1*4882a593Smuzhiyun#!/usr/bin/env python3 2*4882a593Smuzhiyun# 3*4882a593Smuzhiyun# Copyright 2018, The Android Open Source Project 4*4882a593Smuzhiyun# 5*4882a593Smuzhiyun# Licensed under the Apache License, Version 2.0 (the "License"); 6*4882a593Smuzhiyun# you may not use this file except in compliance with the License. 7*4882a593Smuzhiyun# You may obtain a copy of the License at 8*4882a593Smuzhiyun# 9*4882a593Smuzhiyun# http://www.apache.org/licenses/LICENSE-2.0 10*4882a593Smuzhiyun# 11*4882a593Smuzhiyun# Unless required by applicable law or agreed to in writing, software 12*4882a593Smuzhiyun# distributed under the License is distributed on an "AS IS" BASIS, 13*4882a593Smuzhiyun# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 14*4882a593Smuzhiyun# See the License for the specific language governing permissions and 15*4882a593Smuzhiyun# limitations under the License. 16*4882a593Smuzhiyun 17*4882a593Smuzhiyun"""Unpacks the boot image. 18*4882a593Smuzhiyun 19*4882a593SmuzhiyunExtracts the kernel, ramdisk, second bootloader, dtb and recovery dtbo images. 20*4882a593Smuzhiyun""" 21*4882a593Smuzhiyun 22*4882a593Smuzhiyunfrom argparse import ArgumentParser, RawDescriptionHelpFormatter 23*4882a593Smuzhiyunfrom struct import unpack 24*4882a593Smuzhiyunimport os 25*4882a593Smuzhiyunimport shlex 26*4882a593Smuzhiyun 27*4882a593SmuzhiyunBOOT_IMAGE_HEADER_V3_PAGESIZE = 4096 28*4882a593SmuzhiyunVENDOR_RAMDISK_NAME_SIZE = 32 29*4882a593SmuzhiyunVENDOR_RAMDISK_TABLE_ENTRY_BOARD_ID_SIZE = 16 30*4882a593Smuzhiyun 31*4882a593Smuzhiyun 32*4882a593Smuzhiyundef create_out_dir(dir_path): 33*4882a593Smuzhiyun """creates a directory 'dir_path' if it does not exist""" 34*4882a593Smuzhiyun if not os.path.exists(dir_path): 35*4882a593Smuzhiyun os.makedirs(dir_path) 36*4882a593Smuzhiyun 37*4882a593Smuzhiyun 38*4882a593Smuzhiyundef extract_image(offset, size, bootimage, extracted_image_name): 39*4882a593Smuzhiyun """extracts an image from the bootimage""" 40*4882a593Smuzhiyun bootimage.seek(offset) 41*4882a593Smuzhiyun with open(extracted_image_name, 'wb') as file_out: 42*4882a593Smuzhiyun file_out.write(bootimage.read(size)) 43*4882a593Smuzhiyun 44*4882a593Smuzhiyun 45*4882a593Smuzhiyundef get_number_of_pages(image_size, page_size): 46*4882a593Smuzhiyun """calculates the number of pages required for the image""" 47*4882a593Smuzhiyun return (image_size + page_size - 1) // page_size 48*4882a593Smuzhiyun 49*4882a593Smuzhiyun 50*4882a593Smuzhiyundef cstr(s): 51*4882a593Smuzhiyun """Remove first NULL character and any character beyond.""" 52*4882a593Smuzhiyun return s.split('\0', 1)[0] 53*4882a593Smuzhiyun 54*4882a593Smuzhiyun 55*4882a593Smuzhiyundef format_os_version(os_version): 56*4882a593Smuzhiyun if os_version == 0: 57*4882a593Smuzhiyun return None 58*4882a593Smuzhiyun a = os_version >> 14 59*4882a593Smuzhiyun b = os_version >> 7 & ((1<<7) - 1) 60*4882a593Smuzhiyun c = os_version & ((1<<7) - 1) 61*4882a593Smuzhiyun return f'{a}.{b}.{c}' 62*4882a593Smuzhiyun 63*4882a593Smuzhiyun 64*4882a593Smuzhiyundef format_os_patch_level(os_patch_level): 65*4882a593Smuzhiyun if os_patch_level == 0: 66*4882a593Smuzhiyun return None 67*4882a593Smuzhiyun y = os_patch_level >> 4 68*4882a593Smuzhiyun y += 2000 69*4882a593Smuzhiyun m = os_patch_level & ((1<<4) - 1) 70*4882a593Smuzhiyun return f'{y:04d}-{m:02d}' 71*4882a593Smuzhiyun 72*4882a593Smuzhiyun 73*4882a593Smuzhiyundef decode_os_version_patch_level(os_version_patch_level): 74*4882a593Smuzhiyun """Returns a tuple of (os_version, os_patch_level).""" 