blob: 2a2f8eae17e9b182b52b4e09e6947fbe8ce1d6ae [file] [log] [blame]
Yilin Yang19da6932019-12-10 13:39:28 +08001#!/usr/bin/env python3
Jon Salze60307f2014-08-05 16:20:00 +08002# -*- coding: utf-8 -*-
3# Copyright 2014 The Chromium OS Authors. All rights reserved.
Tammo Spalink9a96b8a2012-04-03 11:10:41 +08004# Use of this source code is governed by a BSD-style license that can be
5# found in the LICENSE file.
6
Jon Salze60307f2014-08-05 16:20:00 +08007
Tammo Spalink9a96b8a2012-04-03 11:10:41 +08008"""Google Factory Tool.
9
You-Cheng Syu461ec032017-03-06 15:56:58 +080010This tool is intended to be used on factory assembly lines. It
Tammo Spalink9a96b8a2012-04-03 11:10:41 +080011provides all of the Google required test functionality and must be run
12on each device as part of the assembly process.
13"""
14
Tammo Spalink9a96b8a2012-04-03 11:10:41 +080015import logging
16import os
Jon Salz65266432012-07-30 19:02:49 +080017import pipes
Tammo Spalink9a96b8a2012-04-03 11:10:41 +080018import re
19import sys
Peter Shihfdf17682017-05-26 11:38:39 +080020from tempfile import gettempdir
Cheng-Yi Chiang9fc121c2014-01-27 11:23:22 +080021import threading
Hung-Te Lin6bd16472012-06-20 16:26:47 +080022import time
Yilin Yange02d5722019-10-23 11:07:36 +080023import xmlrpc.client
Peter Shihfdf17682017-05-26 11:38:39 +080024
Wei-Han Chen0a3320e2016-04-23 01:32:07 +080025from cros.factory.gooftool.common import ExecFactoryPar
Hung-Te Lin0e0f9362015-11-18 18:18:05 +080026from cros.factory.gooftool.common import Shell
Peter Shihfdf17682017-05-26 11:38:39 +080027from cros.factory.gooftool.core import Gooftool
28from cros.factory.gooftool import crosfw
Peter Shihfdf17682017-05-26 11:38:39 +080029from cros.factory.gooftool import report_upload
Yong Hong65bda312018-12-13 20:05:58 +080030from cros.factory.gooftool import vpd
Hung-Te Lin604e0c22015-11-24 15:17:07 +080031from cros.factory.hwid.v3 import hwid_utils
Yong Hong863d3262017-10-30 16:23:34 +080032from cros.factory.probe.functions import chromeos_firmware
Wei-Han Chen2ebb92d2016-01-12 14:51:41 +080033from cros.factory.test.env import paths
Peter Shihfdf17682017-05-26 11:38:39 +080034from cros.factory.test import event_log
Wei-Han Chenaff56232016-04-16 09:17:59 +080035from cros.factory.test.rules import phase
Hung-Te Lin3f096842016-01-13 17:37:06 +080036from cros.factory.test.rules.privacy import FilterDict
Philip Chen6ada02c2019-11-04 19:41:54 +000037from cros.factory.test import state
Cheng Yueh14f50af2020-11-25 13:49:10 +080038from cros.factory.test.utils.cbi_utils import CbiEepromWpStatus
Peter Shihfdf17682017-05-26 11:38:39 +080039from cros.factory.utils import argparse_utils
Hung-Te Lin03bf7ab2016-06-16 17:26:19 +080040from cros.factory.utils.argparse_utils import CmdArg
Hung-Te Lin03bf7ab2016-06-16 17:26:19 +080041from cros.factory.utils.argparse_utils import ParseCmdline
Wei-Han Chenb34bdff2019-09-26 13:07:50 +080042from cros.factory.utils.argparse_utils import VERBOSITY_CMD_ARG
Peter Shihfdf17682017-05-26 11:38:39 +080043from cros.factory.utils.debug_utils import SetupLogging
Jon Salz40b9f822014-07-25 16:39:55 +080044from cros.factory.utils import file_utils
Peter Shih67c7c0f2018-02-26 11:23:59 +080045from cros.factory.utils.process_utils import Spawn
Wei-Han Chena5c01a02016-04-23 19:27:19 +080046from cros.factory.utils import sys_utils
Chun-Ta Lin53cbbd52016-06-08 21:42:19 +080047from cros.factory.utils import time_utils
Joel Kitchingd3bc2662014-12-16 16:03:32 -080048from cros.factory.utils.type_utils import Error
Tammo Spalink86a61c62012-05-25 15:10:35 +080049
Tammo Spalink5c699832012-07-03 17:50:39 +080050
Tammo Spalink5c699832012-07-03 17:50:39 +080051# TODO(tammo): Replace calls to sys.exit with raise Exit, and maybe
52# treat that specially (as a smoot exit, as opposed to the more
53# verbose output for generic Error).
