36 Commits

Author SHA1 Message Date
Andrew Gunnerson 44d62f5147 Add release management tasks
Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-08-30 19:23:07 -04:00
Andrew Gunnerson 8549fa1dfc avbroot 2.0: Rewrite in Rust
Why?
----

It was always my intention to write avbroot in a compiled language.
Python was a stop-gap solution since it was possible to use the various
tools and parsers from AOSP to make the initial prototyping and
implementation easier. However, doing so required a whole lot of hacks
since nearly all of the Python modules we use were intended to be used
as executables, not libraries, and they were definitely not meant to be
used outside of AOSP's code base.

Although the dependencies on AOSP code have been reduced over time,
working on the Python code is still frustrating. The majority of the
modules we use from both the standard library and external dependencies
are lacking type annotations. All of the Python language servers and
type checker tools I've used choked on them. There have been serveral
avbroot bugs in the past that wouldn't have happened with any
statically typed language.

The catalyst for me working on this recently was dealing with some
python-protobuf versions that wouldn't work with AOSP's pregenerated
protobuf bindings. When parsing protobuf messages, it would fail
with obscure runtime type errors. I need my projects to not feel
frustrating or else I'll just get burnt out.

Hence, the Rust rewrite. With fewer hacks this time! avbroot no longer
has any dependencies on external tools like openssl. I'll be providing
precompiled binaries for the three major desktop OS's, built by GitHub
Actions. avbroot will also be versioned now, starting at 2.0.0.

Whats new?
----------

* A new `avbroot ota verify` subcommand has been added to check that all
  OTA and AVB related components have been properly hashed and signed.
  This works for all OTA images, including stock ones.
* A couple new `avbroot avb` subcommands have been added for dumping
  vbmeta header/footer information and verifying AVB signatures. These
  are roughly equivalent to avbtool's `info_image` and `verify_image`
  subcommands, though avbroot is about an order of magnitude faster than
  the latter.
* A new set of `avbroot boot` subcommands have been added for packing
  and unpacking boot images. It supports Android v0-v4 images and vendor
  v3-v4 images. Repacking is lossless even when using deprecated fields,
  like the boot image v4 VTS signature.
* A new `avbroot ramdisk` subcommand has been added for inspecting
  the CPIO structure of ramdisks.
* A new set of `avbroot key` subcommands have been added for generating
  signing keys so that it's no longer necessary to install openssl and
  avbtool (though of course, keys generated by other tools remain fully
  compatible).
* Since avbroot has a ton of CLI options, a new `avbroot completion`
  subcommand has been added for generating tab-completion configs for
  various shells (eg. bash, zsh, fish, powershell).

What was removed?
-----------------

Nothing :) The `patch` and `extract` subcommands have been moved under
`avbroot ota` and the `magisk-info` subcommand has been moved under
`avbroot boot`, but there are compatibility shims in place to keep all
the old commands working.

The command-line interface will remain backwards compatible for as long
as possible, even with new major releases. The Rust API, however, has no
backwards compatibility guarantees. I currently don't intend for
avbroot's "library" components to be used anywhere outside of Custota
and avbroot itself.

Performance
-----------

Due to having better access to low-level APIs (especially `pread` and
`pwrite`), nearly everything that can be multithreaded in avbroot is now
multithreaded. In addition, during the patching operation, everything
is done entirely in memory without temp files and the maximum memory
usage is still about 100MB lower than with the Python implementation.

The new implementation is bottlenecked by how fast a single CPU core can
calculate 3 SHA256 hashes of overlapping regions spanning the majority
of the OTA file. About 90% of the CPU time is spent calculating SHA256
hashes and another 5% or so performing XZ-compression.

Some numbers:

* Patching should take roughly 40%-70% of the time it took before.
* Extracting with `--all` should take roughly 10%-30% of the time it
  took before.

Folks with x86_64 CPUs supporting SHA-NI extensions (eg. Intel 11th gen
and newer) should see even bigger improvements.

Reproducibility
---------------

The new implementation's output files are bit-for-bit identical when the
inputs are the same. However, they do not exactly match what the Python
implementation produced.

