Bob Badour | 2efc476 | 2021-02-03 18:36:27 -0800 | [diff] [blame] | 1 | package { |
| 2 | default_applicable_licenses: ["Android-Apache-2.0"], |
| 3 | } |
| 4 | |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 5 | microdroid_shell_and_utilities = [ |
| 6 | "reboot", |
| 7 | "sh", |
Victor Hsieh | 1ef3cb7 | 2021-07-21 08:49:10 -0700 | [diff] [blame] | 8 | "strace", |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 9 | "toolbox", |
| 10 | "toybox", |
| 11 | ] |
| 12 | |
Inseob Kim | 5ffc082 | 2021-02-09 21:23:36 +0900 | [diff] [blame] | 13 | microdroid_rootdirs = [ |
| 14 | "dev", |
| 15 | "proc", |
| 16 | "sys", |
| 17 | |
Inseob Kim | 5ffc082 | 2021-02-09 21:23:36 +0900 | [diff] [blame] | 18 | "system", |
Inseob Kim | 5ffc082 | 2021-02-09 21:23:36 +0900 | [diff] [blame] | 19 | "vendor", |
Inseob Kim | 5ffc082 | 2021-02-09 21:23:36 +0900 | [diff] [blame] | 20 | "debug_ramdisk", |
| 21 | "mnt", |
Inseob Kim | afd9dc0 | 2021-04-23 14:47:44 +0900 | [diff] [blame] | 22 | "data", |
Inseob Kim | 5ffc082 | 2021-02-09 21:23:36 +0900 | [diff] [blame] | 23 | |
| 24 | "apex", |
| 25 | "linkerconfig", |
| 26 | "second_stage_resources", |
Inseob Kim | 5ffc082 | 2021-02-09 21:23:36 +0900 | [diff] [blame] | 27 | ] |
| 28 | |
| 29 | microdroid_symlinks = [ |
| 30 | { |
| 31 | target: "/sys/kernel/debug", |
| 32 | name: "d", |
| 33 | }, |
Inseob Kim | 13ca2c8 | 2021-04-23 09:12:29 +0900 | [diff] [blame] | 34 | { |
| 35 | target: "/system/etc", |
| 36 | name: "etc", |
| 37 | }, |
Inseob Kim | 4e207a1 | 2021-08-04 03:36:47 +0000 | [diff] [blame] | 38 | { |
| 39 | target: "/system/bin", |
| 40 | name: "bin", |
| 41 | }, |
Inseob Kim | 5ffc082 | 2021-02-09 21:23:36 +0900 | [diff] [blame] | 42 | ] |
| 43 | |
Jiyong Park | 92199ce | 2021-04-16 21:35:58 +0900 | [diff] [blame] | 44 | android_system_image { |
Jiyong Park | b552bb6 | 2021-01-25 19:12:47 +0900 | [diff] [blame] | 45 | name: "microdroid", |
| 46 | use_avb: true, |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 47 | avb_private_key: ":microdroid_sign_key", |
Jiyong Park | b552bb6 | 2021-01-25 19:12:47 +0900 | [diff] [blame] | 48 | avb_algorithm: "SHA256_RSA4096", |
Jiyong Park | d4326f3 | 2021-03-15 23:25:46 +0900 | [diff] [blame] | 49 | partition_name: "system", |
Jiyong Park | b552bb6 | 2021-01-25 19:12:47 +0900 | [diff] [blame] | 50 | deps: [ |
| 51 | "init_second_stage", |
Inseob Kim | 23ce158 | 2021-04-06 21:25:57 +0900 | [diff] [blame] | 52 | "microdroid_build_prop", |
Jiyong Park | 4069961 | 2021-05-24 16:55:06 +0900 | [diff] [blame] | 53 | "microdroid_init_rc", |
Jiyong Park | 4d22895 | 2021-10-18 18:28:57 +0900 | [diff] [blame] | 54 | "microdroid_ueventd_rc", |
Jiyong Park | 4069961 | 2021-05-24 16:55:06 +0900 | [diff] [blame] | 55 | "microdroid_launcher", |
Jooyung Han | 7ce2e53 | 2021-06-16 16:52:02 +0900 | [diff] [blame] | 56 | |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 57 | "libbinder", |
Jooyung Han | 837eef5 | 2021-05-15 11:33:48 +0900 | [diff] [blame] | 58 | "libbinder_ndk", |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 59 | "libstdc++", |
| 60 | "logcat", |
| 61 | "logd", |
| 62 | "run-as", |
| 63 | "secilc", |
Jooyung Han | 017916b | 2021-04-20 03:57:19 +0900 | [diff] [blame] | 64 | |
| 65 | // "com.android.adbd" requires these, |
| 66 | "libadbd_auth", |
| 67 | "libadbd_fs", |
| 68 | |
Jooyung Han | 730b7b8 | 2021-05-12 14:09:38 +0900 | [diff] [blame] | 69 | // "com.android.art" requires |
| 70 | "heapprofd_client_api", |
Victor Hsieh | 527b81d | 2021-06-11 10:41:11 -0700 | [diff] [blame] | 71 | "libartpalette-system", |
Jooyung Han | 730b7b8 | 2021-05-12 14:09:38 +0900 | [diff] [blame] | 72 | |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 73 | "apexd", |
| 74 | "debuggerd", |
Jiyong Park | 1b3bcdc | 2021-09-30 16:40:19 +0900 | [diff] [blame] | 75 | "keystore2_microdroid", |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 76 | "linker", |
Inseob Kim | 870e76b | 2021-02-25 17:38:32 +0900 | [diff] [blame] | 77 | "linkerconfig", |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 78 | "servicemanager", |