54
Cheng-Yi Chiang9fc121c2014-01-27 11:23:22 +080055_global_gooftool = None
56_gooftool_lock = threading.Lock()
Philip Chen04fb90b2019-11-06 12:10:33 -080057_has_fpmcu = None
Tammo Spalink5c699832012-07-03 17:50:39 +080058
Hung-Te Lin56b18402015-01-16 14:52:30 +080059
Ricky Lianga70a1202013-03-15 15:03:17 +080060def GetGooftool(options):
Peter Shihfdf17682017-05-26 11:38:39 +080061 global _global_gooftool # pylint: disable=global-statement
Ricky Lianga70a1202013-03-15 15:03:17 +080062
Cheng-Yi Chiang9fc121c2014-01-27 11:23:22 +080063 if _global_gooftool is None:
64 with _gooftool_lock:
Shen-En Shihc5d15d62017-08-04 13:02:59 +080065 if _global_gooftool is None:
66 project = getattr(options, 'project', None)
67 hwdb_path = getattr(options, 'hwdb_path', None)
68 _global_gooftool = Gooftool(hwid_version=3, project=project,
69 hwdb_path=hwdb_path)
Cheng-Yi Chiang9fc121c2014-01-27 11:23:22 +080070
71 return _global_gooftool
Ricky Lianga70a1202013-03-15 15:03:17 +080072
Philip Chen04fb90b2019-11-06 12:10:33 -080073def HasFpmcu():
74 global _has_fpmcu # pylint: disable=global-statement
75
76 if _has_fpmcu is None:
77 FPMCU_PATH = '/dev/cros_fp'
Philip Chen04fb90b2019-11-06 12:10:33 -080078 has_cros_config_fpmcu = False
Philip Chencf6642b2019-12-02 19:38:59 -080079 cros_config_output = Shell(['cros_config', '/fingerprint', 'board'])
80 if cros_config_output.success and cros_config_output.stdout:
Philip Chen04fb90b2019-11-06 12:10:33 -080081 has_cros_config_fpmcu = True
82
Alex Chou5b071392020-08-13 09:45:14 +080083 if not os.path.exists(FPMCU_PATH) and has_cros_config_fpmcu:
Philip Chen04fb90b2019-11-06 12:10:33 -080084 raise Error('FPMCU found in cros_config but missing in %s.' % FPMCU_PATH)
Philip Chen04fb90b2019-11-06 12:10:33 -080085
Alex Chou5b071392020-08-13 09:45:14 +080086 _has_fpmcu = has_cros_config_fpmcu
Philip Chen04fb90b2019-11-06 12:10:33 -080087
88 return _has_fpmcu
Hung-Te Lin56b18402015-01-16 14:52:30 +080089
Ting Shen18a06382016-08-30 16:18:21 +080090def Command(cmd_name, *args, **kwargs):
You-Cheng Syu8fc2a602017-12-22 17:05:05 +080091 """Decorator for commands in gooftool.
Ting Shen18a06382016-08-30 16:18:21 +080092
93 This is similar to argparse_utils.Command, but all gooftool commands
94 can be waived during `gooftool finalize` or `gooftool verify` using
Wei-Han Chen60c5d332017-01-05 17:15:10 +080095 --waive_list or --skip_list option.
