blob: f42974f6a5c6682f98934aadab7ba9143ad1fdc7 [file] [log] [blame]
Doug Zongkereef39442009-04-02 12:14:19 -07001#!/usr/bin/env python
2#
3# Copyright (C) 2008 The Android Open Source Project
4#
5# Licensed under the Apache License, Version 2.0 (the "License");
6# you may not use this file except in compliance with the License.
7# You may obtain a copy of the License at
8#
9# http://www.apache.org/licenses/LICENSE-2.0
10#
11# Unless required by applicable law or agreed to in writing, software
12# distributed under the License is distributed on an "AS IS" BASIS,
13# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14# See the License for the specific language governing permissions and
15# limitations under the License.
16
17"""
Tao Bao30df8b42018-04-23 15:32:53 -070018Given a target-files zipfile, produces an OTA package that installs that build.
19An incremental OTA is produced if -i is given, otherwise a full OTA is produced.
Doug Zongkereef39442009-04-02 12:14:19 -070020
Tao Bao30df8b42018-04-23 15:32:53 -070021Usage: ota_from_target_files [options] input_target_files output_ota_package
Doug Zongkereef39442009-04-02 12:14:19 -070022
Tao Bao30df8b42018-04-23 15:32:53 -070023Common options that apply to both of non-A/B and A/B OTAs
24
25 --downgrade
26 Intentionally generate an incremental OTA that updates from a newer build
Tao Baofaa8e0b2018-04-12 14:31:43 -070027 to an older one (e.g. downgrading from P preview back to O MR1).
28 "ota-downgrade=yes" will be set in the package metadata file. A data wipe
29 will always be enforced when using this flag, so "ota-wipe=yes" will also
30 be included in the metadata file. The update-binary in the source build
31 will be used in the OTA package, unless --binary flag is specified. Please
32 also check the comment for --override_timestamp below.
Tao Bao30df8b42018-04-23 15:32:53 -070033
34 -i (--incremental_from) <file>
35 Generate an incremental OTA using the given target-files zip as the
36 starting build.
37
38 -k (--package_key) <key>
39 Key to use to sign the package (default is the value of
40 default_system_dev_certificate from the input target-files's
Tao Bao59cf0c52019-06-25 10:04:24 -070041 META/misc_info.txt, or "build/make/target/product/security/testkey" if
42 that value is not specified).
Doug Zongkerafb32ea2011-09-22 10:28:04 -070043
44 For incremental OTAs, the default value is based on the source
45 target-file, not the target build.
Doug Zongkereef39442009-04-02 12:14:19 -070046
Tao Bao30df8b42018-04-23 15:32:53 -070047 --override_timestamp
48 Intentionally generate an incremental OTA that updates from a newer build
Tao Baofaa8e0b2018-04-12 14:31:43 -070049 to an older one (based on timestamp comparison), by setting the downgrade
50 flag in the package metadata. This differs from --downgrade flag, as we
51 don't enforce a data wipe with this flag. Because we know for sure this is
52 NOT an actual downgrade case, but two builds happen to be cut in a reverse
53 order (e.g. from two branches). A legit use case is that we cut a new
54 build C (after having A and B), but want to enfore an update path of A ->
55 C -> B. Specifying --downgrade may not help since that would enforce a
56 data wipe for C -> B update.
57
58 We used to set a fake timestamp in the package metadata for this flow. But
59 now we consolidate the two cases (i.e. an actual downgrade, or a downgrade
60 based on timestamp) with the same "ota-downgrade=yes" flag, with the
61 difference being whether "ota-wipe=yes" is set.
Doug Zongkereef39442009-04-02 12:14:19 -070062
Tao Bao30df8b42018-04-23 15:32:53 -070063 --wipe_user_data
64 Generate an OTA package that will wipe the user data partition when
65 installed.
66
Yifan Hong50e79542018-11-08 17:44:12 -080067 --retrofit_dynamic_partitions
68 Generates an OTA package that updates a device to support dynamic
69 partitions (default False). This flag is implied when generating
70 an incremental OTA where the base build does not support dynamic
71 partitions but the target build does. For A/B, when this flag is set,
72 --skip_postinstall is implied.
73
xunchangabfa2652019-02-19 16:27:10 -080074 --skip_compatibility_check
Yifan Hong9276cf02019-08-21 16:37:04 -070075 Skip checking compatibility of the input target files package.
xunchangabfa2652019-02-19 16:27:10 -080076
xunchang1cfe2512019-02-19 14:14:48 -080077 --output_metadata_path
78 Write a copy of the metadata to a separate file. Therefore, users can
79 read the post build fingerprint without extracting the OTA package.
80
Yifan Hong65afc072020-04-17 10:08:10 -070081 --force_non_ab
82 This flag can only be set on an A/B device that also supports non-A/B
83 updates. Implies --two_step.
84 If set, generate that non-A/B update package.
85 If not set, generates A/B package for A/B device and non-A/B package for
86 non-A/B device.
87
Tao Bao30df8b42018-04-23 15:32:53 -070088Non-A/B OTA specific options
89
90 -b (--binary) <file>
91 Use the given binary as the update-binary in the output package, instead
92 of the binary in the build's target_files. Use for development only.
93
94 --block
95 Generate a block-based OTA for non-A/B device. We have deprecated the
96 support for file-based OTA since O. Block-based OTA will be used by
97 default for all non-A/B devices. Keeping this flag here to not break
98 existing callers.
99
100 -e (--extra_script) <file>
101 Insert the contents of file at the end of the update script.
Tao Bao43078aa2015-04-21 14:32:35 -0700102
leozwangaa6c1a12015-08-14 10:57:58 -0700103 --full_bootloader
104 Similar to --full_radio. When generating an incremental OTA, always
105 include a full copy of bootloader image.
106
Tao Bao30df8b42018-04-23 15:32:53 -0700107 --full_radio
108 When generating an incremental OTA, always include a full copy of radio
109 image. This option is only meaningful when -i is specified, because a full
110 radio is always included in a full OTA if applicable.
Michael Runge63f01de2014-10-28 19:24:19 -0700111
Tao Bao30df8b42018-04-23 15:32:53 -0700112 --log_diff <file>
113 Generate a log file that shows the differences in the source and target
114 builds for an incremental package. This option is only meaningful when -i
115 is specified.
116
117 -o (--oem_settings) <main_file[,additional_files...]>
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800118 Comma seperated list of files used to specify the expected OEM-specific
Tao Bao481bab82017-12-21 11:23:09 -0800119 properties on the OEM partition of the intended device. Multiple expected
120 values can be used by providing multiple files. Only the first dict will
121 be used to compute fingerprint, while the rest will be used to assert
122 OEM-specific properties.
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800123
Tao Bao8608cde2016-02-25 19:49:55 -0800124 --oem_no_mount
Tao Bao30df8b42018-04-23 15:32:53 -0700125 For devices with OEM-specific properties but without an OEM partition, do
126 not mount the OEM partition in the updater-script. This should be very
127 rarely used, since it's expected to have a dedicated OEM partition for
128 OEM-specific properties. Only meaningful when -o is specified.
Tao Bao8608cde2016-02-25 19:49:55 -0800129
Tao Bao30df8b42018-04-23 15:32:53 -0700130 --stash_threshold <float>
131 Specify the threshold that will be used to compute the maximum allowed
132 stash size (defaults to 0.8).
Doug Zongkerdbfaae52009-04-21 17:12:54 -0700133
Tao Bao30df8b42018-04-23 15:32:53 -0700134 -t (--worker_threads) <int>
135 Specify the number of worker-threads that will be used when generating
136 patches for incremental updates (defaults to 3).
Tao Bao3e6161a2017-02-28 11:48:48 -0800137
Tao Bao30df8b42018-04-23 15:32:53 -0700138 --verify
139 Verify the checksums of the updated system and vendor (if any) partitions.
140 Non-A/B incremental OTAs only.
Doug Zongker1c390a22009-05-14 19:06:36 -0700141
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800142 -2 (--two_step)
Tao Bao30df8b42018-04-23 15:32:53 -0700143 Generate a 'two-step' OTA package, where recovery is updated first, so
144 that any changes made to the system partition are done using the new
145 recovery (new kernel, etc.).
146
147A/B OTA specific options
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800148
Tianjie Xu1b079832019-08-28 12:19:23 -0700149 --disable_fec_computation
150 Disable the on device FEC data computation for incremental updates.
151
Tao Baof7140c02018-01-30 17:09:24 -0800152 --include_secondary
153 Additionally include the payload for secondary slot images (default:
154 False). Only meaningful when generating A/B OTAs.
155
156 By default, an A/B OTA package doesn't contain the images for the
157 secondary slot (e.g. system_other.img). Specifying this flag allows
158 generating a separate payload that will install secondary slot images.
159
160 Such a package needs to be applied in a two-stage manner, with a reboot
161 in-between. During the first stage, the updater applies the primary
162 payload only. Upon finishing, it reboots the device into the newly updated
163 slot. It then continues to install the secondary payload to the inactive
164 slot, but without switching the active slot at the end (needs the matching
165 support in update_engine, i.e. SWITCH_SLOT_ON_REBOOT flag).