| 79 | "tombstoned", |
| 80 | "cgroups.json", |
Jooyung Han | 1c82073 | 2021-04-15 05:16:23 +0900 | [diff] [blame] | 81 | "public.libraries.android.txt", |
Inseob Kim | d8cf762 | 2021-02-18 19:12:06 +0900 | [diff] [blame] | 82 | |
Inseob Kim | 8f095c9 | 2021-05-26 12:04:54 +0900 | [diff] [blame] | 83 | // TODO(b/185767624): remove hidl after full keymint support |
| 84 | "hwservicemanager", |
| 85 | |
Inseob Kim | ff43be2 | 2021-06-07 16:56:56 +0900 | [diff] [blame] | 86 | "microdroid_plat_sepolicy_and_mapping.sha256", |
| 87 | "microdroid_file_contexts", |
| 88 | "microdroid_hwservice_contexts", |
| 89 | "microdroid_property_contexts", |
| 90 | "microdroid_service_contexts", |
| 91 | "microdroid_keystore2_key_contexts", |
Inseob Kim | 8f095c9 | 2021-05-26 12:04:54 +0900 | [diff] [blame] | 92 | "microdroid_compatibility_matrix", |
| 93 | "microdroid_manifest", |
Jooyung Han | 8a17ef7 | 2021-08-04 15:39:54 +0900 | [diff] [blame] | 94 | |
| 95 | // TODO(b/195425111) these four should be added automatically |
| 96 | "android.hardware.security.secureclock-V1-ndk", |
| 97 | "android.hardware.security.sharedsecret-V1-ndk", |
| 98 | "libcrypto", |
| 99 | "liblzma", |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 100 | ] + microdroid_shell_and_utilities, |
| 101 | multilib: { |
| 102 | common: { |
| 103 | deps: [ |
Jooyung Han | 1c2d758 | 2021-09-08 22:46:42 +0900 | [diff] [blame] | 104 | // non-updatable & mandatory apexes |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 105 | "com.android.runtime", |
Jooyung Han | 1c2d758 | 2021-09-08 22:46:42 +0900 | [diff] [blame] | 106 | |
Inseob Kim | ff43be2 | 2021-06-07 16:56:56 +0900 | [diff] [blame] | 107 | "microdroid_plat_sepolicy.cil", |
| 108 | "microdroid_plat_mapping_file", |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 109 | ], |
| 110 | }, |
Jiyong Park | cc5d26b | 2021-05-17 11:27:34 +0900 | [diff] [blame] | 111 | lib64: { |
| 112 | deps: [ |
Jooyung Han | 7ce2e53 | 2021-06-16 16:52:02 +0900 | [diff] [blame] | 113 | "apkdmverity", |
Victor Hsieh | 2445e33 | 2021-06-04 16:44:53 -0700 | [diff] [blame] | 114 | "authfs", |
Victor Hsieh | 8bb67b6 | 2021-08-04 12:10:58 -0700 | [diff] [blame] | 115 | "authfs_service", |
Jiyong Park | 21ce2c5 | 2021-08-28 02:32:17 +0900 | [diff] [blame] | 116 | "microdroid_manager", |
Jiyong Park | cc5d26b | 2021-05-17 11:27:34 +0900 | [diff] [blame] | 117 | "zipfuse", |
Victor Hsieh | 2445e33 | 2021-06-04 16:44:53 -0700 | [diff] [blame] | 118 | |
| 119 | // TODO(b/184872979): Needed by authfs. Remove once the Rust API is created. |
| 120 | "libbinder_rpc_unstable", |
Jiyong Park | cc5d26b | 2021-05-17 11:27:34 +0900 | [diff] [blame] | 121 | ], |
| 122 | }, |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 123 | }, |
Jiyong Park | 92199ce | 2021-04-16 21:35:58 +0900 | [diff] [blame] | 124 | linker_config_src: "linker.config.json", |
Inseob Kim | a313e56 | 2021-02-15 17:04:39 +0900 | [diff] [blame] | 125 | base_dir: "system", |
Inseob Kim | 5ffc082 | 2021-02-09 21:23:36 +0900 | [diff] [blame] | 126 | dirs: microdroid_rootdirs, |
| 127 | symlinks: microdroid_symlinks, |
Inseob Kim | ff43be2 | 2021-06-07 16:56:56 +0900 | [diff] [blame] | 128 | file_contexts: ":microdroid_file_contexts.gen", |
Jiyong Park | b552bb6 | 2021-01-25 19:12:47 +0900 | [diff] [blame] | 129 | } |
Jiyong Park | 153d355 | 2021-02-04 08:54:31 +0900 | [diff] [blame] | 130 | |
Inseob Kim | dc2af86 | 2021-02-17 15:51:56 +0900 | [diff] [blame] | 131 | prebuilt_etc { |
| 132 | name: "microdroid_init_rc", |
| 133 | filename: "init.rc", |
| 134 | src: "init.rc", |
| 135 | relative_install_path: "init/hw", |
| 136 | installable: false, // avoid collision with system partition's init.rc |
| 137 | } |
| 138 | |
Jiyong Park | 4d22895 | 2021-10-18 18:28:57 +0900 | [diff] [blame] | 139 | prebuilt_etc { |
| 140 | name: "microdroid_ueventd_rc", |
| 141 | filename: "ueventd.rc", |
| 142 | src: "ueventd.rc", |