Ting Shen18a06382016-08-30 16:18:21 +080096 """
97 def Decorate(fun):
Wei-Han Chen60c5d332017-01-05 17:15:10 +080098 def CommandWithWaiveSkipCheck(options):
Ting Shen18a06382016-08-30 16:18:21 +080099 waive_list = vars(options).get('waive_list', [])
Wei-Han Chen60c5d332017-01-05 17:15:10 +0800100 skip_list = vars(options).get('skip_list', [])
101 if phase.GetPhase() >= phase.PVT_DOGFOOD and (
102 waive_list != [] or skip_list != []):
Ting Shen18a06382016-08-30 16:18:21 +0800103 raise Error(
Wei-Han Chen60c5d332017-01-05 17:15:10 +0800104 'waive_list and skip_list should be empty for phase %s' %
105 phase.GetPhase())
Ting Shen18a06382016-08-30 16:18:21 +0800106
Wei-Han Chen60c5d332017-01-05 17:15:10 +0800107 if cmd_name not in skip_list:
108 try:
109 fun(options)
110 except Exception as e:
111 if cmd_name in waive_list:
112 logging.exception(e)
113 else:
114 raise
Ting Shen18a06382016-08-30 16:18:21 +0800115
116 return argparse_utils.Command(cmd_name, *args, **kwargs)(
Wei-Han Chen60c5d332017-01-05 17:15:10 +0800117 CommandWithWaiveSkipCheck)
Ting Shen18a06382016-08-30 16:18:21 +0800118 return Decorate
119
120
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800121@Command('write_hwid',
122 CmdArg('hwid', metavar='HWID', help='HWID string'))
Andy Chengc92e6f92012-11-20 16:55:53 +0800123def WriteHWID(options):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800124 """Write specified HWID value into the system BB."""
Andy Cheng7a76cb82012-11-19 18:08:19 +0800125
Tammo Spalink95c43732012-07-25 15:57:14 -0700126 logging.info('writing hwid string %r', options.hwid)
Ricky Lianga70a1202013-03-15 15:03:17 +0800127 GetGooftool(options).WriteHWID(options.hwid)
Andy Cheng0465d132013-03-20 12:12:06 +0800128 event_log.Log('write_hwid', hwid=options.hwid)
Yilin Yang71e39412019-09-24 09:26:46 +0800129 print('Wrote HWID: %r' % options.hwid)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800130
131
Yong Hongc3765412017-12-26 23:12:15 +0800132@Command('read_hwid')
133def ReadHWID(options):
134 """Read the HWID string from GBB."""
135
136 logging.info('reading the hwid string')
Yilin Yang71e39412019-09-24 09:26:46 +0800137 print(GetGooftool(options).ReadHWID())
Yong Hongc3765412017-12-26 23:12:15 +0800138
139
Yong Hong5408f652017-07-11 19:20:25 +0800140_project_cmd_arg = CmdArg(
141 '--project', metavar='PROJECT',
142 default=None, help='Project name to test.')
Ricky Liang53390232013-03-08 15:37:57 +0800143
Tammo Spalink8fab5312012-05-28 18:33:30 +0800144_hwdb_path_cmd_arg = CmdArg(
145 '--hwdb_path', metavar='PATH',
Yong Hong5c6dcd52017-12-27 11:05:01 +0800146 default=hwid_utils.GetDefaultDataPath(),
Tammo Spalink8fab5312012-05-28 18:33:30 +0800147 help='Path to the HWID database.')
148
Tammo Spalink95c43732012-07-25 15:57:14 -0700149_hwid_status_list_cmd_arg = CmdArg(
Hung-Te Lin56b18402015-01-16 14:52:30 +0800150 '--status', nargs='*', default=['supported'],
151 help='allow only HWIDs with these status values')
Tammo Spalink95c43732012-07-25 15:57:14 -0700152
Jon Salzce124fb2012-10-02 17:42:03 +0800153_probe_results_cmd_arg = CmdArg(
Yong Hong55050c12018-02-27 18:19:47 +0800154 '--probe_results', metavar='RESULTS.json',
155 help=('Output from "hwid probe" (used instead of probing this system).'))
Jon Salzce124fb2012-10-02 17:42:03 +0800156
Ricky Liang53390232013-03-08 15:37:57 +0800157_device_info_cmd_arg = CmdArg(
Ricky Liangf89f73a2013-03-19 05:00:24 +0800158 '--device_info', metavar='DEVICE_INFO.yaml', default=None,
You-Cheng Syu8fc2a602017-12-22 17:05:05 +0800159 help='A dict of device info to use instead of fetching from shopfloor '
Ricky Liang53390232013-03-08 15:37:57 +0800160 'server.')
161
Jon Salzce124fb2012-10-02 17:42:03 +0800162_hwid_cmd_arg = CmdArg(
163 '--hwid', metavar='HWID',
Ricky Lianga70a1202013-03-15 15:03:17 +0800164 help='HWID to verify (instead of the currently set HWID of this system).')
Jon Salzce124fb2012-10-02 17:42:03 +0800165
Yong Hong68a0e0d2017-12-20 19:06:54 +0800166_hwid_run_vpd_cmd_arg = CmdArg(
167 '--hwid-run-vpd', action='store_true',
168 help=('Specify the hwid utility to obtain the vpd data by running the '
169 '`vpd` commandline tool.'))