75*4882a593Smuzhiyun os_version = os_version_patch_level >> 11 76*4882a593Smuzhiyun os_patch_level = os_version_patch_level & ((1<<11) - 1) 77*4882a593Smuzhiyun return (format_os_version(os_version), 78*4882a593Smuzhiyun format_os_patch_level(os_patch_level)) 79*4882a593Smuzhiyun 80*4882a593Smuzhiyun 81*4882a593Smuzhiyunclass BootImageInfoFormatter: 82*4882a593Smuzhiyun """Formats the boot image info.""" 83*4882a593Smuzhiyun 84*4882a593Smuzhiyun def format_pretty_text(self): 85*4882a593Smuzhiyun lines = [] 86*4882a593Smuzhiyun lines.append(f'boot magic: {self.boot_magic}') 87*4882a593Smuzhiyun 88*4882a593Smuzhiyun if self.header_version < 3: 89*4882a593Smuzhiyun lines.append(f'kernel_size: {self.kernel_size}') 90*4882a593Smuzhiyun lines.append( 91*4882a593Smuzhiyun f'kernel load address: {self.kernel_load_address:#010x}') 92*4882a593Smuzhiyun lines.append(f'ramdisk size: {self.ramdisk_size}') 93*4882a593Smuzhiyun lines.append( 94*4882a593Smuzhiyun f'ramdisk load address: {self.ramdisk_load_address:#010x}') 95*4882a593Smuzhiyun lines.append(f'second bootloader size: {self.second_size}') 96*4882a593Smuzhiyun lines.append( 97*4882a593Smuzhiyun f'second bootloader load address: ' 98*4882a593Smuzhiyun f'{self.second_load_address:#010x}') 99*4882a593Smuzhiyun lines.append( 100*4882a593Smuzhiyun f'kernel tags load address: {self.tags_load_address:#010x}') 101*4882a593Smuzhiyun lines.append(f'page size: {self.page_size}') 102*4882a593Smuzhiyun else: 103*4882a593Smuzhiyun lines.append(f'kernel_size: {self.kernel_size}') 104*4882a593Smuzhiyun lines.append(f'ramdisk size: {self.ramdisk_size}') 105*4882a593Smuzhiyun 106*4882a593Smuzhiyun lines.append(f'os version: {self.os_version}') 107*4882a593Smuzhiyun lines.append(f'os patch level: {self.os_patch_level}') 108*4882a593Smuzhiyun lines.append(f'boot image header version: {self.header_version}') 109*4882a593Smuzhiyun 110*4882a593Smuzhiyun if self.header_version < 3: 111*4882a593Smuzhiyun lines.append(f'product name: {self.product_name}') 112*4882a593Smuzhiyun 113*4882a593Smuzhiyun lines.append(f'command line args: {self.cmdline}') 114*4882a593Smuzhiyun 115*4882a593Smuzhiyun if self.header_version < 3: 116*4882a593Smuzhiyun lines.append(f'additional command line args: {self.extra_cmdline}') 117*4882a593Smuzhiyun 118*4882a593Smuzhiyun if self.header_version in {1, 2}: 119*4882a593Smuzhiyun lines.append(f'recovery dtbo size: {self.recovery_dtbo_size}') 120*4882a593Smuzhiyun lines.append( 121*4882a593Smuzhiyun f'recovery dtbo offset: {self.recovery_dtbo_offset:#018x}') 122*4882a593Smuzhiyun lines.append(f'boot header size: {self.boot_header_size}') 123*4882a593Smuzhiyun 124*4882a593Smuzhiyun if self.header_version == 2: 125*4882a593Smuzhiyun lines.append(f'dtb size: {self.dtb_size}') 126*4882a593Smuzhiyun lines.append(f'dtb address: {self.dtb_load_address:#018x}') 127*4882a593Smuzhiyun 128*4882a593Smuzhiyun if self.header_version >= 4: 129*4882a593Smuzhiyun lines.append( 130*4882a593Smuzhiyun f'boot.img signature size: {self.boot_signature_size}') 131*4882a593Smuzhiyun 132*4882a593Smuzhiyun return '\n'.join(lines) 133*4882a593Smuzhiyun 134*4882a593Smuzhiyun def format_mkbootimg_argument(self): 135*4882a593Smuzhiyun args = [] 136*4882a593Smuzhiyun args.extend(['--header_version', str(self.header_version)]) 137*4882a593Smuzhiyun if self.os_version: 138*4882a593Smuzhiyun args.extend(['--os_version', self.os_version]) 139*4882a593Smuzhiyun if self.os_patch_level: 140*4882a593Smuzhiyun args.extend(['--os_patch_level', self.os_patch_level]) 141*4882a593Smuzhiyun 142*4882a593Smuzhiyun args.extend(['--kernel', os.path.join(self.image_dir, 'kernel')]) 143*4882a593Smuzhiyun args.extend(['--ramdisk', os.path.join(self.image_dir, 'ramdisk')]) 144*4882a593Smuzhiyun 145*4882a593Smuzhiyun if self.header_version <= 2: 146*4882a593Smuzhiyun if self.second_size > 0: 147*4882a593Smuzhiyun args.extend(['--second', 148*4882a593Smuzhiyun os.path.join(self.image_dir, 'second')]) 149*4882a593Smuzhiyun if self.recovery_dtbo_size > 0: 150*4882a593Smuzhiyun args.extend(['--recovery_dtbo', 151*4882a593Smuzhiyun os.path.join(self.image_dir, 'recovery_dtbo')]) 152*4882a593Smuzhiyun if self.dtb_size > 0: 153*4882a593Smuzhiyun args.extend(['--dtb', os.path.join(self.image_dir, 'dtb')]) 154*4882a593Smuzhiyun 