No Description
Alessandro Astone 548d6c8d31 recovery: Allow custom bootloader msg offset in block misc 7 months ago
applypatch Add a singleton CacheLocation to replace the hard coded locations 1 year ago
boot_control Drop -Wno-unused-parameter. 1 year ago
bootloader_message recovery: Allow custom bootloader msg offset in block misc 7 months ago
edify Avoid overwrite of the error message in AbortFn 1 year ago
etc recovery: init: mount pstore fs 7 months ago
fonts more font improvements and cleanup 6 years ago
minadbd minadbd: track signature change of service_to_fd. 1 year ago
minui recovery: minui: Implement image scaling 7 months ago
otafault Disable building libapplypatch on mac 1 year ago
otautil Revert "kill package_extract_dir" 11 months ago
private Add a binary path param to update_binary_command(). 2 years ago
res-hdpi/images recovery: New install/progress animation 7 months ago
res-mdpi/images recovery: New install/progress animation 7 months ago
res-xhdpi/images recovery: New install/progress animation 7 months ago
res-xxhdpi/images recovery: New install/progress animation 7 months ago
res-xxxhdpi/images recovery: New install/progress animation 7 months ago
tests Revert "updater: Remove some obsoleted functions for file-based OTA." 11 months ago
tools Import translations. DO NOT MERGE 1 year ago
uncrypt uncrypt: fix f2fs ioctl argument for pin_file 11 months ago
update_verifier update_verifier: skip verity to determine successful on lineage builds 8 months ago
updater update-binary: support reboot_now on older recoveries 7 months ago
volume_manager recovery: Implement a volume manager 7 months ago
.clang-format clang-format: Remove the override of PenaltyExcessCharacter. 1 year ago
Android.bp recovery: Implement a volume manager 7 months ago
Android.mk recovery: Allow detecting user/release build at compile time 7 months ago
CleanSpec.mk recovery: minui: add adf backend 5 years ago
NOTICE Automated import from //branches/master/...@140824,140824 10 years ago
OWNERS Fix owner email address. 1 year ago
PREUPLOAD.cfg Add a repohook to clang-format changes. 1 year ago
README.md Document instructions for using adb under recovery. 1 year ago
adb_install.cpp recovery: Allow bypassing signature verification on non-release builds 7 months ago
adb_install.h recovery: Allow bypassing signature verification on non-release builds 7 months ago
asn1_decoder.cpp Checking unsigned variable less than zero 2 years ago
asn1_decoder.h Refactor asn1_decoder functions into a class. 2 years ago
backup.cpp recovery: bu: Implement backup/restore 7 months ago
bootloader.h Create bootloader_message static library. 3 years ago
bu.cpp recovery: bu: Implement backup/restore 7 months ago
bu.h recovery: bu: Implement backup/restore 7 months ago
common.h sr: Get a proper shell environment in recovery 7 months ago
default_device.cpp Auto-detect whether to use the long-press UI. 4 years ago
device.cpp recovery: Graphical UI 7 months ago
device.h recovery: Graphical UI 7 months ago
fuse_sdcard_provider.cpp recovery: Provide sideload cancellation 7 months ago
fuse_sdcard_provider.h Revert "recovery: Fork a process for fuse when sideloading from SD card." 7 months ago
fuse_sideload.cpp recovery: Provide caching for sideload files 7 months ago
fuse_sideload.h recovery: Provide sideload cancellation 7 months ago
install.cpp Add runtime checks for A/B vs traditional updates 7 months ago
install.h recovery: Allow bypassing signature verification on non-release builds 7 months ago
interlace-frames.py Go back to the old ear-wiggling Android animation. 3 years ago
mounts.cpp recovery: Implement a volume manager 7 months ago
mounts.h recovery: Implement a volume manager 7 months ago
recovery-persist.cpp Fix the android-cloexec-* warnings in bootable/recovery 2 years ago
recovery-persist.rc recovery: reduce overall boot time 1 year ago
recovery-refresh.cpp Cleanup the duplicates of logs rotation functions 2 years ago
recovery-refresh.rc recovery: reduce overall boot time 1 year ago
recovery.cpp recovery: Allow bypassing signature verification on non-release builds 7 months ago
recovery_cmds.h recovery: Add awk lib and driver 7 months ago
res-560dpi Make text for recovery larger on angler 3 years ago
restore.cpp recovery: bu: Implement backup/restore 7 months ago
roots.cpp recovery: Implement a volume manager 7 months ago
roots.h recovery: Implement a volume manager 7 months ago
rotate_logs.cpp rotate_logs: Clean up the header includes. 1 year ago
rotate_logs.h rotate_logs: Clean up the header includes. 1 year ago
screen_ui.cpp recovery: Scale logo image if necessary 7 months ago
screen_ui.h recovery: Fix redraws, flickering, and animation 7 months ago
stub_ui.h recovery: Fix redraws, flickering, and animation 7 months ago
ui.cpp recovery: Allow device specific backlight path 7 months ago
ui.h recovery: Fix redraws, flickering, and animation 7 months ago
verifier.cpp Move rangeset.h and print_sha1.h into otautil. 1 year ago
verifier.h Const modifiers 2 years ago
volclient.cpp recovery: Implement a volume manager 7 months ago
volclient.h recovery: Implement a volume manager 7 months ago
vr_device.cpp Introduce VR recovery ui 2 years ago
vr_ui.cpp Drop -Wno-unused-parameter. 1 year ago
vr_ui.h vr_ui: drawing changes 1 year ago
wear_device.cpp Allow customizing WearRecoveryUI via Makefile variables. 2 years ago
wear_ui.cpp recovery: Fix redraws, flickering, and animation 7 months ago
wear_ui.h recovery: Graphical UI 7 months ago