166
167 Due to the special install procedure, the secondary payload will be always
168 generated as a full payload.
169
Tao Baodea0f8b2016-06-20 17:55:06 -0700170 --payload_signer <signer>
171 Specify the signer when signing the payload and metadata for A/B OTAs.
172 By default (i.e. without this flag), it calls 'openssl pkeyutl' to sign
173 with the package private key. If the private key cannot be accessed
174 directly, a payload signer that knows how to do that should be specified.
175 The signer will be supplied with "-inkey <path_to_key>",
176 "-in <input_file>" and "-out <output_file>" parameters.
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700177
178 --payload_signer_args <args>
179 Specify the arguments needed for payload signer.
Tao Bao15a146a2018-02-21 16:06:59 -0800180
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700181 --payload_signer_maximum_signature_size <signature_size>
182 The maximum signature size (in bytes) that would be generated by the given
183 payload signer. Only meaningful when custom payload signer is specified
184 via '--payload_signer'.
185 If the signer uses a RSA key, this should be the number of bytes to
186 represent the modulus. If it uses an EC key, this is the size of a
187 DER-encoded ECDSA signature.
188
xunchang376cc7c2019-04-08 23:04:58 -0700189 --payload_signer_key_size <key_size>
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700190 Deprecated. Use the '--payload_signer_maximum_signature_size' instead.
xunchang376cc7c2019-04-08 23:04:58 -0700191
Tianjied6867162020-05-10 14:30:13 -0700192 --boot_variable_file <path>
193 A file that contains the possible values of ro.boot.* properties. It's
194 used to calculate the possible runtime fingerprints when some
195 ro.product.* properties are overridden by the 'import' statement.
196 The file expects one property per line, and each line has the following
197 format: 'prop_name=value1,value2'. e.g. 'ro.boot.product.sku=std,pro'
198
Tao Bao15a146a2018-02-21 16:06:59 -0800199 --skip_postinstall
200 Skip the postinstall hooks when generating an A/B OTA package (default:
201 False). Note that this discards ALL the hooks, including non-optional
202 ones. Should only be used if caller knows it's safe to do so (e.g. all the
203 postinstall work is to dexopt apps and a data wipe will happen immediately
204 after). Only meaningful when generating A/B OTAs.
Doug Zongkereef39442009-04-02 12:14:19 -0700205"""
206
Tao Bao89fbb0f2017-01-10 10:47:58 -0800207from __future__ import print_function
208
Tao Bao32fcdab2018-10-12 10:30:39 -0700209import logging
Doug Zongkerfc44a512014-08-26 13:10:25 -0700210import multiprocessing
Tao Bao2dd1c482017-02-03 16:49:39 -0800211import os.path
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700212import shlex
Tao Bao15a146a2018-02-21 16:06:59 -0800213import shutil
Tao Bao85f16982018-03-08 16:28:33 -0800214import struct
Tao Bao481bab82017-12-21 11:23:09 -0800215import sys
Doug Zongkereef39442009-04-02 12:14:19 -0700216import zipfile
217
218import common
Kelvin Zhang0876c412020-06-23 15:06:58 -0400219import target_files_diff
Kelvin Zhangcff4d762020-07-29 16:37:51 -0400220from check_target_files_vintf import CheckVintfIfTrebleEnabled
221from non_ab_ota import GenerateNonAbOtaPackage
222from ota_utils import (UNZIP_PATTERN, FinalizeMetadata, GetPackageMetadata,
223 PropertyFiles)
Kelvin Zhang0876c412020-06-23 15:06:58 -0400224
Tao Bao481bab82017-12-21 11:23:09 -0800225if sys.hexversion < 0x02070000:
226 print("Python 2.7 or newer is required.", file=sys.stderr)
227 sys.exit(1)
228
Tao Bao32fcdab2018-10-12 10:30:39 -0700229logger = logging.getLogger(__name__)
Tao Bao481bab82017-12-21 11:23:09 -0800230
Doug Zongkereef39442009-04-02 12:14:19 -0700231OPTIONS = common.OPTIONS
Doug Zongkerafb32ea2011-09-22 10:28:04 -0700232OPTIONS.package_key = None
Doug Zongkereef39442009-04-02 12:14:19 -0700233OPTIONS.incremental_source = None
Michael Runge63f01de2014-10-28 19:24:19 -0700234OPTIONS.verify = False
Doug Zongkereef39442009-04-02 12:14:19 -0700235OPTIONS.patch_threshold = 0.95
Doug Zongkerdbfaae52009-04-21 17:12:54 -0700236OPTIONS.wipe_user_data = False
Tao Bao5d182562016-02-23 11:38:39 -0800237OPTIONS.downgrade = False
Doug Zongker1c390a22009-05-14 19:06:36 -0700238OPTIONS.extra_script = None
Doug Zongkerfc44a512014-08-26 13:10:25 -0700239OPTIONS.worker_threads = multiprocessing.cpu_count() // 2
240if OPTIONS.worker_threads == 0:
241 OPTIONS.worker_threads = 1
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800242OPTIONS.two_step = False
Tao Baof7140c02018-01-30 17:09:24 -0800243OPTIONS.include_secondary = False
Takeshi Kanemotoe153b342013-11-14 17:20:50 +0900244OPTIONS.no_signing = False
Tao Bao457cbf62017-03-06 09:56:01 -0800245OPTIONS.block_based = True
Doug Zongker25568482014-03-03 10:21:27 -0800246OPTIONS.updater_binary = None
Tianjie Xu9afb2212020-05-10 21:48:15 +0000247OPTIONS.oem_dicts = None
Michael Runge6e836112014-04-15 17:40:21 -0700248OPTIONS.oem_source = None
Tao Bao8608cde2016-02-25 19:49:55 -0800249OPTIONS.oem_no_mount = False
Tao Bao43078aa2015-04-21 14:32:35 -0700250OPTIONS.full_radio = False
leozwangaa6c1a12015-08-14 10:57:58 -0700251OPTIONS.full_bootloader = False
Tao Baod47d8e12015-05-21 14:09:49 -0700252# Stash size cannot exceed cache_size * threshold.
253OPTIONS.cache_size = None
254OPTIONS.stash_threshold = 0.8
Tao Baod62c6032015-11-30 09:40:20 -0800255OPTIONS.log_diff = None
Tao Baodea0f8b2016-06-20 17:55:06 -0700256OPTIONS.payload_signer = None
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700257OPTIONS.payload_signer_args = []
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700258OPTIONS.payload_signer_maximum_signature_size = None
Tao Bao5f8ff932017-03-21 22:35:00 -0700259OPTIONS.extracted_input = None
Christian Oderf63e2cd2017-05-01 22:30:15 +0200260OPTIONS.key_passwords = []
Tao Bao15a146a2018-02-21 16:06:59 -0800261OPTIONS.skip_postinstall = False
Yifan Hong50e79542018-11-08 17:44:12 -0800262OPTIONS.retrofit_dynamic_partitions = False
xunchangabfa2652019-02-19 16:27:10 -0800263OPTIONS.skip_compatibility_check = False
xunchang1cfe2512019-02-19 14:14:48 -0800264OPTIONS.output_metadata_path = None
Tianjie Xu1b079832019-08-28 12:19:23 -0700265OPTIONS.disable_fec_computation = False
Yifan Hong65afc072020-04-17 10:08:10 -0700266OPTIONS.force_non_ab = False
Tianjied6867162020-05-10 14:30:13 -0700267OPTIONS.boot_variable_file = None
Tao Bao15a146a2018-02-21 16:06:59 -0800268
Tao Bao8dcf7382015-05-21 14:09:49 -0700269
Tao Bao15a146a2018-02-21 16:06:59 -0800270POSTINSTALL_CONFIG = 'META/postinstall_config.txt'
Yifan Hong50e79542018-11-08 17:44:12 -0800271DYNAMIC_PARTITION_INFO = 'META/dynamic_partitions_info.txt'
Yifan Hongb433eba2019-03-06 12:42:53 -0800272AB_PARTITIONS = 'META/ab_partitions.txt'
Kelvin Zhangcff4d762020-07-29 16:37:51 -0400273
Tao Baof0c4aa22018-04-30 20:29:30 -0700274# Files to be unzipped for target diffing purpose.
275TARGET_DIFFING_UNZIP_PATTERN = ['BOOT', 'RECOVERY', 'SYSTEM/*', 'VENDOR/*',
Yifan Hongcfb917a2020-05-07 14:58:20 -0700276 'PRODUCT/*', 'SYSTEM_EXT/*', 'ODM/*',
Yifan Hongf496f1b2020-07-15 16:52:59 -0700277 'VENDOR_DLKM/*', 'ODM_DLKM/*']
Yifan Hongb433eba2019-03-06 12:42:53 -0800278RETROFIT_DAP_UNZIP_PATTERN = ['OTA/super_*.img', AB_PARTITIONS]
Tao Bao3e759462019-09-17 22:43:11 -0700279
280# Images to be excluded from secondary payload. We essentially only keep
281# 'system_other' and bootloader partitions.
