blob: f8208ceca02e52fb7d114bef37f387017ebc7bab [file] [log] [blame]
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -08001/*
2 * Copyright (C) 2007 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17#include <ctype.h>
18#include <errno.h>
19#include <fcntl.h>
20#include <getopt.h>
21#include <limits.h>
22#include <linux/input.h>
23#include <stdio.h>
24#include <stdlib.h>
25#include <string.h>
26#include <sys/reboot.h>
Doug Zongker23ceeea2010-07-08 17:27:55 -070027#include <sys/stat.h>
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -080028#include <sys/types.h>
29#include <time.h>
30#include <unistd.h>
31
32#include "bootloader.h"
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -080033#include "common.h"
34#include "cutils/properties.h"
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -080035#include "install.h"
36#include "minui/minui.h"
37#include "minzip/DirUtil.h"
38#include "roots.h"
Doug Zongkerddd6a282009-06-09 12:22:33 -070039#include "recovery_ui.h"
Oscar Montemayor52219a62010-02-25 16:47:02 -080040#include "encryptedfs_provisioning.h"
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -080041
42static const struct option OPTIONS[] = {
43 { "send_intent", required_argument, NULL, 's' },
44 { "update_package", required_argument, NULL, 'u' },
45 { "wipe_data", no_argument, NULL, 'w' },
46 { "wipe_cache", no_argument, NULL, 'c' },
Oscar Montemayor52219a62010-02-25 16:47:02 -080047 { "set_encrypted_filesystems", required_argument, NULL, 'e' },
Doug Zongker4bc98062010-09-03 11:00:13 -070048 { "show_text", no_argument, NULL, 't' },
Doug Zongker988500b2009-10-06 14:41:38 -070049 { NULL, 0, NULL, 0 },
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -080050};
51
52static const char *COMMAND_FILE = "CACHE:recovery/command";
53static const char *INTENT_FILE = "CACHE:recovery/intent";
54static const char *LOG_FILE = "CACHE:recovery/log";
Ying Wang532c8602010-09-01 14:52:22 -070055static const char *SDCARD_PACKAGE_FILE = "SDCARD:update.zip";
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -080056static const char *TEMPORARY_LOG_FILE = "/tmp/recovery.log";
Doug Zongker23ceeea2010-07-08 17:27:55 -070057static const char *SIDELOAD_TEMP_DIR = "TMP:sideload";
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -080058
59/*
60 * The recovery tool communicates with the main system through /cache files.
61 * /cache/recovery/command - INPUT - command line for tool, one arg per line
62 * /cache/recovery/log - OUTPUT - combined log file from recovery run(s)
63 * /cache/recovery/intent - OUTPUT - intent that was passed in
64 *
65 * The arguments which may be supplied in the recovery.command file:
66 * --send_intent=anystring - write the text out to recovery.intent
67 * --update_package=root:path - verify install an OTA package file
68 * --wipe_data - erase user data (and cache), then reboot
69 * --wipe_cache - wipe cache (but not user data), then reboot
Oscar Montemayor05231562009-11-30 08:40:57 -080070 * --set_encrypted_filesystem=on|off - enables / diasables encrypted fs
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -080071 *
72 * After completing, we remove /cache/recovery/command and reboot.
73 * Arguments may also be supplied in the bootloader control block (BCB).
74 * These important scenarios must be safely restartable at any point:
75 *
76 * FACTORY RESET
77 * 1. user selects "factory reset"
78 * 2. main system writes "--wipe_data" to /cache/recovery/command
79 * 3. main system reboots into recovery
80 * 4. get_args() writes BCB with "boot-recovery" and "--wipe_data"
81 * -- after this, rebooting will restart the erase --
82 * 5. erase_root() reformats /data
83 * 6. erase_root() reformats /cache
84 * 7. finish_recovery() erases BCB
85 * -- after this, rebooting will restart the main system --
86 * 8. main() calls reboot() to boot main system
87 *
88 * OTA INSTALL
89 * 1. main system downloads OTA package to /cache/some-filename.zip
90 * 2. main system writes "--update_package=CACHE:some-filename.zip"
91 * 3. main system reboots into recovery
92 * 4. get_args() writes BCB with "boot-recovery" and "--update_package=..."
