1 //
2 // Copyright (C) 2015 The Android Open Source Project
3 //
4 // Licensed under the Apache License, Version 2.0 (the "License");
5 // you may not use this file except in compliance with the License.
6 // You may obtain a copy of the License at
7 //
8 // http://www.apache.org/licenses/LICENSE-2.0
9 //
10 // Unless required by applicable law or agreed to in writing, software
11 // distributed under the License is distributed on an "AS IS" BASIS,
12 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 // See the License for the specific language governing permissions and
14 // limitations under the License.
15 //
16
17 #include "update_engine/payload_generator/payload_file.h"
18
19 #include <endian.h>
20
21 #include <algorithm>
22 #include <map>
23 #include <utility>
24
25 #include <base/strings/stringprintf.h>
26
27 #include "update_engine/common/hash_calculator.h"
28 #include "update_engine/common/utils.h"
29 #include "update_engine/payload_consumer/file_writer.h"
30 #include "update_engine/payload_consumer/payload_constants.h"
31 #include "update_engine/payload_generator/annotated_operation.h"
32 #include "update_engine/payload_generator/delta_diff_utils.h"
33 #include "update_engine/payload_generator/payload_signer.h"
34
35 using std::string;
36 using std::vector;
37
38 namespace chromeos_update_engine {
39
40 namespace {
41
42 struct DeltaObject {
DeltaObjectchromeos_update_engine::__anon3fa7f6d60111::DeltaObject43 DeltaObject(const string& in_name, const int in_type, const off_t in_size)
44 : name(in_name), type(in_type), size(in_size) {}
operator <chromeos_update_engine::__anon3fa7f6d60111::DeltaObject45 bool operator<(const DeltaObject& object) const {
46 return (size != object.size) ? (size < object.size) : (name < object.name);
47 }
48 string name;
49 int type;
50 off_t size;
51 };
52
53 // Writes the uint64_t passed in in host-endian to the file as big-endian.
54 // Returns true on success.
WriteUint64AsBigEndian(FileWriter * writer,const uint64_t value)55 bool WriteUint64AsBigEndian(FileWriter* writer, const uint64_t value) {
56 uint64_t value_be = htobe64(value);
57 TEST_AND_RETURN_FALSE(writer->Write(&value_be, sizeof(value_be)));
58 return true;
59 }
60
61 } // namespace
62
Init(const PayloadGenerationConfig & config)63 bool PayloadFile::Init(const PayloadGenerationConfig& config) {
64 TEST_AND_RETURN_FALSE(config.version.Validate());
65 major_version_ = config.version.major;
66 manifest_.set_minor_version(config.version.minor);
67 manifest_.set_block_size(config.block_size);
68 manifest_.set_max_timestamp(config.max_timestamp);
69 if (!config.security_patch_level.empty()) {
70 manifest_.set_security_patch_level(config.security_patch_level);
71 }
72
73 if (config.target.dynamic_partition_metadata != nullptr)
74 *(manifest_.mutable_dynamic_partition_metadata()) =
75 *(config.target.dynamic_partition_metadata);
76
77 if (config.is_partial_update) {
78 manifest_.set_partial_update(true);
79 }
80
81 if (!config.apex_info_file.empty()) {
82 ApexMetadata apex_metadata;
83 int fd = open(config.apex_info_file.c_str(), O_RDONLY);
84 if (fd < 0) {
85 PLOG(FATAL) << "Failed to open " << config.apex_info_file << " for read.";
86 }
87 ScopedFdCloser closer{&fd};
88 CHECK(apex_metadata.ParseFromFileDescriptor(fd));
89 if (apex_metadata.apex_info_size() > 0) {
90 *manifest_.mutable_apex_info() =
91 std::move(*apex_metadata.mutable_apex_info());
92 }
93 }
94 return true;
95 }
96
AddPartition(const PartitionConfig & old_conf,const PartitionConfig & new_conf,vector<AnnotatedOperation> aops,vector<CowMergeOperation> merge_sequence,const android::snapshot::CowSizeInfo & cow_info)97 bool PayloadFile::AddPartition(const PartitionConfig& old_conf,
98 const PartitionConfig& new_conf,
99 vector<AnnotatedOperation> aops,
100 vector<CowMergeOperation> merge_sequence,
101 const android::snapshot::CowSizeInfo& cow_info) {
102 Partition part;
103 part.name = new_conf.name;
104 part.aops = std::move(aops);
105 part.cow_merge_sequence = std::move(merge_sequence);
106 part.postinstall = new_conf.postinstall;
107 part.verity = new_conf.verity;
108 part.version = new_conf.version;
109 part.cow_info = cow_info;
110 // Initialize the PartitionInfo objects if present.