282SECONDARY_PAYLOAD_SKIPPED_IMAGES = [
Yifan Hongf496f1b2020-07-15 16:52:59 -0700283 'boot', 'dtbo', 'modem', 'odm', 'odm_dlkm', 'product', 'radio', 'recovery',
Tianjiec3850642020-05-13 14:47:31 -0700284 'system_ext', 'vbmeta', 'vbmeta_system', 'vbmeta_vendor', 'vendor',
Yifan Hongf496f1b2020-07-15 16:52:59 -0700285 'vendor_boot']
Tao Bao6b0b2f92017-03-05 11:38:11 -0800286
Tao Bao2dd1c482017-02-03 16:49:39 -0800287
Tao Baofabe0832018-01-17 15:52:28 -0800288class PayloadSigner(object):
289 """A class that wraps the payload signing works.
290
291 When generating a Payload, hashes of the payload and metadata files will be
292 signed with the device key, either by calling an external payload signer or
293 by calling openssl with the package key. This class provides a unified
294 interface, so that callers can just call PayloadSigner.Sign().
295
296 If an external payload signer has been specified (OPTIONS.payload_signer), it
297 calls the signer with the provided args (OPTIONS.payload_signer_args). Note
298 that the signing key should be provided as part of the payload_signer_args.
299 Otherwise without an external signer, it uses the package key
300 (OPTIONS.package_key) and calls openssl for the signing works.
301 """
302
303 def __init__(self):
304 if OPTIONS.payload_signer is None:
305 # Prepare the payload signing key.
306 private_key = OPTIONS.package_key + OPTIONS.private_key_suffix
307 pw = OPTIONS.key_passwords[OPTIONS.package_key]
308
309 cmd = ["openssl", "pkcs8", "-in", private_key, "-inform", "DER"]
310 cmd.extend(["-passin", "pass:" + pw] if pw else ["-nocrypt"])
311 signing_key = common.MakeTempFile(prefix="key-", suffix=".key")
312 cmd.extend(["-out", signing_key])
Tao Baobec89c12018-10-15 11:53:28 -0700313 common.RunAndCheckOutput(cmd, verbose=False)
Tao Baofabe0832018-01-17 15:52:28 -0800314
315 self.signer = "openssl"
316 self.signer_args = ["pkeyutl", "-sign", "-inkey", signing_key,
317 "-pkeyopt", "digest:sha256"]
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700318 self.maximum_signature_size = self._GetMaximumSignatureSizeInBytes(
319 signing_key)
Tao Baofabe0832018-01-17 15:52:28 -0800320 else:
321 self.signer = OPTIONS.payload_signer
322 self.signer_args = OPTIONS.payload_signer_args
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700323 if OPTIONS.payload_signer_maximum_signature_size:
324 self.maximum_signature_size = int(
325 OPTIONS.payload_signer_maximum_signature_size)
xunchang376cc7c2019-04-08 23:04:58 -0700326 else:
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700327 # The legacy config uses RSA2048 keys.
328 logger.warning("The maximum signature size for payload signer is not"
329 " set, default to 256 bytes.")
330 self.maximum_signature_size = 256
xunchang376cc7c2019-04-08 23:04:58 -0700331
332 @staticmethod
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700333 def _GetMaximumSignatureSizeInBytes(signing_key):
334 out_signature_size_file = common.MakeTempFile("signature_size")
335 cmd = ["delta_generator", "--out_maximum_signature_size_file={}".format(
336 out_signature_size_file), "--private_key={}".format(signing_key)]
337 common.RunAndCheckOutput(cmd)
338 with open(out_signature_size_file) as f:
339 signature_size = f.read().rstrip()
Luca Stefani88e1a142020-03-27 14:05:12 +0100340 logger.info("%s outputs the maximum signature size: %s", cmd[0],
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700341 signature_size)
342 return int(signature_size)
Tao Baofabe0832018-01-17 15:52:28 -0800343
344 def Sign(self, in_file):
345 """Signs the given input file. Returns the output filename."""
346 out_file = common.MakeTempFile(prefix="signed-", suffix=".bin")
347 cmd = [self.signer] + self.signer_args + ['-in', in_file, '-out', out_file]
Tao Bao718faed2019-08-02 13:24:19 -0700348 common.RunAndCheckOutput(cmd)
Tao Baofabe0832018-01-17 15:52:28 -0800349 return out_file
350
351
Tao Bao40b18822018-01-30 18:19:04 -0800352class Payload(object):
353 """Manages the creation and the signing of an A/B OTA Payload."""
354
355 PAYLOAD_BIN = 'payload.bin'
356 PAYLOAD_PROPERTIES_TXT = 'payload_properties.txt'
Tao Baof7140c02018-01-30 17:09:24 -0800357 SECONDARY_PAYLOAD_BIN = 'secondary/payload.bin'
358 SECONDARY_PAYLOAD_PROPERTIES_TXT = 'secondary/payload_properties.txt'
Tao Bao40b18822018-01-30 18:19:04 -0800359
Tao Bao667ff572018-02-10 00:02:40 -0800360 def __init__(self, secondary=False):
361 """Initializes a Payload instance.
362
363 Args:
364 secondary: Whether it's generating a secondary payload (default: False).
365 """
Tao Bao40b18822018-01-30 18:19:04 -0800366 self.payload_file = None
367 self.payload_properties = None
Tao Bao667ff572018-02-10 00:02:40 -0800368 self.secondary = secondary
Tao Bao40b18822018-01-30 18:19:04 -0800369
Tao Baof0c4aa22018-04-30 20:29:30 -0700370 def _Run(self, cmd): # pylint: disable=no-self-use
Tao Bao718faed2019-08-02 13:24:19 -0700371 # Don't pipe (buffer) the output if verbose is set. Let
372 # brillo_update_payload write to stdout/stderr directly, so its progress can
373 # be monitored.
374 if OPTIONS.verbose:
375 common.RunAndCheckOutput(cmd, stdout=None, stderr=None)
376 else:
377 common.RunAndCheckOutput(cmd)
378
Tao Bao40b18822018-01-30 18:19:04 -0800379 def Generate(self, target_file, source_file=None, additional_args=None):
380 """Generates a payload from the given target-files zip(s).
381
382 Args:
383 target_file: The filename of the target build target-files zip.
384 source_file: The filename of the source build target-files zip; or None if
385 generating a full OTA.
386 additional_args: A list of additional args that should be passed to
387 brillo_update_payload script; or None.
388 """
389 if additional_args is None:
390 additional_args = []
391
392 payload_file = common.MakeTempFile(prefix="payload-", suffix=".bin")
393 cmd = ["brillo_update_payload", "generate",
394 "--payload", payload_file,
395 "--target_image", target_file]
396 if source_file is not None:
397 cmd.extend(["--source_image", source_file])
Tianjie Xu1b079832019-08-28 12:19:23 -0700398 if OPTIONS.disable_fec_computation:
399 cmd.extend(["--disable_fec_computation", "true"])
Tao Bao40b18822018-01-30 18:19:04 -0800400 cmd.extend(additional_args)
Tao Bao718faed2019-08-02 13:24:19 -0700401 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800402
403 self.payload_file = payload_file
404 self.payload_properties = None
405
406 def Sign(self, payload_signer):
407 """Generates and signs the hashes of the payload and metadata.
408
409 Args:
410 payload_signer: A PayloadSigner() instance that serves the signing work.
411
412 Raises:
413 AssertionError: On any failure when calling brillo_update_payload script.
414 """
415 assert isinstance(payload_signer, PayloadSigner)
416
417 # 1. Generate hashes of the payload and metadata files.
418 payload_sig_file = common.MakeTempFile(prefix="sig-", suffix=".bin")
419 metadata_sig_file = common.MakeTempFile(prefix="sig-", suffix=".bin")
420 cmd = ["brillo_update_payload", "hash",
421 "--unsigned_payload", self.payload_file,
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700422 "--signature_size", str(payload_signer.maximum_signature_size),
Tao Bao40b18822018-01-30 18:19:04 -0800423 "--metadata_hash_file", metadata_sig_file,
424 "--payload_hash_file", payload_sig_file]
Tao Bao718faed2019-08-02 13:24:19 -0700425 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800426
427 # 2. Sign the hashes.
428 signed_payload_sig_file = payload_signer.Sign(payload_sig_file)
429 signed_metadata_sig_file = payload_signer.Sign(metadata_sig_file)
430
431 # 3. Insert the signatures back into the payload file.
432 signed_payload_file = common.MakeTempFile(prefix="signed-payload-",
433 suffix=".bin")
434 cmd = ["brillo_update_payload", "sign",
435 "--unsigned_payload", self.payload_file,
436 "--payload", signed_payload_file,
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700437 "--signature_size", str(payload_signer.maximum_signature_size),
Tao Bao40b18822018-01-30 18:19:04 -0800438 "--metadata_signature_file", signed_metadata_sig_file,
439 "--payload_signature_file", signed_payload_sig_file]
Tao Bao718faed2019-08-02 13:24:19 -0700440 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800441
442 # 4. Dump the signed payload properties.
