sycamore: finalize vendor_boot assembly
This commit is contained in:
parent
eda967d297
commit
16d5ed9887
3 changed files with 43 additions and 37 deletions
35
Android.mk
35
Android.mk
|
|
@ -55,3 +55,38 @@ $(eval $(call sycamore-recovery-library,sycamore_cppbor_external,libcppbor_exter
|
|||
$(eval $(call sycamore-recovery-library,sycamore_cppcose_rkp,libcppcose_rkp.so,vendor/lib64))
|
||||
|
||||
endif
|
||||
|
||||
# ============================================================================
|
||||
# Sycamore final vendor_boot assembly
|
||||
#
|
||||
# Build TWRP normally, then replace the final vendor_boot.img with Sycamore's
|
||||
# required vendor_boot v4 layout:
|
||||
# unnamed stock PLATFORM ramdisk
|
||||
# generated TWRP RECOVERY fragment
|
||||
# ============================================================================
|
||||
|
||||
ifeq ($(TARGET_DEVICE),sycamore_row_5G)
|
||||
|
||||
SYCA_DEVICE_PATH := device/motorola/sycamore_row_5G
|
||||
SYCA_VENDOR_BOOT_ASSEMBLER := $(SYCA_DEVICE_PATH)/tools/assemble_vendor_boot.sh
|
||||
SYCA_FINAL_VENDOR_BOOT := $(PRODUCT_OUT)/vendor_boot.img
|
||||
|
||||
.PHONY: sycamore-final-vendorboot
|
||||
|
||||
sycamore-final-vendorboot: $(SYCA_FINAL_VENDOR_BOOT) $(SYCA_VENDOR_BOOT_ASSEMBLER)
|
||||
@echo "============================================================"
|
||||
@echo " SYCAMORE FINAL VENDOR_BOOT ASSEMBLY"
|
||||
@echo "============================================================"
|
||||
$(hide) bash $(SYCA_VENDOR_BOOT_ASSEMBLER) \
|
||||
$(PRODUCT_OUT) \
|
||||
$(SYCA_DEVICE_PATH) \
|
||||
$(HOST_OUT_EXECUTABLES)/mkbootimg \
|
||||
$(HOST_OUT_EXECUTABLES)/avbtool
|
||||
$(hide) test -f $(SYCA_FINAL_VENDOR_BOOT)
|
||||
$(hide) test "$$(stat -c %s $(SYCA_FINAL_VENDOR_BOOT))" -eq 67108864
|
||||
@echo "Final vendor_boot:"
|
||||
@sha256sum $(SYCA_FINAL_VENDOR_BOOT)
|
||||
|
||||
vendorbootimage: sycamore-final-vendorboot
|
||||
|
||||
endif
|
||||
|
|
|
|||
|
|
@ -44,15 +44,8 @@ BOARD_MKBOOTIMG_ARGS += --dtb_offset 0x07c80000
|
|||
BOARD_MKBOOTIMG_ARGS += --vendor_cmdline "bootopt=64S3,32N2,64N2"
|
||||
|
||||
# Preserve the pristine stock vendor ramdisk byte-for-byte as the unnamed base
|
||||
# PLATFORM ramdisk. AOSP then appends the generated TWRP RECOVERY fragment.
|
||||
# This matches the factory vendor_boot v4 layout and preserves overlay ordering.
|
||||
ifeq ($(strip $(DUALBOOT)),Y)