111 if (!old_conf.path.empty())
112 TEST_AND_RETURN_FALSE(
113 diff_utils::InitializePartitionInfo(old_conf, &part.old_info));
114 TEST_AND_RETURN_FALSE(
115 diff_utils::InitializePartitionInfo(new_conf, &part.new_info));
116 part_vec_.push_back(std::move(part));
117 return true;
118 }
119
WritePayload(const string & payload_file,const string & data_blobs_path,const string & private_key_path,uint64_t * metadata_size_out)120 bool PayloadFile::WritePayload(const string& payload_file,
121 const string& data_blobs_path,
122 const string& private_key_path,
123 uint64_t* metadata_size_out) {
124 // Reorder the data blobs with the manifest_.
125 ScopedTempFile ordered_blobs_file("CrAU_temp_data.ordered.XXXXXX");
126 TEST_AND_RETURN_FALSE(
127 ReorderDataBlobs(data_blobs_path, ordered_blobs_file.path()));
128
129 // Check that install op blobs are in order.
130 uint64_t next_blob_offset = 0;
131 for (const auto& part : part_vec_) {
132 for (const auto& aop : part.aops) {
133 if (!aop.op.has_data_offset())
134 continue;
135 if (aop.op.data_offset() != next_blob_offset) {
136 LOG(FATAL) << "bad blob offset! " << aop.op.data_offset()
137 << " != " << next_blob_offset;
138 }
139 next_blob_offset += aop.op.data_length();
140 }
141 }
142
143 // Copy the operations and partition info from the part_vec_ to the manifest.
144 manifest_.clear_partitions();
145 for (const auto& part : part_vec_) {
146 PartitionUpdate* partition = manifest_.add_partitions();
147 partition->set_partition_name(part.name);
148 if (!part.version.empty()) {
149 partition->set_version(part.version);
150 }
151 if (part.cow_info.cow_size > 0) {
152 partition->set_estimate_cow_size(part.cow_info.cow_size);
153 }
154 if (part.cow_info.op_count_max > 0) {
155 partition->set_estimate_op_count_max(part.cow_info.op_count_max);
156 }
157 if (part.postinstall.run) {
158 partition->set_run_postinstall(true);
159 if (!part.postinstall.path.empty())
160 partition->set_postinstall_path(part.postinstall.path);
161 if (!part.postinstall.filesystem_type.empty())
162 partition->set_filesystem_type(part.postinstall.filesystem_type);
163 partition->set_postinstall_optional(part.postinstall.optional);
164 }
165 if (!part.verity.IsEmpty()) {
166 if (part.verity.hash_tree_extent.num_blocks() != 0) {
167 *partition->mutable_hash_tree_data_extent() =
168 part.verity.hash_tree_data_extent;
169 *partition->mutable_hash_tree_extent() = part.verity.hash_tree_extent;
170 partition->set_hash_tree_algorithm(part.verity.hash_tree_algorithm);
171 if (!part.verity.hash_tree_salt.empty())
172 partition->set_hash_tree_salt(part.verity.hash_tree_salt.data(),
173 part.verity.hash_tree_salt.size());
174 }
175 if (part.verity.fec_extent.num_blocks() != 0) {
176 *partition->mutable_fec_data_extent() = part.verity.fec_data_extent;
177 *partition->mutable_fec_extent() = part.verity.fec_extent;
178 partition->set_fec_roots(part.verity.fec_roots);
179 }
180 }
181 for (const AnnotatedOperation& aop : part.aops) {
182 *partition->add_operations() = aop.op;
183 }
184 for (const auto& merge_op : part.cow_merge_sequence) {
185 *partition->add_merge_operations() = merge_op;
186 }
187
188 if (part.old_info.has_size() || part.old_info.has_hash())
189 *(partition->mutable_old_partition_info()) = part.old_info;
190 if (part.new_info.has_size() || part.new_info.has_hash())
191 *(partition->mutable_new_partition_info()) = part.new_info;
192 }
193
194 // Signatures appear at the end of the blobs. Note the offset in the
195 // |manifest_|.