170
171_hwid_vpd_data_file_cmd_arg = CmdArg(
172 '--hwid-vpd-data-file', metavar='FILE.json', type=str, default=None,
173 help=('Specify the hwid utility to obtain the vpd data from the specified '
174 'file.'))
175
Cheng-Han Yang663763b2020-09-15 20:46:23 +0800176_no_write_protect_cmd_arg = CmdArg(
177 '--no_write_protect', action='store_true',
178 help='Do not enable firmware write protection.')
179
Bernie Thompson3c11c872013-07-22 18:22:45 -0700180_rma_mode_cmd_arg = CmdArg(
181 '--rma_mode', action='store_true',
182 help='Enable RMA mode, do not check for deprecated components.')
Tammo Spalink95c43732012-07-25 15:57:14 -0700183
Cheng-Han Yang40a19e22021-01-05 20:01:26 +0800184_replacement_mlb_mode_cmd_arg = CmdArg(
185 '--replacement_mlb_mode', action='store_true',
186 help='Enable replacement MLB mode, only do cr50 finalize.')
187
Chih-Yu Huang714dbc42015-07-21 16:42:16 +0800188_cros_core_cmd_arg = CmdArg(
189 '--cros_core', action='store_true',
190 help='Finalize for ChromeOS Core devices (may add or remove few test '
Hung-Te Lin53c49402017-07-26 13:10:58 +0800191 'items. For example, registration codes or firmware bitmap '
Chih-Yu Huang714dbc42015-07-21 16:42:16 +0800192 'locale settings).')
193
Pin-Yen Lin215b7542020-05-05 09:45:37 +0800194_has_ec_pubkey_cmd_arg = CmdArg(
195 '--has_ec_pubkey', action='store_true', default=None,
196 help='The device has EC public key for EFS and need to run VerifyECKey.')
Yilun Lin599833f2017-12-22 14:07:46 +0800197
bowgotsai13820f42015-09-10 23:18:04 +0800198_enforced_release_channels_cmd_arg = CmdArg(
199 '--enforced_release_channels', nargs='*', default=None,
200 help='Enforced release image channels.')
201
Yilun Lin34f54802017-11-16 11:58:25 +0800202_ec_pubkey_path_cmd_arg = CmdArg(
203 '--ec_pubkey_path',
204 default=None,
205 help='Path to public key in vb2 format. Verify EC key with pubkey file.')
206
207_ec_pubkey_hash_cmd_arg = CmdArg(
208 '--ec_pubkey_hash',
209 default=None,
210 help='A string for public key hash. Verify EC key with the given hash.')
211
Hung-Te Lincdb96522016-04-15 16:51:10 +0800212_release_rootfs_cmd_arg = CmdArg(
213 '--release_rootfs', help='Location of release image rootfs partition.')
214
215_firmware_path_cmd_arg = CmdArg(
216 '--firmware_path', help='Location of firmware image partition.')
Ricky Liang43b879b2014-02-24 11:36:55 +0800217
Wei-Han Chenbe1355a2016-04-24 19:31:03 +0800218_shopfloor_url_args_cmd_arg = CmdArg(
219 '--shopfloor_url',
Earl Ou51182222016-09-09 12:16:48 +0800220 help='Shopfloor server url to be informed when wiping is done. '
221 'After wiping, a XML-RPC request will be sent to the '
222 'given url to indicate the completion of wiping.')
Wei-Han Chenbe1355a2016-04-24 19:31:03 +0800223
224_station_ip_cmd_arg = CmdArg(
225 '--station_ip',
226 help='IP of remote station')
227
228_station_port_cmd_arg = CmdArg(
229 '--station_port',
230 help='Port on remote station')
231
232_wipe_finish_token_cmd_arg = CmdArg(
233 '--wipe_finish_token',
234 help='Required token when notifying station after wipe finished')
235
Wei-Han Chenf3924112019-02-25 14:52:58 +0800236_keep_developer_mode_flag_after_clobber_state_cmd_arg = CmdArg(
237 # The argument name is super long because you should never use it by
238 # yourself when using command line tools.
239 '--keep_developer_mode_flag_after_clobber_state',
240 action='store_true', default=None,
241 help='After clobber-state, do not delete .developer_mode')
242
Ting Shen18a06382016-08-30 16:18:21 +0800243_waive_list_cmd_arg = CmdArg(
244 '--waive_list', nargs='*', default=[], metavar='SUBCMD',
You-Cheng Syu8fc2a602017-12-22 17:05:05 +0800245 help='A list of waived checks, separated by whitespace. '
246 'Each item should be a sub-command of gooftool. '
Ting Shen18a06382016-08-30 16:18:21 +0800247 'e.g. "gooftool verify --waive_list verify_tpm clear_gbb_flags".')
