[Tutorial] How to generate chained vbmeta, vbmeta_system and vbmeta_vendor
[Tutorial] How to generate chained vbmeta, vbmeta_system and vbmeta_vendor
python3 avbtool extract_public_key --key testkey_rsa2048.pem --output keys/testkey_rsa2048_pub.binFollow the steps below to generate vbmeta.img, vbmeta_system.img and vbmeta_vendor.img correctly
python3 avbtool.py info_image --image 'vbmeta.img'
python3 avbtool.py info_image --image 'vbmeta_system.img'
python3 avbtool.py info_image --image 'vbmeta_vendor.img'Minimum libavb version: 1.0
Header Block: 256 bytes
Authentication Block: 320 bytes
Auxiliary Block: 3968 bytes
Public key (sha1): cdbb77177f731920bbe0a0f94f84d9038ae0617d
Algorithm: SHA256_RSA2048
Rollback Index: 0
Flags: 0
Rollback Index Location: 0
Release String: 'avbtool 1.2.0'
Descriptors:
Chain Partition descriptor:
Partition Name: boot
Rollback Index Location: 3
Public key (sha1): 9d808b0995768d0677fccb1efcddb7cf9e153d99
Chain Partition descriptor:
Partition Name: vbmeta_system
Rollback Index Location: 2
Public key (sha1): fa41159a5d696abdef93176a07d0b0d001263f01
Chain Partition descriptor:
Partition Name: vbmeta_vendor
Rollback Index Location: 4
Public key (sha1): 9577bc6c0772975ecce93c4d8a178662c728dadf
Prop: com.android.build.product.os_version -> '14'
Prop: com.android.build.product.fingerprint -> 'alps/sys_mssi_64_cn/mssi_64_cn:14/UP1A.231005.007/20250215:userdebug/release-keys'
Prop: com.android.build.product.security_patch -> '2024-12-05'
Prop: com.android.build.system_ext.os_version -> '14'
Prop: com.android.build.system_ext.fingerprint -> 'alps/sys_mssi_64_cn/mssi_64_cn:14/UP1A.231005.007/20250215:userdebug/release-keys'
Prop: com.android.build.system_ext.security_patch -> '2024-12-05'
Prop: com.android.build.dtbo.fingerprint -> 'alps/vnd_k62v1_64_bsp/k62v1_64_bsp:12/SP1A.210812.016/20250215:userdebug/release-keys'
Hash descriptor:
Image Size: 42880 bytes
Hash Algorithm: sha256
Partition Name: dtbo
Salt: cb1883746952dfc51ed033a1529d5c16a48d069f042bebc05c020a326ac9cb5e
Digest: 712fe0a44c924e074f57eb63352fa42e8da41b5cd5c8751c488aa824493db71b
Flags: 0
Hashtree descriptor:
Version of dm-verity: 1
Image Size: 959086592 bytes
Tree Offset: 959086592
Tree Size: 7561216 bytes
Data Block Size: 4096 bytes
Hash Block Size: 4096 bytes
FEC num roots: 2
FEC offset: 966647808
FEC size: 7643136 bytes
Hash Algorithm: sha256
Partition Name: product
Salt: 327191cdaa5d70999b1fa8d7232254690b8555934b95a3ef85042407db01bdfe
Root Digest: 1dd14d3e80b5a8c4ca5db43f1956fcae512d388323d7047232a7211efa6abbc4
Flags: 0
Hashtree descriptor:
Version of dm-verity: 1
Image Size: 752238592 bytes
Tree Offset: 752238592
Tree Size: 5931008 bytes
Data Block Size: 4096 bytes
Hash Block Size: 4096 bytes
FEC num roots: 2
FEC offset: 758169600
FEC size: 5996544 bytes
Hash Algorithm: sha256
Partition Name: system_ext
Salt: 327191cdaa5d70999b1fa8d7232254690b8555934b95a3ef85042407db01bdfe
Root Digest: 2609119fafccec755e72f1be1e9d4aa312e403faad8b1d0a2cca57ed2575bca2
Flags: 0Minimum libavb version: 1.0
Header Block: 256 bytes
Authentication Block: 320 bytes
Auxiliary Block: 1088 bytes
Public key (sha1): fa41159a5d696abdef93176a07d0b0d001263f01
Algorithm: SHA256_RSA2048
Rollback Index: 0
Flags: 0
Rollback Index Location: 0
Release String: 'avbtool 1.2.0'
Descriptors:
Prop: com.android.build.system.os_version -> '14'
Prop: com.android.build.system.fingerprint -> 'alps/sys_mssi_64_cn/mssi_64_cn:14/UP1A.231005.007/20250215:userdebug/release-keys'
Prop: com.android.build.system.security_patch -> '2024-12-05'
Hashtree descriptor:
Version of dm-verity: 1
Image Size: 1090768896 bytes
Tree Offset: 1090768896
Tree Size: 8597504 bytes
Data Block Size: 4096 bytes
Hash Block Size: 4096 bytes
FEC num roots: 2
FEC offset: 1099366400
FEC size: 8691712 bytes