| 143 | installable: false, // avoid collision with system partition's ueventd.rc |
| 144 | } |
| 145 | |
Inseob Kim | 23ce158 | 2021-04-06 21:25:57 +0900 | [diff] [blame] | 146 | prebuilt_root { |
| 147 | name: "microdroid_build_prop", |
| 148 | filename: "build.prop", |
| 149 | src: "build.prop", |
Jiyong Park | 68f560c | 2021-05-24 17:38:27 +0900 | [diff] [blame] | 150 | arch: { |
| 151 | x86_64: { |
| 152 | src: ":microdroid_build_prop_gen_x86_64", |
| 153 | }, |
| 154 | arm64: { |
| 155 | src: ":microdroid_build_prop_gen_arm64", |
| 156 | }, |
| 157 | }, |
Inseob Kim | 23ce158 | 2021-04-06 21:25:57 +0900 | [diff] [blame] | 158 | installable: false, |
| 159 | } |
| 160 | |
Jiyong Park | 68f560c | 2021-05-24 17:38:27 +0900 | [diff] [blame] | 161 | genrule { |
| 162 | name: "microdroid_build_prop_gen_x86_64", |
| 163 | srcs: ["build.prop"], |
| 164 | out: ["build.prop.out"], |
| 165 | cmd: "cp $(in) $(out); echo ro.product.cpu.abilist=x86_64 >> $(out)", |
| 166 | } |
| 167 | |
| 168 | genrule { |
| 169 | name: "microdroid_build_prop_gen_arm64", |
| 170 | srcs: ["build.prop"], |
| 171 | out: ["build.prop.out"], |
| 172 | cmd: "cp $(in) $(out); echo ro.product.cpu.abilist=arm64-v8a >> $(out)", |
| 173 | } |
| 174 | |
Jiyong Park | 6e2bc7c | 2021-03-03 14:56:18 +0000 | [diff] [blame] | 175 | android_filesystem { |
| 176 | name: "microdroid_vendor", |
Jiyong Park | 52ea083 | 2021-09-01 12:10:18 +0900 | [diff] [blame] | 177 | partition_name: "vendor", |
Jiyong Park | 6e2bc7c | 2021-03-03 14:56:18 +0000 | [diff] [blame] | 178 | use_avb: true, |
| 179 | deps: [ |
Andrew Scull | 9ba2657 | 2021-05-27 19:20:46 +0000 | [diff] [blame] | 180 | "android.hardware.security.keymint-service.microdroid", |
Inseob Kim | afd9dc0 | 2021-04-23 14:47:44 +0900 | [diff] [blame] | 181 | "microdroid_fstab", |
Inseob Kim | 28dddd8 | 2021-03-11 17:51:22 +0900 | [diff] [blame] | 182 | "microdroid_precompiled_sepolicy.plat_sepolicy_and_mapping.sha256", |
Inseob Kim | 8f095c9 | 2021-05-26 12:04:54 +0900 | [diff] [blame] | 183 | "microdroid_vendor_manifest", |
| 184 | "microdroid_vendor_compatibility_matrix", |
Jiyong Park | 6e2bc7c | 2021-03-03 14:56:18 +0000 | [diff] [blame] | 185 | ], |
Inseob Kim | abcd10a | 2021-03-25 15:43:07 +0900 | [diff] [blame] | 186 | multilib: { |
| 187 | common: { |
| 188 | deps: [ |
| 189 | "microdroid_vendor_sepolicy.cil", |
| 190 | "microdroid_plat_pub_versioned.cil", |
Inseob Kim | cd06dca | 2021-04-30 00:19:00 +0900 | [diff] [blame] | 191 | "microdroid_plat_sepolicy_vers.txt", |
Inseob Kim | 998c27f | 2021-09-27 13:44:09 +0000 | [diff] [blame] | 192 | "microdroid_precompiled_sepolicy", |
Inseob Kim | abcd10a | 2021-03-25 15:43:07 +0900 | [diff] [blame] | 193 | ], |
| 194 | }, |
| 195 | }, |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 196 | avb_private_key: ":microdroid_sign_key", |
Jiyong Park | 6e2bc7c | 2021-03-03 14:56:18 +0000 | [diff] [blame] | 197 | avb_algorithm: "SHA256_RSA4096", |
Inseob Kim | ff43be2 | 2021-06-07 16:56:56 +0900 | [diff] [blame] | 198 | file_contexts: ":microdroid_vendor_file_contexts.gen", |
Jiyong Park | 6e2bc7c | 2021-03-03 14:56:18 +0000 | [diff] [blame] | 199 | } |
| 200 | |
Jiyong Park | c1500e8 | 2021-02-24 01:39:51 +0900 | [diff] [blame] | 201 | logical_partition { |
| 202 | name: "microdroid_super", |
| 203 | sparse: true, |
Inseob Kim | c95b642 | 2021-03-31 16:31:27 +0900 | [diff] [blame] | 204 | size: "auto", |
Inseob Kim | d100475 | 2021-03-30 16:57:27 +0900 | [diff] [blame] | 205 | default_group: [ |
Jiyong Park | c1500e8 | 2021-02-24 01:39:51 +0900 | [diff] [blame] | 206 | { |
Jiyong Park | 52ea083 | 2021-09-01 12:10:18 +0900 | [diff] [blame] | 207 | name: "system_a", |
Inseob Kim | d100475 | 2021-03-30 16:57:27 +0900 | [diff] [blame] | 208 | filesystem: ":microdroid", |
| 209 | }, |
| 210 | { |
Jiyong Park | 52ea083 | 2021-09-01 12:10:18 +0900 | [diff] [blame] | 211 | name: "vendor_a", |
Inseob Kim | d100475 | 2021-03-30 16:57:27 +0900 | [diff] [blame] | 212 | filesystem: ":microdroid_vendor", |
