blob: 176cf504c687154ec52f8bb223713562999dbd8b [file] [log] [blame]
Yifan Hong537802d2018-08-15 13:15:42 -07001//
2// Copyright (C) 2018 The Android Open Source Project
3//
4// Licensed under the Apache License, Version 2.0 (the "License");
5// you may not use this file except in compliance with the License.
6// You may obtain a copy of the License at
7//
8// http://www.apache.org/licenses/LICENSE-2.0
9//
10// Unless required by applicable law or agreed to in writing, software
11// distributed under the License is distributed on an "AS IS" BASIS,
12// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13// See the License for the specific language governing permissions and
14// limitations under the License.
15//
16
Amin Hassaniec7bc112020-10-29 16:47:58 -070017#ifndef UPDATE_ENGINE_AOSP_DYNAMIC_PARTITION_CONTROL_ANDROID_H_
18#define UPDATE_ENGINE_AOSP_DYNAMIC_PARTITION_CONTROL_ANDROID_H_
Yifan Hong537802d2018-08-15 13:15:42 -070019
David Andersona4b7ba62023-05-10 21:41:37 -070020#include <array>
Yifan Hong537802d2018-08-15 13:15:42 -070021#include <memory>
22#include <set>
23#include <string>
Kelvin Zhang91ad6622021-03-01 13:46:17 -050024#include <string_view>
David Andersona4b7ba62023-05-10 21:41:37 -070025#include <vector>
Yifan Hong537802d2018-08-15 13:15:42 -070026
Yifan Hong3a1a5612019-11-05 16:34:32 -080027#include <base/files/file_util.h>
Yifan Hong2c62c132019-10-24 14:53:40 -070028#include <libsnapshot/auto_device.h>
Yifan Hong420db9b2019-07-23 20:50:33 -070029#include <libsnapshot/snapshot.h>
30
Yifan Hong15726b92019-11-05 19:06:48 -080031#include "update_engine/common/dynamic_partition_control_interface.h"
32
Yifan Hong537802d2018-08-15 13:15:42 -070033namespace chromeos_update_engine {
34
35class DynamicPartitionControlAndroid : public DynamicPartitionControlInterface {
36 public:
Kelvin Zhang91ad6622021-03-01 13:46:17 -050037 // A directory where all partitions mapped by VABC is expected to be found.
38 // Per earlier discussion with VAB team, this directory is unlikely to change.
39 // So we declare it as a constant here.
40 static constexpr std::string_view VABC_DEVICE_DIR = "/dev/block/mapper/";
Kelvin Zhangebd115e2021-03-08 16:10:25 -050041 explicit DynamicPartitionControlAndroid(uint32_t source_slot);
Yifan Hong537802d2018-08-15 13:15:42 -070042 ~DynamicPartitionControlAndroid();
Kelvin Zhang91d95fa2020-11-05 13:52:00 -050043
Yifan Hong186bb682019-07-23 14:04:39 -070044 FeatureFlag GetDynamicPartitionsFeatureFlag() override;
Yifan Hong413d5722019-07-23 14:21:09 -070045 FeatureFlag GetVirtualAbFeatureFlag() override;
Kelvin Zhangda1b3142020-09-24 17:09:02 -040046 FeatureFlag GetVirtualAbCompressionFeatureFlag() override;
Kelvin Zhang1c4b9812022-04-06 17:29:00 -070047 FeatureFlag GetVirtualAbCompressionXorFeatureFlag() override;
David Andersone35b4382022-03-08 23:18:29 -080048 FeatureFlag GetVirtualAbUserspaceSnapshotsFeatureFlag() override;
Yifan Hongf5261562020-03-10 10:28:10 -070049 bool OptimizeOperation(const std::string& partition_name,
