Home Forum Blog Private Support Courses
Our courses are now on YouTube! Start Watching
Hovatek Forum OPERATING SYSTEMS Android [Tutorial] How to generate chained vbmeta, vbmeta_system and vbmeta_vendor

[Tutorial] How to generate chained vbmeta, vbmeta_system and vbmeta_vendor

[Tutorial] How to generate chained vbmeta, vbmeta_system and vbmeta_vendor

hovatek
hovatek
hovatek
Administrator
51,002
15-02-2026, 09:52 AM
#1



This tutorial will explain how to generate a chained vbmeta.img, vbmeta_system.img and vbmeta_vendor.img. It comes in handy when you wish to modify partitions referenced in these vbmetas. Those looking to modify partitions in the super partition/super.img (e.g., system, vendor, product, odm, etc.) would find this guide helpful.

The Objective

I'll be working with a super.img in this example so my commands are specific to its component files and vbmeta images. The objective is to modify the system and vendor partitions, then generate corresponding vbmeta images to sign these changes, because failure to do so would result in a bootloop. You can modify other partitions, like product and vendor, if you wish; it's the same principle.

This technique would work on any chipset that uses AVB v2, including MediaTek, Unisoc/Spreadtrum, Qualcomm, Exynos, etc.

Note

This guide makes the following assumptions:

Your images or configuration might vary from what you see in this guide, so focus on understanding the principle/technique and adapt as required in your situation.


Requirements

  • Linux-based PC. Windows users can setup Ubuntu on Windows
  • avbtool, private key, public keys
  • super.img or files of partitions chained in vbmeta.img, vbmeta_system.img and vbmeta_vendor.img


Steps to generate chained vbmeta, vbmeta_system and vbmeta_vendor


Follow the steps below to generate vbmeta.img, vbmeta_system.img and vbmeta_vendor.img correctly


See the video tutorial below or @ https://youtu.be/FaSGenaqkM8


  1. Unpack your super.img and place its component files (system, product, vendor, etc. in the same directory as avbtool.py)

  2. Run the following commands to get the info of your vbmeta.img, vbmeta_system.img and vbmeta_vendor.img

    Code:

    python3 avbtool.py info_image --image 'vbmeta.img' python3 avbtool.py info_image --image 'vbmeta_system.img' python3 avbtool.py info_image --image 'vbmeta_vendor.img'

    Save the outputs for each command in a text file because you'll need to reference them later. It's always a good idea to try to regenerate a replica of your stock vbmeta images so you're sure that all your keys and commands are correct.

    The output of mine looked something like this:

    vbmeta.img

    Code:

    Minimum libavb version:   1.0 Header Block:             256 bytes Authentication Block:     320 bytes Auxiliary Block:          3968 bytes Public key (sha1):        cdbb77177f731920bbe0a0f94f84d9038ae0617d Algorithm:                SHA256_RSA2048 Rollback Index:           0 Flags:                    0 Rollback Index Location:  0 Release String:           'avbtool 1.2.0' Descriptors:     Chain Partition descriptor:       Partition Name:          boot       Rollback Index Location: 3       Public key (sha1):       9d808b0995768d0677fccb1efcddb7cf9e153d99     Chain Partition descriptor:       Partition Name:          vbmeta_system       Rollback Index Location: 2       Public key (sha1):       fa41159a5d696abdef93176a07d0b0d001263f01     Chain Partition descriptor:       Partition Name:          vbmeta_vendor       Rollback Index Location: 4       Public key (sha1):       9577bc6c0772975ecce93c4d8a178662c728dadf     Prop: com.android.build.product.os_version -> '14'     Prop: com.android.build.product.fingerprint -> 'alps/sys_mssi_64_cn/mssi_64_cn:14/UP1A.231005.007/20250215:userdebug/release-keys'     Prop: com.android.build.product.security_patch -> '2024-12-05'     Prop: com.android.build.system_ext.os_version -> '14'     Prop: com.android.build.system_ext.fingerprint -> 'alps/sys_mssi_64_cn/mssi_64_cn:14/UP1A.231005.007/20250215:userdebug/release-keys'     Prop: com.android.build.system_ext.security_patch -> '2024-12-05'     Prop: com.android.build.dtbo.fingerprint -> 'alps/vnd_k62v1_64_bsp/k62v1_64_bsp:12/SP1A.210812.016/20250215:userdebug/release-keys'     Hash descriptor:       Image Size:            42880 bytes       Hash Algorithm:        sha256       Partition Name:        dtbo       Salt:                  cb1883746952dfc51ed033a1529d5c16a48d069f042bebc05c020a326ac9cb5e       Digest:                712fe0a44c924e074f57eb63352fa42e8da41b5cd5c8751c488aa824493db71b       Flags:                 0     Hashtree descriptor:       Version of dm-verity:  1       Image Size:            959086592 bytes       Tree Offset:           959086592       Tree Size:             7561216 bytes       Data Block Size:       4096 bytes       Hash Block Size:       4096 bytes       FEC num roots:         2       FEC offset:            966647808       FEC size:              7643136 bytes       Hash Algorithm:        sha256       Partition Name:        product       Salt:                  327191cdaa5d70999b1fa8d7232254690b8555934b95a3ef85042407db01bdfe       Root Digest:           1dd14d3e80b5a8c4ca5db43f1956fcae512d388323d7047232a7211efa6abbc4       Flags:                 0     Hashtree descriptor:       Version of dm-verity:  1       Image Size:            752238592 bytes       Tree Offset:           752238592       Tree Size:             5931008 bytes       Data Block Size:       4096 bytes       Hash Block Size:       4096 bytes       FEC num roots:         2       FEC offset:            758169600       FEC size:              5996544 bytes       Hash Algorithm:        sha256       Partition Name:        system_ext       Salt:                  327191cdaa5d70999b1fa8d7232254690b8555934b95a3ef85042407db01bdfe       Root Digest:           2609119fafccec755e72f1be1e9d4aa312e403faad8b1d0a2cca57ed2575bca2       Flags:                 0


