnabled(target_file, target_info)
1131
Kelvin Zhang39aea442020-08-17 11:04:25 -04001132 # Metadata to comply with Android OTA package format.
1133 metadata = GetPackageMetadata(target_info, source_info)
Tao Bao40b18822018-01-30 18:19:04 -08001134 # Generate payload.
1135 payload = Payload()
1136
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001137 partition_timestamps_flags = []
Tao Bao40b18822018-01-30 18:19:04 -08001138 # Enforce a max timestamp this payload can be applied on top of.
Tao Baoff1b86e2017-10-03 14:17:57 -07001139 if OPTIONS.downgrade:
Tao Bao2a12ed72018-01-22 11:35:00 -08001140 max_timestamp = source_info.GetBuildProp("ro.build.date.utc")
Kelvin Zhang80195722020-11-04 14:38:34 -05001141 partition_timestamps_flags = GeneratePartitionTimestampFlagsDowngrade(
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001142 metadata.precondition.partition_state,
1143 metadata.postcondition.partition_state
1144 )
Tao Baoff1b86e2017-10-03 14:17:57 -07001145 else:
Tianjiea2076132020-08-19 17:25:32 -07001146 max_timestamp = str(metadata.postcondition.timestamp)
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001147 partition_timestamps_flags = GeneratePartitionTimestampFlags(
1148 metadata.postcondition.partition_state)
Tao Baoc098e9e2016-01-07 13:03:56 -08001149
Kelvin Zhangbbfa1822021-02-03 17:19:44 -05001150 if OPTIONS.disable_vabc:
1151 additional_args += ["--disable_vabc", "true"]
Kelvin Zhangf66caee2021-07-12 09:44:20 -04001152 if OPTIONS.enable_vabc_xor:
1153 additional_args += ["--enable_vabc_xor", "true"]
Tianjiee7ab38d2021-09-08 19:09:38 -07001154 if OPTIONS.force_minor_version:
1155 additional_args += ["--force_minor_version", OPTIONS.force_minor_version]
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -07001156 if OPTIONS.compressor_types:
1157 additional_args += ["--compressor_types", OPTIONS.compressor_types]
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001158 additional_args += ["--max_timestamp", max_timestamp]
1159
Kelvin Zhang65029a22020-11-03 10:07:51 -05001160 if SupportsMainlineGkiUpdates(source_file):
Kelvin Zhang06400172021-03-05 15:42:03 -05001161 logger.warning(
1162 "Detected build with mainline GKI, include full boot image.")
Kelvin Zhang65029a22020-11-03 10:07:51 -05001163 additional_args.extend(["--full_boot", "true"])
1164
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001165 payload.Generate(
1166 target_file,
1167 source_file,
1168 additional_args + partition_timestamps_flags
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001169 )
Tao Baoc098e9e2016-01-07 13:03:56 -08001170
Tao Bao40b18822018-01-30 18:19:04 -08001171 # Sign the payload.
Tao Baof7140c02018-01-30 17:09:24 -08001172 payload_signer = PayloadSigner()
1173 payload.Sign(payload_signer)
Tao Baoc098e9e2016-01-07 13:03:56 -08001174
Tao Bao40b18822018-01-30 18:19:04 -08001175 # Write the payload into output zip.
1176 payload.WriteToZip(output_zip)
Tao Baoc098e9e2016-01-07 13:03:56 -08001177
Tao Baof7140c02018-01-30 17:09:24 -08001178 # Generate and include the secondary payload that installs secondary images
1179 # (e.g. system_other.img).
1180 if OPTIONS.include_secondary:
1181 # We always include a full payload for the secondary slot, even when
1182 # building an incremental OTA. See the comments for "--include_secondary".
Tao Bao15a146a2018-02-21 16:06:59 -08001183 secondary_target_file = GetTargetFilesZipForSecondaryImages(
1184 target_file, OPTIONS.skip_postinstall)
Tao Bao667ff572018-02-10 00:02:40 -08001185 secondary_payload = Payload(secondary=True)
Tao Baodb1fe412018-02-09 23:15:05 -08001186 secondary_payload.Generate(secondary_target_file,
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001187 additional_args=["--max_timestamp",
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001188 max_timestamp])
Tao Baof7140c02018-01-30 17:09:24 -08001189 secondary_payload.Sign(payload_signer)
Tao Bao667ff572018-02-10 00:02:40 -08001190 secondary_payload.WriteToZip(output_zip)
Tao Baof7140c02018-01-30 17:09:24 -08001191
Tianjie Xucfa86222016-03-07 16:31:19 -08001192 # If dm-verity is supported for the device, copy contents of care_map
1193 # into A/B OTA package.