93 * -- after this, rebooting will attempt to reinstall the update --
94 * 5. install_package() attempts to install the update
95 * NOTE: the package install must itself be restartable from any point
96 * 6. finish_recovery() erases BCB
97 * -- after this, rebooting will (try to) restart the main system --
98 * 7. ** if install failed **
99 * 7a. prompt_and_wait() shows an error icon and waits for the user
100 * 7b; the user reboots (pulling the battery, etc) into the main system
101 * 8. main() calls maybe_install_firmware_update()
102 * ** if the update contained radio/hboot firmware **:
103 * 8a. m_i_f_u() writes BCB with "boot-recovery" and "--wipe_cache"
104 * -- after this, rebooting will reformat cache & restart main system --
105 * 8b. m_i_f_u() writes firmware image into raw cache partition
106 * 8c. m_i_f_u() writes BCB with "update-radio/hboot" and "--wipe_cache"
107 * -- after this, rebooting will attempt to reinstall firmware --
108 * 8d. bootloader tries to flash firmware
109 * 8e. bootloader writes BCB with "boot-recovery" (keeping "--wipe_cache")
110 * -- after this, rebooting will reformat cache & restart main system --
111 * 8f. erase_root() reformats /cache
112 * 8g. finish_recovery() erases BCB
113 * -- after this, rebooting will (try to) restart the main system --
114 * 9. main() calls reboot() to boot main system
Oscar Montemayor05231562009-11-30 08:40:57 -0800115 *
Oscar Montemayor52219a62010-02-25 16:47:02 -0800116 * SECURE FILE SYSTEMS ENABLE/DISABLE
Oscar Montemayor05231562009-11-30 08:40:57 -0800117 * 1. user selects "enable encrypted file systems"
Oscar Montemayor52219a62010-02-25 16:47:02 -0800118 * 2. main system writes "--set_encrypted_filesystems=on|off" to
Oscar Montemayor05231562009-11-30 08:40:57 -0800119 * /cache/recovery/command
120 * 3. main system reboots into recovery
121 * 4. get_args() writes BCB with "boot-recovery" and
122 * "--set_encrypted_filesystems=on|off"
123 * -- after this, rebooting will restart the transition --
124 * 5. read_encrypted_fs_info() retrieves encrypted file systems settings from /data
125 * Settings include: property to specify the Encrypted FS istatus and
126 * FS encryption key if enabled (not yet implemented)
127 * 6. erase_root() reformats /data
128 * 7. erase_root() reformats /cache
129 * 8. restore_encrypted_fs_info() writes required encrypted file systems settings to /data
130 * Settings include: property to specify the Encrypted FS status and
131 * FS encryption key if enabled (not yet implemented)
132 * 9. finish_recovery() erases BCB
133 * -- after this, rebooting will restart the main system --
134 * 10. main() calls reboot() to boot main system
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800135 */
136
137static const int MAX_ARG_LENGTH = 4096;
138static const int MAX_ARGS = 100;
139
140// open a file given in root:path format, mounting partitions as necessary
141static FILE*
142fopen_root_path(const char *root_path, const char *mode) {
143 if (ensure_root_path_mounted(root_path) != 0) {
144 LOGE("Can't mount %s\n", root_path);
145 return NULL;
146 }
147
148 char path[PATH_MAX] = "";
149 if (translate_root_path(root_path, path, sizeof(path)) == NULL) {
150 LOGE("Bad path %s\n", root_path);
151 return NULL;
152 }
153
154 // When writing, try to create the containing directory, if necessary.
155 // Use generous permissions, the system (init.rc) will reset them.