155*4882a593Smuzhiyun args.extend(['--pagesize', f'{self.page_size:#010x}']) 156*4882a593Smuzhiyun 157*4882a593Smuzhiyun # Kernel load address is base + kernel_offset in mkbootimg.py. 158*4882a593Smuzhiyun # However we don't know the value of 'base' when unpacking a boot 159*4882a593Smuzhiyun # image in this script, so we set 'base' to zero and 'kernel_offset' 160*4882a593Smuzhiyun # to the kernel load address, 'ramdisk_offset' to the ramdisk load 161*4882a593Smuzhiyun # address, ... etc. 162*4882a593Smuzhiyun args.extend(['--base', f'{0:#010x}']) 163*4882a593Smuzhiyun args.extend(['--kernel_offset', 164*4882a593Smuzhiyun f'{self.kernel_load_address:#010x}']) 165*4882a593Smuzhiyun args.extend(['--ramdisk_offset', 166*4882a593Smuzhiyun f'{self.ramdisk_load_address:#010x}']) 167*4882a593Smuzhiyun args.extend(['--second_offset', 168*4882a593Smuzhiyun f'{self.second_load_address:#010x}']) 169*4882a593Smuzhiyun args.extend(['--tags_offset', f'{self.tags_load_address:#010x}']) 170*4882a593Smuzhiyun 171*4882a593Smuzhiyun # dtb is added in boot image v2, and is absent in v1 or v0. 172*4882a593Smuzhiyun if self.header_version == 2: 173*4882a593Smuzhiyun # dtb_offset is uint64_t. 174*4882a593Smuzhiyun args.extend(['--dtb_offset', f'{self.dtb_load_address:#018x}']) 175*4882a593Smuzhiyun 176*4882a593Smuzhiyun args.extend(['--board', self.product_name]) 177*4882a593Smuzhiyun args.extend(['--cmdline', self.cmdline + self.extra_cmdline]) 178*4882a593Smuzhiyun else: 179*4882a593Smuzhiyun args.extend(['--cmdline', self.cmdline]) 180*4882a593Smuzhiyun 181*4882a593Smuzhiyun return args 182*4882a593Smuzhiyun 183*4882a593Smuzhiyun 184*4882a593Smuzhiyundef unpack_boot_image(boot_img, output_dir): 185*4882a593Smuzhiyun """extracts kernel, ramdisk, second bootloader and recovery dtbo""" 186*4882a593Smuzhiyun info = BootImageInfoFormatter() 187*4882a593Smuzhiyun info.boot_magic = unpack('8s', boot_img.read(8))[0].decode() 188*4882a593Smuzhiyun 189*4882a593Smuzhiyun kernel_ramdisk_second_info = unpack('9I', boot_img.read(9 * 4)) 190*4882a593Smuzhiyun # header_version is always at [8] regardless of the value of header_version. 191*4882a593Smuzhiyun info.header_version = kernel_ramdisk_second_info[8] 192*4882a593Smuzhiyun 193*4882a593Smuzhiyun if info.header_version < 3: 194*4882a593Smuzhiyun info.kernel_size = kernel_ramdisk_second_info[0] 195*4882a593Smuzhiyun info.kernel_load_address = kernel_ramdisk_second_info[1] 196*4882a593Smuzhiyun info.ramdisk_size = kernel_ramdisk_second_info[2] 197*4882a593Smuzhiyun info.ramdisk_load_address = kernel_ramdisk_second_info[3] 198*4882a593Smuzhiyun info.second_size = kernel_ramdisk_second_info[4] 199*4882a593Smuzhiyun info.second_load_address = kernel_ramdisk_second_info[5] 200*4882a593Smuzhiyun info.tags_load_address = kernel_ramdisk_second_info[6] 201*4882a593Smuzhiyun info.page_size = kernel_ramdisk_second_info[7] 202*4882a593Smuzhiyun os_version_patch_level = unpack('I', boot_img.read(1 * 4))[0] 203*4882a593Smuzhiyun else: 204*4882a593Smuzhiyun info.kernel_size = kernel_ramdisk_second_info[0] 205*4882a593Smuzhiyun info.ramdisk_size = kernel_ramdisk_second_info[1] 206*4882a593Smuzhiyun os_version_patch_level = kernel_ramdisk_second_info[2] 207*4882a593Smuzhiyun info.second_size = 0 208*4882a593Smuzhiyun info.page_size = BOOT_IMAGE_HEADER_V3_PAGESIZE 209*4882a593Smuzhiyun 210*4882a593Smuzhiyun info.os_version, info.os_patch_level = decode_os_version_patch_level( 211*4882a593Smuzhiyun os_version_patch_level) 212*4882a593Smuzhiyun 213*4882a593Smuzhiyun if info.header_version < 3: 214*4882a593Smuzhiyun info.product_name = cstr(unpack('16s', 215*4882a593Smuzhiyun boot_img.read(16))[0].decode()) 216*4882a593Smuzhiyun info.cmdline = cstr(unpack('512s', boot_img.read(512))[0].decode()) 217*4882a593Smuzhiyun boot_img.read(32) # ignore SHA 218*4882a593Smuzhiyun info.extra_cmdline = cstr(unpack('1024s', 219*4882a593Smuzhiyun