* The zip entries, aside from `metadata` and `metadata.pb`, are written
  in sorted order.
* All zip entries are stored without compression.
* All zip entries are stored without additional metadata (eg.
  modification timestamp).
* The OTA certificate, both in the OTA zip and in the recovery ramdisk's
  `otacerts.zip`, goes through deserialization + serialization before
  being written. Text in the certificate file before the header and
  after the footer will be stripped out.
* The protobuf structures (payload header and OTA metadata) are
  serialized differently. Protobuf has more than one way to encode the
  same messages "on the wire". The Rust quick_protobuf library
  serializes messages a bit differently than python-protobuf, but the
  outputs are mutually compatible.
* XZ compression of modified partition images in the payload is now done
  at compression level 0 instead of 6. This reduces the patching time by
  several seconds at the cost of a couple MiB increase in file size.
* Ramdisks are now compressed with standard LZ4 instead of LZ4HC (high
  compression mode). For our use case, the difference is <100 KiB, but
  using standard LZ4 allows us to use a pure-Rust LZ4 library and makes
  the compression step much faster.
* Older ramdisks compressed with gzip are slightly different due to a
  different gzip implementation being used (flate2 vs. zlib). The two
  implementations structure the gzip frames slightly differently, but
  the output is identical when decompressed.
* Magisk's config file in the ramdisk (`.backup/.magisk`) will have the
  `SHA1` field set to all zeros. This allows avbroot to keep track of
  less information during patching for better performance. The field is
  only used for Magisk's uninstall feature, which can't ever be used in
  a locked bootloader setup anyway.

Misc
----

While working on the new `avbroot ota verify` subcommand, I found that
the `ossi` stock image (OnePlus 10 Pro) used in avbroot's tests has an
invalid vbmeta hash for the `odm` partition. I thought it was an avbroot
bug, but AOSP's avbtool reports the same invalid hash too. If that image
actually boots, then I'm not sure AVB can be trusted on those devices...

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-08-29 15:54:53 -04:00
Andrew Gunnerson 4db33db175 Add GitHub Actions workflow to build modules
Fixes: #123

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-08-11 15:17:22 -04:00
Andrew Gunnerson bbd547e5e4 README.md: Mention Custota as an alternative to the clearotacerts module
Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-08-03 13:06:38 -04:00
Andrew Gunnerson 93dcd63829 Add support for replacing any partition image
This commit adds support for replacing any partition image within
the payload with a custom image. This is useful, for example, to add a
custom kernel to an OTA, which may involve partitions that wouldn't
normally be touched (eg. `vendor_dlkm`).

Any image specified via `--replace` will have its corresponding
descriptor in the vbmeta image updated. This is handled recursively. For
example, replacing `vendor_dlkm` would update both `vbmeta_vendor` and
`vbmeta`. This requires all vbmeta images to be extracted during the
patching process so that a complete dependency graph can be computed.
The performance hit in doing so is negligible, but does require the
checksums of the stripped images to be updated for the tests.

Fixes: #102

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-06-28 21:04:49 -04:00
Andrew Gunnerson 48318f333a Add support for ignoring boot image checks for --prepatched
There are 3 levels of warnings:

* Level 0: Warnings that don't affect booting
    * Mismatched `id` or `os_version` fields
* Level 1: Warnings that may affect booting
    * Mismatched `cmdline` or `extra_cmdline` fields
    * Unexpected addition of `kernel`, `second`, `recovery_dtbo`, `dtb`,
      or `bootconfig`
* Level 2: Warnings that are very likely to affect booting
    * All other mismatched, added, or removed fields

By default, any warning of level 1 or higher is treated as a fatal
error. Each time `--ignore-prepatched-compat` is passed in, the
permitted warning level is increased.

Fixes: #108

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-06-28 19:40:50 -04:00
Andrew Gunnerson 1b5d98d718 README.md: Improve project description and remove suggestion for compiling AOSP from source
Issue: #106

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-06-22 19:56:23 -04:00
Andrew Gunnerson 0ff1bb2b2f README.md: Add note about using unencrypted private keys
Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-05-31 00:04:48 -04:00
Andrew Gunnerson 601c24222f Add support for supplying the private key passphrases non-interactively
Fixes: #99

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-05-30 22:35:49 -04:00
Andrew Gunnerson da3c9da2bf Add option to skip applying the root patch entirely
This allows users to use avbroot for just resigning an OTA with their
own signing keys.