Jiyong Park | c1500e8 | 2021-02-24 01:39:51 +0900 | [diff] [blame] | 213 | }, |
| 214 | ], |
| 215 | } |
| 216 | |
Jiyong Park | c893717 | 2021-08-30 18:41:52 +0900 | [diff] [blame] | 217 | microdroid_boot_cmdline = [ |
| 218 | "panic=-1", |
| 219 | "bootconfig", |
| 220 | ] |
Jiyong Park | 89e81cb | 2021-04-13 13:13:55 +0900 | [diff] [blame] | 221 | |
Jiyong Park | 153d355 | 2021-02-04 08:54:31 +0900 | [diff] [blame] | 222 | bootimg { |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 223 | name: "microdroid_boot-5.10", |
Jiyong Park | 153d355 | 2021-02-04 08:54:31 +0900 | [diff] [blame] | 224 | ramdisk_module: "microdroid_ramdisk-5.10", |
Jiyong Park | dfa3aec | 2021-03-09 20:32:15 +0900 | [diff] [blame] | 225 | // We don't have kernel for arm and x86. But Soong demands one when it builds for |
| 226 | // arm or x86 target. Satisfy that by providing an empty file as the kernel. |
| 227 | kernel_prebuilt: "empty_kernel", |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 228 | arch: { |
| 229 | arm64: { |
| 230 | kernel_prebuilt: ":kernel_prebuilts-5.10-arm64", |
Jiyong Park | b810cfe | 2021-07-05 13:05:48 +0900 | [diff] [blame] | 231 | cmdline: microdroid_boot_cmdline, |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 232 | }, |
| 233 | x86_64: { |
| 234 | kernel_prebuilt: ":kernel_prebuilts-5.10-x86_64", |
Jiyong Park | 747d636 | 2021-10-19 17:12:52 +0900 | [diff] [blame] | 235 | cmdline: microdroid_boot_cmdline + [ |
| 236 | // console=none is to work around the x86 specific u-boot behavior which when |
| 237 | // console= option is not found in the kernel commandline console=ttyS0 is |
| 238 | // automatically added. By adding console=none, we can prevent u-boot from doing |
| 239 | // that. Note that console is set to hvc0 by bootconfig if the VM is configured as |
| 240 | // debuggable. |
| 241 | "console=none", |
| 242 | "acpi=noirq", |
| 243 | ], |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 244 | }, |
| 245 | }, |
Jiyong Park | c893717 | 2021-08-30 18:41:52 +0900 | [diff] [blame] | 246 | |
Jiyong Park | 153d355 | 2021-02-04 08:54:31 +0900 | [diff] [blame] | 247 | dtb_prebuilt: "dummy_dtb.img", |
Jiyong Park | 9ecac55 | 2021-03-05 18:51:35 +0900 | [diff] [blame] | 248 | header_version: "4", |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 249 | partition_name: "boot", |
Jiyong Park | d4326f3 | 2021-03-15 23:25:46 +0900 | [diff] [blame] | 250 | use_avb: true, |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 251 | avb_private_key: ":microdroid_sign_key", |
Jiyong Park | 153d355 | 2021-02-04 08:54:31 +0900 | [diff] [blame] | 252 | } |
| 253 | |
| 254 | android_filesystem { |
| 255 | name: "microdroid_ramdisk-5.10", |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 256 | deps: [ |
Inseob Kim | 9733096 | 2021-06-11 12:59:59 +0900 | [diff] [blame] | 257 | "init_first_stage", |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 258 | ], |
| 259 | dirs: [ |
| 260 | "dev", |
| 261 | "proc", |
| 262 | "sys", |
| 263 | |
| 264 | // TODO(jiyong): remove these |
| 265 | "mnt", |
| 266 | "debug_ramdisk", |
| 267 | "second_stage_resources", |
| 268 | ], |
| 269 | type: "compressed_cpio", |
| 270 | } |
| 271 | |
| 272 | bootimg { |
| 273 | name: "microdroid_vendor_boot-5.10", |
| 274 | ramdisk_module: "microdroid_vendor_ramdisk-5.10", |
| 275 | dtb_prebuilt: "dummy_dtb.img", |
Jiyong Park | 9ecac55 | 2021-03-05 18:51:35 +0900 | [diff] [blame] | 276 | header_version: "4", |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 277 | vendor_boot: true, |
Jiyong Park | b810cfe | 2021-07-05 13:05:48 +0900 | [diff] [blame] | 278 | arch: { |
| 279 | arm64: { |
| 280 | bootconfig: ":microdroid_bootconfig_arm64_gen", |
| 281 | }, |
| 282 | x86_64: { |
| 283 | bootconfig: ":microdroid_bootconfig_x86_64_gen", |
| 284 | }, |
| 285 | }, |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 286 | partition_name: "vendor_boot", |