boot_img.read(1024))[0].decode()) 220*4882a593Smuzhiyun else: 221*4882a593Smuzhiyun info.cmdline = cstr(unpack('1536s', 222*4882a593Smuzhiyun boot_img.read(1536))[0].decode()) 223*4882a593Smuzhiyun 224*4882a593Smuzhiyun if info.header_version in {1, 2}: 225*4882a593Smuzhiyun info.recovery_dtbo_size = unpack('I', boot_img.read(1 * 4))[0] 226*4882a593Smuzhiyun info.recovery_dtbo_offset = unpack('Q', boot_img.read(8))[0] 227*4882a593Smuzhiyun info.boot_header_size = unpack('I', boot_img.read(4))[0] 228*4882a593Smuzhiyun else: 229*4882a593Smuzhiyun info.recovery_dtbo_size = 0 230*4882a593Smuzhiyun 231*4882a593Smuzhiyun if info.header_version == 2: 232*4882a593Smuzhiyun info.dtb_size = unpack('I', boot_img.read(4))[0] 233*4882a593Smuzhiyun info.dtb_load_address = unpack('Q', boot_img.read(8))[0] 234*4882a593Smuzhiyun else: 235*4882a593Smuzhiyun info.dtb_size = 0 236*4882a593Smuzhiyun info.dtb_load_address = 0 237*4882a593Smuzhiyun 238*4882a593Smuzhiyun if info.header_version >= 4: 239*4882a593Smuzhiyun info.boot_signature_size = unpack('I', boot_img.read(4))[0] 240*4882a593Smuzhiyun else: 241*4882a593Smuzhiyun info.boot_signature_size = 0 242*4882a593Smuzhiyun 243*4882a593Smuzhiyun # The first page contains the boot header 244*4882a593Smuzhiyun num_header_pages = 1 245*4882a593Smuzhiyun 246*4882a593Smuzhiyun # Convenient shorthand. 247*4882a593Smuzhiyun page_size = info.page_size 248*4882a593Smuzhiyun 249*4882a593Smuzhiyun num_kernel_pages = get_number_of_pages(info.kernel_size, page_size) 250*4882a593Smuzhiyun kernel_offset = page_size * num_header_pages # header occupies a page 251*4882a593Smuzhiyun image_info_list = [(kernel_offset, info.kernel_size, 'kernel')] 252*4882a593Smuzhiyun 253*4882a593Smuzhiyun num_ramdisk_pages = get_number_of_pages(info.ramdisk_size, page_size) 254*4882a593Smuzhiyun ramdisk_offset = page_size * (num_header_pages + num_kernel_pages 255*4882a593Smuzhiyun ) # header + kernel 256*4882a593Smuzhiyun image_info_list.append((ramdisk_offset, info.ramdisk_size, 'ramdisk')) 257*4882a593Smuzhiyun 258*4882a593Smuzhiyun if info.second_size > 0: 259*4882a593Smuzhiyun second_offset = page_size * ( 260*4882a593Smuzhiyun num_header_pages + num_kernel_pages + num_ramdisk_pages 261*4882a593Smuzhiyun ) # header + kernel + ramdisk 262*4882a593Smuzhiyun image_info_list.append((second_offset, info.second_size, 'second')) 263*4882a593Smuzhiyun 264*4882a593Smuzhiyun if info.recovery_dtbo_size > 0: 265*4882a593Smuzhiyun image_info_list.append((info.recovery_dtbo_offset, 266*4882a593Smuzhiyun info.recovery_dtbo_size, 267*4882a593Smuzhiyun 'recovery_dtbo')) 268*4882a593Smuzhiyun if info.dtb_size > 0: 269*4882a593Smuzhiyun num_second_pages = get_number_of_pages(info.second_size, page_size) 270*4882a593Smuzhiyun num_recovery_dtbo_pages = get_number_of_pages( 271*4882a593Smuzhiyun info.recovery_dtbo_size, page_size) 272*4882a593Smuzhiyun dtb_offset = page_size * ( 273*4882a593Smuzhiyun num_header_pages + num_kernel_pages + num_ramdisk_pages + 274*4882a593Smuzhiyun num_second_pages + num_recovery_dtbo_pages) 275*4882a593Smuzhiyun 276*4882a593Smuzhiyun image_info_list.append((dtb_offset, info.dtb_size, 'dtb')) 277*4882a593Smuzhiyun 278*4882a593Smuzhiyun if info.boot_signature_size > 0: 279*4882a593Smuzhiyun # boot signature only exists in boot.img version >= v4. 280*4882a593Smuzhiyun # There are only kernel and ramdisk pages before the signature. 