• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (C) 2008 The Android Open Source Project
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *  * Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  *  * Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in
12  *    the documentation and/or other materials provided with the
13  *    distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19  * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 
29 #include "fastboot.h"
30 
31 #include <errno.h>
32 #include <fcntl.h>
33 #include <getopt.h>
34 #include <inttypes.h>
35 #include <limits.h>
36 #include <stdint.h>
37 #include <stdio.h>
38 #include <stdlib.h>
39 #include <string.h>
40 #include <sys/stat.h>
41 #include <sys/time.h>
42 #include <sys/types.h>
43 #include <unistd.h>
44 
45 #include <chrono>
46 #include <functional>
47 #include <iostream>
48 #include <memory>
49 #include <regex>
50 #include <string>
51 #include <thread>
52 #include <utility>
53 #include <vector>
54 
55 #include <android-base/endian.h>
56 #include <android-base/file.h>
57 #include <android-base/logging.h>
58 #include <android-base/macros.h>
59 #include <android-base/parseint.h>
60 #include <android-base/parsenetaddress.h>
61 #include <android-base/stringprintf.h>
62 #include <android-base/strings.h>
63 #include <android-base/unique_fd.h>
64 #include <build/version.h>
65 #include <libavb/libavb.h>
66 #include <liblp/liblp.h>
67 #include <liblp/super_layout_builder.h>
68 #include <platform_tools_version.h>
69 #include <sparse/sparse.h>
70 #include <ziparchive/zip_archive.h>
71 
72 #include "bootimg_utils.h"
73 #include "constants.h"
74 #include "diagnose_usb.h"
75 #include "fastboot_driver.h"
76 #include "fastboot_driver_interface.h"
77 #include "fs.h"
78 #include "storage.h"
79 #include "task.h"
80 #include "tcp.h"
81 #include "transport.h"
82 #include "udp.h"
83 #include "usb.h"
84 #include "util.h"
85 #include "vendor_boot_img_utils.h"
86 
87 using android::base::borrowed_fd;
88 using android::base::ReadFully;
89 using android::base::Split;
90 using android::base::Trim;
91 using android::base::unique_fd;
92 using namespace std::placeholders;
93 
94 #define FASTBOOT_INFO_VERSION 1
95 
96 static const char* serial = nullptr;
97 
98 static bool g_long_listing = false;
99 // Don't resparse files in too-big chunks.
100 // libsparse will support INT_MAX, but this results in large allocations, so
101 // let's keep it at 1GB to avoid memory pressure on the host.
102 static constexpr int64_t RESPARSE_LIMIT = 1 * 1024 * 1024 * 1024;
103 static int64_t target_sparse_limit = -1;
104 
105 static unsigned g_base_addr = 0x10000000;
106 static boot_img_hdr_v2 g_boot_img_hdr = {};
107 static std::string g_cmdline;
108 static std::string g_dtb_path;
109 
110 static bool g_disable_verity = false;
111 static bool g_disable_verification = false;
112 
113 fastboot::FastBootDriver* fb = nullptr;
114 
115 static std::vector<Image> images = {
116         // clang-format off
117     { "boot",     "boot.img",         "boot.sig",     "boot",     false, ImageType::BootCritical },
118     { "bootloader",
119                   "bootloader.img",   "",             "bootloader",
120                                                                   true,  ImageType::Extra },
121     { "init_boot",
122                   "init_boot.img",    "init_boot.sig",
123                                                       "init_boot",
124                                                                   true,  ImageType::BootCritical },
125     { "",    "boot_other.img",   "boot.sig",     "boot",     true,  ImageType::Normal },
126     { "cache",    "cache.img",        "cache.sig",    "cache",    true,  ImageType::Extra },
127     { "dtbo",     "dtbo.img",         "dtbo.sig",     "dtbo",     true,  ImageType::BootCritical },
128     { "dts",      "dt.img",           "dt.sig",       "dts",      true,  ImageType::BootCritical },
129     { "odm",      "odm.img",          "odm.sig",      "odm",      true,  ImageType::Normal },
130     { "odm_dlkm", "odm_dlkm.img",     "odm_dlkm.sig", "odm_dlkm", true,  ImageType::Normal },
131     { "product",  "product.img",      "product.sig",  "product",  true,  ImageType::Normal },
132     { "pvmfw",    "pvmfw.img",        "pvmfw.sig",    "pvmfw",    true,  ImageType::BootCritical },
133     { "radio",    "radio.img",        "",             "radio",    true,  ImageType::Extra },
134     { "recovery", "recovery.img",     "recovery.sig", "recovery", true,  ImageType::BootCritical },
135     { "super",    "super.img",        "super.sig",    "super",    true,  ImageType::Extra },
136     { "system",   "system.img",       "system.sig",   "system",   false, ImageType::Normal },
137     { "system_dlkm",
138                   "system_dlkm.img",  "system_dlkm.sig",
139                                                       "system_dlkm",
140                                                                   true,  ImageType::Normal },
141     { "system_ext",
142                   "system_ext.img",   "system_ext.sig",
143                                                       "system_ext",
144                                                                   true,  ImageType::Normal },
145     { "",    "system_other.img", "system.sig",   "system",   true,  ImageType::Normal },
146     { "userdata", "userdata.img",     "userdata.sig", "userdata", true,  ImageType::Extra },
147     { "vbmeta",   "vbmeta.img",       "vbmeta.sig",   "vbmeta",   true,  ImageType::BootCritical },
148     { "vbmeta_system",
149                   "vbmeta_system.img",
150                                       "vbmeta_system.sig",
151                                                       "vbmeta_system",
152                                                                   true,  ImageType::BootCritical },
153     { "vbmeta_vendor",
154                   "vbmeta_vendor.img",
155                                       "vbmeta_vendor.sig",
156                                                       "vbmeta_vendor",
157                                                                   true,  ImageType::BootCritical },
158     { "vendor",   "vendor.img",       "vendor.sig",   "vendor",   true,  ImageType::Normal },
159     { "vendor_boot",
160                   "vendor_boot.img",  "vendor_boot.sig",
161                                                       "vendor_boot",
162                                                                   true,  ImageType::BootCritical },
163     { "vendor_dlkm",
164                   "vendor_dlkm.img",  "vendor_dlkm.sig",
165                                                       "vendor_dlkm",
166                                                                   true,  ImageType::Normal },
167     { "vendor_kernel_boot",
168                   "vendor_kernel_boot.img",
169                                       "vendor_kernel_boot.sig",
170                                                       "vendor_kernel_boot",
171                                                                   true,  ImageType::BootCritical },
172     { "",    "vendor_other.img", "vendor.sig",   "vendor",   true,  ImageType::Normal },
173         // clang-format on
174 };
175 
get_android_product_out()176 char* get_android_product_out() {
177     char* dir = getenv("ANDROID_PRODUCT_OUT");
178     if (dir == nullptr || dir[0] == '\0') {
179         return nullptr;
180     }
181     return dir;
182 }
183 
find_item_given_name(const std::string & img_name)184 static std::string find_item_given_name(const std::string& img_name) {
185     char* dir = get_android_product_out();
186     if (!dir) {
187         die("ANDROID_PRODUCT_OUT not set");
188     }
189     return std::string(dir) + "/" + img_name;
190 }
191 
find_item(const std::string & item)192 std::string find_item(const std::string& item) {
193     for (size_t i = 0; i < images.size(); ++i) {
194         if (!images[i].nickname.empty() && item == images[i].nickname) {
195             return find_item_given_name(images[i].img_name);
196         }
197     }
198 
199     fprintf(stderr, "unknown partition '%s'\n", item.c_str());
200     return "";
201 }
202 
203 double last_start_time;
204 
Status(const std::string & message)205 static void Status(const std::string& message) {
206     if (!message.empty()) {
207         static constexpr char kStatusFormat[] = "%-50s ";
208         fprintf(stderr, kStatusFormat, message.c_str());
209     }
210     last_start_time = now();
211 }
212 
Epilog(int status)213 static void Epilog(int status) {
214     if (status) {
215         fprintf(stderr, "FAILED (%s)\n", fb->Error().c_str());
216         die("Command failed");
217     } else {
218         double split = now();
219         fprintf(stderr, "OKAY [%7.3fs]\n", (split - last_start_time));
220     }
221 }
222 
InfoMessage(const std::string & info)223 static void InfoMessage(const std::string& info) {
224     fprintf(stderr, "(bootloader) %s\n", info.c_str());
225 }
226 
TextMessage(const std::string & text)227 static void TextMessage(const std::string& text) {
228     fprintf(stderr, "%s", text.c_str());
229 }
230 
ReadFileToVector(const std::string & file,std::vector<char> * out)231 bool ReadFileToVector(const std::string& file, std::vector<char>* out) {
232     out->clear();
233 
234     unique_fd fd(TEMP_FAILURE_RETRY(open(file.c_str(), O_RDONLY | O_CLOEXEC | O_BINARY)));
235     if (fd == -1) {
236         return false;
237     }
238 
239     out->resize(get_file_size(fd));
240     return ReadFully(fd, out->data(), out->size());
241 }
242 
match_fastboot_with_serial(usb_ifc_info * info,const char * local_serial)243 static int match_fastboot_with_serial(usb_ifc_info* info, const char* local_serial) {
244     if (info->ifc_class != 0xff || info->ifc_subclass != 0x42 || info->ifc_protocol != 0x03) {
245         return -1;
246     }
247 
248     // require matching serial number or device path if requested
249     // at the command line with the -s option.
250     if (local_serial && (strcmp(local_serial, info->serial_number) != 0 &&
251                          strcmp(local_serial, info->device_path) != 0))
252         return -1;
253     return 0;
254 }
255 
match_fastboot(const char * local_serial=serial)256 static ifc_match_func match_fastboot(const char* local_serial = serial) {
257     return [local_serial](usb_ifc_info* info) -> int {
258         return match_fastboot_with_serial(info, local_serial);
259     };
260 }
261 
262 // output compatible with "adb devices"
PrintDevice(const char * local_serial,const char * status=nullptr,const char * details=nullptr)263 static void PrintDevice(const char* local_serial, const char* status = nullptr,
264                         const char* details = nullptr) {
265     if (local_serial == nullptr || strlen(local_serial) == 0) {
266         return;
267     }
268 
269     if (g_long_listing) {
270         printf("%-22s", local_serial);
271     } else {
272         printf("%s\t", local_serial);
273     }
274 
275     if (status != nullptr && strlen(status) > 0) {
276         printf(" %s", status);
277     }
278 
279     if (g_long_listing) {
280         if (details != nullptr && strlen(details) > 0) {
281             printf(" %s", details);
282         }
283     }
284 
285     putchar('\n');
286 }
287 
list_devices_callback(usb_ifc_info * info)288 static int list_devices_callback(usb_ifc_info* info) {
289     if (match_fastboot_with_serial(info, nullptr) == 0) {
290         std::string serial = info->serial_number;
291         std::string interface = info->interface;
292         if (interface.empty()) {
293             interface = "fastboot";
294         }
295         if (!info->writable) {
296             serial = UsbNoPermissionsShortHelpText();
297         }
298         if (!serial[0]) {
299             serial = "????????????";
300         }
301 
302         PrintDevice(serial.c_str(), interface.c_str(), info->device_path);
303     }
304 
305     return -1;
306 }
307 
ParseNetworkSerial(const std::string & serial)308 Result<NetworkSerial, FastbootError> ParseNetworkSerial(const std::string& serial) {
309     Socket::Protocol protocol;
310     const char* net_address = nullptr;
311     int port = 0;
312 
313     if (android::base::StartsWith(serial, "tcp:")) {
314         protocol = Socket::Protocol::kTcp;
315         net_address = serial.c_str() + strlen("tcp:");
316         port = tcp::kDefaultPort;
317     } else if (android::base::StartsWith(serial, "udp:")) {
318         protocol = Socket::Protocol::kUdp;
319         net_address = serial.c_str() + strlen("udp:");
320         port = udp::kDefaultPort;
321     } else {
322         return Error<FastbootError>(FastbootError::Type::NETWORK_SERIAL_WRONG_PREFIX)
323                << "protocol prefix ('tcp:' or 'udp:') is missed: " << serial << ". "
324                << "Expected address format:\n"
325                << "<protocol>:<address>:<port> (tcp:localhost:5554)";
326     }
327 
328     std::string error;
329     std::string host;
330     if (!android::base::ParseNetAddress(net_address, &host, &port, nullptr, &error)) {
331         return Error<FastbootError>(FastbootError::Type::NETWORK_SERIAL_WRONG_ADDRESS)
332                << "invalid network address '" << net_address << "': " << error;
333     }
334 
335     return NetworkSerial{protocol, host, port};
336 }
337 
338 // Opens a new Transport connected to the particular device.
339 // arguments:
340 //
341 // local_serial - device to connect (can be a network or usb serial name)
342 // wait_for_device - flag indicates whether we need to wait for device
343 // announce - flag indicates whether we need to print error to stdout in case
344 // we cannot connect to the device
345 //
346 // The returned Transport is a singleton, so multiple calls to this function will return the same
347 // object, and the caller should not attempt to delete the returned Transport.
open_device(const char * local_serial,bool wait_for_device=true,bool announce=true)348 static std::unique_ptr<Transport> open_device(const char* local_serial, bool wait_for_device = true,
349                                               bool announce = true) {
350     const Result<NetworkSerial, FastbootError> network_serial = ParseNetworkSerial(local_serial);
351 
352     std::unique_ptr<Transport> transport;
353     while (true) {
354         if (network_serial.ok()) {
355             std::string error;
356             if (network_serial->protocol == Socket::Protocol::kTcp) {
357                 transport = tcp::Connect(network_serial->address, network_serial->port, &error);
358             } else if (network_serial->protocol == Socket::Protocol::kUdp) {
359                 transport = udp::Connect(network_serial->address, network_serial->port, &error);
360             }
361 
362             if (!transport && announce) {
363                 LOG(ERROR) << "error: " << error;
364             }
365         } else if (network_serial.error().code() ==
366                    FastbootError::Type::NETWORK_SERIAL_WRONG_PREFIX) {
367             // WRONG_PREFIX is special because it happens when user wants to communicate with USB
368             // device
369             transport = usb_open(match_fastboot(local_serial));
370         } else {
371             Expect(network_serial);
372         }
373 
374         if (transport) {
375             return transport;
376         }
377 
378         if (!wait_for_device) {
379             return transport;
380         }
381 
382         if (announce) {
383             announce = false;
384             LOG(ERROR) << "< waiting for " << local_serial << ">";
385         }
386         std::this_thread::sleep_for(std::chrono::seconds(1));
387     }
388 }
389 
NetworkDeviceConnected(bool print=false)390 static std::unique_ptr<Transport> NetworkDeviceConnected(bool print = false) {
391     std::unique_ptr<Transport> transport;
392     std::unique_ptr<Transport> result;
393 
394     ConnectedDevicesStorage storage;
395     std::set<std::string> devices;
396     if (storage.Exists()) {
397         FileLock lock = storage.Lock();
398         devices = storage.ReadDevices(lock);
399     }
400 
401     for (const std::string& device : devices) {
402         transport = open_device(device.c_str(), false, false);
403 
404         if (print) {
405             PrintDevice(device.c_str(), transport ? "fastboot" : "offline");
406         }
407 
408         if (transport) {
409             result = std::move(transport);
410         }
411     }
412 
413     return result;
414 }
415 
416 // Detects the fastboot connected device to open a new Transport.