50 const InstallOperation& operation,
51 InstallOperation* optimized) override;
Yifan Hong537802d2018-08-15 13:15:42 -070052 void Cleanup() override;
Yifan Hong012508e2019-07-22 18:30:40 -070053
Yifan Hongf0f4a912019-09-26 17:51:33 -070054 bool PreparePartitionsForUpdate(uint32_t source_slot,
55 uint32_t target_slot,
56 const DeltaArchiveManifest& manifest,
Yifan Hongf033ecb2020-01-07 18:13:56 -080057 bool update,
Daniel Zhengeede4c82023-06-13 11:21:06 -070058 uint64_t* required_size,
59 ErrorCode* error = nullptr) override;
Yifan Hong7b3910a2020-03-24 17:47:32 -070060 bool FinishUpdate(bool powerwash_required) override;
Yifan Hong90965502020-02-19 15:22:47 -080061 std::unique_ptr<AbstractAction> GetCleanupPreviousUpdateAction(
62 BootControlInterface* boot_control,
63 PrefsInterface* prefs,
64 CleanupPreviousUpdateActionDelegateInterface* delegate) override;
Yifan Hong012508e2019-07-22 18:30:40 -070065
Yifan Hong6a6d0f12020-03-11 13:20:52 -070066 bool ResetUpdate(PrefsInterface* prefs) override;
67
Tianjie99d570d2020-06-04 14:57:19 -070068 bool ListDynamicPartitionsForSlot(
Tianjie3a55fc22021-02-13 16:02:22 -080069 uint32_t slot,
70 uint32_t current_slot,
71 std::vector<std::string>* partitions) override;
Tianjie99d570d2020-06-04 14:57:19 -070072
Tianjie24f96092020-06-30 12:26:25 -070073 bool VerifyExtentsForUntouchedPartitions(
74 uint32_t source_slot,
75 uint32_t target_slot,
76 const std::vector<std::string>& partitions) override;
77
Tianjie99d570d2020-06-04 14:57:19 -070078 bool GetDeviceDir(std::string* path) override;
79
Yifan Hong3a1a5612019-11-05 16:34:32 -080080 // Return the device for partition |partition_name| at slot |slot|.
81 // |current_slot| should be set to the current active slot.
82 // Note: this function is only used by BootControl*::GetPartitionDevice.
83 // Other callers should prefer BootControl*::GetPartitionDevice over
84 // BootControl*::GetDynamicPartitionControl()->GetPartitionDevice().
Kelvin Zhang91d95fa2020-11-05 13:52:00 -050085 std::optional<PartitionDevice> GetPartitionDevice(
86 const std::string& partition_name,
87 uint32_t slot,
88 uint32_t current_slot,
Kelvin Zhang66a9ebb2021-01-25 13:35:10 -050089 bool not_in_payload);
Kelvin Zhang91d95fa2020-11-05 13:52:00 -050090 // Deprecated, please use GetPartitionDevice(string, uint32_t, uint32_t);
91 // TODO(zhangkelvin) Remove below deprecated APIs.
Yifan Hong3a1a5612019-11-05 16:34:32 -080092 bool GetPartitionDevice(const std::string& partition_name,
93 uint32_t slot,
94 uint32_t current_slot,
Tianjie51a5a392020-06-03 14:39:32 -070095 bool not_in_payload,
96 std::string* device,
97 bool* is_dynamic);
98
99 bool GetPartitionDevice(const std::string& partition_name,
100 uint32_t slot,
101 uint32_t current_slot,
Yifan Hong3a1a5612019-11-05 16:34:32 -0800102 std::string* device);
103
Kelvin Zhang34618522020-09-28 09:21:02 -0400104 // Partition name is expected to be unsuffixed. e.g. system, vendor
Daniel Zhengb873c1c2023-09-18 13:29:31 -0700105 // Return an interface to write to a snapshotted partition.