Hash Algorithm: sha256
Partition Name: system
Salt: 327191cdaa5d70999b1fa8d7232254690b8555934b95a3ef85042407db01bdfe
Root Digest: 7c5fa406a30bc13a46513a3d80bdd61cb8921ca7bf708adfe530522d6df6c94c
Flags: 0Minimum libavb version: 1.0
Header Block: 256 bytes
Authentication Block: 320 bytes
Auxiliary Block: 1152 bytes
Public key (sha1): 9577bc6c0772975ecce93c4d8a178662c728dadf
Algorithm: SHA256_RSA2048
Rollback Index: 0
Flags: 0
Rollback Index Location: 0
Release String: 'avbtool 1.2.0'
Descriptors:
Prop: com.android.build.vendor.fingerprint -> 'alps/vnd_k62v1_64_bsp/k62v1_64_bsp:12/SP1A.210812.016/20250215:userdebug/release-keys'
Prop: com.android.build.vendor.os_version -> '12'
Prop: com.android.build.vendor.security_patch -> '2024-12-05'
Hashtree descriptor:
Version of dm-verity: 1
Image Size: 358219776 bytes
Tree Offset: 358219776
Tree Size: 2830336 bytes
Data Block Size: 4096 bytes
Hash Block Size: 4096 bytes
FEC num roots: 2
FEC offset: 361050112
FEC size: 2859008 bytes
Hash Algorithm: sha256
Partition Name: vendor
Salt: e8538763a0c4966991e3a7916c5bcf20fb6cf45121ad9f866bed9f38de6e8ba9
Root Digest: 32bc2663f0f682af8b3044421e8eff969fa8f50da18268f7f6ebd7e324ae19f6
Flags: 0python3 avbtool.py make_vbmeta_image \
--key 'testkey_rsa2048.pem' --algorithm 'SHA256_RSA2048' --flag 0 \
--chain_partition boot:3:'keys/key_boot.bin' \
--chain_partition vbmeta_system:2:'keys/key_vbmeta_system.bin' \
--chain_partition vbmeta_vendor:4:'keys/key_vbmeta_vendor.bin' \
--include_descriptors_from_image 'product_a.img' \
--include_descriptors_from_image 'system_ext_a.img' \
--include_descriptors_from_image 'dtbo.img' \
--padding_size '8192' --output 'vbmeta_stock.img'python3 avbtool.py info_image --image 'vbmeta_stock.img'python3 avbtool.py make_vbmeta_image \
--key 'testkey_rsa2048.pem' --algorithm 'SHA256_RSA2048' --flag 0 \
--chain_partition boot:3:'keys/key_boot.bin' \
--chain_partition vbmeta_system:2:'keys/testkey_rsa2048_pub.bin' \
--chain_partition vbmeta_vendor:4:'keys/testkey_rsa2048_pub.bin' \
--include_descriptors_from_image 'product_a.img' \
--include_descriptors_from_image 'system_ext_a.img' \
--include_descriptors_from_image 'dtbo.img' \
--padding_size '8192' --output 'vbmeta_custom.img'resize2fs system_a.img 2G
mkdir system
sudo mount -t ext4 -o loop system_a.img system
# make your changes here
sudo umount system
e2fsck -yf system_a.img
resize2fs -M system_a.img
e2fsck -yf system_a.imgresize2fs vendor_a.img 2G
mkdir vendor
sudo mount -t ext4 -o loop vendor_a.img vendor
# make your changes here
sudo umount vendor
e2fsck -yf vendor_a.img
resize2fs -M vendor_a.img
e2fsck -yf vendor_a.imgpython3 avbtool.py add_hashtree_footer \
--image 'system_a.img' \
--partition_name 'system' \
--do_not_generate_fec \
--prop com.android.build.system.os_version:14 \
--prop com.android.build.system.fingerprint:alps/sys_mssi_64_cn/mssi_64_cn:14/UP1A.231005.007/20250215:userdebug/release-keys \
--prop com.android.build.system.security_patch:2024-12-05python3 avbtool.py make_vbmeta_image \
--key 'testkey_rsa2048.pem' --algorithm 'SHA256_RSA2048' --flag 0 \
--include_descriptors_from_image system_a.img \
--padding_size '4096' --output 'vbmeta_system_custom.img'python3 avbtool.py add_hashtree_footer \
--image 'vendor_a.img' \
--partition_name 'vendor' \
--do_not_generate_fec \
--prop com.android.build.vendor.fingerprint:alps/vnd_k62v1_64_bsp/k62v1_64_bsp:12/SP1A.210812.016/20250215:userdebug/release-keys \
--prop com.android.build.vendor.os_version:12 \
--prop com.android.build.vendor.security_patch:2024-12-05python3 avbtool.py make_vbmeta_image \
--key 'testkey_rsa2048.pem' --algorithm 'SHA256_RSA2048' --flag 0 \
--include_descriptors_from_image vendor_a.img \
--padding_size '4096' --output 'vbmeta_vendor_custom.img'