417 // Detecting logic:
418 //
419 // if serial is provided - try to connect to this particular usb/network device
420 // othervise:
421 // 1. Check connected usb devices and return the last connected one
422 // 2. Check connected network devices and return the last connected one
423 // 2. If nothing is connected - wait for any device by repeating p. 1 and 2
424 //
425 // The returned Transport is a singleton, so multiple calls to this function will return the same
426 // object, and the caller should not attempt to delete the returned Transport.
open_device()427 static std::unique_ptr<Transport> open_device() {
428     if (serial != nullptr) {
429         return open_device(serial);
430     }
431 
432     bool announce = true;
433     std::unique_ptr<Transport> transport;
434     while (true) {
435         transport = usb_open(match_fastboot(nullptr));
436         if (transport) {
437             return transport;
438         }
439 
440         transport = NetworkDeviceConnected();
441         if (transport) {
442             return transport;
443         }
444 
445         if (announce) {
446             announce = false;
447             LOG(ERROR) << "< waiting for any device >";
448         }
449         std::this_thread::sleep_for(std::chrono::seconds(1));
450     }
451 
452     return transport;
453 }
454 
Connect(int argc,char * argv[])455 static int Connect(int argc, char* argv[]) {
456     if (argc != 1) {
457         LOG(FATAL) << "connect command requires to receive only 1 argument. Usage:" << std::endl
458                    << "fastboot connect [tcp:|udp:host:port]";
459     }
460 
461     const char* local_serial = *argv;
462     Expect(ParseNetworkSerial(local_serial));
463 
464     if (!open_device(local_serial, false)) {
465         return 1;
466     }
467 
468     ConnectedDevicesStorage storage;
469     {
470         FileLock lock = storage.Lock();
471         std::set<std::string> devices = storage.ReadDevices(lock);
472         devices.insert(local_serial);
473         storage.WriteDevices(lock, devices);
474     }
475 
476     return 0;
477 }
478 
Disconnect(const char * local_serial)479 static int Disconnect(const char* local_serial) {
480     Expect(ParseNetworkSerial(local_serial));
481 
482     ConnectedDevicesStorage storage;
483     {
484         FileLock lock = storage.Lock();
485         std::set<std::string> devices = storage.ReadDevices(lock);
486         devices.erase(local_serial);
487         storage.WriteDevices(lock, devices);
488     }
489 
490     return 0;
491 }
492 
Disconnect()493 static int Disconnect() {
494     ConnectedDevicesStorage storage;
495     {
496         FileLock lock = storage.Lock();
497         storage.Clear(lock);
498     }
499 
500     return 0;
501 }
502 
Disconnect(int argc,char * argv[])503 static int Disconnect(int argc, char* argv[]) {
504     switch (argc) {
505         case 0: {
506             return Disconnect();
507         }
508         case 1: {
509             return Disconnect(*argv);
510         }
511         default:
512             LOG(FATAL) << "disconnect command can receive only 0 or 1 arguments. Usage:"
513                        << std::endl
514                        << "fastboot disconnect # disconnect all devices" << std::endl
515                        << "fastboot disconnect [tcp:|udp:host:port] # disconnect device";
516     }
517 
518     return 0;
519 }
520 
list_devices()521 static void list_devices() {
522     // We don't actually open a USB device here,
523     // just getting our callback called so we can
524     // list all the connected devices.
525     usb_open(list_devices_callback);
526     NetworkDeviceConnected(/* print */ true);
527 }
528 
syntax_error(const char * fmt,...)529 void syntax_error(const char* fmt, ...) {
530     fprintf(stderr, "fastboot: usage: ");
531 
532     va_list ap;
533     va_start(ap, fmt);
534     vfprintf(stderr, fmt, ap);
535     va_end(ap);
536 
537     fprintf(stderr, "\n");
538     exit(1);
539 }
540 
show_help()541 static int show_help() {
542     // clang-format off
543     fprintf(stdout,
544 //                    1         2         3         4         5         6         7         8
545 //           12345678901234567890123456789012345678901234567890123456789012345678901234567890
546             "usage: fastboot [OPTION...] COMMAND...\n"
547             "\n"
548             "flashing:\n"
549             " update ZIP                 Flash all partitions from an update.zip package.\n"
550             " flashall                   Flash all partitions from $ANDROID_PRODUCT_OUT.\n"
551             "                            On A/B devices, flashed slot is set as active.\n"
552             "                            Secondary images may be flashed to inactive slot.\n"
553             " flash PARTITION [FILENAME] Flash given partition, using the image from\n"
554             "                            $ANDROID_PRODUCT_OUT if no filename is given.\n"
555             " flash vendor_boot:RAMDISK [FILENAME]\n"
556             "                            Flash vendor_boot ramdisk, fetching the existing\n"
557             "                            vendor_boot image and repackaging it with the new\n"
558             "                            ramdisk.\n"
559             " --dtb DTB                  If set with flash vendor_boot:RAMDISK, then\n"
560             "                            update the vendor_boot image with provided DTB.\n"
561             "\n"
562             "basics:\n"
563             " devices [-l]               List devices in bootloader (-l: with device paths).\n"
564             " getvar NAME                Display given bootloader variable.\n"
565             " reboot [bootloader]        Reboot device.\n"
566             "\n"
567             "locking/unlocking:\n"
568             " flashing lock|unlock       Lock/unlock partitions for flashing\n"
569             " flashing lock_critical|unlock_critical\n"
570             "                            Lock/unlock 'critical' bootloader partitions.\n"
571             " flashing get_unlock_ability\n"
572             "                            Check whether unlocking is allowed (1) or not(0).\n"
573             "\n"
574             "advanced:\n"
575             " erase PARTITION            Erase a flash partition.\n"
576             " format[:FS_TYPE[:SIZE]] PARTITION\n"
577             "                            Format a flash partition.\n"
578             " set_active SLOT            Set the active slot.\n"
579             " oem [COMMAND...]           Execute OEM-specific command.\n"
580             " gsi wipe|disable|status    Wipe, disable or show status of a GSI installation\n"
581             "                            (fastbootd only).\n"
582             " wipe-super [SUPER_EMPTY]   Wipe the super partition. This will reset it to\n"
583             "                            contain an empty set of default dynamic partitions.\n"
584             " create-logical-partition NAME SIZE\n"
585             "                            Create a logical partition with the given name and\n"
586             "                            size, in the super partition.\n"
587             " delete-logical-partition NAME\n"
588             "                            Delete a logical partition with the given name.\n"
589             " resize-logical-partition NAME SIZE\n"
590             "                            Change the size of the named logical partition.\n"
591             " snapshot-update cancel     On devices that support snapshot-based updates, cancel\n"
592             "                            an in-progress update. This may make the device\n"
593             "                            unbootable until it is reflashed.\n"
594             " snapshot-update merge      On devices that support snapshot-based updates, finish\n"
595             "                            an in-progress update if it is in the \"merging\"\n"
596             "                            phase.\n"
597             " fetch PARTITION OUT_FILE   Fetch a partition image from the device."
598             "\n"
599             "boot image:\n"
600             " boot KERNEL [RAMDISK [SECOND]]\n"
601             "                            Download and boot kernel from RAM.\n"
602             " flash:raw PARTITION KERNEL [RAMDISK [SECOND]]\n"
603             "                            Create boot image and flash it.\n"
604             " --dtb DTB                  Specify path to DTB for boot image header version 2.\n"
605             " --cmdline CMDLINE          Override kernel command line.\n"
606             " --base ADDRESS             Set kernel base address (default: 0x10000000).\n"
607             " --kernel-offset            Set kernel offset (default: 0x00008000).\n"
608             " --ramdisk-offset           Set ramdisk offset (default: 0x01000000).\n"
609             " --tags-offset              Set tags offset (default: 0x00000100).\n"
610             " --dtb-offset               Set dtb offset (default: 0x01100000).\n"
611             " --page-size BYTES          Set flash page size (default: 2048).\n"
612             " --header-version VERSION   Set boot image header version.\n"
613             " --os-version MAJOR[.MINOR[.PATCH]]\n"
614             "                            Set boot image OS version (default: 0.0.0).\n"
615             " --os-patch-level YYYY-MM-DD\n"
616             "                            Set boot image OS security patch level.\n"
617             // TODO: still missing: `second_addr`, `name`, `id`, `recovery_dtbo_*`.
618             "\n"
619             // TODO: what device(s) used this? is there any documentation?
620             //" continue                               Continue with autoboot.\n"
621             //"\n"
622             "Android Things:\n"
623             " stage IN_FILE              Sends given file to stage for the next command.\n"
624             " get_staged OUT_FILE        Writes data staged by the last command to a file.\n"
625             "\n"
626             "options:\n"
627             " -w                         Wipe userdata.\n"
628             " -s SERIAL                  Specify a USB device.\n"
629             " -s tcp|udp:HOST[:PORT]     Specify a network device.\n"
630             " -S SIZE[K|M|G]             Break into sparse files no larger than SIZE.\n"
631             " --force                    Force a flash operation that may be unsafe.\n"
632             " --slot SLOT                Use SLOT; 'all' for both slots, 'other' for\n"
633             "                            non-current slot (default: current active slot).\n"
634             " --set-active[=SLOT]        Sets the active slot before rebooting.\n"
635             " --skip-secondary           Don't flash secondary slots in flashall/update.\n"
636             " --skip-reboot              Don't reboot device after flashing.\n"
637             " --disable-verity           Sets disable-verity when flashing vbmeta.\n"
638             " --disable-verification     Sets disable-verification when flashing vbmeta.\n"
639             " --disable-super-optimization\n"
640             "                            Disables optimizations on flashing super partition.\n"
641             " --exclude-dynamic-partitions\n"
642             "                            Excludes flashing of dynamic partitions.\n"
643             " --disable-fastboot-info    Will collects tasks from image list rather than \n"
644             "                            $OUT/fastboot-info.txt.\n"
645             " --fs-options=OPTION[,OPTION]\n"
646             "                            Enable filesystem features. OPTION supports casefold, projid, compress\n"
647             // TODO: remove --unbuffered?
648             " --unbuffered               Don't buffer input or output.\n"
649             " --verbose, -v              Verbose output.\n"
650             " --version                  Display version.\n"
651             " --help, -h                 Show this message.\n"
652         );
653     // clang-format on
654     return 0;
655 }
656 
LoadBootableImage(const std::string & kernel,const std::string & ramdisk,const std::string & second_stage)657 static std::vector<char> LoadBootableImage(const std::string& kernel, const std::string& ramdisk,
658                                            const std::string& second_stage) {
659     std::vector<char> kernel_data;
660     if (!ReadFileToVector(kernel, &kernel_data)) {
661         die("cannot load '%s': %s", kernel.c_str(), strerror(errno));
662     }
663 
664     // Is this actually a boot image?
665     if (kernel_data.size() < sizeof(boot_img_hdr_v3)) {
666         die("cannot load '%s': too short", kernel.c_str());
667     }
668     if (!memcmp(kernel_data.data(), BOOT_MAGIC, BOOT_MAGIC_SIZE)) {
669         if (!g_cmdline.empty()) {
670             bootimg_set_cmdline(reinterpret_cast<boot_img_hdr_v2*>(kernel_data.data()), g_cmdline);
671         }
672 
673         if (!ramdisk.empty()) die("cannot boot a boot.img *and* ramdisk");
674 
675         return kernel_data;
676     }
677 
678     std::vector<char> ramdisk_data;
679     if (!ramdisk.empty()) {
680         if (!ReadFileToVector(ramdisk, &ramdisk_data)) {
681             die("cannot load '%s': %s", ramdisk.c_str(), strerror(errno));
682         }
683     }
684 
685     std::vector<char> second_stage_data;
686     if (!second_stage.empty()) {
687         if (!ReadFileToVector(second_stage, &second_stage_data)) {
688             die("cannot load '%s': %s", second_stage.c_str(), strerror(errno));
689         }
690     }
691 
692     std::vector<char> dtb_data;
693     if (!g_dtb_path.empty()) {
694         if (g_boot_img_hdr.header_version != 2) {
695             die("Argument dtb not supported for boot image header version %d\n",
696                 g_boot_img_hdr.header_version);
697         }
698         if (!ReadFileToVector(g_dtb_path, &dtb_data)) {
699             die("cannot load '%s': %s", g_dtb_path.c_str(), strerror(errno));
700         }
701     }
702 
703     fprintf(stderr, "creating boot image...\n");
704 
705     std::vector<char> out;
706     mkbootimg(kernel_data, ramdisk_data, second_stage_data, dtb_data, g_base_addr, g_boot_img_hdr,
707               &out);
708 
709     if (!g_cmdline.empty()) {
710         bootimg_set_cmdline(reinterpret_cast<boot_img_hdr_v2*>(out.data()), g_cmdline);
711     }
712     fprintf(stderr, "creating boot image - %zu bytes\n", out.size());
713     return out;
714 }
715 
UnzipToMemory(ZipArchiveHandle zip,const std::string & entry_name,std::vector<char> * out)716 static bool UnzipToMemory(ZipArchiveHandle zip, const std::string& entry_name,
717                           std::vector<char>* out) {
718     ZipEntry64 zip_entry;
719     if (FindEntry(zip, entry_name, &zip_entry) != 0) {
720         fprintf(stderr, "archive does not contain '%s'\n", entry_name.c_str());
721         return false;
722     }
723 
724     if (zip_entry.uncompressed_length > std::numeric_limits<size_t>::max()) {
725         die("entry '%s' is too large: %" PRIu64, entry_name.c_str(), zip_entry.uncompressed_length);
726     }
727     out->resize(zip_entry.uncompressed_length);
728 
729     fprintf(stderr, "extracting %s (%zu MB) to RAM...\n", entry_name.c_str(),
730             out->size() / 1024 / 1024);
731 
732     int error =
733             ExtractToMemory(zip, &zip_entry, reinterpret_cast<uint8_t*>(out->data()), out->size());
734     if (error != 0) die("failed to extract '%s': %s", entry_name.c_str(), ErrorCodeString(error));
735 
736     return true;
737 }
738 
739 #if defined(_WIN32)
740 
741 // TODO: move this to somewhere it can be shared.