Jiyong Park | d4326f3 | 2021-03-15 23:25:46 +0900 | [diff] [blame] | 287 | use_avb: true, |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 288 | avb_private_key: ":microdroid_sign_key", |
Jiyong Park | c8b4003 | 2021-02-18 23:15:41 +0900 | [diff] [blame] | 289 | } |
| 290 | |
| 291 | android_filesystem { |
| 292 | name: "microdroid_vendor_ramdisk-5.10", |
Jiyong Park | 153d355 | 2021-02-04 08:54:31 +0900 | [diff] [blame] | 293 | arch: { |
| 294 | arm64: { |
| 295 | deps: ["virt_device_prebuilts_kernel_modules-5.10-arm64"], |
| 296 | }, |
| 297 | x86_64: { |
| 298 | deps: ["virt_device_prebuilts_kernel_modules-5.10-x86_64"], |
| 299 | }, |
| 300 | }, |
Jiyong Park | 3eb11f7 | 2021-02-23 12:53:30 +0900 | [diff] [blame] | 301 | deps: [ |
| 302 | "microdroid_fstab", |
| 303 | ], |
| 304 | base_dir: "first_stage_ramdisk", |
Jiyong Park | 153d355 | 2021-02-04 08:54:31 +0900 | [diff] [blame] | 305 | type: "compressed_cpio", |
Jiyong Park | 3eb11f7 | 2021-02-23 12:53:30 +0900 | [diff] [blame] | 306 | symlinks: [ |
| 307 | { |
Inseob Kim | 67ab436 | 2021-05-11 16:51:03 +0900 | [diff] [blame] | 308 | target: "etc/fstab.microdroid", |
Jiyong Park | 3eb11f7 | 2021-02-23 12:53:30 +0900 | [diff] [blame] | 309 | name: "first_stage_ramdisk/fstab.microdroid", |
| 310 | }, |
| 311 | { |
| 312 | target: "first_stage_ramdisk/lib", |
| 313 | name: "lib", |
| 314 | }, |
| 315 | ], |
| 316 | } |
| 317 | |
Jiyong Park | b810cfe | 2021-07-05 13:05:48 +0900 | [diff] [blame] | 318 | genrule { |
| 319 | name: "microdroid_bootconfig_arm64_gen", |
| 320 | srcs: [ |
| 321 | "bootconfig.common", |
| 322 | "bootconfig.arm64", |
| 323 | ], |
| 324 | out: ["bootconfig"], |
| 325 | cmd: "cat $(in) > $(out)", |
| 326 | } |
| 327 | |
| 328 | genrule { |
| 329 | name: "microdroid_bootconfig_x86_64_gen", |
| 330 | srcs: [ |
| 331 | "bootconfig.common", |
| 332 | "bootconfig.x86_64", |
| 333 | ], |
| 334 | out: ["bootconfig"], |
| 335 | cmd: "cat $(in) > $(out)", |
| 336 | } |
| 337 | |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 338 | vbmeta { |
| 339 | name: "microdroid_vbmeta_bootconfig", |
| 340 | partition_name: "vbmeta", |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 341 | private_key: ":microdroid_sign_key", |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 342 | chained_partitions: [ |
| 343 | { |
| 344 | name: "bootconfig", |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 345 | private_key: ":microdroid_sign_key", |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 346 | }, |
| 347 | ], |
| 348 | } |
| 349 | |
| 350 | // See external/avb/avbtool.py |
| 351 | // MAX_VBMETA_SIZE=64KB, MAX_FOOTER_SIZE=4KB |
| 352 | avb_hash_footer_kb = "68" |
| 353 | |
Jiyong Park | c2a49cc | 2021-10-15 00:02:12 +0900 | [diff] [blame] | 354 | // TODO(b/203031847) sign these bootconfig images using avb |
Jiyong Park | b810cfe | 2021-07-05 13:05:48 +0900 | [diff] [blame] | 355 | prebuilt_etc { |
Jiyong Park | c2a49cc | 2021-10-15 00:02:12 +0900 | [diff] [blame] | 356 | name: "microdroid_bootconfig_normal", |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 357 | src: ":microdroid_bootconfig_normal_gen", |
Jiyong Park | c2a49cc | 2021-10-15 00:02:12 +0900 | [diff] [blame] | 358 | filename: "microdroid_bootconfig.normal", |
| 359 | } |
| 360 | |
| 361 | prebuilt_etc { |
| 362 | name: "microdroid_bootconfig_app_debuggable", |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 363 | src: ":microdroid_bootconfig_app_debuggable_gen", |
Jiyong Park | c2a49cc | 2021-10-15 00:02:12 +0900 | [diff] [blame] | 364 | filename: "microdroid_bootconfig.app_debuggable", |
| 365 | } |
| 366 | |
| 367 | prebuilt_etc { |
| 368 | name: "microdroid_bootconfig_full_debuggable", |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 369 | src: ":microdroid_bootconfig_full_debuggable_gen", |
Jiyong Park | c2a49cc | 2021-10-15 00:02:12 +0900 | [diff] [blame] | 370 | filename: "microdroid_bootconfig.full_debuggable", |
Jiyong Park | b810cfe | 2021-07-05 13:05:48 +0900 | [diff] [blame] | 371 | } |
| 372 | |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 373 | // TODO(jiyong): make a new module type that does the avb signing |