Kelvin Zhang928c2342020-09-22 16:15:57 -04001194 target_zip = zipfile.ZipFile(target_file, "r", allowZip64=True)
Tao Bao481bab82017-12-21 11:23:09 -08001195 if (target_info.get("verity") == "true" or
Kelvin Zhang06400172021-03-05 15:42:03 -05001196 target_info.get("avb_enable") == "true"):
Tianjie Xu4c05f4a2018-09-14 16:24:41 -07001197 care_map_list = [x for x in ["care_map.pb", "care_map.txt"] if
1198 "META/" + x in target_zip.namelist()]
1199
1200 # Adds care_map if either the protobuf format or the plain text one exists.
1201 if care_map_list:
1202 care_map_name = care_map_list[0]
1203 care_map_data = target_zip.read("META/" + care_map_name)
1204 # In order to support streaming, care_map needs to be packed as
Tao Bao40b18822018-01-30 18:19:04 -08001205 # ZIP_STORED.
Tianjie Xu4c05f4a2018-09-14 16:24:41 -07001206 common.ZipWriteStr(output_zip, care_map_name, care_map_data,
Tao Bao481bab82017-12-21 11:23:09 -08001207 compress_type=zipfile.ZIP_STORED)
Tianjie Xucfa86222016-03-07 16:31:19 -08001208 else:
Tao Bao32fcdab2018-10-12 10:30:39 -07001209 logger.warning("Cannot find care map file in target_file package")
Tao Bao21803d32017-04-19 10:16:09 -07001210
Tianjiea5fca032021-06-01 22:06:28 -07001211 # Add the source apex version for incremental ota updates, and write the
1212 # result apex info to the ota package.
1213 ota_apex_info = ota_utils.ConstructOtaApexInfo(target_zip, source_file)
1214 if ota_apex_info is not None:
1215 common.ZipWriteStr(output_zip, "apex_info.pb", ota_apex_info,
1216 compress_type=zipfile.ZIP_STORED)
Kelvin Zhang7bd09912021-01-21 10:33:13 -05001217
Tao Bao21803d32017-04-19 10:16:09 -07001218 common.ZipClose(target_zip)
Tianjie Xucfa86222016-03-07 16:31:19 -08001219
Tao Baofe5b69a2018-03-02 09:47:43 -08001220 # We haven't written the metadata entry yet, which will be handled in
1221 # FinalizeMetadata().
Tao Baoc96316c2017-01-24 22:10:49 -08001222 common.ZipClose(output_zip)
1223
Tao Bao85f16982018-03-08 16:28:33 -08001224 # AbOtaPropertyFiles intends to replace StreamingPropertyFiles, as it covers
1225 # all the info of the latter. However, system updaters and OTA servers need to
1226 # take time to switch to the new flag. We keep both of the flags for
1227 # P-timeframe, and will remove StreamingPropertyFiles in later release.