156 if (strchr("wa", mode[0])) dirCreateHierarchy(path, 0777, NULL, 1);
157
158 FILE *fp = fopen(path, mode);
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800159 return fp;
160}
161
162// close a file, log an error if the error indicator is set
163static void
164check_and_fclose(FILE *fp, const char *name) {
165 fflush(fp);
166 if (ferror(fp)) LOGE("Error in %s\n(%s)\n", name, strerror(errno));
167 fclose(fp);
168}
169
170// command line args come from, in decreasing precedence:
171// - the actual command line
172// - the bootloader control block (one per line, after "recovery")
173// - the contents of COMMAND_FILE (one per line)
174static void
175get_args(int *argc, char ***argv) {
176 struct bootloader_message boot;
177 memset(&boot, 0, sizeof(boot));
178 get_bootloader_message(&boot); // this may fail, leaving a zeroed structure
179
180 if (boot.command[0] != 0 && boot.command[0] != 255) {
181 LOGI("Boot command: %.*s\n", sizeof(boot.command), boot.command);
182 }
183
184 if (boot.status[0] != 0 && boot.status[0] != 255) {
185 LOGI("Boot status: %.*s\n", sizeof(boot.status), boot.status);
186 }
187
188 // --- if arguments weren't supplied, look in the bootloader control block
189 if (*argc <= 1) {
190 boot.recovery[sizeof(boot.recovery) - 1] = '\0'; // Ensure termination
191 const char *arg = strtok(boot.recovery, "\n");
192 if (arg != NULL && !strcmp(arg, "recovery")) {
193 *argv = (char **) malloc(sizeof(char *) * MAX_ARGS);
194 (*argv)[0] = strdup(arg);
195 for (*argc = 1; *argc < MAX_ARGS; ++*argc) {
196 if ((arg = strtok(NULL, "\n")) == NULL) break;
197 (*argv)[*argc] = strdup(arg);
198 }
199 LOGI("Got arguments from boot message\n");
200 } else if (boot.recovery[0] != 0 && boot.recovery[0] != 255) {
201 LOGE("Bad boot message\n\"%.20s\"\n", boot.recovery);
202 }
203 }
204
205 // --- if that doesn't work, try the command file
206 if (*argc <= 1) {
207 FILE *fp = fopen_root_path(COMMAND_FILE, "r");
208 if (fp != NULL) {
209 char *argv0 = (*argv)[0];
210 *argv = (char **) malloc(sizeof(char *) * MAX_ARGS);
211 (*argv)[0] = argv0; // use the same program name
212
213 char buf[MAX_ARG_LENGTH];
214 for (*argc = 1; *argc < MAX_ARGS; ++*argc) {
215 if (!fgets(buf, sizeof(buf), fp)) break;
216 (*argv)[*argc] = strdup(strtok(buf, "\r\n")); // Strip newline.
217 }
218
219 check_and_fclose(fp, COMMAND_FILE);
220 LOGI("Got arguments from %s\n", COMMAND_FILE);
221 }
222 }
223
224 // --> write the arguments we have back into the bootloader control block
225 // always boot into recovery after this (until finish_recovery() is called)
226 strlcpy(boot.command, "boot-recovery", sizeof(boot.command));
227 strlcpy(boot.recovery, "recovery\n", sizeof(boot.recovery));
228 int i;
229 for (i = 1; i < *argc; ++i) {
230 strlcat(boot.recovery, (*argv)[i], sizeof(boot.recovery));
231 strlcat(boot.recovery, "\n", sizeof(boot.recovery));
232 }
233 set_bootloader_message(&boot);
234}
235
Doug Zongker34c98df2009-08-18 12:05:45 -0700236static void
Oscar Montemayor05231562009-11-30 08:40:57 -0800237set_sdcard_update_bootloader_message() {
Doug Zongker34c98df2009-08-18 12:05:45 -0700238 struct bootloader_message boot;
239 memset(&boot, 0, sizeof(boot));
240 strlcpy(boot.command, "boot-recovery", sizeof(boot.command));
241 strlcpy(boot.recovery, "recovery\n", sizeof(boot.recovery));
242 set_bootloader_message(&boot);
243}
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800244
245// clear the recovery command and prepare to boot a (hopefully working) system,
246// copy our log file to cache as well (for the system to read), and
247// record any intent we were asked to communicate back to the system.