248
Wei-Han Chen60c5d332017-01-05 17:15:10 +0800249_skip_list_cmd_arg = CmdArg(
250 '--skip_list', nargs='*', default=[], metavar='SUBCMD',
You-Cheng Syu8fc2a602017-12-22 17:05:05 +0800251 help='A list of skipped checks, separated by whitespace. '
252 'Each item should be a sub-command of gooftool. '
Wei-Han Chen60c5d332017-01-05 17:15:10 +0800253 'e.g. "gooftool verify --skip_list verify_tpm clear_gbb_flags".')
254
Meng-Huan Yu7a4f0f52020-01-07 20:11:01 +0800255_test_umount_cmd_arg = CmdArg(
256 '--test_umount', action='store_true',
257 help='(For testing only) Only umount rootfs and stateful partition '
258 'instead of running full wiping and cutoff process.')
259
Wei-Han Cheneb4f9a22018-03-09 14:52:23 +0800260_rlz_embargo_end_date_offset_cmd_arg = CmdArg(
Kevin Line4c64de2019-11-22 15:28:34 +0800261 '--embargo_offset', type=int, default=7, choices=list(range(7, 15)),
Wei-Han Cheneb4f9a22018-03-09 14:52:23 +0800262 help='Change the offset of embargo end date, cannot less than 7 days or '
263 'more than 14 days.')
264
Marco Chena681b2e2018-08-31 11:41:41 +0800265_no_ectool_cmd_arg = CmdArg(
266 '--no_ectool', action='store_false', dest='has_ectool',
267 help='There is no ectool utility so tests rely on ectool should be '
268 'skipped.')
Tammo Spalink8fab5312012-05-28 18:33:30 +0800269
chuntsenaf1232f2019-03-20 15:45:54 +0800270_no_generate_mfg_date_cmd_arg = CmdArg(
271 '--no_generate_mfg_date', action='store_false', dest='generate_mfg_date',
272 help='Do not generate manufacturing date nor write mfg_date into VPD.')
273
Stimim Chenc9fbdfc2020-05-21 17:00:53 +0800274_enable_zero_touch_cmd_arg = CmdArg(
275 '--enable_zero_touch', action='store_true',
276 help='Set attested_device_id for zero-touch feature.')
277
Cheng Yueh14f50af2020-11-25 13:49:10 +0800278_cbi_eeprom_wp_status_cmd_arg = CmdArg(
279 '--cbi_eeprom_wp_status', type=str, default=CbiEepromWpStatus.Locked,
280 choices=CbiEepromWpStatus,
281 help='The expected status of CBI EEPROM after factory mode disabled.')
282
chuntsenaf1232f2019-03-20 15:45:54 +0800283
Yilun Lin34f54802017-11-16 11:58:25 +0800284@Command(
285 'verify_ec_key',
286 _ec_pubkey_path_cmd_arg,
287 _ec_pubkey_hash_cmd_arg)
288def VerifyECKey(options):
289 """Verify EC key."""
290 return GetGooftool(options).VerifyECKey(
291 options.ec_pubkey_path, options.ec_pubkey_hash)
292
293
Philip Chen84c16262020-07-30 17:35:27 -0700294@Command('verify_fp_key')
295def VerifyFpKey(options):
296 """Verify fingerprint firmware key."""
297 return GetGooftool(options).VerifyFpKey()
298
299
Hung-Te Line1d80f62016-03-31 14:58:13 +0800300@Command('verify_keys',
Hung-Te Lincdb96522016-04-15 16:51:10 +0800301 _release_rootfs_cmd_arg,
302 _firmware_path_cmd_arg)
Peter Shihfdf17682017-05-26 11:38:39 +0800303def VerifyKeys(options):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800304 """Verify keys in firmware and SSD match."""
Hung-Te Line1d80f62016-03-31 14:58:13 +0800305 return GetGooftool(options).VerifyKeys(
Hung-Te Lincdb96522016-04-15 16:51:10 +0800306 options.release_rootfs, options.firmware_path)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800307
308
309@Command('set_fw_bitmap_locale')
Peter Shihfdf17682017-05-26 11:38:39 +0800310def SetFirmwareBitmapLocale(options):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800311 """Use VPD locale value to set firmware bitmap default language."""