Tao Baod3fc38a2018-03-08 16:09:01 -08001228 needed_property_files = (
Tao Bao85f16982018-03-08 16:28:33 -08001229 AbOtaPropertyFiles(),
Tao Baod3fc38a2018-03-08 16:09:01 -08001230 StreamingPropertyFiles(),
1231 )
1232 FinalizeMetadata(metadata, staging_file, output_file, needed_property_files)
Tao Baoc96316c2017-01-24 22:10:49 -08001233
Tao Baoc098e9e2016-01-07 13:03:56 -08001234
Doug Zongkereef39442009-04-02 12:14:19 -07001235def main(argv):
1236
1237 def option_handler(o, a):
Tao Bao4b76a0e2017-10-31 12:13:33 -07001238 if o in ("-k", "--package_key"):
Doug Zongkereef39442009-04-02 12:14:19 -07001239 OPTIONS.package_key = a
Doug Zongkereef39442009-04-02 12:14:19 -07001240 elif o in ("-i", "--incremental_from"):
1241 OPTIONS.incremental_source = a
Tao Bao43078aa2015-04-21 14:32:35 -07001242 elif o == "--full_radio":
1243 OPTIONS.full_radio = True
leozwangaa6c1a12015-08-14 10:57:58 -07001244 elif o == "--full_bootloader":
1245 OPTIONS.full_bootloader = True
Tao Bao337633f2017-12-06 15:20:19 -08001246 elif o == "--wipe_user_data":
Doug Zongkerdbfaae52009-04-21 17:12:54 -07001247 OPTIONS.wipe_user_data = True
Tao Bao5d182562016-02-23 11:38:39 -08001248 elif o == "--downgrade":
1249 OPTIONS.downgrade = True
1250 OPTIONS.wipe_user_data = True
Tao Bao3e6161a2017-02-28 11:48:48 -08001251 elif o == "--override_timestamp":
Tao Baofaa8e0b2018-04-12 14:31:43 -07001252 OPTIONS.downgrade = True
Michael Runge6e836112014-04-15 17:40:21 -07001253 elif o in ("-o", "--oem_settings"):
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -08001254 OPTIONS.oem_source = a.split(',')
Tao Bao8608cde2016-02-25 19:49:55 -08001255 elif o == "--oem_no_mount":
1256 OPTIONS.oem_no_mount = True
Doug Zongker1c390a22009-05-14 19:06:36 -07001257 elif o in ("-e", "--extra_script"):
1258 OPTIONS.extra_script = a
Martin Blumenstingl374e1142014-05-31 20:42:55 +02001259 elif o in ("-t", "--worker_threads"):
1260 if a.isdigit():
1261 OPTIONS.worker_threads = int(a)
1262 else:
1263 raise ValueError("Cannot parse value %r for option %r - only "
1264 "integers are allowed." % (a, o))
Doug Zongker9b23f2c2013-11-25 14:44:12 -08001265 elif o in ("-2", "--two_step"):
1266 OPTIONS.two_step = True
Tao Baof7140c02018-01-30 17:09:24 -08001267 elif o == "--include_secondary":
1268 OPTIONS.include_secondary = True
Doug Zongker26e66192014-02-20 13:22:07 -08001269 elif o == "--no_signing":
Takeshi Kanemotoe153b342013-11-14 17:20:50 +09001270 OPTIONS.no_signing = True
Dan Albert8b72aef2015-03-23 19:13:21 -07001271 elif o == "--verify":
Michael Runge63f01de2014-10-28 19:24:19 -07001272 OPTIONS.verify = True
Doug Zongker26e66192014-02-20 13:22:07 -08001273 elif o == "--block":
1274 OPTIONS.block_based = True
Doug Zongker25568482014-03-03 10:21:27 -08001275 elif o in ("-b", "--binary"):
1276 OPTIONS.updater_binary = a
Tao Bao8dcf7382015-05-21 14:09:49 -07001277 elif o == "--stash_threshold":
1278 try:
1279 OPTIONS.stash_threshold = float(a)
1280 except ValueError:
1281 raise ValueError("Cannot parse value %r for option %r - expecting "
1282 "a float" % (a, o))
Tao Baod62c6032015-11-30 09:40:20 -08001283 elif o == "--log_diff":
1284 OPTIONS.log_diff = a
Tao Baodea0f8b2016-06-20 17:55:06 -07001285 elif o == "--payload_signer":
1286 OPTIONS.payload_signer = a
Baligh Uddin2abbbd02016-06-22 12:14:16 -07001287 elif o == "--payload_signer_args":
1288 OPTIONS.payload_signer_args = shlex.split(a)
Tianjie Xu21e6deb2019-10-07 18:01:00 -07001289 elif o == "--payload_signer_maximum_signature_size":
1290 OPTIONS.payload_signer_maximum_signature_size = a
xunchang376cc7c2019-04-08 23:04:58 -07001291 elif o == "--payload_signer_key_size":
Tianjie Xu21e6deb2019-10-07 18:01:00 -07001292 # TODO(Xunchang) remove this option after cleaning up the callers.
1293 logger.warning("The option '--payload_signer_key_size' is deprecated."
1294 " Use '--payload_signer_maximum_signature_size' instead.")