David Andersona4b7ba62023-05-10 21:41:37 -0700106 std::unique_ptr<android::snapshot::ICowWriter> OpenCowWriter(
Kelvin Zhang34618522020-09-28 09:21:02 -0400107 const std::string& unsuffixed_partition_name,
108 const std::optional<std::string>& source_path,
David Andersona4b7ba62023-05-10 21:41:37 -0700109 std::optional<uint64_t> label) override;
Kelvin Zhang1a0ed712022-01-26 16:09:05 -0800110 std::unique_ptr<FileDescriptor> OpenCowFd(
111 const std::string& unsuffixed_partition_name,
112 const std::optional<std::string>&,
David Andersona4b7ba62023-05-10 21:41:37 -0700113 bool is_append) override;
Kelvin Zhang34618522020-09-28 09:21:02 -0400114
Kelvin Zhang02fe6622021-11-01 16:37:58 -0700115 bool MapAllPartitions() override;
Kelvin Zhang9d87d6d2020-10-23 17:03:59 -0400116 bool UnmapAllPartitions() override;
117
Kelvin Zhangebd115e2021-03-08 16:10:25 -0500118 bool IsDynamicPartition(const std::string& part_name, uint32_t slot) override;
Kelvin Zhangeb9de162020-11-16 15:47:28 -0500119
Yifan Hongb0cbd392021-02-04 11:11:45 -0800120 bool UpdateUsesSnapshotCompression() override;
121
Kelvin Zhang3fe49642021-10-04 15:35:02 -0700122 std::optional<base::FilePath> GetSuperDevice();
123
Yifan Hong012508e2019-07-22 18:30:40 -0700124 protected:
125 // These functions are exposed for testing.
126
127 // Unmap logical partition on device mapper. This is the reverse operation
128 // of MapPartitionOnDeviceMapper.
129 // Returns true if unmapped successfully.
130 virtual bool UnmapPartitionOnDeviceMapper(
131 const std::string& target_partition_name);
132
Tianjie24f96092020-06-30 12:26:25 -0700133 // Retrieves metadata from |super_device| at slot |slot|.
134 virtual std::unique_ptr<android::fs_mgr::MetadataBuilder> LoadMetadataBuilder(
135 const std::string& super_device, uint32_t slot);
136
Kelvin Zhang91d95fa2020-11-05 13:52:00 -0500137 // Retrieves metadata from |super_device| at slot |source_slot|. And
138 // modifies the metadata so that during updates, the metadata can be written
139 // to |target_slot|. In particular, on retrofit devices, the returned
140 // metadata automatically includes block devices at |target_slot|.
Yifan Hong012508e2019-07-22 18:30:40 -0700141 virtual std::unique_ptr<android::fs_mgr::MetadataBuilder> LoadMetadataBuilder(
Yifan Hong6e706b12018-11-09 16:50:51 -0800142 const std::string& super_device,
143 uint32_t source_slot,
Yifan Hong012508e2019-07-22 18:30:40 -0700144 uint32_t target_slot);
145
146 // Write metadata |builder| to |super_device| at slot |target_slot|.
147 virtual bool StoreMetadata(const std::string& super_device,
148 android::fs_mgr::MetadataBuilder* builder,
149 uint32_t target_slot);
Yifan Hong537802d2018-08-15 13:15:42 -0700150
Yifan Hong3a1a5612019-11-05 16:34:32 -0800151 // Map logical partition on device-mapper.
152 // |super_device| is the device path of the physical partition ("super").
153 // |target_partition_name| is the identifier used in metadata; for example,
154 // "vendor_a"
155 // |slot| is the selected slot to mount; for example, 0 for "_a".
156 // Returns true if mapped successfully; if so, |path| is set to the device
157 // path of the mapped logical partition.
158 virtual bool MapPartitionOnDeviceMapper(
159 const std::string& super_device,
160 const std::string& target_partition_name,
161 uint32_t slot,
162 bool force_writable,
163 std::string* path);
164
165 // Return true if a static partition exists at device path |path|.
166 virtual bool DeviceExists(const std::string& path);
167
168 // Returns the current state of the underlying device mapper device
169 // with given name.
170 // One of INVALID, SUSPENDED or ACTIVE.
171 virtual android::dm::DmDeviceState GetState(const std::string& name);
172
173 // Returns the path to the device mapper device node in '/dev' corresponding
174 // to 'name'. If the device does not exist, false is returned, and the path
175 // parameter is not set.