742 
743 #include <windows.h>
744 
745 // Windows' tmpfile(3) requires administrator rights because
746 // it creates temporary files in the root directory.
win32_tmpfile()747 static FILE* win32_tmpfile() {
748     char temp_path[PATH_MAX];
749     DWORD nchars = GetTempPath(sizeof(temp_path), temp_path);
750     if (nchars == 0 || nchars >= sizeof(temp_path)) {
751         die("GetTempPath failed, error %ld", GetLastError());
752     }
753 
754     char filename[PATH_MAX];
755     if (GetTempFileName(temp_path, "fastboot", 0, filename) == 0) {
756         die("GetTempFileName failed, error %ld", GetLastError());
757     }
758 
759     return fopen(filename, "w+bTD");
760 }
761 
762 #define tmpfile win32_tmpfile
763 
make_temporary_fd(const char *)764 static int make_temporary_fd(const char* /*what*/) {
765     // TODO: reimplement to avoid leaking a FILE*.
766     return fileno(tmpfile());
767 }
768 
769 #else
770 
make_temporary_template()771 static std::string make_temporary_template() {
772     const char* tmpdir = getenv("TMPDIR");
773     if (tmpdir == nullptr) tmpdir = P_tmpdir;
774     return std::string(tmpdir) + "/fastboot_userdata_XXXXXX";
775 }
776 
make_temporary_fd(const char * what)777 static int make_temporary_fd(const char* what) {
778     std::string path_template(make_temporary_template());
779     int fd = mkstemp(&path_template[0]);
780     if (fd == -1) {
781         die("failed to create temporary file for %s with template %s: %s\n", path_template.c_str(),
782             what, strerror(errno));
783     }
784     unlink(path_template.c_str());
785     return fd;
786 }
787 
788 #endif
789 
UnzipToFile(ZipArchiveHandle zip,const char * entry_name)790 static unique_fd UnzipToFile(ZipArchiveHandle zip, const char* entry_name) {
791     unique_fd fd(make_temporary_fd(entry_name));
792 
793     ZipEntry64 zip_entry;
794     if (FindEntry(zip, entry_name, &zip_entry) != 0) {
795         fprintf(stderr, "archive does not contain '%s'\n", entry_name);
796         errno = ENOENT;
797         return unique_fd();
798     }
799 
800     fprintf(stderr, "extracting %s (%" PRIu64 " MB) to disk...", entry_name,
801             zip_entry.uncompressed_length / 1024 / 1024);
802     double start = now();
803     int error = ExtractEntryToFile(zip, &zip_entry, fd.get());
804     if (error != 0) {
805         die("\nfailed to extract '%s': %s", entry_name, ErrorCodeString(error));
806     }
807 
808     if (lseek(fd.get(), 0, SEEK_SET) != 0) {
809         die("\nlseek on extracted file '%s' failed: %s", entry_name, strerror(errno));
810     }
811 
812     fprintf(stderr, " took %.3fs\n", now() - start);
813 
814     return fd;
815 }
816 
CheckRequirement(const std::string & cur_product,const std::string & var,const std::string & product,bool invert,const std::vector<std::string> & options)817 static bool CheckRequirement(const std::string& cur_product, const std::string& var,
818                              const std::string& product, bool invert,
819                              const std::vector<std::string>& options) {
820     Status("Checking '" + var + "'");
821 
822     double start = now();
823 
824     if (!product.empty()) {
825         if (product != cur_product) {
826             double split = now();
827             fprintf(stderr, "IGNORE, product is %s required only for %s [%7.3fs]\n",
828                     cur_product.c_str(), product.c_str(), (split - start));
829             return true;
830         }
831     }
832 
833     std::string var_value;
834     if (fb->GetVar(var, &var_value) != fastboot::SUCCESS) {
835         fprintf(stderr, "FAILED\n\n");
836         fprintf(stderr, "Could not getvar for '%s' (%s)\n\n", var.c_str(), fb->Error().c_str());
837         return false;
838     }
839 
840     bool match = false;
841     for (const auto& option : options) {
842         if (option == var_value ||
843             (option.back() == '*' &&
844              !var_value.compare(0, option.length() - 1, option, 0, option.length() - 1))) {
845             match = true;
846             break;
847         }
848     }
849 
850     if (invert) {
851         match = !match;
852     }
853 
854     if (match) {
855         double split = now();
856         fprintf(stderr, "OKAY [%7.3fs]\n", (split - start));
857         return true;
858     }
859 
860     fprintf(stderr, "FAILED\n\n");
861     fprintf(stderr, "Device %s is '%s'.\n", var.c_str(), var_value.c_str());
862     fprintf(stderr, "Update %s '%s'", invert ? "rejects" : "requires", options[0].c_str());
863     for (auto it = std::next(options.begin()); it != options.end(); ++it) {
864         fprintf(stderr, " or '%s'", it->c_str());
865     }
866     fprintf(stderr, ".\n\n");
867     return false;
868 }
869 
ParseRequirementLine(const std::string & line,std::string * name,std::string * product,bool * invert,std::vector<std::string> * options)870 bool ParseRequirementLine(const std::string& line, std::string* name, std::string* product,
871                           bool* invert, std::vector<std::string>* options) {
872     // "require product=alpha|beta|gamma"
873     // "require version-bootloader=1234"
874     // "require-for-product:gamma version-bootloader=istanbul|constantinople"
875     // "require partition-exists=vendor"
876     *product = "";
877     *invert = false;
878 
879     auto require_reject_regex = std::regex{"(require\\s+|reject\\s+)?\\s*(\\S+)\\s*=\\s*(.*)"};
880     auto require_product_regex =
881             std::regex{"require-for-product:\\s*(\\S+)\\s+(\\S+)\\s*=\\s*(.*)"};
882     std::smatch match_results;
883 
884     if (std::regex_match(line, match_results, require_reject_regex)) {
885         *invert = Trim(match_results[1]) == "reject";
886     } else if (std::regex_match(line, match_results, require_product_regex)) {
887         *product = match_results[1];
888     } else {
889         return false;
890     }
891 
892     *name = match_results[2];
893     // Work around an unfortunate name mismatch.
894     if (*name == "board") {
895         *name = "product";
896     }
897 
898     auto raw_options = Split(match_results[3], "|");
899     for (const auto& option : raw_options) {
900         auto trimmed_option = Trim(option);
901         options->emplace_back(trimmed_option);
902     }
903 
904     return true;
905 }
906 
907 // "require partition-exists=x" is a special case, added because of the trouble we had when
908 // Pixel 2 shipped with new partitions and users used old versions of fastboot to flash them,
909 // missing out new partitions. A device with new partitions can use "partition-exists" to
910 // override the fields `optional_if_no_image` in the `images` array.
HandlePartitionExists(const std::vector<std::string> & options)911 static void HandlePartitionExists(const std::vector<std::string>& options) {
912     const std::string& partition_name = options[0];
913     std::string has_slot;
914     if (fb->GetVar("has-slot:" + partition_name, &has_slot) != fastboot::SUCCESS ||
915         (has_slot != "yes" && has_slot != "no")) {
916         die("device doesn't have required partition %s!", partition_name.c_str());
917     }
918     bool known_partition = false;
919     for (size_t i = 0; i < images.size(); ++i) {
920         if (!images[i].nickname.empty() && images[i].nickname == partition_name) {
921             images[i].optional_if_no_image = false;
922             known_partition = true;
923         }
924     }
925     if (!known_partition) {
926         die("device requires partition %s which is not known to this version of fastboot",
927             partition_name.c_str());
928     }
929 }
930 
CheckRequirements(const std::string & data,bool force_flash)931 static void CheckRequirements(const std::string& data, bool force_flash) {
932     std::string cur_product;
933     if (fb->GetVar("product", &cur_product) != fastboot::SUCCESS) {
934         fprintf(stderr, "getvar:product FAILED (%s)\n", fb->Error().c_str());
935     }
936 
937     auto lines = Split(data, "\n");
938     for (const auto& line : lines) {
939         if (line.empty()) {
940             continue;
941         }
942 
943         std::string name;
944         std::string product;
945         bool invert;
946         std::vector<std::string> options;
947 
948         if (!ParseRequirementLine(line, &name, &product, &invert, &options)) {
949             fprintf(stderr, "android-info.txt syntax error: %s\n", line.c_str());
950             continue;
951         }
952         if (name == "partition-exists") {
953             HandlePartitionExists(options);
954         } else {
955             bool met = CheckRequirement(cur_product, name, product, invert, options);
956             if (!met) {
957                 if (!force_flash) {
958                     die("requirements not met!");
959                 } else {
960                     fprintf(stderr, "requirements not met! but proceeding due to --force\n");
961                 }
962             }
963         }
964     }
965 }
966 
DisplayVarOrError(const std::string & label,const std::string & var)967 static void DisplayVarOrError(const std::string& label, const std::string& var) {
968     std::string value;
969 
970     if (fb->GetVar(var, &value) != fastboot::SUCCESS) {
971         Status("getvar:" + var);
972         fprintf(stderr, "FAILED (%s)\n", fb->Error().c_str());
973         return;
974     }
975     fprintf(stderr, "%s: %s\n", label.c_str(), value.c_str());
976 }
977 
DumpInfo()978 static void DumpInfo() {
979     fprintf(stderr, "--------------------------------------------\n");
980     DisplayVarOrError("Bootloader Version...", "version-bootloader");
981     DisplayVarOrError("Baseband Version.....", "version-baseband");
982     DisplayVarOrError("Serial Number........", "serialno");
983     fprintf(stderr, "--------------------------------------------\n");
984 }
985 
resparse_file(sparse_file * s,int64_t max_size)986 std::vector<SparsePtr> resparse_file(sparse_file* s, int64_t max_size) {
987     if (max_size <= 0 || max_size > std::numeric_limits<uint32_t>::max()) {
988         die("invalid max size %" PRId64, max_size);
989     }
990 
991     const int files = sparse_file_resparse(s, max_size, nullptr, 0);
992     if (files < 0) die("Failed to compute resparse boundaries");
993 
994     auto temp = std::make_unique<sparse_file*[]>(files);
995     const int rv = sparse_file_resparse(s, max_size, temp.get(), files);
996     if (rv < 0) die("Failed to resparse");
997 
998     std::vector<SparsePtr> out_s;
999     for (int i = 0; i < files; i++) {
1000         out_s.emplace_back(temp[i], sparse_file_destroy);
1001     }
1002     return out_s;
1003 }
1004 
load_sparse_files(int fd,int64_t max_size)1005 static std::vector<SparsePtr> load_sparse_files(int fd, int64_t max_size) {
1006     SparsePtr s(sparse_file_import_auto(fd, false, true), sparse_file_destroy);
1007     if (!s) die("cannot sparse read file");
1008 
1009     return resparse_file(s.get(), max_size);
1010 }
1011 
get_uint_var(const char * var_name,fastboot::IFastBootDriver * fb)1012 static uint64_t get_uint_var(const char* var_name, fastboot::IFastBootDriver* fb) {
1013     std::string value_str;
1014     if (fb->GetVar(var_name, &value_str) != fastboot::SUCCESS || value_str.empty()) {
1015         verbose("target didn't report %s", var_name);
1016         return 0;
1017     }
1018 
1019     // Some bootloaders (angler, for example) send spurious whitespace too.
1020     value_str = android::base::Trim(value_str);
1021 
1022     uint64_t value;
1023     if (!android::base::ParseUint(value_str, &value)) {
1024         fprintf(stderr, "couldn't parse %s '%s'\n", var_name, value_str.c_str());
1025         return 0;
1026     }
1027     if (value > 0) verbose("target reported %s of %" PRId64 " bytes", var_name, value);
1028     return value;
1029 }
1030 
get_sparse_limit(int64_t size,const FlashingPlan * fp)1031 int64_t get_sparse_limit(int64_t size, const FlashingPlan* fp) {
1032     if (!fp) return 0;
1033 
1034     int64_t limit = int64_t(fp->sparse_limit);
1035     if (limit == 0) {
1036         // Unlimited, so see what the target device's limit is.
1037         // TODO: shouldn't we apply this limit even if you've used -S?
1038         if (target_sparse_limit == -1) {
1039             target_sparse_limit = static_cast<int64_t>(get_uint_var("max-download-size", fp->fb));
1040         }
1041         if (target_sparse_limit > 0) {
1042             limit = target_sparse_limit;
1043         } else {
1044             return 0;
1045         }
1046     }
1047 
1048     if (size > limit) {
1049         return std::min(limit, RESPARSE_LIMIT);
1050     }
1051 
1052     return 0;
1053 }
1054 
load_buf_fd(unique_fd fd,struct fastboot_buffer * buf,const FlashingPlan * fp)1055 static bool load_buf_fd(unique_fd fd, struct fastboot_buffer* buf, const FlashingPlan* fp) {
1056     int64_t sz = get_file_size(fd);
1057     if (sz == -1) {
1058         return false;
1059     }
1060 
1061     if (sparse_file* s = sparse_file_import(fd.get(), false, false)) {
1062         buf->image_size = sparse_file_len(s, false, false);
1063         if (buf->image_size < 0) {
1064             LOG(ERROR) << "Could not compute length of sparse file";
1065             return false;
1066         }
1067         sparse_file_destroy(s);
1068         buf->file_type = FB_BUFFER_SPARSE;
1069     } else {
1070         buf->image_size = sz;
1071         buf->file_type = FB_BUFFER_FD;
1072     }
1073 
1074     lseek(fd.get(), 0, SEEK_SET);
1075     int64_t limit = get_sparse_limit(sz, fp);
1076     buf->fd = std::move(fd);
1077     if (limit) {
1078         buf->files = load_sparse_files(buf->fd.get(), limit);
1079         if (buf->files.empty()) {
1080             return false;
1081         }
1082         buf->type = FB_BUFFER_SPARSE;
1083     } else {
1084         buf->type = FB_BUFFER_FD;
1085         buf->sz = sz;
1086     }
1087 
1088     return true;
1089 }
1090 
load_buf(const char * fname,struct fastboot_buffer * buf,const FlashingPlan * fp)1091 static bool load_buf(const char* fname, struct fastboot_buffer* buf, const FlashingPlan* fp) {
1092     unique_fd fd(TEMP_FAILURE_RETRY(open(fname, O_RDONLY | O_BINARY)));
1093 
1094     if (fd == -1) {
1095         return false;
1096     }
1097 
1098     struct stat s;
1099     if (fstat(fd.get(), &s)) {
1100         return false;
1101     }
1102     if (!S_ISREG(s.st_mode)) {
1103         errno = S_ISDIR(s.st_mode) ? EISDIR : EINVAL;
1104         return false;
1105     }
1106 
1107     return load_buf_fd(std::move(fd), buf, fp);
1108 }
1109 
rewrite_vbmeta_buffer(struct fastboot_buffer * buf,bool vbmeta_in_boot)1110 static void rewrite_vbmeta_buffer(struct fastboot_buffer* buf, bool vbmeta_in_boot) {
1111     // Buffer needs to be at least the size of the VBMeta struct which
1112     // is 256 bytes.