281*4882a593Smuzhiyun boot_signature_offset = page_size * ( 282*4882a593Smuzhiyun num_header_pages + num_kernel_pages + num_ramdisk_pages) 283*4882a593Smuzhiyun 284*4882a593Smuzhiyun image_info_list.append((boot_signature_offset, info.boot_signature_size, 285*4882a593Smuzhiyun 'boot_signature')) 286*4882a593Smuzhiyun 287*4882a593Smuzhiyun create_out_dir(output_dir) 288*4882a593Smuzhiyun for offset, size, name in image_info_list: 289*4882a593Smuzhiyun extract_image(offset, size, boot_img, os.path.join(output_dir, name)) 290*4882a593Smuzhiyun info.image_dir = output_dir 291*4882a593Smuzhiyun 292*4882a593Smuzhiyun return info 293*4882a593Smuzhiyun 294*4882a593Smuzhiyun 295*4882a593Smuzhiyunclass VendorBootImageInfoFormatter: 296*4882a593Smuzhiyun """Formats the vendor_boot image info.""" 297*4882a593Smuzhiyun 298*4882a593Smuzhiyun def format_pretty_text(self): 299*4882a593Smuzhiyun lines = [] 300*4882a593Smuzhiyun lines.append(f'boot magic: {self.boot_magic}') 301*4882a593Smuzhiyun lines.append(f'vendor boot image header version: {self.header_version}') 302*4882a593Smuzhiyun lines.append(f'page size: {self.page_size:#010x}') 303*4882a593Smuzhiyun lines.append(f'kernel load address: {self.kernel_load_address:#010x}') 304*4882a593Smuzhiyun lines.append(f'ramdisk load address: {self.ramdisk_load_address:#010x}') 305*4882a593Smuzhiyun if self.header_version > 3: 306*4882a593Smuzhiyun lines.append( 307*4882a593Smuzhiyun f'vendor ramdisk total size: {self.vendor_ramdisk_size}') 308*4882a593Smuzhiyun else: 309*4882a593Smuzhiyun lines.append(f'vendor ramdisk size: {self.vendor_ramdisk_size}') 310*4882a593Smuzhiyun lines.append(f'vendor command line args: {self.cmdline}') 311*4882a593Smuzhiyun lines.append( 312*4882a593Smuzhiyun f'kernel tags load address: {self.tags_load_address:#010x}') 313*4882a593Smuzhiyun lines.append(f'product name: {self.product_name}') 314*4882a593Smuzhiyun lines.append(f'vendor boot image header size: {self.header_size}') 315*4882a593Smuzhiyun lines.append(f'dtb size: {self.dtb_size}') 316*4882a593Smuzhiyun lines.append(f'dtb address: {self.dtb_load_address:#018x}') 317*4882a593Smuzhiyun if self.header_version > 3: 318*4882a593Smuzhiyun lines.append( 319*4882a593Smuzhiyun f'vendor ramdisk table size: {self.vendor_ramdisk_table_size}') 320*4882a593Smuzhiyun lines.append('vendor ramdisk table: [') 321*4882a593Smuzhiyun indent = lambda level: ' ' * 4 * level 322*4882a593Smuzhiyun for entry in self.vendor_ramdisk_table: 323*4882a593Smuzhiyun (output_ramdisk_name, ramdisk_size, ramdisk_offset, 324*4882a593Smuzhiyun ramdisk_type, ramdisk_name, board_id) = entry 325*4882a593Smuzhiyun lines.append(indent(1) + f'{output_ramdisk_name}: ''{') 326*4882a593Smuzhiyun lines.append(indent(2) + f'size: {ramdisk_size}') 327*4882a593Smuzhiyun lines.append(indent(2) + f'offset: {ramdisk_offset}') 328*4882a593Smuzhiyun lines.append(indent(2) + f'type: {ramdisk_type:#x}') 329*4882a593Smuzhiyun lines.append(indent(2) + f'name: {ramdisk_name}') 330*4882a593Smuzhiyun lines.append(indent(2) + 'board_id: [') 331*4882a593Smuzhiyun stride = 4 332*4882a593Smuzhiyun for row_idx in range(0, len(board_id), stride): 333*4882a593Smuzhiyun row = board_id[row_idx:row_idx + stride] 334*4882a593Smuzhiyun lines.append( 335*4882a593Smuzhiyun indent(3) + ' '.join(f'{e:#010x},' for e in row)) 336*4882a593Smuzhiyun lines.append(indent(2) + ']') 337*4882a593Smuzhiyun lines.append(indent(1) + '}') 338*4882a593Smuzhiyun lines.append(']') 339*4882a593Smuzhiyun lines.append( 340*4882a593Smuzhiyun f'vendor bootconfig size: {self.vendor_bootconfig_size}') 341*4882a593Smuzhiyun 342*4882a593Smuzhiyun return '\n'.join(lines) 343*4882a593Smuzhiyun 344*4882a593Smuzhiyun def format_mkbootimg_argument(self): 345*4882a593Smuzhiyun args = [] 346*4882a593Smuzhiyun args.extend(['--header_version', str(self.header_version)]) 347*4882a593Smuzhiyun args.extend(['--pagesize', f'{self.page_size:#010x}']) 348*4882a593Smuzhiyun args.extend(['--base', f'{0:#010x}']) 349*4882a593Smuzhiyun args.extend(['--kernel_offset', f'{self.kernel_load_address:#010x}']) 350*4882a593Smuzhiyun args.extend(['--ramdisk_offset', f'{self.ramdisk_load_address:#010x}']) 351*4882a593Smuzhiyun args.extend(['--tags_offset', f'{self.tags_load_address:#010x}']) 352*4882a593Smuzhiyun args.extend(['--dtb_offset', f'{self.dtb_load_address:#018x}']) 353*4882a593Smuzhiyun args.extend(['--vendor_cmdline', self.cmdline]) 