248// this function is idempotent: call it as many times as you like.
249static void
Oscar Montemayor05231562009-11-30 08:40:57 -0800250finish_recovery(const char *send_intent) {
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800251 // By this point, we're ready to return to the main system...
252 if (send_intent != NULL) {
253 FILE *fp = fopen_root_path(INTENT_FILE, "w");
Jay Freeman (saurik)619ec2f2008-11-17 01:56:05 +0000254 if (fp == NULL) {
255 LOGE("Can't open %s\n", INTENT_FILE);
256 } else {
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800257 fputs(send_intent, fp);
258 check_and_fclose(fp, INTENT_FILE);
259 }
260 }
261
262 // Copy logs to cache so the system can find out what happened.
263 FILE *log = fopen_root_path(LOG_FILE, "a");
Jay Freeman (saurik)619ec2f2008-11-17 01:56:05 +0000264 if (log == NULL) {
265 LOGE("Can't open %s\n", LOG_FILE);
266 } else {
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800267 FILE *tmplog = fopen(TEMPORARY_LOG_FILE, "r");
268 if (tmplog == NULL) {
269 LOGE("Can't open %s\n", TEMPORARY_LOG_FILE);
270 } else {
271 static long tmplog_offset = 0;
272 fseek(tmplog, tmplog_offset, SEEK_SET); // Since last write
273 char buf[4096];
274 while (fgets(buf, sizeof(buf), tmplog)) fputs(buf, log);
275 tmplog_offset = ftell(tmplog);
276 check_and_fclose(tmplog, TEMPORARY_LOG_FILE);
277 }
278 check_and_fclose(log, LOG_FILE);
279 }
280
Oscar Montemayor05231562009-11-30 08:40:57 -0800281 // Reset to mormal system boot so recovery won't cycle indefinitely.
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800282 struct bootloader_message boot;
283 memset(&boot, 0, sizeof(boot));
284 set_bootloader_message(&boot);
285
286 // Remove the command file, so recovery won't repeat indefinitely.
287 char path[PATH_MAX] = "";
288 if (ensure_root_path_mounted(COMMAND_FILE) != 0 ||
289 translate_root_path(COMMAND_FILE, path, sizeof(path)) == NULL ||
290 (unlink(path) && errno != ENOENT)) {
291 LOGW("Can't unlink %s\n", COMMAND_FILE);
292 }
293
294 sync(); // For good measure.
295}
296
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800297static int
Oscar Montemayor05231562009-11-30 08:40:57 -0800298erase_root(const char *root) {
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800299 ui_set_background(BACKGROUND_ICON_INSTALLING);
300 ui_show_indeterminate_progress();
301 ui_print("Formatting %s...\n", root);
302 return format_root_device(root);
303}
304
Doug Zongker23ceeea2010-07-08 17:27:55 -0700305static char*
306copy_sideloaded_package(const char* original_root_path) {
307 if (ensure_root_path_mounted(original_root_path) != 0) {
308 LOGE("Can't mount %s\n", original_root_path);
309 return NULL;
310 }
311
312 char original_path[PATH_MAX] = "";
313 if (translate_root_path(original_root_path, original_path,
314 sizeof(original_path)) == NULL) {
315 LOGE("Bad path %s\n", original_root_path);
316 return NULL;
317 }
318
319 if (ensure_root_path_mounted(SIDELOAD_TEMP_DIR) != 0) {
320 LOGE("Can't mount %s\n", SIDELOAD_TEMP_DIR);
321 return NULL;
322 }
323
324 char copy_path[PATH_MAX] = "";
325 if (translate_root_path(SIDELOAD_TEMP_DIR, copy_path,
326 sizeof(copy_path)) == NULL) {
327 LOGE("Bad path %s\n", SIDELOAD_TEMP_DIR);
328 return NULL;
329 }
330
331 if (mkdir(copy_path, 0700) != 0) {
332 if (errno != EEXIST) {
333 LOGE("Can't mkdir %s (%s)\n", SIDELOAD_TEMP_DIR, strerror(errno));