1113     if (buf->sz < 256) {
1114         return;
1115     }
1116 
1117     std::string data;
1118     if (!android::base::ReadFdToString(buf->fd, &data)) {
1119         die("Failed reading from vbmeta");
1120     }
1121 
1122     uint64_t vbmeta_offset = 0;
1123     if (vbmeta_in_boot) {
1124         // Tries to locate top-level vbmeta from boot.img footer.
1125         uint64_t footer_offset = buf->sz - AVB_FOOTER_SIZE;
1126         if (0 != data.compare(footer_offset, AVB_FOOTER_MAGIC_LEN, AVB_FOOTER_MAGIC)) {
1127             die("Failed to find AVB_FOOTER at offset: %" PRId64 ", is BOARD_AVB_ENABLE true?",
1128                 footer_offset);
1129         }
1130         const AvbFooter* footer = reinterpret_cast<const AvbFooter*>(data.c_str() + footer_offset);
1131         vbmeta_offset = be64toh(footer->vbmeta_offset);
1132     }
1133     // Ensures there is AVB_MAGIC at vbmeta_offset.
1134     if (0 != data.compare(vbmeta_offset, AVB_MAGIC_LEN, AVB_MAGIC)) {
1135         die("Failed to find AVB_MAGIC at offset: %" PRId64, vbmeta_offset);
1136     }
1137 
1138     fprintf(stderr, "Rewriting vbmeta struct at offset: %" PRId64 "\n", vbmeta_offset);
1139 
1140     // There's a 32-bit big endian |flags| field at offset 120 where
1141     // bit 0 corresponds to disable-verity and bit 1 corresponds to
1142     // disable-verification.
1143     //
1144     // See external/avb/libavb/avb_vbmeta_image.h for the layout of
1145     // the VBMeta struct.
1146     uint64_t flags_offset = 123 + vbmeta_offset;
1147     if (g_disable_verity) {
1148         data[flags_offset] |= 0x01;
1149     }
1150     if (g_disable_verification) {
1151         data[flags_offset] |= 0x02;
1152     }
1153 
1154     unique_fd fd(make_temporary_fd("vbmeta rewriting"));
1155     if (!android::base::WriteStringToFd(data, fd)) {
1156         die("Failed writing to modified vbmeta");
1157     }
1158     buf->fd = std::move(fd);
1159     lseek(buf->fd.get(), 0, SEEK_SET);
1160 }
1161 
has_vbmeta_partition()1162 static bool has_vbmeta_partition() {
1163     std::string partition_type;
1164     return fb->GetVar("partition-type:vbmeta", &partition_type) == fastboot::SUCCESS ||
1165            fb->GetVar("partition-type:vbmeta_a", &partition_type) == fastboot::SUCCESS ||
1166            fb->GetVar("partition-type:vbmeta_b", &partition_type) == fastboot::SUCCESS;
1167 }
1168 
is_vbmeta_partition(const std::string & partition)1169 static bool is_vbmeta_partition(const std::string& partition) {
1170     return android::base::EndsWith(partition, "vbmeta") ||
1171            android::base::EndsWith(partition, "vbmeta_a") ||
1172            android::base::EndsWith(partition, "vbmeta_b");
1173 }
1174 
1175 // Note: this only works in userspace fastboot. In the bootloader, use
1176 // should_flash_in_userspace().
is_logical(const std::string & partition)1177 bool is_logical(const std::string& partition) {
1178     std::string value;
1179     return fb->GetVar("is-logical:" + partition, &value) == fastboot::SUCCESS && value == "yes";
1180 }
1181 
get_partition_size(const std::string & partition)1182 static uint64_t get_partition_size(const std::string& partition) {
1183     std::string partition_size_str;
1184     if (fb->GetVar("partition-size:" + partition, &partition_size_str) != fastboot::SUCCESS) {
1185         if (!is_logical(partition)) {
1186             return 0;
1187         }
1188         die("cannot get partition size for %s", partition.c_str());
1189     }
1190 
1191     partition_size_str = fb_fix_numeric_var(partition_size_str);
1192     uint64_t partition_size;
1193     if (!android::base::ParseUint(partition_size_str, &partition_size)) {
1194         if (!is_logical(partition)) {
1195             return 0;
1196         }
1197         die("Couldn't parse partition size '%s'.", partition_size_str.c_str());
1198     }
1199     return partition_size;
1200 }
1201 
copy_avb_footer(const ImageSource * source,const std::string & partition,struct fastboot_buffer * buf)1202 static void copy_avb_footer(const ImageSource* source, const std::string& partition,
1203                             struct fastboot_buffer* buf) {
1204     if (buf->sz < AVB_FOOTER_SIZE || is_logical(partition) ||
1205         should_flash_in_userspace(source, partition)) {
1206         return;
1207     }
1208 
1209     // If the image is sparse, moving the footer will simply corrupt the sparse
1210     // format, so currently we don't support moving the footer on sparse files.
1211     if (buf->file_type == FB_BUFFER_SPARSE) {
1212         LOG(ERROR) << "Warning: skip copying " << partition << " image avb footer due to sparse "
1213                    << "image.";
1214         return;
1215     }
1216 
1217     // If overflows and negative, it should be < buf->sz.
1218     int64_t partition_size = static_cast<int64_t>(get_partition_size(partition));
1219 
1220     if (partition_size == buf->sz) {
1221         return;
1222     }
1223     // Some device bootloaders might not implement `fastboot getvar partition-size:boot[_a|_b]`.
1224     // In this case, partition_size will be zero.
1225     if (partition_size < buf->sz) {
1226         fprintf(stderr,
1227                 "Warning: skip copying %s image avb footer"
1228                 " (%s partition size: %" PRId64 ", %s image size: %" PRId64 ").\n",
1229                 partition.c_str(), partition.c_str(), partition_size, partition.c_str(), buf->sz);
1230         return;
1231     }
1232 
1233     // IMPORTANT: after the following read, we need to reset buf->fd before return (if not die).
1234     // Because buf->fd will still be used afterwards.
1235     std::string data;
1236     if (!android::base::ReadFdToString(buf->fd, &data)) {
1237         die("Failed reading from %s", partition.c_str());
1238     }
1239 
1240     uint64_t footer_offset = buf->sz - AVB_FOOTER_SIZE;
1241     if (0 != data.compare(footer_offset, AVB_FOOTER_MAGIC_LEN, AVB_FOOTER_MAGIC)) {
1242         lseek(buf->fd.get(), 0, SEEK_SET);  // IMPORTANT: resets buf->fd before return.
1243         return;
1244     }
1245 
1246     const std::string tmp_fd_template = partition + " rewriting";
1247     unique_fd fd(make_temporary_fd(tmp_fd_template.c_str()));
1248     if (!android::base::WriteStringToFd(data, fd)) {
1249         die("Failed writing to modified %s", partition.c_str());
1250     }
1251     lseek(fd.get(), partition_size - AVB_FOOTER_SIZE, SEEK_SET);
1252     if (!android::base::WriteStringToFd(data.substr(footer_offset), fd)) {
1253         die("Failed copying AVB footer in %s", partition.c_str());
1254     }
1255     buf->fd = std::move(fd);
1256     buf->sz = partition_size;
1257     lseek(buf->fd.get(), 0, SEEK_SET);
1258 }
1259 
flash_partition_files(const std::string & partition,const std::vector<SparsePtr> & files)1260 void flash_partition_files(const std::string& partition, const std::vector<SparsePtr>& files) {
1261     for (size_t i = 0; i < files.size(); i++) {
1262         sparse_file* s = files[i].get();
1263         int64_t sz = sparse_file_len(s, true, false);
1264         if (sz < 0) {
1265             LOG(FATAL) << "Could not compute length of sparse image for " << partition;
1266         }
1267         fb->FlashPartition(partition, s, sz, i + 1, files.size());
1268     }
1269 }
1270 
flash_buf(const ImageSource * source,const std::string & partition,struct fastboot_buffer * buf,const bool apply_vbmeta)1271 static void flash_buf(const ImageSource* source, const std::string& partition,
1272                       struct fastboot_buffer* buf, const bool apply_vbmeta) {
1273     copy_avb_footer(source, partition, buf);
1274 
1275     // Rewrite vbmeta if that's what we're flashing and modification has been requested.
1276     if (g_disable_verity || g_disable_verification) {
1277         // The vbmeta partition might have additional prefix if running in virtual machine
1278         // e.g., guest_vbmeta_a.
1279         if (apply_vbmeta) {
1280             rewrite_vbmeta_buffer(buf, false /* vbmeta_in_boot */);
1281         } else if (!has_vbmeta_partition() &&
1282                    (partition == "boot" || partition == "boot_a" || partition == "boot_b")) {
1283             rewrite_vbmeta_buffer(buf, true /* vbmeta_in_boot */);
1284         }
1285     }
1286 
1287     switch (buf->type) {
1288         case FB_BUFFER_SPARSE: {
1289             flash_partition_files(partition, buf->files);
1290             break;
1291         }
1292         case FB_BUFFER_FD:
1293             fb->FlashPartition(partition, buf->fd, buf->sz);
1294             break;
1295         default:
1296             die("unknown buffer type: %d", buf->type);
1297     }
1298 }
1299 
get_current_slot()1300 std::string get_current_slot() {
1301     std::string current_slot;
1302     if (fb->GetVar("current-slot", &current_slot) != fastboot::SUCCESS) return "";
1303     if (current_slot[0] == '_') current_slot.erase(0, 1);
1304     return current_slot;
1305 }
1306 
get_slot_count(fastboot::IFastBootDriver * fb)1307 static int get_slot_count(fastboot::IFastBootDriver* fb) {
1308     std::string var;
1309     int count = 0;
1310     if (fb->GetVar("slot-count", &var) != fastboot::SUCCESS ||
1311         !android::base::ParseInt(var, &count)) {
1312         return 0;
1313     }
1314     return count;
1315 }
1316 
supports_AB(fastboot::IFastBootDriver * fb)1317 bool supports_AB(fastboot::IFastBootDriver* fb) {
1318     return get_slot_count(fb) >= 2;
1319 }
1320 
1321 // Given a current slot, this returns what the 'other' slot is.
get_other_slot(const std::string & current_slot,int count)1322 static std::string get_other_slot(const std::string& current_slot, int count) {
1323     if (count == 0) return "";
1324 
1325     char next = (current_slot[0] - 'a' + 1) % count + 'a';
1326     return std::string(1, next);
1327 }
1328 
get_other_slot(const std::string & current_slot)1329 static std::string get_other_slot(const std::string& current_slot) {
1330     return get_other_slot(current_slot, get_slot_count(fb));
1331 }
1332 
get_other_slot(int count)1333 static std::string get_other_slot(int count) {
1334     return get_other_slot(get_current_slot(), count);
1335 }
1336 
get_other_slot()1337 static std::string get_other_slot() {
1338     return get_other_slot(get_current_slot(), get_slot_count(fb));
1339 }
1340 
verify_slot(const std::string & slot_name,bool allow_all)1341 static std::string verify_slot(const std::string& slot_name, bool allow_all) {
1342     std::string slot = slot_name;
1343     if (slot == "all") {
1344         if (allow_all) {
1345             return "all";
1346         } else {
1347             int count = get_slot_count(fb);
1348             if (count > 0) {
1349                 return "a";
1350             } else {
1351                 die("No known slots");
1352             }
1353         }
1354     }
1355 
1356     int count = get_slot_count(fb);
1357     if (count == 0) die("Device does not support slots");
1358 
1359     if (slot == "other") {
1360         std::string other = get_other_slot(count);
1361         if (other == "") {
1362             die("No known slots");
1363         }
1364         return other;
1365     }
1366 
1367     if (slot.size() == 1 && (slot[0] - 'a' >= 0 && slot[0] - 'a' < count)) return slot;
1368 
1369     fprintf(stderr, "Slot %s does not exist. supported slots are:\n", slot.c_str());
1370     for (int i = 0; i < count; i++) {
1371         fprintf(stderr, "%c\n", (char)(i + 'a'));
1372     }
1373 
1374     exit(1);
1375 }
1376 
verify_slot(const std::string & slot)1377 static std::string verify_slot(const std::string& slot) {
1378     return verify_slot(slot, true);
1379 }
1380 
do_for_partition(const std::string & part,const std::string & slot,const std::function<void (const std::string &)> & func,bool force_slot)1381 static void do_for_partition(const std::string& part, const std::string& slot,
1382                              const std::function<void(const std::string&)>& func, bool force_slot) {
1383     std::string has_slot;
1384     std::string current_slot;
1385     // |part| can be vendor_boot:default. Append slot to the first token.
1386     auto part_tokens = android::base::Split(part, ":");
1387 
1388     if (fb->GetVar("has-slot:" + part_tokens[0], &has_slot) != fastboot::SUCCESS) {
1389         /* If has-slot is not supported, the answer is no. */
1390         has_slot = "no";
1391     }
1392     if (has_slot == "yes") {
1393         if (slot == "") {
1394             current_slot = get_current_slot();
1395             if (current_slot == "") {
1396                 die("Failed to identify current slot");
1397             }
1398             part_tokens[0] += "_" + current_slot;
1399         } else {
1400             part_tokens[0] += "_" + slot;
1401         }
1402         func(android::base::Join(part_tokens, ":"));
1403     } else {
1404         if (force_slot && slot != "") {
1405             fprintf(stderr, "Warning: %s does not support slots, and slot %s was requested.\n",
1406                     part_tokens[0].c_str(), slot.c_str());
1407         }
1408         func(part);
1409     }
1410 }
1411 
1412 /* This function will find the real partition name given a base name, and a slot. If slot is NULL or
1413  * empty, it will use the current slot. If slot is "all", it will return a list of all possible
1414  * partition names. If force_slot is true, it will fail if a slot is specified, and the given
1415  * partition does not support slots.