    vbmeta_system.img

    Code:

    Minimum libavb version:   1.0 Header Block:             256 bytes Authentication Block:     320 bytes Auxiliary Block:          1088 bytes Public key (sha1):        fa41159a5d696abdef93176a07d0b0d001263f01 Algorithm:                SHA256_RSA2048 Rollback Index:           0 Flags:                    0 Rollback Index Location:  0 Release String:           'avbtool 1.2.0' Descriptors:     Prop: com.android.build.system.os_version -> '14'     Prop: com.android.build.system.fingerprint -> 'alps/sys_mssi_64_cn/mssi_64_cn:14/UP1A.231005.007/20250215:userdebug/release-keys'     Prop: com.android.build.system.security_patch -> '2024-12-05'     Hashtree descriptor:       Version of dm-verity:  1       Image Size:            1090768896 bytes       Tree Offset:           1090768896       Tree Size:             8597504 bytes       Data Block Size:       4096 bytes       Hash Block Size:       4096 bytes       FEC num roots:         2       FEC offset:            1099366400       FEC size:              8691712 bytes       Hash Algorithm:        sha256       Partition Name:        system       Salt:                  327191cdaa5d70999b1fa8d7232254690b8555934b95a3ef85042407db01bdfe       Root Digest:           7c5fa406a30bc13a46513a3d80bdd61cb8921ca7bf708adfe530522d6df6c94c       Flags:                 0


    vbmeta_vendor.img

    Code:

    Minimum libavb version:   1.0 Header Block:             256 bytes Authentication Block:     320 bytes Auxiliary Block:          1152 bytes Public key (sha1):        9577bc6c0772975ecce93c4d8a178662c728dadf Algorithm:                SHA256_RSA2048 Rollback Index:           0 Flags:                    0 Rollback Index Location:  0 Release String:           'avbtool 1.2.0' Descriptors:     Prop: com.android.build.vendor.fingerprint -> 'alps/vnd_k62v1_64_bsp/k62v1_64_bsp:12/SP1A.210812.016/20250215:userdebug/release-keys'     Prop: com.android.build.vendor.os_version -> '12'     Prop: com.android.build.vendor.security_patch -> '2024-12-05'     Hashtree descriptor:       Version of dm-verity:  1       Image Size:            358219776 bytes       Tree Offset:           358219776       Tree Size:             2830336 bytes       Data Block Size:       4096 bytes       Hash Block Size:       4096 bytes       FEC num roots:         2       FEC offset:            361050112       FEC size:              2859008 bytes       Hash Algorithm:        sha256       Partition Name:        vendor       Salt:                  e8538763a0c4966991e3a7916c5bcf20fb6cf45121ad9f866bed9f38de6e8ba9       Root Digest:           32bc2663f0f682af8b3044421e8eff969fa8f50da18268f7f6ebd7e324ae19f6       Flags:                 0


  3. From the above outputs, vbmeta.img chains (or verifies) /boot, /vbmeta_system and /vbmeta_vendor. vbmeta_system.img verifies /system and vbmeta_vendor verifies /vendor. Now I know which vbmeta I need to target for whatever partition I wish to modify.