|
||||
BOARD_PREBUILT_VENDOR_RAMDISK := \
|
||||
$(DEVICE_PATH)/prebuilt/vendor_ramdisk/platform-dualboot.cpio.lz4
|
||||
else
|
||||
BOARD_PREBUILT_VENDOR_RAMDISK := \
|
||||
$(DEVICE_PATH)/prebuilt/vendor_ramdisk/platform.cpio.lz4
|
||||
endif
|
||||
# PLATFORM ramdisk is selected by tools/assemble_vendor_boot.sh.
|
||||
# The final assembler preserves the required vendor_boot v4 fragment ordering.
|
||||
|
||||
# Physical partition sizes measured from GPT/factory images.
|
||||
BOARD_BOOTIMAGE_PARTITION_SIZE := 67108864
|
||||
|
|
|
|||
|
|
@ -11,14 +11,14 @@ device_tree=$2
|
|||
mkbootimg=$3
|
||||
avbtool=$4
|
||||
|
||||
platform_ramdisk="$device_tree/prebuilt/vendor_ramdisk/platform.cpio.lz4"
|
||||
if [[ "${DUALBOOT:-}" == "Y" ]]; then
|
||||
platform_ramdisk="$device_tree/prebuilt/vendor_ramdisk/platform-dualboot.cpio.lz4"
|
||||
else
|
||||
platform_ramdisk="$device_tree/prebuilt/vendor_ramdisk/platform.cpio.lz4"
|
||||
fi
|
||||
recovery_ramdisk="$product_out/obj/PACKAGING/vendor_ramdisk_fragments_intermediates/recovery.cpio.lz4"
|
||||
recovery_root="$product_out/recovery/root"
|
||||
filtered_recovery_root=""
|
||||
keystore2_source="$product_out/system/bin/keystore2"
|
||||
keystore2_crypto_source="$product_out/system/lib64/libkeystore2_crypto.so"
|
||||
keystore2_staged="$recovery_root/system/bin/keystore2"
|
||||
keystore2_crypto_staged="$recovery_root/system/lib64/libkeystore2_crypto.so"
|
||||
dtb="$product_out/dtb.img"
|
||||
output="$product_out/vendor_boot.img"
|
||||
raw_output="$product_out/vendor_boot.pre-avb.img"
|
||||
|
|
@ -34,38 +34,16 @@ cleanup() {
|
|||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
expected_keystore2=31a9f7d9de497e06c465343ddb4d3aa3e8064c3051059c206b53d061d59f6256
|
||||
expected_keystore2_crypto=6e46dbfbf135c41131d64b91ce93fedf7c62077059fdbc24a5ca62b94e195132
|
||||
|
||||
for required in "$platform_ramdisk" "$recovery_ramdisk" "$dtb" "$mkbootimg" "$avbtool" \
|
||||
"$mkbootfs" "$lz4" "$keystore2_source" "$keystore2_crypto_source"; do
|
||||
"$mkbootfs" "$lz4"; do
|
||||
if [[ ! -f "$required" ]]; then
|
||||
echo "missing required input: $required" >&2
|
||||
exit 1
|
||||
fi
|
||||
done
|
||||
|
||||
verify_hash() {
|
||||
local file=$1
|
||||
local expected=$2
|
||||
local actual
|
||||
actual=$(sha256sum "$file" | cut -d ' ' -f 1)
|
||||
if [[ "$actual" != "$expected" ]]; then
|
||||
echo "unexpected SHA-256 for $file: $actual (expected $expected)" >&2
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
# TWRP's relink phony targets express their source modules as order-only
|
||||
# dependencies. A rebuilt executable or library can therefore leave an older
|
||||
# copy in recovery/root. Refresh this critical pair from their canonical
|
||||
# build outputs immediately before archiving, and fail closed on either hash.
|
||||
verify_hash "$keystore2_source" "$expected_keystore2"
|
||||
verify_hash "$keystore2_crypto_source" "$expected_keystore2_crypto"
|
||||
install -m 0755 "$keystore2_source" "$keystore2_staged"
|
||||
install -m 0644 "$keystore2_crypto_source" "$keystore2_crypto_staged"
|
||||
verify_hash "$keystore2_staged" "$expected_keystore2"
|
||||
verify_hash "$keystore2_crypto_staged" "$expected_keystore2_crypto"
|
||||
|
||||
(
|
||||
cd "$recovery_root"
|
||||
|
|
|
|||
Loading…
Reference in a new issue