1416  */
do_for_partitions(const std::string & part,const std::string & slot,const std::function<void (const std::string &)> & func,bool force_slot)1417 void do_for_partitions(const std::string& part, const std::string& slot,
1418                        const std::function<void(const std::string&)>& func, bool force_slot) {
1419     std::string has_slot;
1420     // |part| can be vendor_boot:default. Query has-slot on the first token only.
1421     auto part_tokens = android::base::Split(part, ":");
1422 
1423     if (slot == "all") {
1424         if (fb->GetVar("has-slot:" + part_tokens[0], &has_slot) != fastboot::SUCCESS) {
1425             die("Could not check if partition %s has slot %s", part_tokens[0].c_str(),
1426                 slot.c_str());
1427         }
1428         if (has_slot == "yes") {
1429             for (int i = 0; i < get_slot_count(fb); i++) {
1430                 do_for_partition(part, std::string(1, (char)(i + 'a')), func, force_slot);
1431             }
1432         } else {
1433             do_for_partition(part, "", func, force_slot);
1434         }
1435     } else {
1436         do_for_partition(part, slot, func, force_slot);
1437     }
1438 }
1439 
1440 // Fetch a partition from the device to a given fd. This is a wrapper over FetchToFd to fetch
1441 // the full image.
fetch_partition(const std::string & partition,borrowed_fd fd,fastboot::IFastBootDriver * fb)1442 static uint64_t fetch_partition(const std::string& partition, borrowed_fd fd,
1443                                 fastboot::IFastBootDriver* fb) {
1444     uint64_t fetch_size = get_uint_var(FB_VAR_MAX_FETCH_SIZE, fb);
1445     if (fetch_size == 0) {
1446         die("Unable to get %s. Device does not support fetch command.", FB_VAR_MAX_FETCH_SIZE);
1447     }
1448     uint64_t partition_size = get_partition_size(partition);
1449     if (partition_size <= 0) {
1450         die("Invalid partition size for partition %s: %" PRId64, partition.c_str(), partition_size);
1451     }
1452 
1453     uint64_t offset = 0;
1454     while (offset < partition_size) {
1455         uint64_t chunk_size = std::min(fetch_size, partition_size - offset);
1456         if (fb->FetchToFd(partition, fd, offset, chunk_size) != fastboot::RetCode::SUCCESS) {
1457             die("Unable to fetch %s (offset=%" PRIx64 ", size=%" PRIx64 ")", partition.c_str(),
1458                 offset, chunk_size);
1459         }
1460         offset += chunk_size;
1461     }
1462     return partition_size;
1463 }
1464 
do_fetch(const std::string & partition,const std::string & slot_override,const std::string & outfile,fastboot::IFastBootDriver * fb)1465 static void do_fetch(const std::string& partition, const std::string& slot_override,
1466                      const std::string& outfile, fastboot::IFastBootDriver* fb) {
1467     unique_fd fd(TEMP_FAILURE_RETRY(
1468             open(outfile.c_str(), O_WRONLY | O_CREAT | O_TRUNC | O_CLOEXEC | O_BINARY, 0644)));
1469     auto fetch = std::bind(fetch_partition, _1, borrowed_fd(fd), fb);
1470     do_for_partitions(partition, slot_override, fetch, false /* force slot */);
1471 }
1472 
1473 // Return immediately if not flashing a vendor boot image. If flashing a vendor boot image,
1474 // repack vendor_boot image with an updated ramdisk. After execution, buf is set
1475 // to the new image to flash, and return value is the real partition name to flash.
repack_ramdisk(const char * pname,struct fastboot_buffer * buf,fastboot::IFastBootDriver * fb)1476 static std::string repack_ramdisk(const char* pname, struct fastboot_buffer* buf,
1477                                   fastboot::IFastBootDriver* fb) {
1478     std::string_view pname_sv{pname};
1479     struct fastboot_buffer dtb_buf = {.sz = 0, .fd = unique_fd(-1)};
1480 
1481     if (!android::base::StartsWith(pname_sv, "vendor_boot:") &&
1482         !android::base::StartsWith(pname_sv, "vendor_boot_a:") &&
1483         !android::base::StartsWith(pname_sv, "vendor_boot_b:")) {
1484         return std::string(pname_sv);
1485     }
1486     if (buf->type != FB_BUFFER_FD) {
1487         die("Flashing sparse vendor ramdisk image is not supported.");
1488     }
1489     if (buf->sz <= 0) {
1490         die("repack_ramdisk() sees negative size: %" PRId64, buf->sz);
1491     }
1492     std::string partition(pname_sv.substr(0, pname_sv.find(':')));
1493     std::string ramdisk(pname_sv.substr(pname_sv.find(':') + 1));
1494 
1495     if (!g_dtb_path.empty()) {
1496         if (!load_buf(g_dtb_path.c_str(), &dtb_buf, nullptr)) {
1497             die("cannot load '%s': %s", g_dtb_path.c_str(), strerror(errno));
1498         }
1499 
1500         if (dtb_buf.type != FB_BUFFER_FD) {
1501             die("Flashing sparse vendor ramdisk image with dtb is not supported.");
1502         }
1503         if (dtb_buf.sz <= 0) {
1504             die("repack_ramdisk() sees invalid dtb size: %" PRId64, buf->sz);
1505         }
1506         verbose("Updating DTB with %s", pname_sv.data());
1507     }
1508 
1509     unique_fd vendor_boot(make_temporary_fd("vendor boot repack"));
1510     uint64_t vendor_boot_size = fetch_partition(partition, vendor_boot, fb);
1511     auto repack_res = replace_vendor_ramdisk(vendor_boot, vendor_boot_size, ramdisk, buf->fd,
1512                                              static_cast<uint64_t>(buf->sz), dtb_buf.fd,
1513                                              static_cast<uint64_t>(dtb_buf.sz));
1514     if (!repack_res.ok()) {
1515         die("%s", repack_res.error().message().c_str());
1516     }
1517 
1518     buf->fd = std::move(vendor_boot);
1519     buf->sz = vendor_boot_size;
1520     buf->image_size = vendor_boot_size;
1521     return partition;
1522 }
1523 
do_flash(const char * pname,const char * fname,const bool apply_vbmeta,const FlashingPlan * fp)1524 void do_flash(const char* pname, const char* fname, const bool apply_vbmeta,
1525               const FlashingPlan* fp) {
1526     if (!fp) {
1527         die("do flash was called without a valid flashing plan");
1528     }
1529     verbose("Do flash %s %s", pname, fname);
1530     struct fastboot_buffer buf;
1531 
1532     if (fp->source) {
1533         unique_fd fd = fp->source->OpenFile(fname);
1534         if (fd < 0 || !load_buf_fd(std::move(fd), &buf, fp)) {
1535             die("could not load '%s': %s", fname, strerror(errno));
1536         }
1537         std::vector<char> signature_data;
1538         std::string file_string(fname);
1539         if (fp->source->ReadFile(file_string.substr(0, file_string.find('.')) + ".sig",
1540                                  &signature_data)) {
1541             fb->Download("signature", signature_data);
1542             fb->RawCommand("signature", "installing signature");
1543         }
1544     } else if (!load_buf(fname, &buf, fp)) {
1545         die("cannot load '%s': %s", fname, strerror(errno));
1546     }
1547 
1548     if (is_logical(pname)) {
1549         fb->ResizePartition(pname, std::to_string(buf.image_size));
1550     }
1551     std::string flash_pname = repack_ramdisk(pname, &buf, fp->fb);
1552     flash_buf(fp->source.get(), flash_pname, &buf, apply_vbmeta);
1553 }
1554 
1555 // Sets slot_override as the active slot. If slot_override is blank,
1556 // set current slot as active instead. This clears slot-unbootable.
set_active(const std::string & slot_override)1557 static void set_active(const std::string& slot_override) {
1558     if (!supports_AB(fb)) return;
1559 
1560     if (slot_override != "") {
1561         fb->SetActive(slot_override);
1562     } else {
1563         std::string current_slot = get_current_slot();
1564         if (current_slot != "") {
1565             fb->SetActive(current_slot);
1566         }
1567     }
1568 }
1569 
is_userspace_fastboot()1570 bool is_userspace_fastboot() {
1571     std::string value;
1572     return fb->GetVar("is-userspace", &value) == fastboot::SUCCESS && value == "yes";
1573 }
1574 
reboot_to_userspace_fastboot()1575 void reboot_to_userspace_fastboot() {
1576     fb->RebootTo("fastboot");
1577     if (fb->WaitForDisconnect() != fastboot::SUCCESS) {
1578         die("Error waiting for USB disconnect.");
1579     }
1580     fb->set_transport(nullptr);
1581 
1582     // Not all platforms support WaitForDisconnect. There also isn't a great way to tell whether
1583     // or not WaitForDisconnect is supported. So, just wait a bit extra for everyone, in order to
1584     // make sure that the device has had time to initiate its reboot and disconnect itself.
1585     std::this_thread::sleep_for(std::chrono::seconds(1));
1586 
1587     fb->set_transport(open_device());
1588 
1589     if (!is_userspace_fastboot()) {
1590         die("Failed to boot into userspace fastboot; one or more components might be unbootable.");
1591     }
1592 
1593     // Reset target_sparse_limit after reboot to userspace fastboot. Max
1594     // download sizes may differ in bootloader and fastbootd.
1595     target_sparse_limit = -1;
1596 }
1597 
CancelSnapshotIfNeeded()1598 static void CancelSnapshotIfNeeded() {
1599     std::string merge_status = "none";
1600     if (fb->GetVar(FB_VAR_SNAPSHOT_UPDATE_STATUS, &merge_status) == fastboot::SUCCESS &&
1601         !merge_status.empty() && merge_status != "none") {
1602         fb->SnapshotUpdateCommand("cancel");
1603     }
1604 }
1605 
GetPartitionName(const ImageEntry & entry,const std::string & current_slot)1606 std::string GetPartitionName(const ImageEntry& entry, const std::string& current_slot) {
1607     auto slot = entry.second;
1608     if (slot.empty()) {
1609         slot = current_slot;
1610     }
1611     if (slot.empty()) {
1612         return entry.first->part_name;
1613     }
1614     if (slot == "all") {
1615         LOG(FATAL) << "Cannot retrieve a singular name when using all slots";
1616     }
1617     return entry.first->part_name + "_" + slot;
1618 }
1619 
ParseFlashCommand(const FlashingPlan * fp,const std::vector<std::string> & parts)1620 std::unique_ptr<FlashTask> ParseFlashCommand(const FlashingPlan* fp,
1621                                              const std::vector<std::string>& parts) {
1622     bool apply_vbmeta = false;
1623     std::string slot = fp->slot_override;
1624     std::string partition;
1625     std::string img_name;
1626     for (auto& part : parts) {
1627         if (part == "--apply-vbmeta") {
1628             apply_vbmeta = true;
1629         } else if (part == "--slot-other") {
1630             slot = fp->secondary_slot;
1631         } else if (partition.empty()) {
1632             partition = part;
1633         } else if (img_name.empty()) {
1634             img_name = part;
1635         } else {
1636             LOG(ERROR) << "unknown argument" << part
1637                        << " in fastboot-info.txt. parts: " << android::base::Join(parts, " ");
1638             return nullptr;
1639         }
1640     }
1641     if (partition.empty()) {
1642         LOG(ERROR) << "partition name not found when parsing fastboot-info.txt. parts: "
1643                    << android::base::Join(parts, " ");
1644         return nullptr;
1645     }
1646     if (img_name.empty()) {
1647         img_name = partition + ".img";
1648     }
1649     return std::make_unique<FlashTask>(slot, partition, img_name, apply_vbmeta, fp);
1650 }
1651 
ParseRebootCommand(const FlashingPlan * fp,const std::vector<std::string> & parts)1652 std::unique_ptr<RebootTask> ParseRebootCommand(const FlashingPlan* fp,
1653                                                const std::vector<std::string>& parts) {
1654     if (parts.empty()) return std::make_unique<RebootTask>(fp);
1655     if (parts.size() > 1) {
1656         LOG(ERROR) << "unknown arguments in reboot {target} in fastboot-info.txt: "
1657                    << android::base::Join(parts, " ");
1658         return nullptr;
1659     }
1660     return std::make_unique<RebootTask>(fp, parts[0]);
1661 }
1662 
ParseWipeCommand(const FlashingPlan * fp,const std::vector<std::string> & parts)1663 std::unique_ptr<WipeTask> ParseWipeCommand(const FlashingPlan* fp,
1664                                            const std::vector<std::string>& parts) {
1665     if (parts.size() != 1) {
1666         LOG(ERROR) << "unknown arguments in erase {partition} in fastboot-info.txt: "
1667                    << android::base::Join(parts, " ");
1668         return nullptr;
1669     }
1670     return std::make_unique<WipeTask>(fp, parts[0]);
1671 }
1672 
ParseFastbootInfoLine(const FlashingPlan * fp,const std::vector<std::string> & command)1673 std::unique_ptr<Task> ParseFastbootInfoLine(const FlashingPlan* fp,
1674                                             const std::vector<std::string>& command) {
1675     if (command.size() == 0) {
1676         return nullptr;
1677     }
1678     std::unique_ptr<Task> task;
1679 
1680     if (command[0] == "flash") {
1681         task = ParseFlashCommand(fp, std::vector<std::string>{command.begin() + 1, command.end()});
1682     } else if (command[0] == "reboot") {
1683         task = ParseRebootCommand(fp, std::vector<std::string>{command.begin() + 1, command.end()});
1684     } else if (command[0] == "update-super" && command.size() == 1) {
1685         task = std::make_unique<UpdateSuperTask>(fp);
1686     } else if (command[0] == "erase" && command.size() == 2) {
1687         task = ParseWipeCommand(fp, std::vector<std::string>{command.begin() + 1, command.end()});
1688     }
1689     if (!task) {
1690         LOG(ERROR) << "unknown command parsing fastboot-info.txt line: "
1691                    << android::base::Join(command, " ");
1692     }
1693     return task;
1694 }
1695 
AddResizeTasks(const FlashingPlan * fp,std::vector<std::unique_ptr<Task>> * tasks)1696 bool AddResizeTasks(const FlashingPlan* fp, std::vector<std::unique_ptr<Task>>* tasks) {
1697     // expands "resize-partitions" into individual commands : resize {os_partition_1}, resize
1698     // {os_partition_2}, etc.