334 return NULL;
335 }
336 }
337
338 struct stat st;
339 if (stat(copy_path, &st) != 0) {
340 LOGE("failed to stat %s (%s)\n", copy_path, strerror(errno));
341 return NULL;
342 }
343 if (!S_ISDIR(st.st_mode)) {
344 LOGE("%s isn't a directory\n", copy_path);
345 return NULL;
346 }
347 if ((st.st_mode & 0777) != 0700) {
348 LOGE("%s has perms %o\n", copy_path, st.st_mode);
349 return NULL;
350 }
351 if (st.st_uid != 0) {
352 LOGE("%s owned by %lu; not root\n", copy_path, st.st_uid);
353 return NULL;
354 }
355
356 strcat(copy_path, "/package.zip");
357
358 char* buffer = malloc(BUFSIZ);
359 if (buffer == NULL) {
360 LOGE("Failed to allocate buffer\n");
361 return NULL;
362 }
363
364 size_t read;
365 FILE* fin = fopen(original_path, "rb");
366 if (fin == NULL) {
367 LOGE("Failed to open %s (%s)\n", original_path, strerror(errno));
368 return NULL;
369 }
370 FILE* fout = fopen(copy_path, "wb");
371 if (fout == NULL) {
372 LOGE("Failed to open %s (%s)\n", copy_path, strerror(errno));
373 return NULL;
374 }
375
376 while ((read = fread(buffer, 1, BUFSIZ, fin)) > 0) {
377 if (fwrite(buffer, 1, read, fout) != read) {
378 LOGE("Short write of %s (%s)\n", copy_path, strerror(errno));
379 return NULL;
380 }
381 }
382
383 free(buffer);
384
385 if (fclose(fout) != 0) {
386 LOGE("Failed to close %s (%s)\n", copy_path, strerror(errno));
387 return NULL;
388 }
389
390 if (fclose(fin) != 0) {
391 LOGE("Failed to close %s (%s)\n", original_path, strerror(errno));
392 return NULL;
393 }
394
395 // "adb push" is happy to overwrite read-only files when it's
396 // running as root, but we'll try anyway.
397 if (chmod(copy_path, 0400) != 0) {
398 LOGE("Failed to chmod %s (%s)\n", copy_path, strerror(errno));
399 return NULL;
400 }
401
402 char* copy_root_path = malloc(strlen(SIDELOAD_TEMP_DIR) + 20);
403 strcpy(copy_root_path, SIDELOAD_TEMP_DIR);
404 strcat(copy_root_path, "/package.zip");
405 return copy_root_path;
406}
407
Doug Zongkerf93d8162009-09-22 15:16:02 -0700408static char**
409prepend_title(char** headers) {
Doug Zongkerd6837852009-06-17 22:07:13 -0700410 char* title[] = { "Android system recovery <"
Doug Zongker64893cc2009-07-14 16:31:56 -0700411 EXPAND(RECOVERY_API_VERSION) "e>",
Doug Zongkerd6837852009-06-17 22:07:13 -0700412 "",
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800413 NULL };
414
Doug Zongkerd6837852009-06-17 22:07:13 -0700415 // count the number of lines in our title, plus the
Doug Zongkerf93d8162009-09-22 15:16:02 -0700416 // caller-provided headers.
Doug Zongkerd6837852009-06-17 22:07:13 -0700417 int count = 0;
418 char** p;
419 for (p = title; *p; ++p, ++count);
Doug Zongkerf93d8162009-09-22 15:16:02 -0700420 for (p = headers; *p; ++p, ++count);
Doug Zongkerd6837852009-06-17 22:07:13 -0700421
Doug Zongkerf93d8162009-09-22 15:16:02 -0700422 char** new_headers = malloc((count+1) * sizeof(char*));
423 char** h = new_headers;
Doug Zongkerd6837852009-06-17 22:07:13 -0700424 for (p = title; *p; ++p, ++h) *h = *p;
Doug Zongkerf93d8162009-09-22 15:16:02 -0700425 for (p = headers; *p; ++p, ++h) *h = *p;
Doug Zongkerd6837852009-06-17 22:07:13 -0700426 *h = NULL;
427
Doug Zongkerf93d8162009-09-22 15:16:02 -0700428 return new_headers;
429}
430
431static int
432get_menu_selection(char** headers, char** items, int menu_only) {
433 // throw away keys pressed previously, so user doesn't
434 // accidentally trigger menu items.