354*4882a593Smuzhiyun args.extend(['--board', self.product_name]) 355*4882a593Smuzhiyun 356*4882a593Smuzhiyun if self.dtb_size > 0: 357*4882a593Smuzhiyun args.extend(['--dtb', os.path.join(self.image_dir, 'dtb')]) 358*4882a593Smuzhiyun 359*4882a593Smuzhiyun if self.header_version > 3: 360*4882a593Smuzhiyun args.extend(['--vendor_bootconfig', 361*4882a593Smuzhiyun os.path.join(self.image_dir, 'bootconfig')]) 362*4882a593Smuzhiyun 363*4882a593Smuzhiyun for entry in self.vendor_ramdisk_table: 364*4882a593Smuzhiyun (output_ramdisk_name, _, _, ramdisk_type, 365*4882a593Smuzhiyun ramdisk_name, board_id) = entry 366*4882a593Smuzhiyun args.extend(['--ramdisk_type', str(ramdisk_type)]) 367*4882a593Smuzhiyun args.extend(['--ramdisk_name', ramdisk_name]) 368*4882a593Smuzhiyun for idx, e in enumerate(board_id): 369*4882a593Smuzhiyun if e: 370*4882a593Smuzhiyun args.extend([f'--board_id{idx}', f'{e:#010x}']) 371*4882a593Smuzhiyun vendor_ramdisk_path = os.path.join( 372*4882a593Smuzhiyun self.image_dir, output_ramdisk_name) 373*4882a593Smuzhiyun args.extend(['--vendor_ramdisk_fragment', vendor_ramdisk_path]) 374*4882a593Smuzhiyun else: 375*4882a593Smuzhiyun args.extend(['--vendor_ramdisk', 376*4882a593Smuzhiyun os.path.join(self.image_dir, 'vendor_ramdisk')]) 377*4882a593Smuzhiyun 378*4882a593Smuzhiyun return args 379*4882a593Smuzhiyun 380*4882a593Smuzhiyun 381*4882a593Smuzhiyundef unpack_vendor_boot_image(boot_img, output_dir): 382*4882a593Smuzhiyun info = VendorBootImageInfoFormatter() 383*4882a593Smuzhiyun info.boot_magic = unpack('8s', boot_img.read(8))[0].decode() 384*4882a593Smuzhiyun info.header_version = unpack('I', boot_img.read(4))[0] 385*4882a593Smuzhiyun info.page_size = unpack('I', boot_img.read(4))[0] 386*4882a593Smuzhiyun info.kernel_load_address = unpack('I', boot_img.read(4))[0] 387*4882a593Smuzhiyun info.ramdisk_load_address = unpack('I', boot_img.read(4))[0] 388*4882a593Smuzhiyun info.vendor_ramdisk_size = unpack('I', boot_img.read(4))[0] 389*4882a593Smuzhiyun info.cmdline = cstr(unpack('2048s', boot_img.read(2048))[0].decode()) 390*4882a593Smuzhiyun info.tags_load_address = unpack('I', boot_img.read(4))[0] 391*4882a593Smuzhiyun info.product_name = cstr(unpack('16s', boot_img.read(16))[0].decode()) 392*4882a593Smuzhiyun info.header_size = unpack('I', boot_img.read(4))[0] 393*4882a593Smuzhiyun info.dtb_size = unpack('I', boot_img.read(4))[0] 394*4882a593Smuzhiyun info.dtb_load_address = unpack('Q', boot_img.read(8))[0] 395*4882a593Smuzhiyun 396*4882a593Smuzhiyun # Convenient shorthand. 397*4882a593Smuzhiyun page_size = info.page_size 398*4882a593Smuzhiyun # The first pages contain the boot header 399*4882a593Smuzhiyun num_boot_header_pages = get_number_of_pages(info.header_size, page_size) 400*4882a593Smuzhiyun num_boot_ramdisk_pages = get_number_of_pages( 401*4882a593Smuzhiyun info.vendor_ramdisk_size, page_size) 402*4882a593Smuzhiyun num_boot_dtb_pages = get_number_of_pages(info.dtb_size, page_size) 403*4882a593Smuzhiyun 404*4882a593Smuzhiyun ramdisk_offset_base = page_size * num_boot_header_pages 405*4882a593Smuzhiyun image_info_list = [] 406*4882a593Smuzhiyun 407*4882a593Smuzhiyun if info.header_version > 3: 408*4882a593Smuzhiyun info.vendor_ramdisk_table_size = unpack('I', boot_img.read(4))[0] 409*4882a593Smuzhiyun vendor_ramdisk_table_entry_num = unpack('I', boot_img.read(4))[0] 410*4882a593Smuzhiyun vendor_ramdisk_table_entry_size = unpack('I', boot_img.read(4))[0] 411*4882a593Smuzhiyun info.vendor_bootconfig_size = unpack('I', boot_img.read(4))[0] 412*4882a593Smuzhiyun num_vendor_ramdisk_table_pages = get_number_of_pages( 413*4882a593Smuzhiyun info.vendor_ramdisk_table_size, page_size) 414*4882a593Smuzhiyun vendor_ramdisk_table_offset = page_size * ( 415*4882a593Smuzhiyun num_boot_header_pages + num_boot_ramdisk_pages + num_boot_dtb_pages) 416*4882a593Smuzhiyun 417*4882a593Smuzhiyun vendor_ramdisk_table = [] 418*4882a593Smuzhiyun