1699     std::vector<std::unique_ptr<Task>> resize_tasks;
1700     std::optional<size_t> loc;
1701     std::vector<char> contents;
1702     if (!fp->source->ReadFile("super_empty.img", &contents)) {
1703         return false;
1704     }
1705     auto metadata = android::fs_mgr::ReadFromImageBlob(contents.data(), contents.size());
1706     if (!metadata) {
1707         return false;
1708     }
1709     for (size_t i = 0; i < tasks->size(); i++) {
1710         if (auto flash_task = tasks->at(i)->AsFlashTask()) {
1711             if (FlashTask::IsDynamicPartition(fp->source.get(), flash_task)) {
1712                 if (!loc) {
1713                     loc = i;
1714                 }
1715                 resize_tasks.emplace_back(std::make_unique<ResizeTask>(
1716                         fp, flash_task->GetPartition(), "0", fp->slot_override));
1717             }
1718         }
1719     }
1720     // if no logical partitions (although should never happen since system will always need to be
1721     // flashed)
1722     if (!loc) {
1723         return false;
1724     }
1725     tasks->insert(tasks->begin() + loc.value(), std::make_move_iterator(resize_tasks.begin()),
1726                   std::make_move_iterator(resize_tasks.end()));
1727     return true;
1728 }
1729 
IsIgnore(const std::vector<std::string> & command)1730 static bool IsIgnore(const std::vector<std::string>& command) {
1731     if (command.size() == 0 || command[0][0] == '#') {
1732         return true;
1733     }
1734     return false;
1735 }
1736 
CheckFastbootInfoRequirements(const std::vector<std::string> & command,uint32_t host_tool_version)1737 bool CheckFastbootInfoRequirements(const std::vector<std::string>& command,
1738                                    uint32_t host_tool_version) {
1739     if (command.size() != 2) {
1740         LOG(ERROR) << "unknown characters in version info in fastboot-info.txt -> "
1741                    << android::base::Join(command, " ");
1742         return false;
1743     }
1744     if (command[0] != "version") {
1745         LOG(ERROR) << "unknown characters in version info in fastboot-info.txt -> "
1746                    << android::base::Join(command, " ");
1747         return false;
1748     }
1749 
1750     uint32_t fastboot_info_version;
1751     if (!android::base::ParseUint(command[1], &fastboot_info_version)) {
1752         LOG(ERROR) << "version number contains non-numeric characters in fastboot-info.txt -> "
1753                    << android::base::Join(command, " ");
1754         return false;
1755     }
1756 
1757     LOG(VERBOSE) << "Checking 'fastboot-info.txt version'";
1758     if (fastboot_info_version <= host_tool_version) {
1759         return true;
1760     }
1761 
1762     LOG(ERROR) << "fasboot-info.txt version: " << command[1]
1763                << " not compatible with host tool version --> " << host_tool_version;
1764     return false;
1765 }
1766 
ParseFastbootInfo(const FlashingPlan * fp,const std::vector<std::string> & file)1767 std::vector<std::unique_ptr<Task>> ParseFastbootInfo(const FlashingPlan* fp,
1768                                                      const std::vector<std::string>& file) {
1769     std::vector<std::unique_ptr<Task>> tasks;
1770     // Get os_partitions that need to be resized
1771     for (auto& text : file) {
1772         std::vector<std::string> command = android::base::Tokenize(text, " ");
1773         if (IsIgnore(command)) {
1774             continue;
1775         }
1776         if (command.size() > 1 && command[0] == "version") {
1777             if (!CheckFastbootInfoRequirements(command, FASTBOOT_INFO_VERSION)) {
1778                 return {};
1779             }
1780             continue;
1781         } else if (command.size() >= 2 && command[0] == "if-wipe") {
1782             if (!fp->wants_wipe) {
1783                 continue;
1784             }
1785             command.erase(command.begin());
1786         }
1787         auto task = ParseFastbootInfoLine(fp, command);
1788         if (!task) {
1789             return {};
1790         }
1791         tasks.emplace_back(std::move(task));
1792     }
1793 
1794     if (auto flash_super_task = OptimizedFlashSuperTask::Initialize(fp, tasks)) {
1795         tasks.emplace_back(std::move(flash_super_task));
1796     } else {
1797         if (!AddResizeTasks(fp, &tasks)) {
1798             LOG(WARNING) << "Failed to add resize tasks";
1799         }
1800     }
1801 
1802     return tasks;
1803 }
1804 
FlashAllTool(FlashingPlan * fp)1805 FlashAllTool::FlashAllTool(FlashingPlan* fp) : fp_(fp) {}
1806 
Flash()1807 void FlashAllTool::Flash() {
1808     DumpInfo();
1809     CheckRequirements();
1810 
1811     // Change the slot first, so we boot into the correct recovery image when
1812     // using fastbootd.
1813     if (fp_->slot_override == "all") {
1814         set_active("a");
1815     } else {
1816         set_active(fp_->slot_override);
1817     }
1818 
1819     DetermineSlot();
1820 
1821     CancelSnapshotIfNeeded();
1822 
1823     tasks_ = CollectTasks();
1824 
1825     for (auto& task : tasks_) {
1826         task->Run();
1827     }
1828     return;
1829 }
1830 
CollectTasks()1831 std::vector<std::unique_ptr<Task>> FlashAllTool::CollectTasks() {
1832     std::vector<std::unique_ptr<Task>> tasks;
1833     if (fp_->should_use_fastboot_info) {
1834         tasks = CollectTasksFromFastbootInfo();
1835 
1836     } else {
1837         tasks = CollectTasksFromImageList();
1838     }
1839     if (fp_->exclude_dynamic_partitions) {
1840         auto is_non_static_flash_task = [&](const auto& task) -> bool {
1841             if (auto flash_task = task->AsFlashTask()) {
1842                 if (!should_flash_in_userspace(fp_->source.get(),
1843                                                flash_task->GetPartitionAndSlot())) {
1844                     return false;
1845                 }
1846             }
1847             return true;
1848         };
1849         tasks.erase(std::remove_if(tasks.begin(), tasks.end(), is_non_static_flash_task),
1850                     tasks.end());
1851     }
1852     return tasks;
1853 }
1854 
CheckRequirements()1855 void FlashAllTool::CheckRequirements() {
1856     std::vector<char> contents;
1857     if (!fp_->source->ReadFile("android-info.txt", &contents)) {
1858         die("could not read android-info.txt");
1859     }
1860     ::CheckRequirements({contents.data(), contents.size()}, fp_->force_flash);
1861 }
1862 
DetermineSlot()1863 void FlashAllTool::DetermineSlot() {
1864     if (fp_->slot_override.empty()) {
1865         fp_->current_slot = get_current_slot();
1866     } else {
1867         fp_->current_slot = fp_->slot_override;
1868     }
1869 
1870     if (fp_->skip_secondary) {
1871         return;
1872     }
1873     if (fp_->slot_override != "" && fp_->slot_override != "all") {
1874         fp_->secondary_slot = get_other_slot(fp_->slot_override);
1875     } else {
1876         fp_->secondary_slot = get_other_slot();
1877     }
1878     if (fp_->secondary_slot == "") {
1879         if (supports_AB(fb)) {
1880             fprintf(stderr, "Warning: Could not determine slot for secondary images. Ignoring.\n");
1881         }
1882         fp_->skip_secondary = true;
1883     }
1884 }
1885 
CollectImages()1886 void FlashAllTool::CollectImages() {
1887     for (size_t i = 0; i < images.size(); ++i) {
1888         std::string slot = fp_->slot_override;
1889         if (images[i].IsSecondary()) {
1890             if (fp_->skip_secondary) {
1891                 continue;
1892             }
1893             slot = fp_->secondary_slot;
1894         }
1895         if (images[i].type == ImageType::BootCritical) {
1896             boot_images_.emplace_back(&images[i], slot);
1897         } else if (images[i].type == ImageType::Normal) {
1898             os_images_.emplace_back(&images[i], slot);
1899         }
1900     }
1901 }
1902 
CollectTasksFromImageList()1903 std::vector<std::unique_ptr<Task>> FlashAllTool::CollectTasksFromImageList() {
1904     CollectImages();
1905     // First flash boot partitions. We allow this to happen either in userspace
1906     // or in bootloader fastboot.
1907     std::vector<std::unique_ptr<Task>> tasks;
1908     AddFlashTasks(boot_images_, tasks);
1909 
1910     // Sync the super partition. This will reboot to userspace fastboot if needed.
1911     tasks.emplace_back(std::make_unique<UpdateSuperTask>(fp_));
1912 
1913     AddFlashTasks(os_images_, tasks);
1914 
1915     if (auto flash_super_task = OptimizedFlashSuperTask::Initialize(fp_, tasks)) {
1916         tasks.emplace_back(std::move(flash_super_task));
1917     } else {
1918         // Resize any logical partition to 0, so each partition is reset to 0
1919         // extents, and will achieve more optimal allocation.
1920         if (!AddResizeTasks(fp_, &tasks)) {
1921             LOG(WARNING) << "Failed to add resize tasks";
1922         }
1923     }
1924 
1925     return tasks;
1926 }
1927 
CollectTasksFromFastbootInfo()1928 std::vector<std::unique_ptr<Task>> FlashAllTool::CollectTasksFromFastbootInfo() {
1929     std::vector<std::unique_ptr<Task>> tasks;
1930     std::vector<char> contents;
1931     if (!fp_->source->ReadFile("fastboot-info.txt", &contents)) {
1932         LOG(VERBOSE) << "Flashing from hardcoded images. fastboot-info.txt is empty or does not "
1933                         "exist";
1934         return CollectTasksFromImageList();
1935     }
1936     tasks = ParseFastbootInfo(fp_, Split({contents.data(), contents.size()}, "\n"));
1937     return tasks;
1938 }
1939 
AddFlashTasks(const std::vector<std::pair<const Image *,std::string>> & images,std::vector<std::unique_ptr<Task>> & tasks)1940 void FlashAllTool::AddFlashTasks(const std::vector<std::pair<const Image*, std::string>>& images,
1941                                  std::vector<std::unique_ptr<Task>>& tasks) {
1942     for (const auto& [image, slot] : images) {
1943         fastboot_buffer buf;
1944         unique_fd fd = fp_->source->OpenFile(image->img_name);
1945         if (fd < 0 || !load_buf_fd(std::move(fd), &buf, fp_)) {
1946             if (image->optional_if_no_image) {
1947                 continue;
1948             }
1949             die("could not load '%s': %s", image->img_name.c_str(), strerror(errno));
1950         }
1951         tasks.emplace_back(std::make_unique<FlashTask>(slot, image->part_name, image->img_name,
1952                                                        is_vbmeta_partition(image->part_name), fp_));
1953     }
1954 }
1955 
ReadFile(const std::string & name,std::vector<char> * out) const1956 bool ZipImageSource::ReadFile(const std::string& name, std::vector<char>* out) const {
1957     return UnzipToMemory(zip_, name, out);
1958 }
1959 
OpenFile(const std::string & name) const1960 unique_fd ZipImageSource::OpenFile(const std::string& name) const {
1961     return UnzipToFile(zip_, name.c_str());
1962 }
1963 
do_update(const char * filename,FlashingPlan * fp)1964 static void do_update(const char* filename, FlashingPlan* fp) {
1965     ZipArchiveHandle zip;
1966     int error = OpenArchive(filename, &zip);
1967     if (error != 0) {
1968         die("failed to open zip file '%s': %s", filename, ErrorCodeString(error));
1969     }
1970     fp->source.reset(new ZipImageSource(zip));
1971     FlashAllTool tool(fp);
1972     tool.Flash();
1973 
1974     CloseArchive(zip);
1975 }
1976 
ReadFile(const std::string & name,std::vector<char> * out) const1977 bool LocalImageSource::ReadFile(const std::string& name, std::vector<char>* out) const {
1978     auto path = find_item_given_name(name);
1979     if (path.empty()) {
1980         return false;
1981     }
1982     return ReadFileToVector(path, out);
1983 }
1984 
OpenFile(const std::string & name) const1985 unique_fd LocalImageSource::OpenFile(const std::string& name) const {
1986     auto path = find_item_given_name(name);
1987     return unique_fd(TEMP_FAILURE_RETRY(open(path.c_str(), O_RDONLY | O_BINARY)));
1988 }
1989 
do_flashall(FlashingPlan * fp)1990 static void do_flashall(FlashingPlan* fp) {
1991     fp->source.reset(new LocalImageSource());
1992     FlashAllTool tool(fp);
1993     tool.Flash();
1994 }
1995 
next_arg(std::vector<std::string> * args)1996 static std::string next_arg(std::vector<std::string>* args) {
1997     if (args->empty()) syntax_error("expected argument");
1998     std::string result = args->front();
1999     args->erase(args->begin());
2000     return result;
2001 }
2002 
do_oem_command(const std::string & cmd,std::vector<std::string> * args)2003 static void do_oem_command(const std::string& cmd, std::vector<std::string>* args) {
2004     if (args->empty()) syntax_error("empty oem command");
2005 
2006     std::string command(cmd);
2007     while (!args->empty()) {
2008         command += " " + next_arg(args);
2009     }
2010     fb->RawCommand(command, "");
2011 }
2012 
fb_get_flash_block_size(std::string name)2013 static unsigned fb_get_flash_block_size(std::string name) {
2014     std::string sizeString;
2015     if (fb->GetVar(name, &sizeString) != fastboot::SUCCESS || sizeString.empty()) {
2016         // This device does not report flash block sizes, so return 0.