196 uint64_t signature_blob_length = 0;
197 if (!private_key_path.empty()) {
198 TEST_AND_RETURN_FALSE(PayloadSigner::SignatureBlobLength(
199 {private_key_path}, &signature_blob_length));
200 PayloadSigner::AddSignatureToManifest(
201 next_blob_offset, signature_blob_length, &manifest_);
202 }
203 WritePayload(payload_file,
204 ordered_blobs_file.path(),
205 private_key_path,
206 major_version_,
207 manifest_,
208 metadata_size_out);
209
210 ReportPayloadUsage(*metadata_size_out);
211 return true;
212 }
213
WritePayload(const std::string & payload_file,const std::string & ordered_blobs_file,const std::string & private_key_path,uint64_t major_version_,const DeltaArchiveManifest & manifest,uint64_t * metadata_size_out)214 bool PayloadFile::WritePayload(const std::string& payload_file,
215 const std::string& ordered_blobs_file,
216 const std::string& private_key_path,
217 uint64_t major_version_,
218 const DeltaArchiveManifest& manifest,
219 uint64_t* metadata_size_out) {
220 std::string serialized_manifest;
221
222 TEST_AND_RETURN_FALSE(manifest.SerializeToString(&serialized_manifest));
223 uint64_t metadata_size =
224 sizeof(kDeltaMagic) + 2 * sizeof(uint64_t) + serialized_manifest.size();
225 LOG(INFO) << "Writing final delta file header...";
226 DirectFileWriter writer;
227 TEST_AND_RETURN_FALSE_ERRNO(writer.Open(payload_file.c_str(),
228 O_WRONLY | O_CREAT | O_TRUNC,
229 0644) == 0);
230 ScopedFileWriterCloser writer_closer(&writer);
231
232 // Write header
233 TEST_AND_RETURN_FALSE_ERRNO(writer.Write(kDeltaMagic, sizeof(kDeltaMagic)));
234
235 // Write major version number
236 TEST_AND_RETURN_FALSE(WriteUint64AsBigEndian(&writer, major_version_));
237
238 // Write protobuf length
239 TEST_AND_RETURN_FALSE(
240 WriteUint64AsBigEndian(&writer, serialized_manifest.size()));
241
242 // Metadata signature has the same size as payload signature, because they
243 // are both the same kind of signature for the same kind of hash.
244 const auto signature_blob_length = manifest.signatures_size();
245 // Adding a new scope here so code down below can't access
246 // metadata_signature_size, as the integer is in big endian, not host
247 // endianess.
248 {
249 const uint32_t metadata_signature_size = htobe32(signature_blob_length);
250 TEST_AND_RETURN_FALSE_ERRNO(writer.Write(&metadata_signature_size,
251 sizeof(metadata_signature_size)));
252 metadata_size += sizeof(metadata_signature_size);
253 }
254
255 // Write protobuf
256 LOG(INFO) << "Writing final delta file protobuf... "
257 << serialized_manifest.size();
258 TEST_AND_RETURN_FALSE_ERRNO(
259 writer.Write(serialized_manifest.data(), serialized_manifest.size()));
260
261 // Write metadata signature blob.
262 if (!private_key_path.empty()) {
263 brillo::Blob metadata_hash;
264 TEST_AND_RETURN_FALSE(HashCalculator::RawHashOfFile(
265 payload_file, metadata_size, &metadata_hash));
266 string metadata_signature;
267 TEST_AND_RETURN_FALSE(PayloadSigner::SignHashWithKeys(
268 metadata_hash, {private_key_path}, &metadata_signature));
269 TEST_AND_RETURN_FALSE_ERRNO(
270 writer.Write(metadata_signature.data(), metadata_signature.size()));
271 }
272
273 // Append the data blobs.
274 LOG(INFO) << "Writing final delta file data blobs...";
275 int blobs_fd = open(ordered_blobs_file.c_str(), O_RDONLY, 0);
276 ScopedFdCloser blobs_fd_closer(&blobs_fd);
277 TEST_AND_RETURN_FALSE(blobs_fd >= 0);
278 for (;;) {
279 vector<char> buf(1024 * 1024);
280 ssize_t rc = read(blobs_fd, buf.data(), buf.size());
281 if (0 == rc) {
282 // EOF
283 break;
284 }
285 TEST_AND_RETURN_FALSE_ERRNO(rc > 0);
286 TEST_AND_RETURN_FALSE_ERRNO(writer.Write(buf.data(), rc));
287 }
288 // Write payload signature blob.