443 properties_file = common.MakeTempFile(prefix="payload-properties-",
444 suffix=".txt")
445 cmd = ["brillo_update_payload", "properties",
446 "--payload", signed_payload_file,
447 "--properties_file", properties_file]
Tao Bao718faed2019-08-02 13:24:19 -0700448 self._Run(cmd)
Tao Bao40b18822018-01-30 18:19:04 -0800449
Tao Bao667ff572018-02-10 00:02:40 -0800450 if self.secondary:
451 with open(properties_file, "a") as f:
452 f.write("SWITCH_SLOT_ON_REBOOT=0\n")
453
Tao Bao40b18822018-01-30 18:19:04 -0800454 if OPTIONS.wipe_user_data:
455 with open(properties_file, "a") as f:
456 f.write("POWERWASH=1\n")
457
458 self.payload_file = signed_payload_file
459 self.payload_properties = properties_file
460
Tao Bao667ff572018-02-10 00:02:40 -0800461 def WriteToZip(self, output_zip):
Tao Bao40b18822018-01-30 18:19:04 -0800462 """Writes the payload to the given zip.
463
464 Args:
465 output_zip: The output ZipFile instance.
466 """
467 assert self.payload_file is not None
468 assert self.payload_properties is not None
469
Tao Bao667ff572018-02-10 00:02:40 -0800470 if self.secondary:
Tao Baof7140c02018-01-30 17:09:24 -0800471 payload_arcname = Payload.SECONDARY_PAYLOAD_BIN
472 payload_properties_arcname = Payload.SECONDARY_PAYLOAD_PROPERTIES_TXT
473 else:
474 payload_arcname = Payload.PAYLOAD_BIN
475 payload_properties_arcname = Payload.PAYLOAD_PROPERTIES_TXT
476
Tao Bao40b18822018-01-30 18:19:04 -0800477 # Add the signed payload file and properties into the zip. In order to
478 # support streaming, we pack them as ZIP_STORED. So these entries can be
479 # read directly with the offset and length pairs.
Tao Baof7140c02018-01-30 17:09:24 -0800480 common.ZipWrite(output_zip, self.payload_file, arcname=payload_arcname,
Tao Bao40b18822018-01-30 18:19:04 -0800481 compress_type=zipfile.ZIP_STORED)
482 common.ZipWrite(output_zip, self.payload_properties,
Tao Baof7140c02018-01-30 17:09:24 -0800483 arcname=payload_properties_arcname,
Tao Bao40b18822018-01-30 18:19:04 -0800484 compress_type=zipfile.ZIP_STORED)
485
486
Tao Bao481bab82017-12-21 11:23:09 -0800487def _LoadOemDicts(oem_source):
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800488 """Returns the list of loaded OEM properties dict."""
Tao Bao481bab82017-12-21 11:23:09 -0800489 if not oem_source:
490 return None
491
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800492 oem_dicts = []
Tao Bao481bab82017-12-21 11:23:09 -0800493 for oem_file in oem_source:
494 with open(oem_file) as fp:
495 oem_dicts.append(common.LoadDictionaryFromLines(fp.readlines()))
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800496 return oem_dicts
Doug Zongkereef39442009-04-02 12:14:19 -0700497
Doug Zongkereef39442009-04-02 12:14:19 -0700498
Tao Baod3fc38a2018-03-08 16:09:01 -0800499class StreamingPropertyFiles(PropertyFiles):
500 """A subclass for computing the property-files for streaming A/B OTAs."""
501
502 def __init__(self):
503 super(StreamingPropertyFiles, self).__init__()
504 self.name = 'ota-streaming-property-files'
505 self.required = (
506 # payload.bin and payload_properties.txt must exist.
507 'payload.bin',
508 'payload_properties.txt',
509 )
510 self.optional = (
Tianjie Xu4c05f4a2018-09-14 16:24:41 -0700511 # care_map is available only if dm-verity is enabled.
512 'care_map.pb',
Tao Baod3fc38a2018-03-08 16:09:01 -0800513 'care_map.txt',
514 # compatibility.zip is available only if target supports Treble.
515 'compatibility.zip',
516 )
517
518
Tao Bao85f16982018-03-08 16:28:33 -0800519class AbOtaPropertyFiles(StreamingPropertyFiles):
520 """The property-files for A/B OTA that includes payload_metadata.bin info.
521
522 Since P, we expose one more token (aka property-file), in addition to the ones
523 for streaming A/B OTA, for a virtual entry of 'payload_metadata.bin'.
524 'payload_metadata.bin' is the header part of a payload ('payload.bin'), which
525 doesn't exist as a separate ZIP entry, but can be used to verify if the
526 payload can be applied on the given device.
527
528 For backward compatibility, we keep both of the 'ota-streaming-property-files'
529 and the newly added 'ota-property-files' in P. The new token will only be
530 available in 'ota-property-files'.
531 """
532
533 def __init__(self):
534 super(AbOtaPropertyFiles, self).__init__()
535 self.name = 'ota-property-files'
536
537 def _GetPrecomputed(self, input_zip):
538 offset, size = self._GetPayloadMetadataOffsetAndSize(input_zip)
539 return ['payload_metadata.bin:{}:{}'.format(offset, size)]
540
541 @staticmethod
542 def _GetPayloadMetadataOffsetAndSize(input_zip):
543 """Computes the offset and size of the payload metadata for a given package.
544
545 (From system/update_engine/update_metadata.proto)
546 A delta update file contains all the deltas needed to update a system from
547 one specific version to another specific version. The update format is
548 represented by this struct pseudocode:
549
550 struct delta_update_file {
551 char magic[4] = "CrAU";
552 uint64 file_format_version;
553 uint64 manifest_size; // Size of protobuf DeltaArchiveManifest
554
555 // Only present if format_version > 1:
556 uint32 metadata_signature_size;
557
558 // The Bzip2 compressed DeltaArchiveManifest
559 char manifest[metadata_signature_size];
560
561 // The signature of the metadata (from the beginning of the payload up to
562 // this location, not including the signature itself). This is a
563 // serialized Signatures message.
564 char medatada_signature_message[metadata_signature_size];
565
566 // Data blobs for files, no specific format. The specific offset
567 // and length of each data blob is recorded in the DeltaArchiveManifest.
568 struct {
569 char data[];
570 } blobs[];
571
572 // These two are not signed:
573 uint64 payload_signatures_message_size;
574 char payload_signatures_message[];
575 };
576
577 'payload-metadata.bin' contains all the bytes from the beginning of the
578 payload, till the end of 'medatada_signature_message'.
579 """
580 payload_info = input_zip.getinfo('payload.bin')
Shashikant Baviskar338856f2018-04-12 12:11:22 +0900581 payload_offset = payload_info.header_offset
582 payload_offset += zipfile.sizeFileHeader
583 payload_offset += len(payload_info.extra) + len(payload_info.filename)
Tao Bao85f16982018-03-08 16:28:33 -0800584 payload_size = payload_info.file_size
585
Tao Bao59cf0c52019-06-25 10:04:24 -0700586 with input_zip.open('payload.bin') as payload_fp:
Tao Bao85f16982018-03-08 16:28:33 -0800587 header_bin = payload_fp.read(24)
588
589 # network byte order (big-endian)
590 header = struct.unpack("!IQQL", header_bin)
591
592 # 'CrAU'
593 magic = header[0]
594 assert magic == 0x43724155, "Invalid magic: {:x}".format(magic)
595
596 manifest_size = header[2]
597 metadata_signature_size = header[3]
598 metadata_total = 24 + manifest_size + metadata_signature_size
599 assert metadata_total < payload_size
600
601 return (payload_offset, metadata_total)
602
603
Tao Bao15a146a2018-02-21 16:06:59 -0800604def GetTargetFilesZipForSecondaryImages(input_file, skip_postinstall=False):
Tao Baof7140c02018-01-30 17:09:24 -0800605 """Returns a target-files.zip file for generating secondary payload.
606
607 Although the original target-files.zip already contains secondary slot
608 images (i.e. IMAGES/system_other.img), we need to rename the files to the
609 ones without _other suffix. Note that we cannot instead modify the names in
610 META/ab_partitions.txt, because there are no matching partitions on device.
611
612 For the partitions that don't have secondary images, the ones for primary
613 slot will be used. This is to ensure that we always have valid boot, vbmeta,
614 bootloader images in the inactive slot.
615
616 Args:
617 input_file: The input target-files.zip file.
Tao Bao15a146a2018-02-21 16:06:59 -0800618 skip_postinstall: Whether to skip copying the postinstall config file.
Tao Baof7140c02018-01-30 17:09:24 -0800619
620 Returns:
621 The filename of the target-files.zip for generating secondary payload.
622 """
Tianjie Xu1c808002019-09-11 00:29:26 -0700623
624 def GetInfoForSecondaryImages(info_file):
625 """Updates info file for secondary payload generation.
626
627 Scan each line in the info file, and remove the unwanted partitions from
628 the dynamic partition list in the related properties. e.g.
629 "super_google_dynamic_partitions_partition_list=system vendor product"
630 will become "super_google_dynamic_partitions_partition_list=system".
631
632 Args:
633 info_file: The input info file. e.g. misc_info.txt.
634
635 Returns:
636 A string of the updated info content.
637 """
638
639 output_list = []
640 with open(info_file) as f:
641 lines = f.read().splitlines()
642
643 # The suffix in partition_list variables that follows the name of the
644 # partition group.