2017         return 0;
2018     }
2019     sizeString = fb_fix_numeric_var(sizeString);
2020 
2021     unsigned size;
2022     if (!android::base::ParseUint(sizeString, &size)) {
2023         fprintf(stderr, "Couldn't parse %s '%s'.\n", name.c_str(), sizeString.c_str());
2024         return 0;
2025     }
2026     if ((size & (size - 1)) != 0) {
2027         fprintf(stderr, "Invalid %s %u: must be a power of 2.\n", name.c_str(), size);
2028         return 0;
2029     }
2030     return size;
2031 }
2032 
fb_perform_format(const std::string & partition,int skip_if_not_supported,const std::string & type_override,const std::string & size_override,const unsigned fs_options,const FlashingPlan * fp)2033 void fb_perform_format(const std::string& partition, int skip_if_not_supported,
2034                        const std::string& type_override, const std::string& size_override,
2035                        const unsigned fs_options, const FlashingPlan* fp) {
2036     std::string partition_type, partition_size;
2037 
2038     struct fastboot_buffer buf;
2039     const char* errMsg = nullptr;
2040     const struct fs_generator* gen = nullptr;
2041     TemporaryFile output;
2042     unique_fd fd;
2043 
2044     unsigned int limit = INT_MAX;
2045     if (target_sparse_limit > 0 && target_sparse_limit < limit) {
2046         limit = target_sparse_limit;
2047     }
2048     if (fp->sparse_limit > 0 && fp->sparse_limit < limit) {
2049         limit = fp->sparse_limit;
2050     }
2051 
2052     if (fb->GetVar("partition-type:" + partition, &partition_type) != fastboot::SUCCESS) {
2053         errMsg = "Can't determine partition type.\n";
2054         goto failed;
2055     }
2056     if (!type_override.empty()) {
2057         if (partition_type != type_override) {
2058             fprintf(stderr, "Warning: %s type is %s, but %s was requested for formatting.\n",
2059                     partition.c_str(), partition_type.c_str(), type_override.c_str());
2060         }
2061         partition_type = type_override;
2062     }
2063 
2064     if (fb->GetVar("partition-size:" + partition, &partition_size) != fastboot::SUCCESS) {
2065         errMsg = "Unable to get partition size\n";
2066         goto failed;
2067     }
2068     if (!size_override.empty()) {
2069         if (partition_size != size_override) {
2070             fprintf(stderr, "Warning: %s size is %s, but %s was requested for formatting.\n",
2071                     partition.c_str(), partition_size.c_str(), size_override.c_str());
2072         }
2073         partition_size = size_override;
2074     }
2075     partition_size = fb_fix_numeric_var(partition_size);
2076 
2077     gen = fs_get_generator(partition_type);
2078     if (!gen) {
2079         if (skip_if_not_supported) {
2080             fprintf(stderr, "Erase successful, but not automatically formatting.\n");
2081             fprintf(stderr, "File system type %s not supported.\n", partition_type.c_str());
2082             return;
2083         }
2084         die("Formatting is not supported for file system with type '%s'.", partition_type.c_str());
2085     }
2086 
2087     int64_t size;
2088     if (!android::base::ParseInt(partition_size, &size)) {
2089         die("Couldn't parse partition size '%s'.", partition_size.c_str());
2090     }
2091 
2092     unsigned eraseBlkSize, logicalBlkSize;
2093     eraseBlkSize = fb_get_flash_block_size("erase-block-size");
2094     logicalBlkSize = fb_get_flash_block_size("logical-block-size");
2095 
2096     if (fs_generator_generate(gen, output.path, size, eraseBlkSize, logicalBlkSize, fs_options)) {
2097         die("Cannot generate image for %s", partition.c_str());
2098     }
2099 
2100     fd.reset(open(output.path, O_RDONLY));
2101     if (fd == -1) {
2102         die("Cannot open generated image: %s", strerror(errno));
2103     }
2104     if (!load_buf_fd(std::move(fd), &buf, fp)) {
2105         die("Cannot read image: %s", strerror(errno));
2106     }
2107 
2108     flash_buf(fp->source.get(), partition, &buf, is_vbmeta_partition(partition));
2109     return;
2110 
2111 failed:
2112     if (skip_if_not_supported) {
2113         fprintf(stderr, "Erase successful, but not automatically formatting.\n");
2114         if (errMsg) fprintf(stderr, "%s", errMsg);
2115     }
2116     fprintf(stderr, "FAILED (%s)\n", fb->Error().c_str());
2117     if (!skip_if_not_supported) {
2118         die("Command failed");
2119     }
2120 }
2121 
should_flash_in_userspace(const ImageSource * source,const std::string & partition_name)2122 bool should_flash_in_userspace(const ImageSource* source, const std::string& partition_name) {
2123     if (!source) {
2124         if (!get_android_product_out()) {
2125             return false;
2126         }
2127         auto path = find_item_given_name("super_empty.img");
2128         if (path.empty() || access(path.c_str(), R_OK)) {
2129             return false;
2130         }
2131         auto metadata = android::fs_mgr::ReadFromImageFile(path);
2132         if (!metadata) {
2133             return false;
2134         }
2135         return should_flash_in_userspace(*metadata.get(), partition_name);
2136     }
2137     std::vector<char> contents;
2138     if (!source->ReadFile("super_empty.img", &contents)) {
2139         return false;
2140     }
2141     auto metadata = android::fs_mgr::ReadFromImageBlob(contents.data(), contents.size());
2142     return should_flash_in_userspace(*metadata.get(), partition_name);
2143 }
2144 
wipe_super(const android::fs_mgr::LpMetadata & metadata,const std::string & slot,std::string * message,const FlashingPlan * fp)2145 static bool wipe_super(const android::fs_mgr::LpMetadata& metadata, const std::string& slot,
2146                        std::string* message, const FlashingPlan* fp) {
2147     auto super_device = GetMetadataSuperBlockDevice(metadata);
2148     auto block_size = metadata.geometry.logical_block_size;
2149     auto super_bdev_name = android::fs_mgr::GetBlockDevicePartitionName(*super_device);
2150 
2151     if (super_bdev_name != "super") {
2152         // retrofit devices do not allow flashing to the retrofit partitions,
2153         // so enable it if we can.
2154         fb->RawCommand("oem allow-flash-super");
2155     }
2156 
2157     // Note: do not use die() in here, since we want TemporaryDir's destructor
2158     // to be called.
2159     TemporaryDir temp_dir;
2160 
2161     bool ok;
2162     if (metadata.block_devices.size() > 1) {
2163         ok = WriteSplitImageFiles(temp_dir.path, metadata, block_size, {}, true);
2164     } else {
2165         auto image_path = std::string(temp_dir.path) + "/" + std::string(super_bdev_name) + ".img";
2166         ok = WriteToImageFile(image_path, metadata, block_size, {}, true);
2167     }
2168     if (!ok) {
2169         *message = "Could not generate a flashable super image file";
2170         return false;
2171     }
2172 
2173     for (const auto& block_device : metadata.block_devices) {
2174         auto partition = android::fs_mgr::GetBlockDevicePartitionName(block_device);
2175         bool force_slot = !!(block_device.flags & LP_BLOCK_DEVICE_SLOT_SUFFIXED);
2176 
2177         std::string image_name;
2178         if (metadata.block_devices.size() > 1) {
2179             image_name = "super_" + partition + ".img";
2180         } else {
2181             image_name = partition + ".img";
2182         }
2183 
2184         auto image_path = std::string(temp_dir.path) + "/" + image_name;
2185         auto flash = [&](const std::string& partition_name) {
2186             do_flash(partition_name.c_str(), image_path.c_str(), false, fp);
2187         };
2188         do_for_partitions(partition, slot, flash, force_slot);
2189 
2190         unlink(image_path.c_str());
2191     }
2192     return true;
2193 }
2194 
do_wipe_super(const std::string & image,const std::string & slot_override,const FlashingPlan * fp)2195 static void do_wipe_super(const std::string& image, const std::string& slot_override,
2196                           const FlashingPlan* fp) {
2197     if (access(image.c_str(), R_OK) != 0) {
2198         die("Could not read image: %s", image.c_str());
2199     }
2200     auto metadata = android::fs_mgr::ReadFromImageFile(image);
2201     if (!metadata) {
2202         die("Could not parse image: %s", image.c_str());
2203     }
2204 
2205     auto slot = slot_override;
2206     if (slot.empty()) {
2207         slot = get_current_slot();
2208     }
2209 
2210     std::string message;
2211     if (!wipe_super(*metadata.get(), slot, &message, fp)) {
2212         die(message);
2213     }
2214 }
2215 
FastbootLogger(android::base::LogId,android::base::LogSeverity severity,const char *,const char *,unsigned int,const char * message)2216 static void FastbootLogger(android::base::LogId /* id */, android::base::LogSeverity severity,
2217                            const char* /* tag */, const char* /* file */, unsigned int /* line */,
2218                            const char* message) {
2219     switch (severity) {
2220         case android::base::INFO:
2221             fprintf(stdout, "%s\n", message);
2222             break;
2223         case android::base::ERROR:
2224             fprintf(stderr, "%s\n", message);
2225             break;
2226         default:
2227             verbose("%s\n", message);
2228     }
2229 }
2230 
FastbootAborter(const char * message)2231 static void FastbootAborter(const char* message) {
2232     die("%s", message);
2233 }
2234 
Main(int argc,char * argv[])2235 int FastBootTool::Main(int argc, char* argv[]) {
2236     android::base::InitLogging(argv, FastbootLogger, FastbootAborter);
2237     std::unique_ptr<FlashingPlan> fp = std::make_unique<FlashingPlan>();
2238 
2239     int longindex;
2240     std::string next_active;
2241 
2242     g_boot_img_hdr.kernel_addr = 0x00008000;
2243     g_boot_img_hdr.ramdisk_addr = 0x01000000;
2244     g_boot_img_hdr.second_addr = 0x00f00000;
2245     g_boot_img_hdr.tags_addr = 0x00000100;
2246     g_boot_img_hdr.page_size = 2048;
2247     g_boot_img_hdr.dtb_addr = 0x01100000;
2248 
2249     const struct option longopts[] = {{"base", required_argument, 0, 0},
2250                                       {"cmdline", required_argument, 0, 0},
2251                                       {"disable-verification", no_argument, 0, 0},
2252                                       {"disable-verity", no_argument, 0, 0},
2253                                       {"disable-super-optimization", no_argument, 0, 0},
2254                                       {"exclude-dynamic-partitions", no_argument, 0, 0},
2255                                       {"disable-fastboot-info", no_argument, 0, 0},
2256                                       {"force", no_argument, 0, 0},
2257                                       {"fs-options", required_argument, 0, 0},
2258                                       {"header-version", required_argument, 0, 0},
2259                                       {"help", no_argument, 0, 'h'},
2260                                       {"kernel-offset", required_argument, 0, 0},
2261                                       {"os-patch-level", required_argument, 0, 0},
2262                                       {"os-version", required_argument, 0, 0},
2263                                       {"page-size", required_argument, 0, 0},
2264                                       {"ramdisk-offset", required_argument, 0, 0},
2265                                       {"set-active", optional_argument, 0, 'a'},
2266                                       {"skip-reboot", no_argument, 0, 0},
2267                                       {"skip-secondary", no_argument, 0, 0},
2268                                       {"slot", required_argument, 0, 0},
2269                                       {"tags-offset", required_argument, 0, 0},
2270                                       {"dtb", required_argument, 0, 0},
2271                                       {"dtb-offset", required_argument, 0, 0},
2272                                       {"unbuffered", no_argument, 0, 0},
2273                                       {"verbose", no_argument, 0, 'v'},
2274                                       {"version", no_argument, 0, 0},
2275                                       {0, 0, 0, 0}};
2276 
2277     serial = getenv("FASTBOOT_DEVICE");
2278     if (!serial) {
2279         serial = getenv("ANDROID_SERIAL");
2280     }
2281 
2282     int c;
2283     while ((c = getopt_long(argc, argv, "a::hls:S:vw", longopts, &longindex)) != -1) {
2284         if (c == 0) {
2285             std::string name{longopts[longindex].name};
2286             if (name == "base") {
2287                 g_base_addr = strtoul(optarg, 0, 16);
2288             } else if (name == "cmdline") {
2289                 g_cmdline = optarg;
2290             } else if (name == "disable-verification") {
2291                 g_disable_verification = true;
2292             } else if (name == "disable-verity") {
2293                 g_disable_verity = true;
2294             } else if (name == "disable-super-optimization") {
2295                 fp->should_optimize_flash_super = false;
2296             } else if (name == "exclude-dynamic-partitions") {
2297                 fp->exclude_dynamic_partitions = true;
2298                 fp->should_optimize_flash_super = false;
2299             } else if (name == "disable-fastboot-info") {
2300                 fp->should_use_fastboot_info = false;
2301             } else if (name == "force") {
2302                 fp->force_flash = true;
2303             } else if (name == "fs-options") {
2304                 fp->fs_options = ParseFsOption(optarg);
2305             } else if (name == "header-version") {
2306                 g_boot_img_hdr.header_version = strtoul(optarg, nullptr, 0);
2307             } else if (name == "dtb") {
2308                 g_dtb_path = optarg;
2309             } else if (name == "kernel-offset") {
2310                 g_boot_img_hdr.kernel_addr = strtoul(optarg, 0, 16);
2311             } else if (name == "os-patch-level") {
2312                 ParseOsPatchLevel(&g_boot_img_hdr, optarg);
2313             } else if (name == "os-version") {
2314                 ParseOsVersion(&g_boot_img_hdr, optarg);
2315             } else if (name == "page-size") {
2316                 g_boot_img_hdr.page_size = strtoul(optarg, nullptr, 0);
2317                 if (g_boot_img_hdr.page_size == 0) die("invalid page size");
2318             } else if (name == "ramdisk-offset") {
2319                 g_boot_img_hdr.ramdisk_addr = strtoul(optarg, 0, 16);
2320             } else if (name == "skip-reboot") {
2321                 fp->skip_reboot = true;
2322             } else if (name == "skip-secondary") {
2323                 fp->skip_secondary = true;
2324             } else if (name == "slot") {
2325                 fp->slot_override = optarg;
2326             } else if (name == "dtb-offset") {
2327                 g_boot_img_hdr.dtb_addr = strtoul(optarg, 0, 16);
2328             } else if (name == "tags-offset") {
2329                 g_boot_img_hdr.tags_addr = strtoul(optarg, 0, 16);
2330             } else if (name == "unbuffered") {
2331                 setvbuf(stdout, nullptr, _IONBF, 0);
2332                 setvbuf(stderr, nullptr, _IONBF, 0);
2333             } else if (name == "version") {
2334                 fprintf(stdout, "fastboot version %s-%s\n", PLATFORM_TOOLS_VERSION,
2335                         android::build::GetBuildNumber().c_str());
2336                 fprintf(stdout, "Installed as %s\n", android::base::GetExecutablePath().c_str());
2337                 return 0;
2338             } else {
2339                 die("unknown option %s", longopts[longindex].name);
2340             }
2341         } else {
2342             switch (c) {
2343                 case 'a':
2344                     fp->wants_set_active = true;
2345                     if (optarg) next_active = optarg;
2346                     break;
2347                 case 'h':
2348                     return show_help();
2349                 case 'l':
2350                     g_long_listing = true;
2351                     break;