176 virtual bool GetDmDevicePathByName(const std::string& name,
177 std::string* path);
178
Yifan Hong3a1a5612019-11-05 16:34:32 -0800179 // Return the name of the super partition (which stores super partition
180 // metadata) for a given slot.
181 virtual std::string GetSuperPartitionName(uint32_t slot);
182
Yifan Hong6eec9952019-12-04 13:12:01 -0800183 virtual void set_fake_mapped_devices(const std::set<std::string>& fake);
184
Yifan Hongbae27842019-10-24 16:56:12 -0700185 // Allow mock objects to override this to test recovery mode.
186 virtual bool IsRecovery();
187
Yifan Hong29692902020-03-26 12:47:05 -0700188 // Determine path for system_other partition.
189 // |source_slot| should be current slot.
190 // |target_slot| should be "other" slot.
191 // |partition_name_suffix| should be "system" + suffix(|target_slot|).
192 // Return true and set |path| if successful.
193 // Set |path| to empty if no need to erase system_other.
194 // Set |should_unmap| to true if path needs to be unmapped later.
195 //
196 // Note: system_other cannot use GetPartitionDevice or
197 // GetDynamicPartitionDevice because:
198 // - super partition metadata may be loaded from the source slot
199 // - UPDATED flag needs to be check to skip erasing if partition is not
200 // created by flashing tools
201 // - Snapshots from previous update attempts should not be used.
202 virtual bool GetSystemOtherPath(uint32_t source_slot,
203 uint32_t target_slot,
204 const std::string& partition_name_suffix,
205 std::string* path,
206 bool* should_unmap);
207
208 // Returns true if any entry in the fstab file in |path| has AVB enabled,
209 // false if not enabled, and nullopt for any error.
210 virtual std::optional<bool> IsAvbEnabledInFstab(const std::string& path);
211
212 // Returns true if system_other has AVB enabled, false if not enabled, and
213 // nullopt for any error.
214 virtual std::optional<bool> IsAvbEnabledOnSystemOther();
215
216 // Erase system_other partition that may contain system_other.img.
217 // After the update, the content of system_other may be corrupted but with
218 // valid AVB footer. If the update is rolled back and factory data reset is
219 // triggered, system_b fails to be mapped with verity errors (see
220 // b/152444348). Erase the system_other so that mapping system_other is
221 // skipped.
222 virtual bool EraseSystemOtherAvbFooter(uint32_t source_slot,
223 uint32_t target_slot);
224
Yifan Hong302fa702020-04-16 09:48:29 -0700225 // Helper for PreparePartitionsForUpdate. Used for devices with dynamic
226 // partitions updating without snapshots.
227 // If |delete_source| is set, source partitions are deleted before resizing
228 // target partitions (using DeleteSourcePartitions).
229 virtual bool PrepareDynamicPartitionsForUpdate(
230 uint32_t source_slot,
231 uint32_t target_slot,
232 const DeltaArchiveManifest& manifest,
233 bool delete_source);
234
Kelvin Zhang91d95fa2020-11-05 13:52:00 -0500235 void SetSourceSlot(uint32_t slot) { source_slot_ = slot; }
236 void SetTargetSlot(uint32_t slot) { target_slot_ = slot; }
237
Yifan Hong537802d2018-08-15 13:15:42 -0700238 private:
Yifan Hongc049f932019-07-23 15:06:05 -0700239 friend class DynamicPartitionControlAndroidTest;
Yifan Hong302fa702020-04-16 09:48:29 -0700240 friend class SnapshotPartitionTestP;
Yifan Hongc049f932019-07-23 15:06:05 -0700241
Yifan Hong8546a712019-03-28 14:42:53 -0700242 bool MapPartitionInternal(const std::string& super_device,
243 const std::string& target_partition_name,
244 uint32_t slot,
245 bool force_writable,
246 std::string* path);
Yifan Hong537802d2018-08-15 13:15:42 -0700247
Yifan Hong8d6df9a2020-08-13 13:59:54 -0700248 // Update |builder| according to |partition_metadata|.