645 LIST_SUFFIX = 'partition_list'
646 for line in lines:
647 if line.startswith('#') or '=' not in line:
648 output_list.append(line)
649 continue
650 key, value = line.strip().split('=', 1)
651 if key == 'dynamic_partition_list' or key.endswith(LIST_SUFFIX):
652 partitions = value.split()
653 partitions = [partition for partition in partitions if partition
Tao Bao3e759462019-09-17 22:43:11 -0700654 not in SECONDARY_PAYLOAD_SKIPPED_IMAGES]
Tianjie Xu1c808002019-09-11 00:29:26 -0700655 output_list.append('{}={}'.format(key, ' '.join(partitions)))
Kelvin Zhang0876c412020-06-23 15:06:58 -0400656 elif key in ['virtual_ab', "virtual_ab_retrofit"]:
Yifan Hongfe073432019-11-01 12:28:31 -0700657 # Remove virtual_ab flag from secondary payload so that OTA client
658 # don't use snapshots for secondary update
659 pass
Tianjie Xu1c808002019-09-11 00:29:26 -0700660 else:
661 output_list.append(line)
662 return '\n'.join(output_list)
663
Tao Baof7140c02018-01-30 17:09:24 -0800664 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
665 target_zip = zipfile.ZipFile(target_file, 'w', allowZip64=True)
666
Tao Baodba59ee2018-01-09 13:21:02 -0800667 with zipfile.ZipFile(input_file, 'r') as input_zip:
668 infolist = input_zip.infolist()
Tao Bao12489802018-07-12 14:47:38 -0700669
Tao Bao0ff15de2019-03-20 11:26:06 -0700670 input_tmp = common.UnzipTemp(input_file, UNZIP_PATTERN)
Tao Baodba59ee2018-01-09 13:21:02 -0800671 for info in infolist:
Tao Baof7140c02018-01-30 17:09:24 -0800672 unzipped_file = os.path.join(input_tmp, *info.filename.split('/'))
673 if info.filename == 'IMAGES/system_other.img':
674 common.ZipWrite(target_zip, unzipped_file, arcname='IMAGES/system.img')
675
676 # Primary images and friends need to be skipped explicitly.
677 elif info.filename in ('IMAGES/system.img',
678 'IMAGES/system.map'):
679 pass
Tao Bao3e759462019-09-17 22:43:11 -0700680
681 # Copy images that are not in SECONDARY_PAYLOAD_SKIPPED_IMAGES.
682 elif info.filename.startswith(('IMAGES/', 'RADIO/')):
683 image_name = os.path.basename(info.filename)
684 if image_name not in ['{}.img'.format(partition) for partition in
685 SECONDARY_PAYLOAD_SKIPPED_IMAGES]:
686 common.ZipWrite(target_zip, unzipped_file, arcname=info.filename)
Tao Baof7140c02018-01-30 17:09:24 -0800687
Tao Bao15a146a2018-02-21 16:06:59 -0800688 # Skip copying the postinstall config if requested.
689 elif skip_postinstall and info.filename == POSTINSTALL_CONFIG:
690 pass
691
Tianjie Xu1c808002019-09-11 00:29:26 -0700692 elif info.filename.startswith('META/'):
693 # Remove the unnecessary partitions for secondary images from the
694 # ab_partitions file.
695 if info.filename == AB_PARTITIONS:
696 with open(unzipped_file) as f:
697 partition_list = f.read().splitlines()
698 partition_list = [partition for partition in partition_list if partition
Tao Bao3e759462019-09-17 22:43:11 -0700699 and partition not in SECONDARY_PAYLOAD_SKIPPED_IMAGES]
Kelvin Zhang0876c412020-06-23 15:06:58 -0400700 common.ZipWriteStr(target_zip, info.filename,
701 '\n'.join(partition_list))
Tianjie Xu1c808002019-09-11 00:29:26 -0700702 # Remove the unnecessary partitions from the dynamic partitions list.
703 elif (info.filename == 'META/misc_info.txt' or
704 info.filename == DYNAMIC_PARTITION_INFO):
705 modified_info = GetInfoForSecondaryImages(unzipped_file)
706 common.ZipWriteStr(target_zip, info.filename, modified_info)
707 else:
708 common.ZipWrite(target_zip, unzipped_file, arcname=info.filename)
Tao Baof7140c02018-01-30 17:09:24 -0800709
Tao Baof7140c02018-01-30 17:09:24 -0800710 common.ZipClose(target_zip)
711
712 return target_file
713
714
Tao Bao15a146a2018-02-21 16:06:59 -0800715def GetTargetFilesZipWithoutPostinstallConfig(input_file):
716 """Returns a target-files.zip that's not containing postinstall_config.txt.
717
718 This allows brillo_update_payload script to skip writing all the postinstall
719 hooks in the generated payload. The input target-files.zip file will be
720 duplicated, with 'META/postinstall_config.txt' skipped. If input_file doesn't
721 contain the postinstall_config.txt entry, the input file will be returned.
722
723 Args:
724 input_file: The input target-files.zip filename.
725
726 Returns:
727 The filename of target-files.zip that doesn't contain postinstall config.
728 """
729 # We should only make a copy if postinstall_config entry exists.
730 with zipfile.ZipFile(input_file, 'r') as input_zip:
731 if POSTINSTALL_CONFIG not in input_zip.namelist():
732 return input_file
733
734 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
735 shutil.copyfile(input_file, target_file)
736 common.ZipDelete(target_file, POSTINSTALL_CONFIG)
737 return target_file
738
739
Yifan Hong50e79542018-11-08 17:44:12 -0800740def GetTargetFilesZipForRetrofitDynamicPartitions(input_file,
Yifan Hongb433eba2019-03-06 12:42:53 -0800741 super_block_devices,
742 dynamic_partition_list):
Yifan Hong50e79542018-11-08 17:44:12 -0800743 """Returns a target-files.zip for retrofitting dynamic partitions.
744
745 This allows brillo_update_payload to generate an OTA based on the exact
746 bits on the block devices. Postinstall is disabled.
747
748 Args:
749 input_file: The input target-files.zip filename.
750 super_block_devices: The list of super block devices
Yifan Hongb433eba2019-03-06 12:42:53 -0800751 dynamic_partition_list: The list of dynamic partitions
Yifan Hong50e79542018-11-08 17:44:12 -0800752
753 Returns:
754 The filename of target-files.zip with *.img replaced with super_*.img for
755 each block device in super_block_devices.
756 """
757 assert super_block_devices, "No super_block_devices are specified."
758
759 replace = {'OTA/super_{}.img'.format(dev): 'IMAGES/{}.img'.format(dev)
Tao Bao03fecb62018-11-28 10:59:23 -0800760 for dev in super_block_devices}
Yifan Hong50e79542018-11-08 17:44:12 -0800761
762 target_file = common.MakeTempFile(prefix="targetfiles-", suffix=".zip")
763 shutil.copyfile(input_file, target_file)
764
Tao Baoa3705452019-06-24 15:33:41 -0700765 with zipfile.ZipFile(input_file) as input_zip:
Yifan Hong50e79542018-11-08 17:44:12 -0800766 namelist = input_zip.namelist()
767
Yifan Hongb433eba2019-03-06 12:42:53 -0800768 input_tmp = common.UnzipTemp(input_file, RETROFIT_DAP_UNZIP_PATTERN)
769
770 # Remove partitions from META/ab_partitions.txt that is in
771 # dynamic_partition_list but not in super_block_devices so that
772 # brillo_update_payload won't generate update for those logical partitions.
773 ab_partitions_file = os.path.join(input_tmp, *AB_PARTITIONS.split('/'))
774 with open(ab_partitions_file) as f:
775 ab_partitions_lines = f.readlines()
776 ab_partitions = [line.strip() for line in ab_partitions_lines]
777 # Assert that all super_block_devices are in ab_partitions
778 super_device_not_updated = [partition for partition in super_block_devices
779 if partition not in ab_partitions]
780 assert not super_device_not_updated, \
781 "{} is in super_block_devices but not in {}".format(
782 super_device_not_updated, AB_PARTITIONS)
783 # ab_partitions -= (dynamic_partition_list - super_block_devices)
Kelvin Zhang0876c412020-06-23 15:06:58 -0400784 new_ab_partitions = common.MakeTempFile(
785 prefix="ab_partitions", suffix=".txt")
Yifan Hongb433eba2019-03-06 12:42:53 -0800786 with open(new_ab_partitions, 'w') as f:
787 for partition in ab_partitions:
788 if (partition in dynamic_partition_list and
789 partition not in super_block_devices):
Tao Bao59cf0c52019-06-25 10:04:24 -0700790 logger.info("Dropping %s from ab_partitions.txt", partition)
791 continue
Yifan Hongb433eba2019-03-06 12:42:53 -0800792 f.write(partition + "\n")
793 to_delete = [AB_PARTITIONS]
794
Yifan Hong50e79542018-11-08 17:44:12 -0800795 # Always skip postinstall for a retrofit update.