Andy Cheng7a76cb82012-11-19 18:08:19 +0800312
Ricky Lianga70a1202013-03-15 15:03:17 +0800313 (index, locale) = GetGooftool(options).SetFirmwareBitmapLocale()
Andy Cheng2582d292012-12-04 17:38:28 +0800314 logging.info('Firmware bitmap initial locale set to %d (%s).',
315 index, locale)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800316
317
Hung-Te Line1d80f62016-03-31 14:58:13 +0800318@Command('verify_system_time',
Wei-Han Chen2790d2e2019-01-18 21:13:40 +0800319 _release_rootfs_cmd_arg,
320 _rma_mode_cmd_arg)
Peter Shihfdf17682017-05-26 11:38:39 +0800321def VerifySystemTime(options):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800322 """Verify system time is later than release filesystem creation time."""
Andy Cheng7a76cb82012-11-19 18:08:19 +0800323
Wei-Han Chen2790d2e2019-01-18 21:13:40 +0800324 return GetGooftool(options).VerifySystemTime(options.release_rootfs,
325 rma_mode=options.rma_mode)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800326
327
Hung-Te Line1d80f62016-03-31 14:58:13 +0800328@Command('verify_rootfs',
Hung-Te Lincdb96522016-04-15 16:51:10 +0800329 _release_rootfs_cmd_arg)
Peter Shihfdf17682017-05-26 11:38:39 +0800330def VerifyRootFs(options):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800331 """Verify rootfs on SSD is valid by checking hash."""
Andy Cheng7a76cb82012-11-19 18:08:19 +0800332
Hung-Te Line1d80f62016-03-31 14:58:13 +0800333 return GetGooftool(options).VerifyRootFs(options.release_rootfs)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800334
Hung-Te Lin56b18402015-01-16 14:52:30 +0800335
Cheng-Yi Chiang676b5292013-06-18 12:05:33 +0800336@Command('verify_tpm')
Peter Shihfdf17682017-05-26 11:38:39 +0800337def VerifyTPM(options):
Cheng-Yi Chiang676b5292013-06-18 12:05:33 +0800338 """Verify TPM is cleared."""
339
340 return GetGooftool(options).VerifyTPM()
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800341
Hung-Te Lin56b18402015-01-16 14:52:30 +0800342
Hung-Te Lindd708d42014-07-11 17:05:01 +0800343@Command('verify_me_locked')
Peter Shihfdf17682017-05-26 11:38:39 +0800344def VerifyManagementEngineLocked(options):
You-Cheng Syu461ec032017-03-06 15:56:58 +0800345 """Verify Management Engine is locked."""
Hung-Te Lindd708d42014-07-11 17:05:01 +0800346
347 return GetGooftool(options).VerifyManagementEngineLocked()
348
Hung-Te Lin56b18402015-01-16 14:52:30 +0800349
Marco Chena681b2e2018-08-31 11:41:41 +0800350@Command('verify_switch_wp',
351 _no_ectool_cmd_arg)
Peter Shihfdf17682017-05-26 11:38:39 +0800352def VerifyWPSwitch(options):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800353 """Verify hardware write protection switch is enabled."""
Andy Cheng7a76cb82012-11-19 18:08:19 +0800354
Marco Chena681b2e2018-08-31 11:41:41 +0800355 GetGooftool(options).VerifyWPSwitch(options.has_ectool)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800356
357
Hung-Te Lin53c49402017-07-26 13:10:58 +0800358@Command('verify_vpd')
359def VerifyVPD(options):
360 """Verify that VPD values are properly set.
Jon Salzadd90d32014-04-29 16:16:27 +0800361
Hung-Te Lin53c49402017-07-26 13:10:58 +0800362 Check if mandatory fields are set, and deprecated fields don't exist.
Jon Salzadd90d32014-04-29 16:16:27 +0800363 """
Chun-Tsen Kuo949910e2021-04-09 19:33:37 +0800364 ro_vpd = vpd.VPDTool().GetAllData(partition=vpd.VPD_READONLY_PARTITION_NAME)
365 rw_vpd = vpd.VPDTool().GetAllData(partition=vpd.VPD_READWRITE_PARTITION_NAME)
366 event_log.Log('vpd', ro=FilterDict(ro_vpd), rw=FilterDict(rw_vpd))
Hung-Te Lin53c49402017-07-26 13:10:58 +0800367 return GetGooftool(options).VerifyVPD()
Jon Salzadd90d32014-04-29 16:16:27 +0800368
369
bowgotsai13820f42015-09-10 23:18:04 +0800370@Command('verify_release_channel',
371 _enforced_release_channels_cmd_arg)
Peter Shihfdf17682017-05-26 11:38:39 +0800372def VerifyReleaseChannel(options):
bowgotsai529139c2015-05-30 01:39:49 +0800373 """Verify that release image channel is correct.