1295 OPTIONS.payload_signer_maximum_signature_size = a
Dan Willemsencea5cd22017-03-21 14:44:27 -07001296 elif o == "--extracted_input_target_files":
1297 OPTIONS.extracted_input = a
Tao Bao15a146a2018-02-21 16:06:59 -08001298 elif o == "--skip_postinstall":
1299 OPTIONS.skip_postinstall = True
Yifan Hong50e79542018-11-08 17:44:12 -08001300 elif o == "--retrofit_dynamic_partitions":
1301 OPTIONS.retrofit_dynamic_partitions = True
xunchangabfa2652019-02-19 16:27:10 -08001302 elif o == "--skip_compatibility_check":
1303 OPTIONS.skip_compatibility_check = True
xunchang1cfe2512019-02-19 14:14:48 -08001304 elif o == "--output_metadata_path":
1305 OPTIONS.output_metadata_path = a
Tianjie Xu1b079832019-08-28 12:19:23 -07001306 elif o == "--disable_fec_computation":
1307 OPTIONS.disable_fec_computation = True
Kelvin Zhangcaf7bbc2020-11-20 14:09:42 -05001308 elif o == "--disable_verity_computation":
1309 OPTIONS.disable_verity_computation = True
Yifan Hong65afc072020-04-17 10:08:10 -07001310 elif o == "--force_non_ab":
1311 OPTIONS.force_non_ab = True
Tianjied6867162020-05-10 14:30:13 -07001312 elif o == "--boot_variable_file":
1313 OPTIONS.boot_variable_file = a
Yifan Hong38ab4d82020-06-18 15:19:56 -07001314 elif o == "--partial":
1315 partitions = a.split()
1316 if not partitions:
1317 raise ValueError("Cannot parse partitions in {}".format(a))
1318 OPTIONS.partial = partitions
Hongguang Chen49ab1b902020-10-19 14:15:43 -07001319 elif o == "--custom_image":
1320 custom_partition, custom_image = a.split("=")
1321 OPTIONS.custom_images[custom_partition] = custom_image
Kelvin Zhangbbfa1822021-02-03 17:19:44 -05001322 elif o == "--disable_vabc":
1323 OPTIONS.disable_vabc = True
Kelvin Zhang80ff4662021-02-08 19:57:57 -05001324 elif o == "--spl_downgrade":
1325 OPTIONS.spl_downgrade = True
Kelvin Zhang06400172021-03-05 15:42:03 -05001326 OPTIONS.wipe_user_data = True
Kelvin Zhang2a3e5b12021-05-04 18:20:34 -04001327 elif o == "--vabc_downgrade":
1328 OPTIONS.vabc_downgrade = True
Kelvin Zhangf66caee2021-07-12 09:44:20 -04001329 elif o == "--enable_vabc_xor":
Kelvin Zhang1250bca2021-08-27 15:10:27 -07001330 OPTIONS.enable_vabc_xor = a.lower() != "false"
Tianjiee7ab38d2021-09-08 19:09:38 -07001331 elif o == "--force_minor_version":
1332 OPTIONS.force_minor_version = a
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -07001333 elif o == "--compressor_types":
1334 OPTIONS.compressor_types = a
Doug Zongkereef39442009-04-02 12:14:19 -07001335 else:
1336 return False
Doug Zongkerdbfaae52009-04-21 17:12:54 -07001337 return True
Doug Zongkereef39442009-04-02 12:14:19 -07001338
1339 args = common.ParseOptions(argv, __doc__,
Kelvin Zhang9b6d4ec2021-10-28 09:34:31 -07001340 extra_opts="b:k:i:d:e:t:2o:",
1341 extra_long_opts=[
1342 "package_key=",
1343 "incremental_from=",
1344 "full_radio",
1345 "full_bootloader",
1346 "wipe_user_data",
1347 "downgrade",
1348 "override_timestamp",
1349 "extra_script=",
1350 "worker_threads=",
1351 "two_step",
1352 "include_secondary",
1353 "no_signing",
1354 "block",
1355 "binary=",
1356 "oem_settings=",
1357 "oem_no_mount",
1358 "verify",
1359 "stash_threshold=",
1360 "log_diff=",
1361 "payload_signer=",
1362 "payload_signer_args=",
1363 "payload_signer_maximum_signature_size=",
1364 "payload_signer_key_size=",
1365 "extracted_input_target_files=",
1366 "skip_postinstall",
1367 "retrofit_dynamic_partitions",
1368 "skip_compatibility_check",
1369 "output_metadata_path=",
1370 "disable_fec_computation",
1371 "disable_verity_computation",
1372 "force_non_ab",
1373 "boot_variable_file=",
1374 "partial=",
1375 "custom_image=",
1376 "disable_vabc",
1377 "spl_downgrade",
1378 "vabc_downgrade",
1379 "enable_vabc_xor=",
1380 "force_minor_version=",
1381 "compressor_types=",
1382 ], extra_option_handler=option_handler)
Doug Zongkereef39442009-04-02 12:14:19 -07001383
1384 if len(args) != 2:
1385 common.Usage(__doc__)
1386 sys.exit(1)
1387
Tao Bao32fcdab2018-10-12 10:30:39 -07001388 common.InitLogging()
1389
Tao Bao2db13852018-01-08 22:28:57 -08001390 # Load the build info dicts from the zip directly or the extracted input
1391 # directory. We don't need to unzip the entire target-files zips, because they
1392 # won't be needed for A/B OTAs (brillo_update_payload does that on its own).