Yifan Hongb433eba2019-03-06 12:42:53 -0800796 to_delete += [POSTINSTALL_CONFIG]
Yifan Hong50e79542018-11-08 17:44:12 -0800797
798 # Delete dynamic_partitions_info.txt so that brillo_update_payload thinks this
799 # is a regular update on devices without dynamic partitions support.
800 to_delete += [DYNAMIC_PARTITION_INFO]
801
Tao Bao03fecb62018-11-28 10:59:23 -0800802 # Remove the existing partition images as well as the map files.
Tao Bao59cf0c52019-06-25 10:04:24 -0700803 to_delete += list(replace.values())
Tao Bao03fecb62018-11-28 10:59:23 -0800804 to_delete += ['IMAGES/{}.map'.format(dev) for dev in super_block_devices]
Yifan Hong50e79542018-11-08 17:44:12 -0800805
806 common.ZipDelete(target_file, to_delete)
807
Yifan Hong50e79542018-11-08 17:44:12 -0800808 target_zip = zipfile.ZipFile(target_file, 'a', allowZip64=True)
809
810 # Write super_{foo}.img as {foo}.img.
811 for src, dst in replace.items():
812 assert src in namelist, \
Tao Bao59cf0c52019-06-25 10:04:24 -0700813 'Missing {} in {}; {} cannot be written'.format(src, input_file, dst)
Yifan Hong50e79542018-11-08 17:44:12 -0800814 unzipped_file = os.path.join(input_tmp, *src.split('/'))
815 common.ZipWrite(target_zip, unzipped_file, arcname=dst)
816
Yifan Hongb433eba2019-03-06 12:42:53 -0800817 # Write new ab_partitions.txt file
818 common.ZipWrite(target_zip, new_ab_partitions, arcname=AB_PARTITIONS)
819
Yifan Hong50e79542018-11-08 17:44:12 -0800820 common.ZipClose(target_zip)
821
822 return target_file
823
824
Tao Baof0c4aa22018-04-30 20:29:30 -0700825def GenerateAbOtaPackage(target_file, output_file, source_file=None):
Tao Baofe5b69a2018-03-02 09:47:43 -0800826 """Generates an Android OTA package that has A/B update payload."""
Tao Baodea0f8b2016-06-20 17:55:06 -0700827 # Stage the output zip package for package signing.
Tao Bao491d7e22018-02-21 13:17:22 -0800828 if not OPTIONS.no_signing:
829 staging_file = common.MakeTempFile(suffix='.zip')
830 else:
831 staging_file = output_file
Tao Baoa652c002018-03-01 19:31:38 -0800832 output_zip = zipfile.ZipFile(staging_file, "w",
Tao Baoc098e9e2016-01-07 13:03:56 -0800833 compression=zipfile.ZIP_DEFLATED)
834
Tao Bao481bab82017-12-21 11:23:09 -0800835 if source_file is not None:
Tao Bao1c320f82019-10-04 23:25:12 -0700836 target_info = common.BuildInfo(OPTIONS.target_info_dict, OPTIONS.oem_dicts)
837 source_info = common.BuildInfo(OPTIONS.source_info_dict, OPTIONS.oem_dicts)
Tao Bao481bab82017-12-21 11:23:09 -0800838 else:
Tao Bao1c320f82019-10-04 23:25:12 -0700839 target_info = common.BuildInfo(OPTIONS.info_dict, OPTIONS.oem_dicts)
Tao Bao481bab82017-12-21 11:23:09 -0800840 source_info = None
Tao Baoc098e9e2016-01-07 13:03:56 -0800841
Tao Bao481bab82017-12-21 11:23:09 -0800842 # Metadata to comply with Android OTA package format.
Tao Baodf3a48b2018-01-10 16:30:43 -0800843 metadata = GetPackageMetadata(target_info, source_info)
Tao Baob31892e2017-02-07 11:21:17 -0800844
Yifan Hong50e79542018-11-08 17:44:12 -0800845 if OPTIONS.retrofit_dynamic_partitions:
846 target_file = GetTargetFilesZipForRetrofitDynamicPartitions(
Yifan Hongb433eba2019-03-06 12:42:53 -0800847 target_file, target_info.get("super_block_devices").strip().split(),
848 target_info.get("dynamic_partition_list").strip().split())
Yifan Hong50e79542018-11-08 17:44:12 -0800849 elif OPTIONS.skip_postinstall:
Tao Bao15a146a2018-02-21 16:06:59 -0800850 target_file = GetTargetFilesZipWithoutPostinstallConfig(target_file)
851
Tao Bao40b18822018-01-30 18:19:04 -0800852 # Generate payload.
853 payload = Payload()
854
855 # Enforce a max timestamp this payload can be applied on top of.
Tao Baoff1b86e2017-10-03 14:17:57 -0700856 if OPTIONS.downgrade:
Tao Bao2a12ed72018-01-22 11:35:00 -0800857 max_timestamp = source_info.GetBuildProp("ro.build.date.utc")
Tao Baoff1b86e2017-10-03 14:17:57 -0700858 else:
859 max_timestamp = metadata["post-timestamp"]
Tao Bao40b18822018-01-30 18:19:04 -0800860 additional_args = ["--max_timestamp", max_timestamp]
Tao Baoc098e9e2016-01-07 13:03:56 -0800861
Tao Bao40b18822018-01-30 18:19:04 -0800862 payload.Generate(target_file, source_file, additional_args)
Tao Baoc098e9e2016-01-07 13:03:56 -0800863
Tao Bao40b18822018-01-30 18:19:04 -0800864 # Sign the payload.
Tao Baof7140c02018-01-30 17:09:24 -0800865 payload_signer = PayloadSigner()
866 payload.Sign(payload_signer)
Tao Baoc098e9e2016-01-07 13:03:56 -0800867
Tao Bao40b18822018-01-30 18:19:04 -0800868 # Write the payload into output zip.
869 payload.WriteToZip(output_zip)
Tao Baoc098e9e2016-01-07 13:03:56 -0800870
Tao Baof7140c02018-01-30 17:09:24 -0800871 # Generate and include the secondary payload that installs secondary images
872 # (e.g. system_other.img).
873 if OPTIONS.include_secondary:
874 # We always include a full payload for the secondary slot, even when
875 # building an incremental OTA. See the comments for "--include_secondary".
Tao Bao15a146a2018-02-21 16:06:59 -0800876 secondary_target_file = GetTargetFilesZipForSecondaryImages(
877 target_file, OPTIONS.skip_postinstall)
Tao Bao667ff572018-02-10 00:02:40 -0800878 secondary_payload = Payload(secondary=True)
Tao Baodb1fe412018-02-09 23:15:05 -0800879 secondary_payload.Generate(secondary_target_file,
880 additional_args=additional_args)
Tao Baof7140c02018-01-30 17:09:24 -0800881 secondary_payload.Sign(payload_signer)
Tao Bao667ff572018-02-10 00:02:40 -0800882 secondary_payload.WriteToZip(output_zip)
Tao Baof7140c02018-01-30 17:09:24 -0800883
Tianjie Xucfa86222016-03-07 16:31:19 -0800884 # If dm-verity is supported for the device, copy contents of care_map
885 # into A/B OTA package.
Tao Bao21803d32017-04-19 10:16:09 -0700886 target_zip = zipfile.ZipFile(target_file, "r")
Tao Bao481bab82017-12-21 11:23:09 -0800887 if (target_info.get("verity") == "true" or
888 target_info.get("avb_enable") == "true"):
Tianjie Xu4c05f4a2018-09-14 16:24:41 -0700889 care_map_list = [x for x in ["care_map.pb", "care_map.txt"] if
890 "META/" + x in target_zip.namelist()]
891
892 # Adds care_map if either the protobuf format or the plain text one exists.
893 if care_map_list:
894 care_map_name = care_map_list[0]
895 care_map_data = target_zip.read("META/" + care_map_name)
896 # In order to support streaming, care_map needs to be packed as
Tao Bao40b18822018-01-30 18:19:04 -0800897 # ZIP_STORED.
Tianjie Xu4c05f4a2018-09-14 16:24:41 -0700898 common.ZipWriteStr(output_zip, care_map_name, care_map_data,
Tao Bao481bab82017-12-21 11:23:09 -0800899 compress_type=zipfile.ZIP_STORED)
Tianjie Xucfa86222016-03-07 16:31:19 -0800900 else:
Tao Bao32fcdab2018-10-12 10:30:39 -0700901 logger.warning("Cannot find care map file in target_file package")
Tao Bao21803d32017-04-19 10:16:09 -0700902
Tao Bao21803d32017-04-19 10:16:09 -0700903 common.ZipClose(target_zip)
Tianjie Xucfa86222016-03-07 16:31:19 -0800904
Yifan Hong9276cf02019-08-21 16:37:04 -0700905 CheckVintfIfTrebleEnabled(target_file, target_info)
906
Tao Baofe5b69a2018-03-02 09:47:43 -0800907 # We haven't written the metadata entry yet, which will be handled in
908 # FinalizeMetadata().