| 374 | genrule { |
| 375 | name: "microdroid_bootconfig_normal_gen", |
| 376 | tools: ["avbtool"], |
| 377 | srcs: [ |
| 378 | "bootconfig.normal", |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 379 | ":microdroid_sign_key", |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 380 | ], |
| 381 | out: ["microdroid_bootconfig.normal"], |
| 382 | cmd: "cp $(location bootconfig.normal) $(out) && " + |
| 383 | "$(location avbtool) add_hash_footer " + |
| 384 | "--algorithm SHA256_RSA4096 " + |
| 385 | "--partition_name bootconfig " + |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 386 | "--key $(location :microdroid_sign_key) " + |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 387 | "--partition_size $$(( " + avb_hash_footer_kb + " * 1024 + ( $$(stat --format=%s $(out)) + 4096 - 1 ) / 4096 * 4096 )) " + |
| 388 | "--image $(out)", |
| 389 | } |
| 390 | |
| 391 | genrule { |
| 392 | name: "microdroid_bootconfig_app_debuggable_gen", |
| 393 | tools: ["avbtool"], |
| 394 | srcs: [ |
| 395 | "bootconfig.app_debuggable", |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 396 | ":microdroid_sign_key", |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 397 | ], |
| 398 | out: ["microdroid_bootconfig.app_debuggable"], |
| 399 | cmd: "cp $(location bootconfig.app_debuggable) $(out) && " + |
| 400 | "$(location avbtool) add_hash_footer " + |
| 401 | "--algorithm SHA256_RSA4096 " + |
| 402 | "--partition_name bootconfig " + |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 403 | "--key $(location :microdroid_sign_key) " + |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 404 | "--partition_size $$(( " + avb_hash_footer_kb + " * 1024 + ( $$(stat --format=%s $(out)) + 4096 - 1 ) / 4096 * 4096 )) " + |
| 405 | "--image $(out)", |
| 406 | } |
| 407 | |
| 408 | genrule { |
| 409 | name: "microdroid_bootconfig_full_debuggable_gen", |
| 410 | tools: ["avbtool"], |
| 411 | srcs: [ |
| 412 | "bootconfig.full_debuggable", |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 413 | ":microdroid_sign_key", |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 414 | ], |
| 415 | out: ["microdroid_bootconfig.full_debuggable"], |
| 416 | cmd: "cp $(location bootconfig.full_debuggable) $(out) && " + |
| 417 | "$(location avbtool) add_hash_footer " + |
| 418 | "--algorithm SHA256_RSA4096 " + |
| 419 | "--partition_name bootconfig " + |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 420 | "--key $(location :microdroid_sign_key) " + |
Jiyong Park | acf31b0 | 2021-11-04 20:45:14 +0900 | [diff] [blame] | 421 | "--partition_size $$(( " + avb_hash_footer_kb + " * 1024 + ( $$(stat --format=%s $(out)) + 4096 - 1 ) / 4096 * 4096 )) " + |
| 422 | "--image $(out)", |
| 423 | } |
| 424 | |
Jiyong Park | 3eb11f7 | 2021-02-23 12:53:30 +0900 | [diff] [blame] | 425 | prebuilt_etc { |
| 426 | name: "microdroid_fstab", |
Inseob Kim | 67ab436 | 2021-05-11 16:51:03 +0900 | [diff] [blame] | 427 | src: "fstab.microdroid", |
| 428 | filename: "fstab.microdroid", |
Jiyong Park | 3eb11f7 | 2021-02-23 12:53:30 +0900 | [diff] [blame] | 429 | installable: false, |
Jiyong Park | 153d355 | 2021-02-04 08:54:31 +0900 | [diff] [blame] | 430 | } |
Jiyong Park | f677cfa | 2021-02-19 15:44:52 +0900 | [diff] [blame] | 431 | |
| 432 | prebuilt_etc { |
Jiyong Park | 66aa0fb | 2021-04-08 19:10:44 +0900 | [diff] [blame] | 433 | name: "microdroid_bootloader", |
| 434 | src: ":microdroid_bootloader_gen", |
Jiyong Park | 89e81cb | 2021-04-13 13:13:55 +0900 | [diff] [blame] | 435 | arch: { |
| 436 | x86_64: { |
| 437 | // For unknown reason, the signed bootloader doesn't work on x86_64. Until the problem |
| 438 | // is fixed, let's use the unsigned bootloader for the architecture. |
| 439 | // TODO(b/185115783): remove this |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 440 | src: ":microdroid_bootloader_pubkey_replaced", |
Jiyong Park | 89e81cb | 2021-04-13 13:13:55 +0900 | [diff] [blame] | 441 | }, |