1393 # When loading the info dicts, we don't need to provide the second parameter
1394 # to common.LoadInfoDict(). Specifying the second parameter allows replacing
1395 # some properties with their actual paths, such as 'selinux_fc',
1396 # 'ramdisk_dir', which won't be used during OTA generation.
Dan Willemsencea5cd22017-03-21 14:44:27 -07001397 if OPTIONS.extracted_input is not None:
Tao Bao2db13852018-01-08 22:28:57 -08001398 OPTIONS.info_dict = common.LoadInfoDict(OPTIONS.extracted_input)
Dan Willemsencea5cd22017-03-21 14:44:27 -07001399 else:
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001400 OPTIONS.info_dict = ParseInfoDict(args[0])
Kelvin Zhang80195722020-11-04 14:38:34 -05001401
Kelvin Zhang2a3e5b12021-05-04 18:20:34 -04001402 if OPTIONS.wipe_user_data:
1403 if not OPTIONS.vabc_downgrade:
1404 logger.info("Detected downgrade/datawipe OTA."
1405 "When wiping userdata, VABC OTA makes the user "
1406 "wait in recovery mode for merge to finish. Disable VABC by "
1407 "default. If you really want to do VABC downgrade, pass "
1408 "--vabc_downgrade")
1409 OPTIONS.disable_vabc = True
Kelvin Zhang80195722020-11-04 14:38:34 -05001410 # We should only allow downgrading incrementals (as opposed to full).
1411 # Otherwise the device may go back from arbitrary build with this full
1412 # OTA package.
Kelvin Zhang81641af2021-10-26 16:03:25 -07001413 if OPTIONS.incremental_source is None and OPTIONS.downgrade:
1414 raise ValueError("Cannot generate downgradable full OTAs")
Kelvin Zhang80195722020-11-04 14:38:34 -05001415
Yifan Hong38ab4d82020-06-18 15:19:56 -07001416 # TODO(xunchang) for retrofit and partial updates, maybe we should rebuild the
1417 # target-file and reload the info_dict. So the info will be consistent with
1418 # the modified target-file.
1419
Tao Bao32fcdab2018-10-12 10:30:39 -07001420 logger.info("--- target info ---")
1421 common.DumpInfoDict(OPTIONS.info_dict)
Tao Bao2db13852018-01-08 22:28:57 -08001422
1423 # Load the source build dict if applicable.
1424 if OPTIONS.incremental_source is not None:
1425 OPTIONS.target_info_dict = OPTIONS.info_dict
Kelvin Zhanga59bb272020-10-30 12:52:25 -04001426 OPTIONS.source_info_dict = ParseInfoDict(OPTIONS.incremental_source)
Tao Bao2db13852018-01-08 22:28:57 -08001427
Tao Bao32fcdab2018-10-12 10:30:39 -07001428 logger.info("--- source info ---")
1429 common.DumpInfoDict(OPTIONS.source_info_dict)
Tao Bao2db13852018-01-08 22:28:57 -08001430
Kelvin Zhang83ea7832020-11-11 13:07:10 -05001431 if OPTIONS.partial:
1432 OPTIONS.info_dict['ab_partitions'] = \
Kelvin Zhang06400172021-03-05 15:42:03 -05001433 list(
1434 set(OPTIONS.info_dict['ab_partitions']) & set(OPTIONS.partial)
1435 )
Kelvin Zhang83ea7832020-11-11 13:07:10 -05001436 if OPTIONS.source_info_dict:
1437 OPTIONS.source_info_dict['ab_partitions'] = \
Kelvin Zhang06400172021-03-05 15:42:03 -05001438 list(
1439 set(OPTIONS.source_info_dict['ab_partitions']) &
1440 set(OPTIONS.partial)
1441 )
Kelvin Zhang83ea7832020-11-11 13:07:10 -05001442
Tao Bao2db13852018-01-08 22:28:57 -08001443 # Load OEM dicts if provided.