374
375 ChromeOS has four channels: canary, dev, beta and stable.
376 The last three channels support image auto-updates, checks
377 that release image channel is one of them.
378 """
bowgotsai13820f42015-09-10 23:18:04 +0800379 return GetGooftool(options).VerifyReleaseChannel(
380 options.enforced_release_channels)
bowgotsai529139c2015-05-30 01:39:49 +0800381
382
Wei-Han Chen0de7cfd2020-01-03 16:49:20 +0800383@Command('verify_cros_config')
384def VerifyCrosConfig(options):
385 """Verify entries in cros config make sense."""
386 return GetGooftool(options).VerifyCrosConfig()
387
388
Stimim Chenc9fbdfc2020-05-21 17:00:53 +0800389@Command('verify-sn-bits',
390 _enable_zero_touch_cmd_arg)
Stimim Chen8aaa2952020-05-20 13:04:24 +0800391def VerifySnBits(options):
Stimim Chenc9fbdfc2020-05-21 17:00:53 +0800392 if options.enable_zero_touch:
393 GetGooftool(options).VerifySnBits()
Stimim Chen8aaa2952020-05-20 13:04:24 +0800394
395
Cheng Yueh14f50af2020-11-25 13:49:10 +0800396@Command(
397 'verify_cbi_eeprom_wp_status',
398 _cbi_eeprom_wp_status_cmd_arg,
399)
400def VerifyCBIEEPROMWPStatus(options):
401 """Verify CBI EEPROM status.
402
403 If cbi_eeprom_wp_status is Absent, CBI EEPROM must be absent. If
404 cbi_eeprom_wp_status is Locked, write protection must be on. Otherwise, write
405 protection must be off.
406 """
407
408 return GetGooftool(options).VerifyCBIEEPROMWPStatus(
409 options.cbi_eeprom_wp_status)
410
411
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800412@Command('write_protect')
Peter Shihfdf17682017-05-26 11:38:39 +0800413def EnableFwWp(options):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800414 """Enable then verify firmware write protection."""
Peter Shihfdf17682017-05-26 11:38:39 +0800415 del options # Unused.
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800416
Yong Hongdad230a2017-08-30 22:25:19 +0800417 def WriteProtect(fw):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800418 """Calculate protection size, then invoke flashrom.
419
Yong Hongdad230a2017-08-30 22:25:19 +0800420 The region (offset and size) to write protect may be different per chipset
421 and firmware layout, so we have to read the WP_RO section from FMAP to
422 decide that.
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800423 """
Hung-Te Lin7ea39e82012-07-31 18:39:33 +0800424 wp_section = 'WP_RO'
Hung-Te Lin7ea39e82012-07-31 18:39:33 +0800425
Yong Hongdad230a2017-08-30 22:25:19 +0800426 fmap_image = fw.GetFirmwareImage(
427 sections=(['FMAP'] if fw.target == crosfw.TARGET_MAIN else None))
428 if not fmap_image.has_section(wp_section):
429 raise Error('Could not find %s firmware section: %s' %
430 (fw.target.upper(), wp_section))
431
432 section_data = fw.GetFirmwareImage(
433 sections=[wp_section]).get_section_area(wp_section)
Peter Shihe6afab32018-09-11 17:16:48 +0800434 ro_offset, ro_size = section_data[0:2]
Yong Hongdad230a2017-08-30 22:25:19 +0800435
436 logging.debug('write protecting %s [off=%x size=%x]', fw.target.upper(),
Hung-Te Lin7ea39e82012-07-31 18:39:33 +0800437 ro_offset, ro_size)
Yong Hongdad230a2017-08-30 22:25:19 +0800438 crosfw.Flashrom(fw.target).EnableWriteProtection(ro_offset, ro_size)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800439
Philip Chendbb06202019-11-05 17:24:26 -0800440 if HasFpmcu():
441 # TODO(b/143991572): Implement enable_fpmcu_write_protection in gooftool.