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-05-27 16:35:46 -04:00
Andrew Gunnerson 2982f00ef3 README.md: Add reference to oemunlockonboot in the CalyxOS warning message
Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-05-23 13:43:55 -04:00
Andrew Gunnerson 53e0e30c86 Add Magisk module to enable OEM unlocking on every boot
The module helps reduce the chance of OEM unlocking being disabled,
whether by the user or by some OS's initial setup wizard. It works by
running some Java code at boot, which connects to the `OemLockService`
binder service and calls `setOemUnlockAllowedByUser(true)`, the same as
what the Settings app does.

Fixes: #8
Issue: #84

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-05-23 00:06:24 -04:00
Andrew Gunnerson 27c2bed773 Switch to Magisk 25211's PREINITDEVICE
Unlike the prior RULESDEVICE, PREINITDEVICE uses a block device name
since the rdev major/minor is not guaranteed to remain the same across
reboots. This commit completely drops support for RULESDEVICE (25207
through 25210) since it never made it to a stable Magisk release.

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-03-25 19:51:22 -04:00
Andrew Gunnerson 543d2eafc6 README.md: Add warning about CalyxOS automatically turning off OEM unlocking
Issue: #84

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-03-24 18:32:34 -04:00
Andrew Gunnerson 0a1888ad94 Magisk >=25207 require a rules device ID
Newer Magisk versions no longer try to autodetect a writable ext4
partition for storing SELinux rules during boot. Instead, the block
device is detected during boot image patching and is stored in the
ramdisk's `.backup/.magisk` as `makedev(rdev_maj, rdev_min)`.

This unfortunately complicates the patching process for avbroot. Even if
we replicate Magisk's algorithm for finding a suitable partition,
there's no way to find the block device's rdev for it with the
information contained in the OTA package. This is the first change that
adds a hard dependency on information only attainable from a running
device.

For these newer Magisk versions, the user will have to patch the boot
image once in the Magisk app (must be on the target device) and then run
`avbroot magisk-info` to show the computed device ID. Then, avbroot can
use this during patching via `--magisk-rules-device`. If the user's
device is unable to run the Magisk app prior to patching (eg.
unbootable), they'll have to go through the patching process twice, once
with `--ignore-magisk-warnings` and a second time with the proper device
ID specified.

When using `--ignore-magisk-warnings`, root still works, but there will
be subtle issues, like certain modules failing to load.

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-03-09 17:01:39 -05:00
Andrew Gunnerson ed1310d243 README.md: Add section about extracting the entire OTA
Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-26 22:38:32 -05:00
Andrew Gunnerson a927d09936 Add option to clear vbmeta flags
Some Android builds ship with a root vbmeta image with flags that
disable AVB completely. This commit adds a new check for these flags so
that the patching process will fail and also adds a new
`--clear-vbmeta-flags` option for forcibly setting the flags to 0.

Issue: #60

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-26 19:01:34 -05:00
Andrew Gunnerson d80ce411c7 Add support for using prepatched boot images
This is useful for folks who want to apply the Magisk root patch
themselves via the Magisk app or use KernelSU. When `--prepatched` is
used, avbroot will skip the root patch, but still apply the otacerts
patch.

To help protect against accidental use of the wrong boot image, avbroot
will only accept a prepatched image if all the header fields and section
types match the original image. The only exception is the number of
ramdisks, which is allowed to increase (Magisk may create a ramdisk in
an image that didn't originally have one).

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-26 18:01:03 -05:00
Andrew Gunnerson 7435c49f50 Add support for Python 3.9
This is needed for Debian 11 compatibility.

Fixes: #50

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-15 00:04:12 -05:00
Andrew Gunnerson 3c3b70bcd7 Improve documentation for installing dependencies
Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-11 18:08:09 -05:00
Andrew Gunnerson 333297c7a1 avbroot/openssl.py: Pass in the passphrase via env vars on Windows
openssl does not support reading the passphrase from file descriptors on
Windows. Using an environment variable is the next best option.

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-11 16:49:57 -05:00
Andrew Gunnerson 6c116f0dba Remove dependency on magiskboot
This commit reimplements the magiskboot patching process natively in
Python. By doing so, avbroot gains cross platform support and there's no
longer a need to execute an Android binary on a non-Android Linux system,
which had pitfalls that already had to be worked around.