435 ui_clear_key_queue();
436
437 ui_start_menu(headers, items);
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800438 int selected = 0;
439 int chosen_item = -1;
440
Doug Zongkerf93d8162009-09-22 15:16:02 -0700441 while (chosen_item < 0) {
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800442 int key = ui_wait_key();
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800443 int visible = ui_text_visible();
444
Doug Zongkerddd6a282009-06-09 12:22:33 -0700445 int action = device_handle_key(key, visible);
446
447 if (action < 0) {
448 switch (action) {
449 case HIGHLIGHT_UP:
450 --selected;
451 selected = ui_menu_select(selected);
452 break;
453 case HIGHLIGHT_DOWN:
454 ++selected;
455 selected = ui_menu_select(selected);
456 break;
457 case SELECT_ITEM:
458 chosen_item = selected;
459 break;
460 case NO_ACTION:
461 break;
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800462 }
Doug Zongkerf93d8162009-09-22 15:16:02 -0700463 } else if (!menu_only) {
Doug Zongkerddd6a282009-06-09 12:22:33 -0700464 chosen_item = action;
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800465 }
Doug Zongkerf93d8162009-09-22 15:16:02 -0700466 }
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800467
Doug Zongkerf93d8162009-09-22 15:16:02 -0700468 ui_end_menu();
469 return chosen_item;
470}
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800471
Doug Zongkerf93d8162009-09-22 15:16:02 -0700472static void
473wipe_data(int confirm) {
474 if (confirm) {
475 static char** title_headers = NULL;
Doug Zongkerddd6a282009-06-09 12:22:33 -0700476
Doug Zongkerf93d8162009-09-22 15:16:02 -0700477 if (title_headers == NULL) {
478 char* headers[] = { "Confirm wipe of all user data?",
479 " THIS CAN NOT BE UNDONE.",
480 "",
481 NULL };
482 title_headers = prepend_title(headers);
483 }
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800484
Doug Zongkerf93d8162009-09-22 15:16:02 -0700485 char* items[] = { " No",
486 " No",
487 " No",
488 " No",
489 " No",
490 " No",
491 " No",
492 " Yes -- delete all user data", // [7]
493 " No",
494 " No",
495 " No",
496 NULL };
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800497
Doug Zongkerf93d8162009-09-22 15:16:02 -0700498 int chosen_item = get_menu_selection(title_headers, items, 1);
499 if (chosen_item != 7) {
500 return;
501 }
502 }
Doug Zongker1066d2c2009-04-01 13:57:40 -0700503
Doug Zongkerf93d8162009-09-22 15:16:02 -0700504 ui_print("\n-- Wiping data...\n");
505 device_wipe_data();
506 erase_root("DATA:");
507 erase_root("CACHE:");
508 ui_print("Data wipe complete.\n");
509}
510
511static void
Oscar Montemayor05231562009-11-30 08:40:57 -0800512prompt_and_wait() {
Doug Zongkerf93d8162009-09-22 15:16:02 -0700513 char** headers = prepend_title(MENU_HEADERS);
514
515 for (;;) {
516 finish_recovery(NULL);
517 ui_reset_progress();
518
519 int chosen_item = get_menu_selection(headers, MENU_ITEMS, 0);
520
521 // device-specific code may take some action here. It may
522 // return one of the core actions handled in the switch
523 // statement below.