Tao Bao481bab82017-12-21 11:23:09 -08001444 OPTIONS.oem_dicts = _LoadOemDicts(OPTIONS.oem_source)
1445
Yifan Hong50e79542018-11-08 17:44:12 -08001446 # Assume retrofitting dynamic partitions when base build does not set
Yifan Hong50611032018-11-20 14:27:38 -08001447 # use_dynamic_partitions but target build does.
Yifan Hong50e79542018-11-08 17:44:12 -08001448 if (OPTIONS.source_info_dict and
Yifan Hong50611032018-11-20 14:27:38 -08001449 OPTIONS.source_info_dict.get("use_dynamic_partitions") != "true" and
Kelvin Zhang06400172021-03-05 15:42:03 -05001450 OPTIONS.target_info_dict.get("use_dynamic_partitions") == "true"):
Yifan Hong50e79542018-11-08 17:44:12 -08001451 if OPTIONS.target_info_dict.get("dynamic_partition_retrofit") != "true":
1452 raise common.ExternalError(
1453 "Expect to generate incremental OTA for retrofitting dynamic "
1454 "partitions, but dynamic_partition_retrofit is not set in target "
1455 "build.")
1456 logger.info("Implicitly generating retrofit incremental OTA.")
1457 OPTIONS.retrofit_dynamic_partitions = True
1458
1459 # Skip postinstall for retrofitting dynamic partitions.
1460 if OPTIONS.retrofit_dynamic_partitions:
1461 OPTIONS.skip_postinstall = True
1462
Tao Baoc098e9e2016-01-07 13:03:56 -08001463 ab_update = OPTIONS.info_dict.get("ab_update") == "true"
Yifan Hong65afc072020-04-17 10:08:10 -07001464 allow_non_ab = OPTIONS.info_dict.get("allow_non_ab") == "true"
1465 if OPTIONS.force_non_ab:
Kelvin Zhang22c687c2021-01-21 10:51:57 -05001466 assert allow_non_ab,\
Kelvin Zhang06400172021-03-05 15:42:03 -05001467 "--force_non_ab only allowed on devices that supports non-A/B"
Yifan Hong65afc072020-04-17 10:08:10 -07001468 assert ab_update, "--force_non_ab only allowed on A/B devices"
1469
1470 generate_ab = not OPTIONS.force_non_ab and ab_update
Tao Baoc098e9e2016-01-07 13:03:56 -08001471
Christian Oderf63e2cd2017-05-01 22:30:15 +02001472 # Use the default key to sign the package if not specified with package_key.
1473 # package_keys are needed on ab_updates, so always define them if an
Yifan Hong65afc072020-04-17 10:08:10 -07001474 # A/B update is getting created.