README.md

The Recovery Image

Quick turn-around testing

mm -j && m ramdisk-nodeps && m recoveryimage-nodeps

# To boot into the new recovery image
# without flashing the recovery partition:
adb reboot bootloader
fastboot boot $ANDROID_PRODUCT_OUT/recovery.img

Running the tests

# After setting up environment and lunch.
mmma -j bootable/recovery

# Running the tests on device.
adb root
adb sync data

# 32-bit device
adb shell /data/nativetest/recovery_unit_test/recovery_unit_test
adb shell /data/nativetest/recovery_component_test/recovery_component_test

# Or 64-bit device
adb shell /data/nativetest64/recovery_unit_test/recovery_unit_test
adb shell /data/nativetest64/recovery_component_test/recovery_component_test

Running the manual tests

recovery-refresh and recovery-persist executables exist only on systems without /cache partition. And we need to follow special steps to run tests for them.

  • Execute the test on an A/B device first. The test should fail but it will log some contents to pmsg.

  • Reboot the device immediately and run the test again. The test should save the contents of pmsg buffer into /data/misc/recovery/inject.txt. Test will pass if this file has expected contents.

ResourceTest validates whether the png files are qualified as background text image under recovery.

1. `adb sync data` to make sure the test-dir has the images to test.
2. The test will automatically pickup and verify all `_text.png` files in
   the test dir.

Using adb under recovery

When running recovery image from debuggable builds (i.e. -eng or -userdebug build variants, or ro.debuggable=1 in /prop.default), adbd service is enabled and started by default, which allows adb communication. A device should be listed under adb devices, either in recovery or sideload state.

$ adb devices
List of devices attached
1234567890abcdef    recovery

Although /sbin/adbd shares the same binary between normal boot and recovery images, only a subset of adb commands are meaningful under recovery, such as adb root, adb shell, adb push, adb pull etc. adb shell works only after manually mounting /system from recovery menu (assuming a valid system image on device).

Troubleshooting

adb devices doesn’t show the device.

$ adb devices
List of devices attached
  • Ensure adbd is built and running.

By default, adbd is always included into recovery image, as /sbin/adbd. init starts adbd service automatically only in debuggable builds. This behavior is controlled by the recovery specific /init.rc, whose source code is at bootable/recovery/etc/init.rc.

The best way to confirm a running adbd is by checking the serial output, which shows a service start log as below.

[   18.961986] c1      1 init: starting service 'adbd'...
  • Ensure USB gadget has been enabled.

If adbd service has been started but device not shown under adb devices, use lsusb(8) (on host) to check if the device is visible to the host.

bootable/recovery/etc/init.rc disables Android USB gadget (via sysfs) as part of the fs action trigger, and will only re-enable it in debuggable builds (the on property rule will always run after on fs).

on fs
    write /sys/class/android_usb/android0/enable 0

# Always start adbd on userdebug and eng builds
on property:ro.debuggable=1
    write /sys/class/android_usb/android0/enable 1
    start adbd

If device is using configfs, check if configfs has been properly set up in init rc scripts. See the example configuration for Pixel 2 devices. Note that the flag set via sysfs (i.e. the one above) is no-op when using configfs.

adb devices shows the device, but in unauthorized state.

$ adb devices
List of devices attached
1234567890abcdef    unauthorized

recovery image doesn’t honor the USB debugging toggle and the authorizations added under normal boot (because such authorization data stays in /data, which recovery doesn’t mount), nor does it support authorizing a host device under recovery. We can use one of the following options instead.

  • Option 1 (Recommended): Authorize a host device with adb vendor keys.

For debuggable builds, an RSA keypair can be used to authorize a host device that has the private key. The public key, defined via PRODUCT_ADB_KEYS, will be copied to /adb_keys. When starting the host-side adbd, make sure the filename (or the directory) of the matching private key has been added to $ADB_VENDOR_KEYS.

$ export ADB_VENDOR_KEYS=/path/to/adb/private/key
$ adb kill-server
$ adb devices

-user builds filter out PRODUCT_ADB_KEYS, so no /adb_keys will be included there.

Note that this mechanism applies to both of normal boot and recovery modes.

  • Option 2: Allow adbd to connect without authentication.
    • adbd is compiled with ALLOW_ADBD_NO_AUTH (only on debuggable builds).
    • ro.adb.secure has a value of 0.

Both of the two conditions need to be satisfied. Although ro.adb.secure is a runtime property, its value is set at build time (written into /prop.default). It defaults to 1 on -user builds, and 0 for other build variants. The value is overridable via PRODUCT_DEFAULT_PROPERTY_OVERRIDES.