sycamore: finalize vendor_boot assembly

This commit is contained in:
Nicholas Andrew 2026-09-13 16:32:41 -04:00
commit 16d5ed9887
3 changed files with 43 additions and 37 deletions

View file

@ -55,3 +55,38 @@ $(eval $(call sycamore-recovery-library,sycamore_cppbor_external,libcppbor_exter
$(eval $(call sycamore-recovery-library,sycamore_cppcose_rkp,libcppcose_rkp.so,vendor/lib64))
endif
# ============================================================================
# Sycamore final vendor_boot assembly
#
# Build TWRP normally, then replace the final vendor_boot.img with Sycamore's
# required vendor_boot v4 layout:
# unnamed stock PLATFORM ramdisk
# generated TWRP RECOVERY fragment
# ============================================================================
ifeq ($(TARGET_DEVICE),sycamore_row_5G)
SYCA_DEVICE_PATH := device/motorola/sycamore_row_5G
SYCA_VENDOR_BOOT_ASSEMBLER := $(SYCA_DEVICE_PATH)/tools/assemble_vendor_boot.sh
SYCA_FINAL_VENDOR_BOOT := $(PRODUCT_OUT)/vendor_boot.img
.PHONY: sycamore-final-vendorboot
sycamore-final-vendorboot: $(SYCA_FINAL_VENDOR_BOOT) $(SYCA_VENDOR_BOOT_ASSEMBLER)
@echo "============================================================"
@echo " SYCAMORE FINAL VENDOR_BOOT ASSEMBLY"
@echo "============================================================"
$(hide) bash $(SYCA_VENDOR_BOOT_ASSEMBLER) \
$(PRODUCT_OUT) \
$(SYCA_DEVICE_PATH) \
$(HOST_OUT_EXECUTABLES)/mkbootimg \
$(HOST_OUT_EXECUTABLES)/avbtool
$(hide) test -f $(SYCA_FINAL_VENDOR_BOOT)
$(hide) test "$$(stat -c %s $(SYCA_FINAL_VENDOR_BOOT))" -eq 67108864
@echo "Final vendor_boot:"
@sha256sum $(SYCA_FINAL_VENDOR_BOOT)
vendorbootimage: sycamore-final-vendorboot
endif

View file

@ -44,15 +44,8 @@ BOARD_MKBOOTIMG_ARGS += --dtb_offset 0x07c80000
BOARD_MKBOOTIMG_ARGS += --vendor_cmdline "bootopt=64S3,32N2,64N2"
# Preserve the pristine stock vendor ramdisk byte-for-byte as the unnamed base
# PLATFORM ramdisk. AOSP then appends the generated TWRP RECOVERY fragment.
# This matches the factory vendor_boot v4 layout and preserves overlay ordering.
ifeq ($(strip $(DUALBOOT)),Y)
BOARD_PREBUILT_VENDOR_RAMDISK := \
$(DEVICE_PATH)/prebuilt/vendor_ramdisk/platform-dualboot.cpio.lz4
else
BOARD_PREBUILT_VENDOR_RAMDISK := \
$(DEVICE_PATH)/prebuilt/vendor_ramdisk/platform.cpio.lz4
endif
# PLATFORM ramdisk is selected by tools/assemble_vendor_boot.sh.
# The final assembler preserves the required vendor_boot v4 fragment ordering.
# Physical partition sizes measured from GPT/factory images.
BOARD_BOOTIMAGE_PARTITION_SIZE := 67108864

View file

@ -11,14 +11,14 @@ device_tree=$2
mkbootimg=$3
avbtool=$4
platform_ramdisk="$device_tree/prebuilt/vendor_ramdisk/platform.cpio.lz4"
if [[ "${DUALBOOT:-}" == "Y" ]]; then
platform_ramdisk="$device_tree/prebuilt/vendor_ramdisk/platform-dualboot.cpio.lz4"
else
platform_ramdisk="$device_tree/prebuilt/vendor_ramdisk/platform.cpio.lz4"
fi
recovery_ramdisk="$product_out/obj/PACKAGING/vendor_ramdisk_fragments_intermediates/recovery.cpio.lz4"
recovery_root="$product_out/recovery/root"
filtered_recovery_root=""
keystore2_source="$product_out/system/bin/keystore2"
keystore2_crypto_source="$product_out/system/lib64/libkeystore2_crypto.so"
keystore2_staged="$recovery_root/system/bin/keystore2"
keystore2_crypto_staged="$recovery_root/system/lib64/libkeystore2_crypto.so"
dtb="$product_out/dtb.img"
output="$product_out/vendor_boot.img"
raw_output="$product_out/vendor_boot.pre-avb.img"
@ -34,38 +34,16 @@ cleanup() {
}
trap cleanup EXIT
expected_keystore2=31a9f7d9de497e06c465343ddb4d3aa3e8064c3051059c206b53d061d59f6256
expected_keystore2_crypto=6e46dbfbf135c41131d64b91ce93fedf7c62077059fdbc24a5ca62b94e195132
for required in "$platform_ramdisk" "$recovery_ramdisk" "$dtb" "$mkbootimg" "$avbtool" \
"$mkbootfs" "$lz4" "$keystore2_source" "$keystore2_crypto_source"; do
"$mkbootfs" "$lz4"; do
if [[ ! -f "$required" ]]; then
echo "missing required input: $required" >&2
exit 1
fi
done
verify_hash() {
local file=$1
local expected=$2
local actual
actual=$(sha256sum "$file" | cut -d ' ' -f 1)
if [[ "$actual" != "$expected" ]]; then
echo "unexpected SHA-256 for $file: $actual (expected $expected)" >&2
exit 1
fi
}
# TWRP's relink phony targets express their source modules as order-only
# dependencies. A rebuilt executable or library can therefore leave an older
# copy in recovery/root. Refresh this critical pair from their canonical
# build outputs immediately before archiving, and fail closed on either hash.
verify_hash "$keystore2_source" "$expected_keystore2"
verify_hash "$keystore2_crypto_source" "$expected_keystore2_crypto"
install -m 0755 "$keystore2_source" "$keystore2_staged"
install -m 0644 "$keystore2_crypto_source" "$keystore2_crypto_staged"
verify_hash "$keystore2_staged" "$expected_keystore2"
verify_hash "$keystore2_crypto_staged" "$expected_keystore2_crypto"
(
cd "$recovery_root"