Tao Baoc96316c2017-01-24 22:10:49 -0800909 common.ZipClose(output_zip)
910
Tao Bao85f16982018-03-08 16:28:33 -0800911 # AbOtaPropertyFiles intends to replace StreamingPropertyFiles, as it covers
912 # all the info of the latter. However, system updaters and OTA servers need to
913 # take time to switch to the new flag. We keep both of the flags for
914 # P-timeframe, and will remove StreamingPropertyFiles in later release.
Tao Baod3fc38a2018-03-08 16:09:01 -0800915 needed_property_files = (
Tao Bao85f16982018-03-08 16:28:33 -0800916 AbOtaPropertyFiles(),
Tao Baod3fc38a2018-03-08 16:09:01 -0800917 StreamingPropertyFiles(),
918 )
919 FinalizeMetadata(metadata, staging_file, output_file, needed_property_files)
Tao Baoc96316c2017-01-24 22:10:49 -0800920
Tao Baoc098e9e2016-01-07 13:03:56 -0800921
Doug Zongkereef39442009-04-02 12:14:19 -0700922def main(argv):
923
924 def option_handler(o, a):
Tao Bao4b76a0e2017-10-31 12:13:33 -0700925 if o in ("-k", "--package_key"):
Doug Zongkereef39442009-04-02 12:14:19 -0700926 OPTIONS.package_key = a
Doug Zongkereef39442009-04-02 12:14:19 -0700927 elif o in ("-i", "--incremental_from"):
928 OPTIONS.incremental_source = a
Tao Bao43078aa2015-04-21 14:32:35 -0700929 elif o == "--full_radio":
930 OPTIONS.full_radio = True
leozwangaa6c1a12015-08-14 10:57:58 -0700931 elif o == "--full_bootloader":
932 OPTIONS.full_bootloader = True
Tao Bao337633f2017-12-06 15:20:19 -0800933 elif o == "--wipe_user_data":
Doug Zongkerdbfaae52009-04-21 17:12:54 -0700934 OPTIONS.wipe_user_data = True
Tao Bao5d182562016-02-23 11:38:39 -0800935 elif o == "--downgrade":
936 OPTIONS.downgrade = True
937 OPTIONS.wipe_user_data = True
Tao Bao3e6161a2017-02-28 11:48:48 -0800938 elif o == "--override_timestamp":
Tao Baofaa8e0b2018-04-12 14:31:43 -0700939 OPTIONS.downgrade = True
Michael Runge6e836112014-04-15 17:40:21 -0700940 elif o in ("-o", "--oem_settings"):
Alain Vongsouvanh7f804ba2017-02-16 13:06:55 -0800941 OPTIONS.oem_source = a.split(',')
Tao Bao8608cde2016-02-25 19:49:55 -0800942 elif o == "--oem_no_mount":
943 OPTIONS.oem_no_mount = True
Doug Zongker1c390a22009-05-14 19:06:36 -0700944 elif o in ("-e", "--extra_script"):
945 OPTIONS.extra_script = a
Martin Blumenstingl374e1142014-05-31 20:42:55 +0200946 elif o in ("-t", "--worker_threads"):
947 if a.isdigit():
948 OPTIONS.worker_threads = int(a)
949 else:
950 raise ValueError("Cannot parse value %r for option %r - only "
951 "integers are allowed." % (a, o))
Doug Zongker9b23f2c2013-11-25 14:44:12 -0800952 elif o in ("-2", "--two_step"):
953 OPTIONS.two_step = True
Tao Baof7140c02018-01-30 17:09:24 -0800954 elif o == "--include_secondary":
955 OPTIONS.include_secondary = True
Doug Zongker26e66192014-02-20 13:22:07 -0800956 elif o == "--no_signing":
Takeshi Kanemotoe153b342013-11-14 17:20:50 +0900957 OPTIONS.no_signing = True
Dan Albert8b72aef2015-03-23 19:13:21 -0700958 elif o == "--verify":
Michael Runge63f01de2014-10-28 19:24:19 -0700959 OPTIONS.verify = True
Doug Zongker26e66192014-02-20 13:22:07 -0800960 elif o == "--block":
961 OPTIONS.block_based = True
Doug Zongker25568482014-03-03 10:21:27 -0800962 elif o in ("-b", "--binary"):
963 OPTIONS.updater_binary = a
Tao Bao8dcf7382015-05-21 14:09:49 -0700964 elif o == "--stash_threshold":
965 try:
966 OPTIONS.stash_threshold = float(a)
967 except ValueError:
968 raise ValueError("Cannot parse value %r for option %r - expecting "
969 "a float" % (a, o))
Tao Baod62c6032015-11-30 09:40:20 -0800970 elif o == "--log_diff":
971 OPTIONS.log_diff = a
Tao Baodea0f8b2016-06-20 17:55:06 -0700972 elif o == "--payload_signer":
973 OPTIONS.payload_signer = a
Baligh Uddin2abbbd02016-06-22 12:14:16 -0700974 elif o == "--payload_signer_args":
975 OPTIONS.payload_signer_args = shlex.split(a)
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700976 elif o == "--payload_signer_maximum_signature_size":
977 OPTIONS.payload_signer_maximum_signature_size = a
xunchang376cc7c2019-04-08 23:04:58 -0700978 elif o == "--payload_signer_key_size":
Tianjie Xu21e6deb2019-10-07 18:01:00 -0700979 # TODO(Xunchang) remove this option after cleaning up the callers.
980 logger.warning("The option '--payload_signer_key_size' is deprecated."
981 " Use '--payload_signer_maximum_signature_size' instead.")
982 OPTIONS.payload_signer_maximum_signature_size = a
Dan Willemsencea5cd22017-03-21 14:44:27 -0700983 elif o == "--extracted_input_target_files":
984 OPTIONS.extracted_input = a
Tao Bao15a146a2018-02-21 16:06:59 -0800985 elif o == "--skip_postinstall":
986 OPTIONS.skip_postinstall = True
Yifan Hong50e79542018-11-08 17:44:12 -0800987 elif o == "--retrofit_dynamic_partitions":
988 OPTIONS.retrofit_dynamic_partitions = True
xunchangabfa2652019-02-19 16:27:10 -0800989 elif o == "--skip_compatibility_check":
990 OPTIONS.skip_compatibility_check = True
xunchang1cfe2512019-02-19 14:14:48 -0800991 elif o == "--output_metadata_path":
992 OPTIONS.output_metadata_path = a
Tianjie Xu1b079832019-08-28 12:19:23 -0700993 elif o == "--disable_fec_computation":
994 OPTIONS.disable_fec_computation = True
Yifan Hong65afc072020-04-17 10:08:10 -0700995 elif o == "--force_non_ab":
996 OPTIONS.force_non_ab = True
Tianjied6867162020-05-10 14:30:13 -0700997 elif o == "--boot_variable_file":
998 OPTIONS.boot_variable_file = a
Doug Zongkereef39442009-04-02 12:14:19 -0700999 else:
1000 return False
Doug Zongkerdbfaae52009-04-21 17:12:54 -07001001 return True
Doug Zongkereef39442009-04-02 12:14:19 -07001002
1003 args = common.ParseOptions(argv, __doc__,
Tao Bao337633f2017-12-06 15:20:19 -08001004 extra_opts="b:k:i:d:e:t:2o:",
Dan Albert8b72aef2015-03-23 19:13:21 -07001005 extra_long_opts=[
Dan Albert8b72aef2015-03-23 19:13:21 -07001006 "package_key=",
1007 "incremental_from=",
Tao Bao43078aa2015-04-21 14:32:35 -07001008 "full_radio",
leozwangaa6c1a12015-08-14 10:57:58 -07001009 "full_bootloader",
Dan Albert8b72aef2015-03-23 19:13:21 -07001010 "wipe_user_data",
Tao Bao5d182562016-02-23 11:38:39 -08001011 "downgrade",
Tao Bao3e6161a2017-02-28 11:48:48 -08001012 "override_timestamp",
Dan Albert8b72aef2015-03-23 19:13:21 -07001013 "extra_script=",
1014 "worker_threads=",
Dan Albert8b72aef2015-03-23 19:13:21 -07001015 "two_step",
Tao Baof7140c02018-01-30 17:09:24 -08001016 "include_secondary",
Dan Albert8b72aef2015-03-23 19:13:21 -07001017 "no_signing",
1018 "block",
1019 "binary=",
1020 "oem_settings=",
Tao Bao8608cde2016-02-25 19:49:55 -08001021 "oem_no_mount",
Dan Albert8b72aef2015-03-23 19:13:21 -07001022 "verify",
Tao Bao8dcf7382015-05-21 14:09:49 -07001023 "stash_threshold=",
Tao Baod62c6032015-11-30 09:40:20 -08001024 "log_diff=",
Tao Baodea0f8b2016-06-20 17:55:06 -07001025 "payload_signer=",
Baligh Uddin2abbbd02016-06-22 12:14:16 -07001026 "payload_signer_args=",
Tianjie Xu21e6deb2019-10-07 18:01:00 -07001027 "payload_signer_maximum_signature_size=",
xunchang376cc7c2019-04-08 23:04:58 -07001028 "payload_signer_key_size=",
Dan Willemsencea5cd22017-03-21 14:44:27 -07001029 "extracted_input_target_files=",
Tao Bao15a146a2018-02-21 16:06:59 -08001030 "skip_postinstall",
Yifan Hong50e79542018-11-08 17:44:12 -08001031 "retrofit_dynamic_partitions",
xunchangabfa2652019-02-19 16:27:10 -08001032 "skip_compatibility_check",
xunchang1cfe2512019-02-19 14:14:48 -08001033 "output_metadata_path=",
Tianjie Xu1b079832019-08-28 12:19:23 -07001034 "disable_fec_computation",
Yifan Hong65afc072020-04-17 10:08:10 -07001035 "force_non_ab",
Tianjied6867162020-05-10 14:30:13 -07001036 "boot_variable_file=",
Dan Albert8b72aef2015-03-23 19:13:21 -07001037 ], extra_option_handler=option_handler)
Doug Zongkereef39442009-04-02 12:14:19 -07001038
1039 if len(args) != 2:
1040 common.Usage(__doc__)
1041 sys.exit(1)
1042
Tao Bao32fcdab2018-10-12 10:30:39 -07001043 common.InitLogging()
1044
Tao Bao5d182562016-02-23 11:38:39 -08001045 if OPTIONS.downgrade:
Tao Bao5d182562016-02-23 11:38:39 -08001046 # We should only allow downgrading incrementals (as opposed to full).