vendor_ramdisk_symlinks = [] 419*4882a593Smuzhiyun for idx in range(vendor_ramdisk_table_entry_num): 420*4882a593Smuzhiyun entry_offset = vendor_ramdisk_table_offset + ( 421*4882a593Smuzhiyun vendor_ramdisk_table_entry_size * idx) 422*4882a593Smuzhiyun boot_img.seek(entry_offset) 423*4882a593Smuzhiyun ramdisk_size = unpack('I', boot_img.read(4))[0] 424*4882a593Smuzhiyun ramdisk_offset = unpack('I', boot_img.read(4))[0] 425*4882a593Smuzhiyun ramdisk_type = unpack('I', boot_img.read(4))[0] 426*4882a593Smuzhiyun ramdisk_name = cstr(unpack( 427*4882a593Smuzhiyun f'{VENDOR_RAMDISK_NAME_SIZE}s', 428*4882a593Smuzhiyun boot_img.read(VENDOR_RAMDISK_NAME_SIZE))[0].decode()) 429*4882a593Smuzhiyun board_id = unpack( 430*4882a593Smuzhiyun f'{VENDOR_RAMDISK_TABLE_ENTRY_BOARD_ID_SIZE}I', 431*4882a593Smuzhiyun boot_img.read( 432*4882a593Smuzhiyun 4 * VENDOR_RAMDISK_TABLE_ENTRY_BOARD_ID_SIZE)) 433*4882a593Smuzhiyun output_ramdisk_name = f'vendor_ramdisk{idx:02}' 434*4882a593Smuzhiyun 435*4882a593Smuzhiyun image_info_list.append((ramdisk_offset_base + ramdisk_offset, 436*4882a593Smuzhiyun ramdisk_size, output_ramdisk_name)) 437*4882a593Smuzhiyun vendor_ramdisk_symlinks.append((output_ramdisk_name, ramdisk_name)) 438*4882a593Smuzhiyun vendor_ramdisk_table.append( 439*4882a593Smuzhiyun (output_ramdisk_name, ramdisk_size, ramdisk_offset, 440*4882a593Smuzhiyun ramdisk_type, ramdisk_name, board_id)) 441*4882a593Smuzhiyun 442*4882a593Smuzhiyun info.vendor_ramdisk_table = vendor_ramdisk_table 443*4882a593Smuzhiyun 444*4882a593Smuzhiyun bootconfig_offset = page_size * (num_boot_header_pages 445*4882a593Smuzhiyun + num_boot_ramdisk_pages + num_boot_dtb_pages 446*4882a593Smuzhiyun + num_vendor_ramdisk_table_pages) 447*4882a593Smuzhiyun image_info_list.append((bootconfig_offset, info.vendor_bootconfig_size, 448*4882a593Smuzhiyun 'bootconfig')) 449*4882a593Smuzhiyun else: 450*4882a593Smuzhiyun image_info_list.append( 451*4882a593Smuzhiyun (ramdisk_offset_base, info.vendor_ramdisk_size, 'vendor_ramdisk')) 452*4882a593Smuzhiyun 453*4882a593Smuzhiyun dtb_offset = page_size * (num_boot_header_pages + num_boot_ramdisk_pages 454*4882a593Smuzhiyun ) # header + vendor_ramdisk 455*4882a593Smuzhiyun if info.dtb_size > 0: 456*4882a593Smuzhiyun image_info_list.append((dtb_offset, info.dtb_size, 'dtb')) 457*4882a593Smuzhiyun 458*4882a593Smuzhiyun create_out_dir(output_dir) 459*4882a593Smuzhiyun for offset, size, name in image_info_list: 460*4882a593Smuzhiyun extract_image(offset, size, boot_img, os.path.join(output_dir, name)) 461*4882a593Smuzhiyun info.image_dir = output_dir 462*4882a593Smuzhiyun 463*4882a593Smuzhiyun if info.header_version > 3: 464*4882a593Smuzhiyun vendor_ramdisk_by_name_dir = os.path.join( 465*4882a593Smuzhiyun output_dir, 'vendor-ramdisk-by-name') 466*4882a593Smuzhiyun create_out_dir(vendor_ramdisk_by_name_dir) 467*4882a593Smuzhiyun for src, dst in vendor_ramdisk_symlinks: 468*4882a593Smuzhiyun src_pathname = os.path.join('..', src) 469*4882a593Smuzhiyun dst_pathname = os.path.join( 470*4882a593Smuzhiyun vendor_ramdisk_by_name_dir, f'ramdisk_{dst}') 471*4882a593Smuzhiyun if os.path.lexists(dst_pathname): 472*4882a593Smuzhiyun os.remove(dst_pathname) 473*4882a593Smuzhiyun os.symlink(src_pathname, dst_pathname) 474*4882a593Smuzhiyun 475*4882a593Smuzhiyun return info 476*4882a593Smuzhiyun 477*4882a593Smuzhiyun 478*4882a593Smuzhiyundef unpack_bootimg(boot_img, output_dir): 479*4882a593Smuzhiyun """Unpacks the |boot_img| to |output_dir|, and returns the 'info' object.""" 