249 // - In Android mode, this is only called when the device
250 // does not have Virtual A/B.
251 // - When sideloading, this maybe called as a fallback path if CoW cannot
252 // be created.
Yifan Hong13d41cb2019-09-16 13:18:22 -0700253 bool UpdatePartitionMetadata(android::fs_mgr::MetadataBuilder* builder,
254 uint32_t target_slot,
255 const DeltaArchiveManifest& manifest);
Yifan Hong012508e2019-07-22 18:30:40 -0700256
Kelvin Zhang91d95fa2020-11-05 13:52:00 -0500257 // Helper for PreparePartitionsForUpdate. Used for snapshotted partitions
258 // for Virtual A/B update.
Yifan Hong420db9b2019-07-23 20:50:33 -0700259 bool PrepareSnapshotPartitionsForUpdate(uint32_t source_slot,
260 uint32_t target_slot,
Yifan Hongf033ecb2020-01-07 18:13:56 -0800261 const DeltaArchiveManifest& manifest,
262 uint64_t* required_size);
Yifan Hong420db9b2019-07-23 20:50:33 -0700263
Yifan Hong3a1293a2021-04-16 13:21:20 -0700264 enum SpaceLimit {
265 // Most restricted: if sum(groups) > super / 2, error
266 ERROR_IF_EXCEEDED_HALF_OF_SUPER,
267 // Implies ERROR_IF_EXCEEDED_SUPER; then, if sum(groups) > super / 2, warn
268 WARN_IF_EXCEEDED_HALF_OF_SUPER,
269 // Least restricted: if sum(groups) > super, error
270 ERROR_IF_EXCEEDED_SUPER,
271 };
272 // Helper of CheckSuperPartitionAllocatableSpace. Determine limit for groups
273 // and partitions.
274 SpaceLimit GetSpaceLimit(bool use_snapshot);
275
Tianjie9f4dc7f2021-03-15 16:00:50 -0700276 // Returns true if the allocatable space in super partition is larger than
277 // the size of dynamic partition groups in the manifest.
278 bool CheckSuperPartitionAllocatableSpace(
279 android::fs_mgr::MetadataBuilder* builder,
280 const DeltaArchiveManifest& manifest,
281 bool use_snapshot);
282
Yifan Hong3a1a5612019-11-05 16:34:32 -0800283 enum class DynamicPartitionDeviceStatus {
284 SUCCESS,
285 ERROR,
286 TRY_STATIC,
287 };
288
289 // Return SUCCESS and path in |device| if partition is dynamic.
290 // Return ERROR if any error.
291 // Return TRY_STATIC if caller should resolve the partition as a static
292 // partition instead.
293 DynamicPartitionDeviceStatus GetDynamicPartitionDevice(
294 const base::FilePath& device_dir,
295 const std::string& partition_name_suffix,
296 uint32_t slot,
297 uint32_t current_slot,
Tianjie51a5a392020-06-03 14:39:32 -0700298 bool not_in_payload,
Yifan Hong3a1a5612019-11-05 16:34:32 -0800299 std::string* device);
300
301 // Return true if |partition_name_suffix| is a block device of
302 // super partition metadata slot |slot|.
303 bool IsSuperBlockDevice(const base::FilePath& device_dir,
304 uint32_t current_slot,
305 const std::string& partition_name_suffix);
306
Yifan Hongbae27842019-10-24 16:56:12 -0700307 // If sideloading a full OTA, delete source partitions from |builder|.
308 bool DeleteSourcePartitions(android::fs_mgr::MetadataBuilder* builder,
309 uint32_t source_slot,
310 const DeltaArchiveManifest& manifest);
311
Yifan Hong4d7c5eb2020-04-03 11:31:50 -0700312 // Returns true if metadata is expected to be mounted, false otherwise.
313 // Note that it returns false on non-Virtual A/B devices.
314 //
Kelvin Zhang91d95fa2020-11-05 13:52:00 -0500315 // Almost all functions of SnapshotManager depends on metadata being
316 // mounted.