| 442 | }, |
Jiyong Park | 66aa0fb | 2021-04-08 19:10:44 +0900 | [diff] [blame] | 443 | filename: "microdroid_bootloader", |
| 444 | } |
| 445 | |
Jiyong Park | 66aa0fb | 2021-04-08 19:10:44 +0900 | [diff] [blame] | 446 | genrule { |
| 447 | name: "microdroid_bootloader_gen", |
| 448 | tools: ["avbtool"], |
| 449 | srcs: [ |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 450 | ":microdroid_bootloader_pubkey_replaced", |
| 451 | ":microdroid_sign_key", |
Jiyong Park | 66aa0fb | 2021-04-08 19:10:44 +0900 | [diff] [blame] | 452 | ], |
| 453 | out: ["bootloader-signed"], |
| 454 | // 1. Copy the input to the output becaise avbtool modifies --image in |
| 455 | // place. |
| 456 | // 2. Check if the file is big enough. For arm and x86 we have fake |
| 457 | // bootloader file whose size is 1. It can't pass avbtool. |
| 458 | // 3. Add the hash footer. The partition size is set to (image size + 68KB) |
| 459 | // rounded up to 4KB boundary. |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 460 | cmd: "cp $(location :microdroid_bootloader_pubkey_replaced) $(out) && " + |
Jiyong Park | 66aa0fb | 2021-04-08 19:10:44 +0900 | [diff] [blame] | 461 | "if [ $$(stat --format=%s $(out)) -gt 4096 ]; then " + |
| 462 | "$(location avbtool) add_hash_footer " + |
| 463 | "--algorithm SHA256_RSA4096 " + |
| 464 | "--partition_name bootloader " + |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 465 | "--key $(location :microdroid_sign_key) " + |
Jiyong Park | 66aa0fb | 2021-04-08 19:10:44 +0900 | [diff] [blame] | 466 | "--partition_size $$(( " + avb_hash_footer_kb + " * 1024 + ( $$(stat --format=%s $(out)) + 4096 - 1 ) / 4096 * 4096 )) " + |
| 467 | "--image $(out)" + |
| 468 | "; fi", |
| 469 | } |
| 470 | |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 471 | // Replace avbpubkey of prebuilt bootloader with the avbpubkey of the signing key |
| 472 | genrule { |
| 473 | name: "microdroid_bootloader_pubkey_replaced", |
| 474 | tools: ["replace_bytes"], |
| 475 | srcs: [ |
| 476 | ":microdroid_crosvm_bootloader", // input |
| 477 | ":microdroid_bootloader_avbpubkey_gen", // new bytes |
| 478 | ], |
| 479 | out: ["bootloader-pubkey-replaced"], |
| 480 | // 1. Copy the input to the output (replace_bytes modifies the file in-place) |
| 481 | // 2. Check if the file is big enough. For arm and x86 we have fake |
| 482 | // bootloader file whose size is 1. (replace_bytes fails if key not found) |
| 483 | // 3. Replace embedded pubkey with new one. |
| 484 | cmd: "cp $(location :microdroid_crosvm_bootloader) $(out) && " + |
| 485 | "if [ $$(stat --format=%s $(out)) -gt 4096 ]; then " + |
| 486 | "$(location replace_bytes) $(out) " + |
| 487 | // TODO(b/193504286) use the avbpubkey exposed from the prebuilt. |
| 488 | // For now, replacing it with the same key to ensure that "replace_bytes" works and |
| 489 | // that microdroid_crosvm_bootloader embeds the same pubkey of microdroid_sign_key. |
| 490 | "$(location :microdroid_bootloader_avbpubkey_gen) " + |
| 491 | "$(location :microdroid_bootloader_avbpubkey_gen)" + |
| 492 | "; fi", |
Jooyung Han | 6351310 | 2021-10-29 14:59:59 +0900 | [diff] [blame] | 493 | } |
| 494 | |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 495 | // Apex keeps a copy of avbpubkey embedded in bootloader so that embedded avbpubkey can be replaced |
| 496 | // while re-signing bootloader. |
| 497 | prebuilt_etc { |
| 498 | name: "microdroid_bootloader.avbpubkey", |
| 499 | src: ":microdroid_bootloader_avbpubkey_gen", |
| 500 | } |
| 501 | |
| 502 | // Generate avbpukey from the signing key |
Jooyung Han | 31b1c2b | 2021-10-27 03:35:42 +0900 | [diff] [blame] | 503 | genrule { |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 504 | name: "microdroid_bootloader_avbpubkey_gen", |
Jooyung Han | 31b1c2b | 2021-10-27 03:35:42 +0900 | [diff] [blame] | 505 | tools: ["avbtool"], |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 506 | srcs: [":microdroid_sign_key"], |
| 507 | out: ["bootloader.pubkey"], |