2352                 case 's':
2353                     serial = optarg;
2354                     break;
2355                 case 'S':
2356                     if (!android::base::ParseByteCount(optarg, &fp->sparse_limit)) {
2357                         die("invalid sparse limit %s", optarg);
2358                     }
2359                     break;
2360                 case 'v':
2361                     set_verbose();
2362                     break;
2363                 case 'w':
2364                     fp->wants_wipe = true;
2365                     break;
2366                 case '?':
2367                     return 1;
2368                 default:
2369                     abort();
2370             }
2371         }
2372     }
2373 
2374     argc -= optind;
2375     argv += optind;
2376 
2377     if (argc == 0 && !fp->wants_wipe && !fp->wants_set_active) syntax_error("no command");
2378 
2379     if (argc > 0 && !strcmp(*argv, "devices")) {
2380         list_devices();
2381         return 0;
2382     }
2383 
2384     if (argc > 0 && !strcmp(*argv, "connect")) {
2385         argc -= optind;
2386         argv += optind;
2387         return Connect(argc, argv);
2388     }
2389 
2390     if (argc > 0 && !strcmp(*argv, "disconnect")) {
2391         argc -= optind;
2392         argv += optind;
2393         return Disconnect(argc, argv);
2394     }
2395 
2396     if (argc > 0 && !strcmp(*argv, "help")) {
2397         return show_help();
2398     }
2399 
2400     std::unique_ptr<Transport> transport = open_device();
2401     if (!transport) {
2402         return 1;
2403     }
2404     fastboot::DriverCallbacks driver_callbacks = {
2405             .prolog = Status,
2406             .epilog = Epilog,
2407             .info = InfoMessage,
2408             .text = TextMessage,
2409     };
2410 
2411     fastboot::FastBootDriver fastboot_driver(std::move(transport), driver_callbacks, false);
2412     fb = &fastboot_driver;
2413     fp->fb = &fastboot_driver;
2414 
2415     const double start = now();
2416 
2417     if (fp->slot_override != "") fp->slot_override = verify_slot(fp->slot_override);
2418     if (next_active != "") next_active = verify_slot(next_active, false);
2419 
2420     if (fp->wants_set_active) {
2421         if (next_active == "") {
2422             if (fp->slot_override == "") {
2423                 std::string current_slot;
2424                 if (fb->GetVar("current-slot", &current_slot) == fastboot::SUCCESS) {
2425                     if (current_slot[0] == '_') current_slot.erase(0, 1);
2426                     next_active = verify_slot(current_slot, false);
2427                 } else {
2428                     fp->wants_set_active = false;
2429                 }
2430             } else {
2431                 next_active = verify_slot(fp->slot_override, false);
2432             }
2433         }
2434     }
2435     std::vector<std::unique_ptr<Task>> tasks;
2436     std::vector<std::string> args(argv, argv + argc);
2437     while (!args.empty()) {
2438         std::string command = next_arg(&args);
2439 
2440         if (command == FB_CMD_GETVAR) {
2441             std::string variable = next_arg(&args);
2442             DisplayVarOrError(variable, variable);
2443         } else if (command == FB_CMD_ERASE) {
2444             std::string partition = next_arg(&args);
2445             auto erase = [&](const std::string& partition) {
2446                 std::string partition_type;
2447                 if (fb->GetVar("partition-type:" + partition, &partition_type) ==
2448                             fastboot::SUCCESS &&
2449                     fs_get_generator(partition_type) != nullptr) {
2450                     fprintf(stderr, "******** Did you mean to fastboot format this %s partition?\n",
2451                             partition_type.c_str());
2452                 }
2453 
2454                 fb->Erase(partition);
2455             };
2456             do_for_partitions(partition, fp->slot_override, erase, true);
2457         } else if (android::base::StartsWith(command, "format")) {
2458             // Parsing for: "format[:[type][:[size]]]"
2459             // Some valid things:
2460             //  - select only the size, and leave default fs type:
2461             //    format::0x4000000 userdata
2462             //  - default fs type and size:
2463             //    format userdata
2464             //    format:: userdata
2465             std::vector<std::string> pieces = android::base::Split(command, ":");
2466             std::string type_override;
2467             if (pieces.size() > 1) type_override = pieces[1].c_str();
2468             std::string size_override;
2469             if (pieces.size() > 2) size_override = pieces[2].c_str();
2470 
2471             std::string partition = next_arg(&args);
2472 
2473             auto format = [&](const std::string& partition) {
2474                 fb_perform_format(partition, 0, type_override, size_override, fp->fs_options,
2475                                   fp.get());
2476             };
2477             do_for_partitions(partition, fp->slot_override, format, true);
2478         } else if (command == "signature") {
2479             std::string filename = next_arg(&args);
2480             std::vector<char> data;
2481             if (!ReadFileToVector(filename, &data)) {
2482                 die("could not load '%s': %s", filename.c_str(), strerror(errno));
2483             }
2484             if (data.size() != 256) die("signature must be 256 bytes (got %zu)", data.size());
2485             fb->Download("signature", data);
2486             fb->RawCommand("signature", "installing signature");
2487         } else if (command == FB_CMD_REBOOT) {
2488             if (args.size() == 1) {
2489                 std::string reboot_target = next_arg(&args);
2490                 tasks.emplace_back(std::make_unique<RebootTask>(fp.get(), reboot_target));
2491             } else if (!fp->skip_reboot) {
2492                 tasks.emplace_back(std::make_unique<RebootTask>(fp.get()));
2493             }
2494             if (!args.empty()) syntax_error("junk after reboot command");
2495         } else if (command == FB_CMD_REBOOT_BOOTLOADER) {
2496             tasks.emplace_back(std::make_unique<RebootTask>(fp.get(), "bootloader"));
2497         } else if (command == FB_CMD_REBOOT_RECOVERY) {
2498             tasks.emplace_back(std::make_unique<RebootTask>(fp.get(), "recovery"));
2499         } else if (command == FB_CMD_REBOOT_FASTBOOT) {
2500             tasks.emplace_back(std::make_unique<RebootTask>(fp.get(), "fastboot"));
2501         } else if (command == FB_CMD_CONTINUE) {
2502             fb->Continue();
2503         } else if (command == FB_CMD_BOOT) {
2504             std::string kernel = next_arg(&args);
2505             std::string ramdisk;
2506             if (!args.empty()) ramdisk = next_arg(&args);
2507             std::string second_stage;
2508             if (!args.empty()) second_stage = next_arg(&args);
2509             auto data = LoadBootableImage(kernel, ramdisk, second_stage);
2510             fb->Download("boot.img", data);
2511             fb->Boot();
2512         } else if (command == FB_CMD_FLASH) {
2513             std::string pname = next_arg(&args);
2514             std::string fname;
2515             if (!args.empty()) {
2516                 fname = next_arg(&args);
2517             } else {
2518                 fname = find_item(pname);
2519             }
2520             if (fname.empty()) die("cannot determine image filename for '%s'", pname.c_str());
2521 
2522             FlashTask task(fp->slot_override, pname, fname, is_vbmeta_partition(pname), fp.get());
2523             task.Run();
2524         } else if (command == "flash:raw") {
2525             std::string partition = next_arg(&args);
2526             std::string kernel = next_arg(&args);
2527             std::string ramdisk;
2528             if (!args.empty()) ramdisk = next_arg(&args);
2529             std::string second_stage;
2530             if (!args.empty()) second_stage = next_arg(&args);
2531 
2532             auto data = LoadBootableImage(kernel, ramdisk, second_stage);
2533             auto flashraw = [&data](const std::string& partition) {
2534                 fb->FlashPartition(partition, data);
2535             };
2536             do_for_partitions(partition, fp->slot_override, flashraw, true);
2537         } else if (command == "flashall") {
2538             if (fp->slot_override == "all") {
2539                 fprintf(stderr,
2540                         "Warning: slot set to 'all'. Secondary slots will not be flashed.\n");
2541                 fp->skip_secondary = true;
2542             }
2543             do_flashall(fp.get());
2544 
2545             if (!fp->skip_reboot) {
2546                 tasks.emplace_back(std::make_unique<RebootTask>(fp.get()));
2547             }
2548         } else if (command == "update") {
2549             bool slot_all = (fp->slot_override == "all");
2550             if (slot_all) {
2551                 fprintf(stderr,
2552                         "Warning: slot set to 'all'. Secondary slots will not be flashed.\n");
2553             }
2554             std::string filename = "update.zip";
2555             if (!args.empty()) {
2556                 filename = next_arg(&args);
2557             }
2558             do_update(filename.c_str(), fp.get());
2559             if (!fp->skip_reboot) {
2560                 tasks.emplace_back(std::make_unique<RebootTask>(fp.get()));
2561             }
2562         } else if (command == FB_CMD_SET_ACTIVE) {
2563             std::string slot = verify_slot(next_arg(&args), false);
2564             fb->SetActive(slot);
2565         } else if (command == "stage") {
2566             std::string filename = next_arg(&args);
2567 
2568             struct fastboot_buffer buf;
2569             if (!load_buf(filename.c_str(), &buf, fp.get()) || buf.type != FB_BUFFER_FD) {
2570                 die("cannot load '%s'", filename.c_str());
2571             }
2572             fb->Download(filename, buf.fd.get(), buf.sz);
2573         } else if (command == "get_staged") {
2574             std::string filename = next_arg(&args);
2575             fb->Upload(filename);
2576         } else if (command == FB_CMD_OEM) {
2577             do_oem_command(FB_CMD_OEM, &args);
2578         } else if (command == "flashing") {
2579             if (args.empty()) {
2580                 syntax_error("missing 'flashing' command");
2581             } else if (args.size() == 1 &&
2582                        (args[0] == "unlock" || args[0] == "lock" || args[0] == "unlock_critical" ||
2583                         args[0] == "lock_critical" || args[0] == "get_unlock_ability")) {
2584                 do_oem_command("flashing", &args);
2585             } else {
2586                 syntax_error("unknown 'flashing' command %s", args[0].c_str());
2587             }
2588         } else if (command == FB_CMD_CREATE_PARTITION) {
2589             std::string partition = next_arg(&args);
2590             std::string size = next_arg(&args);
2591             fb->CreatePartition(partition, size);
2592         } else if (command == FB_CMD_DELETE_PARTITION) {
2593             std::string partition = next_arg(&args);
2594             tasks.emplace_back(std::make_unique<DeleteTask>(fp.get(), partition));
2595         } else if (command == FB_CMD_RESIZE_PARTITION) {
2596             std::string partition = next_arg(&args);
2597             std::string size = next_arg(&args);
2598             std::unique_ptr<ResizeTask> resize_task =
2599                     std::make_unique<ResizeTask>(fp.get(), partition, size, fp->slot_override);
2600             resize_task->Run();
2601         } else if (command == "gsi") {
2602             if (args.empty()) syntax_error("invalid gsi command");
2603             std::string cmd("gsi");
2604             while (!args.empty()) {
2605                 cmd += ":" + next_arg(&args);
2606             }
2607             fb->RawCommand(cmd, "");
2608         } else if (command == "wipe-super") {
2609             std::string image;
2610             if (args.empty()) {
2611                 image = find_item_given_name("super_empty.img");
2612             } else {
2613                 image = next_arg(&args);
2614             }
2615             do_wipe_super(image, fp->slot_override, fp.get());
2616         } else if (command == "snapshot-update") {
2617             std::string arg;
2618             if (!args.empty()) {
2619                 arg = next_arg(&args);
2620             }
2621             if (!arg.empty() && (arg != "cancel" && arg != "merge")) {
2622                 syntax_error("expected: snapshot-update [cancel|merge]");
2623             }
2624             fb->SnapshotUpdateCommand(arg);
2625         } else if (command == FB_CMD_FETCH) {
2626             std::string partition = next_arg(&args);
2627             std::string outfile = next_arg(&args);
2628             do_fetch(partition, fp->slot_override, outfile, fp->fb);
2629         } else {
2630             syntax_error("unknown command %s", command.c_str());
2631         }
2632     }
2633 
2634     if (fp->wants_wipe) {
2635         if (fp->force_flash) {
2636             CancelSnapshotIfNeeded();
2637         }
2638         std::vector<std::unique_ptr<Task>> wipe_tasks;
2639         std::vector<std::string> partitions = {"userdata", "cache", "metadata"};
2640         for (const auto& partition : partitions) {
2641             wipe_tasks.emplace_back(std::make_unique<WipeTask>(fp.get(), partition));
2642         }
2643         tasks.insert(tasks.begin(), std::make_move_iterator(wipe_tasks.begin()),
2644                      std::make_move_iterator(wipe_tasks.end()));
2645     }
2646     if (fp->wants_set_active) {
2647         fb->SetActive(next_active);
2648     }
2649     for (auto& task : tasks) {
2650         task->Run();
2651     }
2652     fprintf(stderr, "Finished. Total time: %.3fs\n", (now() - start));
2653 
2654     return 0;
2655 }
2656 
ParseOsPatchLevel(boot_img_hdr_v1 * hdr,const char * arg)2657 void FastBootTool::ParseOsPatchLevel(boot_img_hdr_v1* hdr, const char* arg) {
2658     unsigned year, month, day;
2659     if (sscanf(arg, "%u-%u-%u", &year, &month, &day) != 3) {
2660         syntax_error("OS patch level should be YYYY-MM-DD: %s", arg);
2661     }
2662     if (year < 2000 || year >= 2128) syntax_error("year out of range: %d", year);
2663     if (month < 1 || month > 12) syntax_error("month out of range: %d", month);
2664     hdr->SetOsPatchLevel(year, month);
2665 }
2666 
ParseOsVersion(boot_img_hdr_v1 * hdr,const char * arg)2667 void FastBootTool::ParseOsVersion(boot_img_hdr_v1* hdr, const char* arg) {
2668     unsigned major = 0, minor = 0, patch = 0;
2669     std::vector<std::string> versions = android::base::Split(arg, ".");
2670     if (versions.size() < 1 || versions.size() > 3 ||
2671         (versions.size() >= 1 && !android::base::ParseUint(versions[0], &major)) ||
2672         (versions.size() >= 2 && !android::base::ParseUint(versions[1], &minor)) ||
2673         (versions.size() == 3 && !android::base::ParseUint(versions[2], &patch)) ||
2674         (major > 0x7f || minor > 0x7f || patch > 0x7f)) {
2675         syntax_error("bad OS version: %s", arg);
2676     }
2677     hdr->SetOsVersion(major, minor, patch);
2678 }
2679 
ParseFsOption(const char * arg)2680 unsigned FastBootTool::ParseFsOption(const char* arg) {
2681     unsigned fsOptions = 0;
2682 
2683     std::vector<std::string> options = android::base::Split(arg, ",");
2684     if (options.size() < 1) syntax_error("bad options: %s", arg);
2685 
2686     for (size_t i = 0; i < options.size(); ++i) {
2687         if (options[i] == "casefold")
2688             fsOptions |= (1 << FS_OPT_CASEFOLD);
2689         else if (options[i] == "projid")
2690             fsOptions |= (1 << FS_OPT_PROJID);
2691         else if (options[i] == "compress")
2692             fsOptions |= (1 << FS_OPT_COMPRESS);
2693         else
2694             syntax_error("unsupported options: %s", options[i].c_str());
2695     }
2696     return fsOptions;
2697 }
2698