Yifan Hong4d7c5eb2020-04-03 11:31:50 -0700317 // - In Android mode for Virtual A/B devices, assume it is mounted. If not,
318 // let caller fails when calling into SnapshotManager.
Kelvin Zhang91d95fa2020-11-05 13:52:00 -0500319 // - In recovery for Virtual A/B devices, it is possible that metadata is
320 // not
Yifan Hong4d7c5eb2020-04-03 11:31:50 -0700321 // formatted, hence it cannot be mounted. Caller should not call into
322 // SnapshotManager.
Kelvin Zhang91d95fa2020-11-05 13:52:00 -0500323 // - On non-Virtual A/B devices, updates do not depend on metadata
324 // partition.
Yifan Hong4d7c5eb2020-04-03 11:31:50 -0700325 // Caller should not call into SnapshotManager.
326 //
Kelvin Zhang91d95fa2020-11-05 13:52:00 -0500327 // This function does NOT mount metadata partition. Use
328 // EnsureMetadataMounted to mount metadata partition.
Yifan Hong4d7c5eb2020-04-03 11:31:50 -0700329 bool ExpectMetadataMounted();
330
331 // Ensure /metadata is mounted. Returns true if successful, false otherwise.
332 //
333 // Note that this function returns true on non-Virtual A/B devices without
334 // doing anything.
335 bool EnsureMetadataMounted();
336
Yifan Hongf6f75c22020-07-31 15:20:25 -0700337 // Set boolean flags related to target build. This includes flags like
338 // target_supports_snapshot_ and is_target_dynamic_.
339 bool SetTargetBuildVars(const DeltaArchiveManifest& manifest);
340
Yifan Hong420db9b2019-07-23 20:50:33 -0700341 std::set<std::string> mapped_devices_;
Yifan Hongb38e1af2019-10-17 14:59:22 -0700342 const FeatureFlag dynamic_partitions_;
343 const FeatureFlag virtual_ab_;
Kelvin Zhangda1b3142020-09-24 17:09:02 -0400344 const FeatureFlag virtual_ab_compression_;
Kelvin Zhang1c4b9812022-04-06 17:29:00 -0700345 const FeatureFlag virtual_ab_compression_xor_;
David Andersone35b4382022-03-08 23:18:29 -0800346 const FeatureFlag virtual_ab_userspace_snapshots_;
Yifan Hongf9cb4492020-04-15 13:00:20 -0700347 std::unique_ptr<android::snapshot::ISnapshotManager> snapshot_;
Yifan Hong2c62c132019-10-24 14:53:40 -0700348 std::unique_ptr<android::snapshot::AutoDevice> metadata_device_;
Yifan Hongf0f4a912019-09-26 17:51:33 -0700349 bool target_supports_snapshot_ = false;
Yifan Hong3a1a5612019-11-05 16:34:32 -0800350 // Whether the target partitions should be loaded as dynamic partitions. Set
351 // by PreparePartitionsForUpdate() per each update.
352 bool is_target_dynamic_ = false;
Kelvin Zhang91d95fa2020-11-05 13:52:00 -0500353
Yifan Hong6eec9952019-12-04 13:12:01 -0800354 uint32_t source_slot_ = UINT32_MAX;
355 uint32_t target_slot_ = UINT32_MAX;
Kelvin Zhangff5380b2022-03-16 13:35:04 -0700356 // We assume that there's only 2 slots, A and B. This assumption is unlikely
357 // to change in the future. And certaintly won't change at runtime.
358 std::array<std::vector<std::string>, 2> dynamic_partition_list_{};
Yifan Hong420db9b2019-07-23 20:50:33 -0700359
Yifan Hong537802d2018-08-15 13:15:42 -0700360 DISALLOW_COPY_AND_ASSIGN(DynamicPartitionControlAndroid);
361};
362
363} // namespace chromeos_update_engine
364
Amin Hassaniec7bc112020-10-29 16:47:58 -0700365#endif // UPDATE_ENGINE_AOSP_DYNAMIC_PARTITION_CONTROL_ANDROID_H_