Boot images and cpio archives are handled by new custom parsers added to
avbroot. Legacy lz4 compression is done by a wrapper around the python
lz4 library (a new dependency). Gzip compression is handled natively by
python. Other compression methods and OEM-specific boot image formats
are not supported because devices that use the modern Android A/B OTA
scheme do not use those.

Output files are still bit-for-bit reproducible across runs, but they
are different from what prior avbroot commits produced:

* avbroot's cpio writer follows GNU cpio and libarchive's behavior of
  setting the mode field to 0 in the trailer entry. magiskboot sets the
  mode to 0o755.
* When patching a vendor boot v4 image, the ramdisk table entries are
  now updated correctly. Prior vendor boot images were only bootable
  because:

  * the image only contained a single ramdisk
  * the single ramdisk shrunk in size, stayed the same, or grew little
    enough to not exceed a page boundary
  * the bootloader is lenient in validating boot image fields

  magiskboot does not handle vendor boot v4 images correctly, but it
  doesn't need to just for the regular root patch. avbroot made use of
  it in an unsupported way to patch vendor boot ramdisks.

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-11 01:22:24 -05:00
Andrew Gunnerson 6272ca573d README.md: Improve documentation
* Clarify boot image partitions. It is no longer the case that only
  `boot` and `vendor_boot` are patched.
* Describe how to check if an OTA file is A/B.
* Remove mentions of signapk now that avbroot signs zips itself.
* Minor grammar changes.

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-06 23:39:05 -05:00
Andrew Gunnerson 806d8117f0 Perform all OTA signing ourselves
With this commit, avbroot now performs the entire OTA signing process
itself. This removes the 4 full .zip builds needed for signing before,
which means that avbroot can now do the full patching process in a
single pass.

Since signapk is no longer needed, the java dependency has been dropped.
This also means that avbroot no longer depends on glibc-based Linux
distros, which was the case before due to signapk's conscrypt
dependency.

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-02-01 22:29:01 -05:00
Andrew Gunnerson 9c52dbd8f9 README.md: Clarify that only Linux is supported
Issue: #15

Signed-off-by: Andrew Gunnerson <accounts+github@chiller3.com>
2023-01-28 16:24:12 -05:00
Andrew Gunnerson 15c951e320 README.md: Add note about locking/unlocking the bootloader triggering a data wipe
Issue: #7

Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-12-03 18:44:14 -05:00
Andrew Gunnerson d0373470b4 Merge pull request #6 from chenxiaolong/old
Add support for older Pixel devices
2022-11-28 14:34:41 -05:00
Andrew Gunnerson c83b8f5b17 Add support for older Pixel devices
* Apply OTA certificate patch to the boot image if no `vendor_boot`
  image exists.
* Only manually decompress ramdisk cpio archives if the boot image
  header version is 4. `magiskboot` automatically decompresses older
  header versions.

Fixes: #5

Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-11-27 17:12:11 -05:00
tnagorran 2edb25af31 Update README.md 2022-11-02 15:16:34 +03:00
Andrew Gunnerson 7b697b8daf README.md: python3-protobuf is also required
Issue: #2

Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-10-24 22:08:38 -04:00
Andrew Gunnerson df344bdf84 README.md: Add documentation about git submodule and system dependencies
Issue: #2

Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-10-24 10:38:48 -04:00
Andrew Gunnerson 1ce72c2513 README.md: Add note about Pixel 7 Pro compatibility
Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-10-13 17:27:16 -04:00
Andrew Gunnerson ba7109cc43 Add clearotacerts Magisk module to intentionally make A/B OTAs fail
Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-07-06 17:16:39 -04:00
Andrew Gunnerson e638463fdf README.md: Clarify what devices are supported
Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-07-02 16:26:09 -04:00
Andrew Gunnerson 985325d26c Switch to OTA patching
This is more secure and reliable compared to forcibly enabling fastbootd
in recovery. All of the normal AVB and OTA update flows are preserved,
except with the user's custom keys.

Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-07-02 16:17:13 -04:00
Andrew Gunnerson b87178b628 Initial commit
Signed-off-by: Andrew Gunnerson <chillermillerlong@hotmail.com>
2022-06-25 19:14:20 -04:00