1475 if not OPTIONS.no_signing or generate_ab:
Christian Oderf63e2cd2017-05-01 22:30:15 +02001476 if OPTIONS.package_key is None:
1477 OPTIONS.package_key = OPTIONS.info_dict.get(
1478 "default_system_dev_certificate",
Dan Willemsen0ab1be62019-04-09 21:35:37 -07001479 "build/make/target/product/security/testkey")
Christian Oderf63e2cd2017-05-01 22:30:15 +02001480 # Get signing keys
1481 OPTIONS.key_passwords = common.GetKeyPasswords([OPTIONS.package_key])
Kelvin Zhangeb586ef2021-02-08 20:11:49 -05001482 private_key_path = OPTIONS.package_key + OPTIONS.private_key_suffix
1483 if not os.path.exists(private_key_path):
1484 raise common.ExternalError(
Kelvin Zhang06400172021-03-05 15:42:03 -05001485 "Private key {} doesn't exist. Make sure you passed the"
1486 " correct key path through -k option".format(
1487 private_key_path)
1488 )
Christian Oderf63e2cd2017-05-01 22:30:15 +02001489
Kelvin Zhang80ff4662021-02-08 19:57:57 -05001490 if OPTIONS.source_info_dict:
1491 source_build_prop = OPTIONS.source_info_dict["build.prop"]
1492 target_build_prop = OPTIONS.target_info_dict["build.prop"]
1493 source_spl = source_build_prop.GetProp(SECURITY_PATCH_LEVEL_PROP_NAME)
1494 target_spl = target_build_prop.GetProp(SECURITY_PATCH_LEVEL_PROP_NAME)
Kelvin Zhang05ff7052021-02-10 09:13:26 -05001495 is_spl_downgrade = target_spl < source_spl
Kelvin Zhang06400172021-03-05 15:42:03 -05001496 if is_spl_downgrade and not OPTIONS.spl_downgrade and not OPTIONS.downgrade:
Kelvin Zhang80ff4662021-02-08 19:57:57 -05001497 raise common.ExternalError(
Kelvin Zhang06400172021-03-05 15:42:03 -05001498 "Target security patch level {} is older than source SPL {} applying "
1499 "such OTA will likely cause device fail to boot. Pass --spl_downgrade "
1500 "to override this check. This script expects security patch level to "
1501 "be in format yyyy-mm-dd (e.x. 2021-02-05). It's possible to use "
1502 "separators other than -, so as long as it's used consistenly across "
1503 "all SPL dates".format(target_spl, source_spl))
Kelvin Zhang05ff7052021-02-10 09:13:26 -05001504 elif not is_spl_downgrade and OPTIONS.spl_downgrade:
1505 raise ValueError("--spl_downgrade specified but no actual SPL downgrade"
1506 " detected. Please only pass in this flag if you want a"
1507 " SPL downgrade. Target SPL: {} Source SPL: {}"
1508 .format(target_spl, source_spl))
Yifan Hong65afc072020-04-17 10:08:10 -07001509 if generate_ab:
Tao Baof0c4aa22018-04-30 20:29:30 -07001510 GenerateAbOtaPackage(
Tao Baoc098e9e2016-01-07 13:03:56 -08001511 target_file=args[0],
1512 output_file=args[1],
1513 source_file=OPTIONS.incremental_source)
1514
Dan Willemsencea5cd22017-03-21 14:44:27 -07001515 else:
Tao Baof0c4aa22018-04-30 20:29:30 -07001516 GenerateNonAbOtaPackage(
1517 target_file=args[0],
1518 output_file=args[1],
1519 source_file=OPTIONS.incremental_source)
Doug Zongkerfdd8e692009-08-03 17:27:48 -07001520
Tao Baof0c4aa22018-04-30 20:29:30 -07001521 # Post OTA generation works.
1522 if OPTIONS.incremental_source is not None and OPTIONS.log_diff:
1523 logger.info("Generating diff logs...")
1524 logger.info("Unzipping target-files for diffing...")
1525 target_dir = common.UnzipTemp(args[0], TARGET_DIFFING_UNZIP_PATTERN)
1526 source_dir = common.UnzipTemp(
1527 OPTIONS.incremental_source, TARGET_DIFFING_UNZIP_PATTERN)
Doug Zongkereb0a78a2014-01-27 10:01:06 -08001528
Tao Baof0c4aa22018-04-30 20:29:30 -07001529 with open(OPTIONS.log_diff, 'w') as out_file:
Tao Baof0c4aa22018-04-30 20:29:30 -07001530 target_files_diff.recursiveDiff(
1531 '', source_dir, target_dir, out_file)
Doug Zongker62d4f182014-08-04 16:06:43 -07001532
Tao Bao32fcdab2018-10-12 10:30:39 -07001533 logger.info("done.")
Doug Zongkereef39442009-04-02 12:14:19 -07001534
1535
1536if __name__ == '__main__':
1537 try:
Ying Wang7e6d4e42010-12-13 16:25:36 -08001538 common.CloseInheritedPipes()
Doug Zongkereef39442009-04-02 12:14:19 -07001539 main(sys.argv[1:])
Tao Bao32fcdab2018-10-12 10:30:39 -07001540 except common.ExternalError:
1541 logger.exception("\n ERROR:\n")
Doug Zongkereef39442009-04-02 12:14:19 -07001542 sys.exit(1)
Doug Zongkerfc44a512014-08-26 13:10:25 -07001543 finally:
1544 common.Cleanup()