524 chosen_item = device_perform_action(chosen_item);
525
526 switch (chosen_item) {
527 case ITEM_REBOOT:
528 return;
529
530 case ITEM_WIPE_DATA:
531 wipe_data(ui_text_visible());
532 if (!ui_text_visible()) return;
533 break;
534
535 case ITEM_WIPE_CACHE:
536 ui_print("\n-- Wiping cache...\n");
537 erase_root("CACHE:");
538 ui_print("Cache wipe complete.\n");
539 if (!ui_text_visible()) return;
540 break;
541
542 case ITEM_APPLY_SDCARD:
543 ui_print("\n-- Install from sdcard...\n");
Doug Zongker23ceeea2010-07-08 17:27:55 -0700544 int status = INSTALL_CORRUPT;
545 char* copy = copy_sideloaded_package(SDCARD_PACKAGE_FILE);
546 if (copy != NULL) {
547 set_sdcard_update_bootloader_message();
548 status = install_package(copy);
549 free(copy);
550 }
Doug Zongkerf93d8162009-09-22 15:16:02 -0700551 if (status != INSTALL_SUCCESS) {
552 ui_set_background(BACKGROUND_ICON_ERROR);
553 ui_print("Installation aborted.\n");
554 } else if (!ui_text_visible()) {
555 return; // reboot if logs aren't visible
556 } else {
Doug Zongkere08991e2010-02-02 13:09:52 -0800557 ui_print("\nInstall from sdcard complete.\n");
Doug Zongkerf93d8162009-09-22 15:16:02 -0700558 }
559 break;
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800560 }
561 }
562}
563
564static void
Oscar Montemayor05231562009-11-30 08:40:57 -0800565print_property(const char *key, const char *name, void *cookie) {
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800566 fprintf(stderr, "%s=%s\n", key, name);
567}
568
569int
Oscar Montemayor05231562009-11-30 08:40:57 -0800570main(int argc, char **argv) {
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800571 time_t start = time(NULL);
572
573 // If these fail, there's not really anywhere to complain...
574 freopen(TEMPORARY_LOG_FILE, "a", stdout); setbuf(stdout, NULL);
575 freopen(TEMPORARY_LOG_FILE, "a", stderr); setbuf(stderr, NULL);
576 fprintf(stderr, "Starting recovery on %s", ctime(&start));
577
578 ui_init();
579 get_args(&argc, &argv);
580
581 int previous_runs = 0;
582 const char *send_intent = NULL;
583 const char *update_package = NULL;
Oscar Montemayor52219a62010-02-25 16:47:02 -0800584 const char *encrypted_fs_mode = NULL;
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800585 int wipe_data = 0, wipe_cache = 0;
Oscar Montemayor52219a62010-02-25 16:47:02 -0800586 int toggle_secure_fs = 0;
587 encrypted_fs_info encrypted_fs_data;
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800588
589 int arg;
590 while ((arg = getopt_long(argc, argv, "", OPTIONS, NULL)) != -1) {
591 switch (arg) {
592 case 'p': previous_runs = atoi(optarg); break;
593 case 's': send_intent = optarg; break;
594 case 'u': update_package = optarg; break;
595 case 'w': wipe_data = wipe_cache = 1; break;
596 case 'c': wipe_cache = 1; break;
Oscar Montemayor52219a62010-02-25 16:47:02 -0800597 case 'e': encrypted_fs_mode = optarg; toggle_secure_fs = 1; break;
Doug Zongker4bc98062010-09-03 11:00:13 -0700598 case 't': ui_show_text(1); break;
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800599 case '?':
600 LOGE("Invalid command argument\n");
601 continue;
602 }
603 }
604
Doug Zongkerefa1bab2010-02-01 15:59:12 -0800605 device_recovery_start();
606
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800607 fprintf(stderr, "Command:");
608 for (arg = 0; arg < argc; arg++) {
609 fprintf(stderr, " \"%s\"", argv[arg]);
610 }
611 fprintf(stderr, "\n\n");
612
613 property_list(print_property, NULL);
614 fprintf(stderr, "\n");
615
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800616 int status = INSTALL_SUCCESS;
617
Oscar Montemayor52219a62010-02-25 16:47:02 -0800618 if (toggle_secure_fs) {
619 if (strcmp(encrypted_fs_mode,"on") == 0) {
620 encrypted_fs_data.mode = MODE_ENCRYPTED_FS_ENABLED;
Oscar Montemayor05231562009-11-30 08:40:57 -0800621 ui_print("Enabling Encrypted FS.\n");
Oscar Montemayor52219a62010-02-25 16:47:02 -0800622 } else if (strcmp(encrypted_fs_mode,"off") == 0) {
623 encrypted_fs_data.mode = MODE_ENCRYPTED_FS_DISABLED;
Oscar Montemayor05231562009-11-30 08:40:57 -0800624 ui_print("Disabling Encrypted FS.\n");
625 } else {
626 ui_print("Error: invalid Encrypted FS setting.\n");
627 status = INSTALL_ERROR;
628 }
629
630 // Recovery strategy: if the data partition is damaged, disable encrypted file systems.