480*4882a593Smuzhiyun with open(boot_img, 'rb') as image_file: 481*4882a593Smuzhiyun boot_magic = unpack('8s', image_file.read(8))[0].decode() 482*4882a593Smuzhiyun image_file.seek(0) 483*4882a593Smuzhiyun if boot_magic == 'ANDROID!': 484*4882a593Smuzhiyun info = unpack_boot_image(image_file, output_dir) 485*4882a593Smuzhiyun elif boot_magic == 'VNDRBOOT': 486*4882a593Smuzhiyun info = unpack_vendor_boot_image(image_file, output_dir) 487*4882a593Smuzhiyun else: 488*4882a593Smuzhiyun raise ValueError(f'Not an Android boot image, magic: {boot_magic}') 489*4882a593Smuzhiyun 490*4882a593Smuzhiyun return info 491*4882a593Smuzhiyun 492*4882a593Smuzhiyun 493*4882a593Smuzhiyundef print_bootimg_info(info, output_format, null_separator): 494*4882a593Smuzhiyun """Format and print boot image info.""" 495*4882a593Smuzhiyun if output_format == 'mkbootimg': 496*4882a593Smuzhiyun mkbootimg_args = info.format_mkbootimg_argument() 497*4882a593Smuzhiyun if null_separator: 498*4882a593Smuzhiyun print('\0'.join(mkbootimg_args) + '\0', end='') 499*4882a593Smuzhiyun else: 500*4882a593Smuzhiyun print(shlex.join(mkbootimg_args)) 501*4882a593Smuzhiyun else: 502*4882a593Smuzhiyun print(info.format_pretty_text()) 503*4882a593Smuzhiyun 504*4882a593Smuzhiyun 505*4882a593Smuzhiyundef get_unpack_usage(): 506*4882a593Smuzhiyun return """Output format: 507*4882a593Smuzhiyun 508*4882a593Smuzhiyun * info 509*4882a593Smuzhiyun 510*4882a593Smuzhiyun Pretty-printed info-rich text format suitable for human inspection. 511*4882a593Smuzhiyun 512*4882a593Smuzhiyun * mkbootimg 513*4882a593Smuzhiyun 514*4882a593Smuzhiyun Output shell-escaped (quoted) argument strings that can be used to 515*4882a593Smuzhiyun reconstruct the boot image. For example: 516*4882a593Smuzhiyun 517*4882a593Smuzhiyun $ unpack_bootimg --boot_img vendor_boot.img --out out --format=mkbootimg | 518*4882a593Smuzhiyun tee mkbootimg_args 519*4882a593Smuzhiyun $ sh -c "mkbootimg $(cat mkbootimg_args) --vendor_boot repacked.img" 520*4882a593Smuzhiyun 521*4882a593Smuzhiyun vendor_boot.img and repacked.img would be equivalent. 522*4882a593Smuzhiyun 523*4882a593Smuzhiyun If the -0 option is specified, output unescaped null-terminated argument 524*4882a593Smuzhiyun strings that are suitable to be parsed by a shell script (xargs -0 format): 525*4882a593Smuzhiyun 526*4882a593Smuzhiyun $ unpack_bootimg --boot_img vendor_boot.img --out out --format=mkbootimg \\ 527*4882a593Smuzhiyun -0 | tee mkbootimg_args 528*4882a593Smuzhiyun $ declare -a MKBOOTIMG_ARGS=() 529*4882a593Smuzhiyun $ while IFS= read -r -d '' ARG; do 530*4882a593Smuzhiyun MKBOOTIMG_ARGS+=("${ARG}") 531*4882a593Smuzhiyun done <mkbootimg_args 532*4882a593Smuzhiyun $ mkbootimg "${MKBOOTIMG_ARGS[@]}" --vendor_boot repacked.img 533*4882a593Smuzhiyun""" 534*4882a593Smuzhiyun 535*4882a593Smuzhiyun 536*4882a593Smuzhiyundef parse_cmdline(): 537*4882a593Smuzhiyun """parse command line arguments""" 538*4882a593Smuzhiyun parser = ArgumentParser( 539*4882a593Smuzhiyun formatter_class=RawDescriptionHelpFormatter, 540*4882a593Smuzhiyun description='Unpacks boot, recovery or vendor_boot image.', 541*4882a593Smuzhiyun epilog=get_unpack_usage(), 542*4882a593Smuzhiyun ) 543*4882a593Smuzhiyun parser.add_argument('--boot_img', required=True, 544*4882a593Smuzhiyun help='path to the boot, recovery or vendor_boot image') 545*4882a593Smuzhiyun parser.add_argument('--out', default='out', 546*4882a593Smuzhiyun help='output directory of the unpacked images') 547*4882a593Smuzhiyun parser.add_argument('--format', choices=['info', 'mkbootimg'], 548*4882a593Smuzhiyun default='info', 549*4882a593Smuzhiyun help='text output format (default: info)') 550*4882a593Smuzhiyun parser.add_argument('-0', '--null', action='store_true', 551*4882a593Smuzhiyun help='output null-terminated argument strings') 552*4882a593Smuzhiyun return parser.parse_args() 553*4882a593Smuzhiyun 554*4882a593Smuzhiyun 555*4882a593Smuzhiyundef main(): 556*4882a593Smuzhiyun """parse arguments and unpack boot image""" 557*4882a593Smuzhiyun args = parse_cmdline() 558*4882a593Smuzhiyun info = unpack_bootimg(args.boot_img, args.out) 559*4882a593Smuzhiyun print_bootimg_info(info, args.format, args.null) 560*4882a593Smuzhiyun 561*4882a593Smuzhiyun 562*4882a593Smuzhiyunif __name__ == '__main__': 563*4882a593Smuzhiyun main() 564