  4. Now, I'll regenerate my vbmeta.img based on information I got from its info (I don't have to run a padding script because my vbmeta.img contains no DHTB)

    Code:

    python3 avbtool.py make_vbmeta_image \     --key 'testkey_rsa2048.pem' --algorithm 'SHA256_RSA2048' --flag 0 \     --chain_partition boot:3:'keys/key_boot.bin' \     --chain_partition vbmeta_system:2:'keys/key_vbmeta_system.bin' \     --chain_partition vbmeta_vendor:4:'keys/key_vbmeta_vendor.bin' \     --include_descriptors_from_image 'product_a.img' \     --include_descriptors_from_image 'system_ext_a.img' \     --include_descriptors_from_image 'dtbo.img' \     --padding_size '8192' --output 'vbmeta_stock.img'

  5. Check the info of vbmeta_stock.img and compare it to that of vbmeta.img to confirm they're identical

    Code:

    python3 avbtool.py info_image --image 'vbmeta_stock.img'

  6. Generate a custom vbmeta

    Code:

    python3 avbtool.py make_vbmeta_image \     --key 'testkey_rsa2048.pem' --algorithm 'SHA256_RSA2048' --flag 0 \     --chain_partition boot:3:'keys/key_boot.bin' \     --chain_partition vbmeta_system:2:'keys/testkey_rsa2048_pub.bin' \     --chain_partition vbmeta_vendor:4:'keys/testkey_rsa2048_pub.bin' \     --include_descriptors_from_image 'product_a.img' \     --include_descriptors_from_image 'system_ext_a.img' \     --include_descriptors_from_image 'dtbo.img' \     --padding_size '8192' --output 'vbmeta_custom.img'

    In the command above, I have specified that I wish to modify the vbmeta_system and vbmeta_vendor partitions; hence my use of the testkey_rsa2048_pub.bin public key because I have the corresponding private key, which is testkey_rsa2048.pem

  7. Now, you may modify your system.img, vendor.img, product.img, etc., as you wish. I modified only system_a.img and vendor_a.img in this guide.

    Code:

    resize2fs system_a.img 2G mkdir system sudo mount -t ext4 -o loop system_a.img system # make your changes here sudo umount system e2fsck -yf system_a.img resize2fs -M system_a.img e2fsck -yf system_a.img

    Code:

    resize2fs vendor_a.img 2G mkdir vendor sudo mount -t ext4 -o loop vendor_a.img vendor # make your changes here sudo umount vendor e2fsck -yf vendor_a.img resize2fs -M vendor_a.img e2fsck -yf vendor_a.img

  8. Add a hash tree to the modified system_a.img

    Code:

    python3 avbtool.py add_hashtree_footer \     --image 'system_a.img' \     --partition_name 'system' \     --do_not_generate_fec \     --prop com.android.build.system.os_version:14 \     --prop com.android.build.system.fingerprint:alps/sys_mssi_64_cn/mssi_64_cn:14/UP1A.231005.007/20250215:userdebug/release-keys \     --prop com.android.build.system.security_patch:2024-12-05


  9. Generate a custom vbmeta_system.img

    Code:

    python3 avbtool.py make_vbmeta_image \     --key 'testkey_rsa2048.pem' --algorithm 'SHA256_RSA2048' --flag 0 \     --include_descriptors_from_image system_a.img \     --padding_size '4096' --output 'vbmeta_system_custom.img'

  10. Add a hash tree to the modified vendor_a.img

    Code:

    python3 avbtool.py add_hashtree_footer \     --image 'vendor_a.img' \     --partition_name 'vendor' \     --do_not_generate_fec \     --prop com.android.build.vendor.fingerprint:alps/vnd_k62v1_64_bsp/k62v1_64_bsp:12/SP1A.210812.016/20250215:userdebug/release-keys \     --prop com.android.build.vendor.os_version:12 \     --prop com.android.build.vendor.security_patch:2024-12-05

  11. Generate a custom vbmeta_vendor.img

    Code:

    python3 avbtool.py make_vbmeta_image \     --key 'testkey_rsa2048.pem' --algorithm 'SHA256_RSA2048' --flag 0 \     --include_descriptors_from_image vendor_a.img \     --padding_size '4096' --output 'vbmeta_vendor_custom.img'

  12. You are to flash the vbmeta_custom.img, vbmeta_system_custom.img, vbmeta_vendor_custom.img along with the modified system_a.img and vendor_a.img in this example. You could choose to repack the super.img so you just flash the super.img along with the custom vbmetas


Important Notice
  • The commands above are specific to the images used in the example, so tweak as required, especially the prop and descriptors.
  • Changing the flag from 0 causes a bootloop on some devices
This post was last modified: 16-02-2026, 12:22 PM by hovatek.

Learn MediaTek, Unisoc / Spreadtrum (SPD) and Qualcomm Software Repairs @ https://www.hovatek.com/training
Note!
We have a reply schedule for Forum Support. Please try Private Support if you can't wait.
Users browsing this thread:
 1 Guest(s)
Users browsing this thread:
 1 Guest(s)
WhTlYt