289 if (!private_key_path.empty()) {
290 LOG(INFO) << "Signing the update...";
291 string signature;
292 TEST_AND_RETURN_FALSE(PayloadSigner::SignPayload(
293 payload_file,
294 {private_key_path},
295 metadata_size,
296 signature_blob_length,
297 metadata_size + signature_blob_length + manifest.signatures_offset(),
298 &signature));
299 TEST_AND_RETURN_FALSE_ERRNO(
300 writer.Write(signature.data(), signature.size()));
301 }
302 if (metadata_size_out) {
303 *metadata_size_out = metadata_size;
304 }
305 return true;
306 }
307
ReorderDataBlobs(const string & data_blobs_path,const string & new_data_blobs_path)308 bool PayloadFile::ReorderDataBlobs(const string& data_blobs_path,
309 const string& new_data_blobs_path) {
310 int in_fd = open(data_blobs_path.c_str(), O_RDONLY, 0);
311 TEST_AND_RETURN_FALSE_ERRNO(in_fd >= 0);
312 ScopedFdCloser in_fd_closer(&in_fd);
313
314 DirectFileWriter writer;
315 int rc = writer.Open(
316 new_data_blobs_path.c_str(), O_WRONLY | O_TRUNC | O_CREAT, 0644);
317 if (rc != 0) {
318 PLOG(ERROR) << "Error creating " << new_data_blobs_path;
319 return false;
320 }
321 ScopedFileWriterCloser writer_closer(&writer);
322 uint64_t out_file_size = 0;
323
324 for (auto& part : part_vec_) {
325 for (AnnotatedOperation& aop : part.aops) {
326 if (!aop.op.has_data_offset())
327 continue;
328 CHECK(aop.op.has_data_length());
329 brillo::Blob buf(aop.op.data_length());
330 ssize_t rc = pread(in_fd, buf.data(), buf.size(), aop.op.data_offset());
331 TEST_AND_RETURN_FALSE(rc == static_cast<ssize_t>(buf.size()));
332
333 // Add the hash of the data blobs for this operation
334 TEST_AND_RETURN_FALSE(AddOperationHash(&aop.op, buf));
335
336 aop.op.set_data_offset(out_file_size);
337 TEST_AND_RETURN_FALSE_ERRNO(writer.Write(buf.data(), buf.size()));
338 out_file_size += buf.size();
339 }
340 }
341 return true;
342 }
343
AddOperationHash(InstallOperation * op,const brillo::Blob & buf)344 bool PayloadFile::AddOperationHash(InstallOperation* op,
345 const brillo::Blob& buf) {
346 brillo::Blob hash;
347 TEST_AND_RETURN_FALSE(HashCalculator::RawHashOfData(buf, &hash));
348 op->set_data_sha256_hash(hash.data(), hash.size());
349 return true;
350 }
351
ReportPayloadUsage(uint64_t metadata_size) const352 void PayloadFile::ReportPayloadUsage(uint64_t metadata_size) const {
353 std::map<DeltaObject, int> object_counts;
354 off_t total_size = 0;
355 int total_op = 0;
356
357 for (const auto& part : part_vec_) {
358 string part_prefix = "<" + part.name + ">:";
359 for (const AnnotatedOperation& aop : part.aops) {
360 DeltaObject delta(
361 part_prefix + aop.name, aop.op.type(), aop.op.data_length());
362 object_counts[delta]++;
363 total_size += aop.op.data_length();
364 }
365 total_op += part.aops.size();
366 }
367
368 object_counts[DeltaObject("<manifest-metadata>", -1, metadata_size)] = 1;
369 total_size += metadata_size;
370
371 constexpr char kFormatString[] = "%6.2f%% %10jd %-13s %s %d\n";
372 for (const auto& object_count : object_counts) {
373 const DeltaObject& object = object_count.first;
374 // Use printf() instead of LOG(INFO) because timestamp makes it difficult to
375 // compare two reports.
376 printf(kFormatString,
377 object.size * 100.0 / total_size,
378 object.size,
379 (object.type >= 0
380 ? InstallOperationTypeName(
381 static_cast<InstallOperation::Type>(object.type))
382 : "-"),
383 object.name.c_str(),
384 object_count.second);
385 }
386 printf(kFormatString, 100.0, total_size, "", "<total>", total_op);
387 fflush(stdout);
388 }
389
390 } // namespace chromeos_update_engine
391