| 508 | cmd: "$(location avbtool) extract_public_key " + |
| 509 | "--key $(location :microdroid_sign_key) " + |
| 510 | "--output $(out)", |
Jooyung Han | 31b1c2b | 2021-10-27 03:35:42 +0900 | [diff] [blame] | 511 | } |
| 512 | |
| 513 | prebuilt_etc { |
Jiyong Park | f677cfa | 2021-02-19 15:44:52 +0900 | [diff] [blame] | 514 | name: "microdroid_uboot_env", |
| 515 | src: ":microdroid_uboot_env_gen", |
Jiyong Park | 89e81cb | 2021-04-13 13:13:55 +0900 | [diff] [blame] | 516 | arch: { |
| 517 | x86_64: { |
| 518 | src: ":microdroid_uboot_env_gen_x86_64", |
| 519 | }, |
| 520 | }, |
Jiyong Park | f677cfa | 2021-02-19 15:44:52 +0900 | [diff] [blame] | 521 | filename: "uboot_env.img", |
| 522 | } |
| 523 | |
| 524 | genrule { |
| 525 | name: "microdroid_uboot_env_gen", |
| 526 | tools: ["mkenvimage_host"], |
| 527 | srcs: ["uboot-env.txt"], |
| 528 | out: ["output.img"], |
| 529 | cmd: "$(location mkenvimage_host) -s 4096 -o $(out) $(in)", |
| 530 | } |
Inseob Kim | 28dddd8 | 2021-03-11 17:51:22 +0900 | [diff] [blame] | 531 | |
Jiyong Park | 89e81cb | 2021-04-13 13:13:55 +0900 | [diff] [blame] | 532 | genrule { |
| 533 | name: "microdroid_uboot_env_gen_x86_64", |
| 534 | tools: ["mkenvimage_host"], |
| 535 | srcs: ["uboot-env-x86_64.txt"], |
| 536 | out: ["output.img"], |
| 537 | cmd: "$(location mkenvimage_host) -s 4096 -o $(out) $(in)", |
| 538 | } |
| 539 | |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 540 | // Note that keys can be different for filesystem images even though we're using the same key |
| 541 | // for microdroid. However, the key signing VBmeta should match with the pubkey embedded in |
| 542 | // bootloader. |
| 543 | filegroup { |
| 544 | name: "microdroid_sign_key", |
| 545 | srcs: [":avb_testkey_rsa4096"], |
| 546 | } |
| 547 | |
Jiyong Park | 80d8da8 | 2021-03-15 23:30:11 +0900 | [diff] [blame] | 548 | vbmeta { |
| 549 | name: "microdroid_vbmeta", |
| 550 | partition_name: "vbmeta", |
Jooyung Han | d35952e | 2021-11-08 17:53:47 +0900 | [diff] [blame] | 551 | private_key: ":microdroid_sign_key", |
Jiyong Park | 80d8da8 | 2021-03-15 23:30:11 +0900 | [diff] [blame] | 552 | partitions: [ |
| 553 | "microdroid_vendor", |
| 554 | "microdroid_vendor_boot-5.10", |
Jiyong Park | 80d8da8 | 2021-03-15 23:30:11 +0900 | [diff] [blame] | 555 | "microdroid", |
Jiyong Park | 52ea083 | 2021-09-01 12:10:18 +0900 | [diff] [blame] | 556 | "microdroid_boot-5.10", |
Jiyong Park | 80d8da8 | 2021-03-15 23:30:11 +0900 | [diff] [blame] | 557 | ], |
| 558 | } |
Jooyung Han | 25a2acc | 2021-04-05 11:20:10 +0900 | [diff] [blame] | 559 | |
| 560 | prebuilt_etc { |
Jiyong Park | e9b74d0 | 2021-06-21 14:39:12 +0900 | [diff] [blame] | 561 | name: "microdroid.json", |
| 562 | src: "microdroid.json", |
Jiyong Park | 7851501 | 2021-04-13 17:43:10 +0900 | [diff] [blame] | 563 | } |
Jooyung Han | 017916b | 2021-04-20 03:57:19 +0900 | [diff] [blame] | 564 | |
| 565 | prebuilt_etc { |
Inseob Kim | 8f095c9 | 2021-05-26 12:04:54 +0900 | [diff] [blame] | 566 | name: "microdroid_vendor_manifest", |
| 567 | src: "microdroid_vendor_manifest.xml", |
| 568 | filename: "manifest.xml", |
| 569 | relative_install_path: "vintf", |
| 570 | installable: false, |
| 571 | } |
| 572 | |
| 573 | prebuilt_etc { |
| 574 | name: "microdroid_vendor_compatibility_matrix", |
| 575 | src: "microdroid_vendor_compatibility_matrix.xml", |
| 576 | filename: "compatibility_matrix.xml", |
| 577 | relative_install_path: "vintf", |
| 578 | installable: false, |
| 579 | } |
| 580 | |
| 581 | prebuilt_etc { |
| 582 | name: "microdroid_compatibility_matrix", |
| 583 | src: "microdroid_compatibility_matrix.xml", |
| 584 | filename: "compatibility_matrix.current.xml", |
| 585 | relative_install_path: "vintf", |
| 586 | installable: false, |
| 587 | } |
| 588 | |
| 589 | prebuilt_etc { |
| 590 | name: "microdroid_manifest", |
| 591 | src: "microdroid_manifest.xml", |
| 592 | filename: "manifest.xml", |
| 593 | relative_install_path: "vintf", |
| 594 | installable: false, |
| 595 | } |