631 // This preventsthe device recycling endlessly in recovery mode.
Oscar Montemayor52219a62010-02-25 16:47:02 -0800632 if ((encrypted_fs_data.mode == MODE_ENCRYPTED_FS_ENABLED) &&
633 (read_encrypted_fs_info(&encrypted_fs_data))) {
Oscar Montemayor05231562009-11-30 08:40:57 -0800634 ui_print("Encrypted FS change aborted, resetting to disabled state.\n");
Oscar Montemayor52219a62010-02-25 16:47:02 -0800635 encrypted_fs_data.mode = MODE_ENCRYPTED_FS_DISABLED;
Oscar Montemayor05231562009-11-30 08:40:57 -0800636 }
637
638 if (status != INSTALL_ERROR) {
639 if (erase_root("DATA:")) {
640 ui_print("Data wipe failed.\n");
641 status = INSTALL_ERROR;
642 } else if (erase_root("CACHE:")) {
643 ui_print("Cache wipe failed.\n");
644 status = INSTALL_ERROR;
Oscar Montemayor52219a62010-02-25 16:47:02 -0800645 } else if ((encrypted_fs_data.mode == MODE_ENCRYPTED_FS_ENABLED) &&
646 (restore_encrypted_fs_info(&encrypted_fs_data))) {
Oscar Montemayor05231562009-11-30 08:40:57 -0800647 ui_print("Encrypted FS change aborted.\n");
648 status = INSTALL_ERROR;
649 } else {
650 ui_print("Successfully updated Encrypted FS.\n");
651 status = INSTALL_SUCCESS;
652 }
653 }
654 } else if (update_package != NULL) {
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800655 status = install_package(update_package);
656 if (status != INSTALL_SUCCESS) ui_print("Installation aborted.\n");
Doug Zongkerb128f542009-06-18 15:07:14 -0700657 } else if (wipe_data) {
658 if (device_wipe_data()) status = INSTALL_ERROR;
659 if (erase_root("DATA:")) status = INSTALL_ERROR;
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800660 if (wipe_cache && erase_root("CACHE:")) status = INSTALL_ERROR;
661 if (status != INSTALL_SUCCESS) ui_print("Data wipe failed.\n");
Doug Zongkerb128f542009-06-18 15:07:14 -0700662 } else if (wipe_cache) {
663 if (wipe_cache && erase_root("CACHE:")) status = INSTALL_ERROR;
664 if (status != INSTALL_SUCCESS) ui_print("Cache wipe failed.\n");
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800665 } else {
666 status = INSTALL_ERROR; // No command specified
667 }
668
669 if (status != INSTALL_SUCCESS) ui_set_background(BACKGROUND_ICON_ERROR);
670 if (status != INSTALL_SUCCESS || ui_text_visible()) prompt_and_wait();
671
The Android Open Source Projectc24a8e62009-03-03 19:28:42 -0800672 // Otherwise, get ready to boot the main system...
673 finish_recovery(send_intent);
674 ui_print("Rebooting...\n");
675 sync();
676 reboot(RB_AUTOBOOT);
677 return EXIT_SUCCESS;
678}