1047 # Otherwise the device may go back from arbitrary build with this full
1048 # OTA package.
1049 if OPTIONS.incremental_source is None:
Elliott Hughesd8a52f92016-06-20 14:35:47 -07001050 raise ValueError("Cannot generate downgradable full OTAs")
Tao Bao5d182562016-02-23 11:38:39 -08001051
Tao Bao2db13852018-01-08 22:28:57 -08001052 # Load the build info dicts from the zip directly or the extracted input
1053 # directory. We don't need to unzip the entire target-files zips, because they
1054 # won't be needed for A/B OTAs (brillo_update_payload does that on its own).
1055 # When loading the info dicts, we don't need to provide the second parameter
1056 # to common.LoadInfoDict(). Specifying the second parameter allows replacing
1057 # some properties with their actual paths, such as 'selinux_fc',
1058 # 'ramdisk_dir', which won't be used during OTA generation.
Dan Willemsencea5cd22017-03-21 14:44:27 -07001059 if OPTIONS.extracted_input is not None:
Tao Bao2db13852018-01-08 22:28:57 -08001060 OPTIONS.info_dict = common.LoadInfoDict(OPTIONS.extracted_input)
Dan Willemsencea5cd22017-03-21 14:44:27 -07001061 else:
Tao Bao2db13852018-01-08 22:28:57 -08001062 with zipfile.ZipFile(args[0], 'r') as input_zip:
1063 OPTIONS.info_dict = common.LoadInfoDict(input_zip)
Tao Baoc098e9e2016-01-07 13:03:56 -08001064
Tao Bao32fcdab2018-10-12 10:30:39 -07001065 logger.info("--- target info ---")
1066 common.DumpInfoDict(OPTIONS.info_dict)
Tao Bao2db13852018-01-08 22:28:57 -08001067
1068 # Load the source build dict if applicable.
1069 if OPTIONS.incremental_source is not None:
1070 OPTIONS.target_info_dict = OPTIONS.info_dict
1071 with zipfile.ZipFile(OPTIONS.incremental_source, 'r') as source_zip:
1072 OPTIONS.source_info_dict = common.LoadInfoDict(source_zip)
1073
Tao Bao32fcdab2018-10-12 10:30:39 -07001074 logger.info("--- source info ---")
1075 common.DumpInfoDict(OPTIONS.source_info_dict)
Tao Bao2db13852018-01-08 22:28:57 -08001076
1077 # Load OEM dicts if provided.
Tao Bao481bab82017-12-21 11:23:09 -08001078 OPTIONS.oem_dicts = _LoadOemDicts(OPTIONS.oem_source)
1079
Yifan Hong50e79542018-11-08 17:44:12 -08001080 # Assume retrofitting dynamic partitions when base build does not set
Yifan Hong50611032018-11-20 14:27:38 -08001081 # use_dynamic_partitions but target build does.
Yifan Hong50e79542018-11-08 17:44:12 -08001082 if (OPTIONS.source_info_dict and
Yifan Hong50611032018-11-20 14:27:38 -08001083 OPTIONS.source_info_dict.get("use_dynamic_partitions") != "true" and
1084 OPTIONS.target_info_dict.get("use_dynamic_partitions") == "true"):
Yifan Hong50e79542018-11-08 17:44:12 -08001085 if OPTIONS.target_info_dict.get("dynamic_partition_retrofit") != "true":
1086 raise common.ExternalError(
1087 "Expect to generate incremental OTA for retrofitting dynamic "
1088 "partitions, but dynamic_partition_retrofit is not set in target "
1089 "build.")
1090 logger.info("Implicitly generating retrofit incremental OTA.")
1091 OPTIONS.retrofit_dynamic_partitions = True
1092
1093 # Skip postinstall for retrofitting dynamic partitions.
1094 if OPTIONS.retrofit_dynamic_partitions:
1095 OPTIONS.skip_postinstall = True
1096
Tao Baoc098e9e2016-01-07 13:03:56 -08001097 ab_update = OPTIONS.info_dict.get("ab_update") == "true"
Yifan Hong65afc072020-04-17 10:08:10 -07001098 allow_non_ab = OPTIONS.info_dict.get("allow_non_ab") == "true"
1099 if OPTIONS.force_non_ab:
1100 assert allow_non_ab, "--force_non_ab only allowed on devices that supports non-A/B"
1101 assert ab_update, "--force_non_ab only allowed on A/B devices"
1102
1103 generate_ab = not OPTIONS.force_non_ab and ab_update
Tao Baoc098e9e2016-01-07 13:03:56 -08001104
Christian Oderf63e2cd2017-05-01 22:30:15 +02001105 # Use the default key to sign the package if not specified with package_key.
1106 # package_keys are needed on ab_updates, so always define them if an
Yifan Hong65afc072020-04-17 10:08:10 -07001107 # A/B update is getting created.
1108 if not OPTIONS.no_signing or generate_ab:
Christian Oderf63e2cd2017-05-01 22:30:15 +02001109 if OPTIONS.package_key is None:
1110 OPTIONS.package_key = OPTIONS.info_dict.get(
1111 "default_system_dev_certificate",
Dan Willemsen0ab1be62019-04-09 21:35:37 -07001112 "build/make/target/product/security/testkey")
Christian Oderf63e2cd2017-05-01 22:30:15 +02001113 # Get signing keys
1114 OPTIONS.key_passwords = common.GetKeyPasswords([OPTIONS.package_key])
1115
Yifan Hong65afc072020-04-17 10:08:10 -07001116 if generate_ab:
Tao Baof0c4aa22018-04-30 20:29:30 -07001117 GenerateAbOtaPackage(
Tao Baoc098e9e2016-01-07 13:03:56 -08001118 target_file=args[0],
1119 output_file=args[1],
1120 source_file=OPTIONS.incremental_source)
1121
Dan Willemsencea5cd22017-03-21 14:44:27 -07001122 else:
Tao Baof0c4aa22018-04-30 20:29:30 -07001123 GenerateNonAbOtaPackage(
1124 target_file=args[0],
1125 output_file=args[1],
1126 source_file=OPTIONS.incremental_source)
Doug Zongkerfdd8e692009-08-03 17:27:48 -07001127
Tao Baof0c4aa22018-04-30 20:29:30 -07001128 # Post OTA generation works.
1129 if OPTIONS.incremental_source is not None and OPTIONS.log_diff:
1130 logger.info("Generating diff logs...")
1131 logger.info("Unzipping target-files for diffing...")
1132 target_dir = common.UnzipTemp(args[0], TARGET_DIFFING_UNZIP_PATTERN)
1133 source_dir = common.UnzipTemp(
1134 OPTIONS.incremental_source, TARGET_DIFFING_UNZIP_PATTERN)
Doug Zongkereb0a78a2014-01-27 10:01:06 -08001135
Tao Baof0c4aa22018-04-30 20:29:30 -07001136 with open(OPTIONS.log_diff, 'w') as out_file:
Tao Baof0c4aa22018-04-30 20:29:30 -07001137 target_files_diff.recursiveDiff(
1138 '', source_dir, target_dir, out_file)
Doug Zongker62d4f182014-08-04 16:06:43 -07001139
Tao Bao32fcdab2018-10-12 10:30:39 -07001140 logger.info("done.")
Doug Zongkereef39442009-04-02 12:14:19 -07001141
1142
1143if __name__ == '__main__':
1144 try:
Ying Wang7e6d4e42010-12-13 16:25:36 -08001145 common.CloseInheritedPipes()
Doug Zongkereef39442009-04-02 12:14:19 -07001146 main(sys.argv[1:])
Tao Bao32fcdab2018-10-12 10:30:39 -07001147 except common.ExternalError:
1148 logger.exception("\n ERROR:\n")
Doug Zongkereef39442009-04-02 12:14:19 -07001149 sys.exit(1)
Doug Zongkerfc44a512014-08-26 13:10:25 -07001150 finally:
1151 common.Cleanup()