442 cmd = os.path.join(
443 paths.FACTORY_DIR, 'sh', 'enable_fpmcu_write_protection.sh')
444 cmd_result = Shell(cmd)
445 if not cmd_result.success:
446 raise Error(
447 'Failed to enable FPMCU write protection, stdout=%r, stderr=%r' %
448 (cmd_result.stdout, cmd_result.stderr))
449
Yong Hongdad230a2017-08-30 22:25:19 +0800450 WriteProtect(crosfw.LoadMainFirmware())
Andy Cheng0465d132013-03-20 12:12:06 +0800451 event_log.Log('wp', fw='main')
Hung-Te Lind3b124c2016-10-20 22:22:31 +0800452
Fei Shao21be8242020-04-13 16:57:51 +0800453 # Some EC (mostly PD) does not support "RO_NOW". Instead they will only set
Hung-Te Lind3b124c2016-10-20 22:22:31 +0800454 # "RO_AT_BOOT" when you request to enable RO (These platforms consider
455 # --wp-range with right range identical to --wp-enable), and requires a
456 # 'ectool reboot_ec RO at-shutdown; reboot' to let the RO take effect.
Hung-Te Lin0d10b562016-12-28 10:58:07 +0800457 # After reboot, "flashrom -p host --wp-status" will return protected range.
Hung-Te Lind3b124c2016-10-20 22:22:31 +0800458 # If you don't reboot, returned range will be (0, 0), and running command
459 # "ectool flashprotect" will not have RO_NOW.
Fei Shao21be8242020-04-13 16:57:51 +0800460 # generic_common.test_list.json provides "EnableECWriteProtect" test group
461 # which can be run individually before finalization. Try that out if you're
462 # having trouble enabling RO_NOW flag.
Hung-Te Lind3b124c2016-10-20 22:22:31 +0800463
Yong Hongdad230a2017-08-30 22:25:19 +0800464 for fw in [crosfw.LoadEcFirmware(), crosfw.LoadPDFirmware()]:
465 if fw.GetChipId() is None:
Hung-Te Lind3b124c2016-10-20 22:22:31 +0800466 logging.warning('%s not write protected (seems there is no %s flash).',
Yong Hongdad230a2017-08-30 22:25:19 +0800467 fw.target.upper(), fw.target.upper())
Hung-Te Lind3b124c2016-10-20 22:22:31 +0800468 continue
Yong Hongdad230a2017-08-30 22:25:19 +0800469 WriteProtect(fw)
470 event_log.Log('wp', fw=fw.target)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800471
472
473@Command('clear_gbb_flags')
Peter Shihfdf17682017-05-26 11:38:39 +0800474def ClearGBBFlags(options):
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800475 """Zero out the GBB flags, in preparation for transition to release state.
476
477 No GBB flags are set in release/shipping state, but they are useful
Hung-Te Lin879cff42017-06-19 12:46:37 +0800478 for factory/development. See "futility gbb --flags" for details.
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800479 """
Andy Cheng7a76cb82012-11-19 18:08:19 +0800480
Ricky Lianga70a1202013-03-15 15:03:17 +0800481 GetGooftool(options).ClearGBBFlags()
Andy Cheng0465d132013-03-20 12:12:06 +0800482 event_log.Log('clear_gbb_flags')
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800483
484
Jon Salzaa3a30e2013-05-15 15:56:28 +0800485@Command('clear_factory_vpd_entries')
Peter Shihfdf17682017-05-26 11:38:39 +0800486def ClearFactoryVPDEntries(options):
Jon Salzaa3a30e2013-05-15 15:56:28 +0800487 """Clears factory.* items in the RW VPD."""
488 entries = GetGooftool(options).ClearFactoryVPDEntries()
489 event_log.Log('clear_factory_vpd_entries', entries=FilterDict(entries))
490
491
Mattias Nisslercca761b2015-04-15 21:53:04 +0200492@Command('generate_stable_device_secret')
Peter Shihfdf17682017-05-26 11:38:39 +0800493def GenerateStableDeviceSecret(options):
You-Cheng Syu461ec032017-03-06 15:56:58 +0800494 """Generates a fresh stable device secret and stores it in the RO VPD."""
Mattias Nisslercca761b2015-04-15 21:53:04 +0200495 GetGooftool(options).GenerateStableDeviceSecret()
496 event_log.Log('generate_stable_device_secret')
497
Wei-Han Chenbe1355a2016-04-24 19:31:03 +0800498
Cheng-Han Yang24d42d92020-08-09 04:53:53 +0800499@Command('cr50_set_ro_hash')
500def Cr50SetROHash(options):
501 GetGooftool(options).Cr50SetROHash()
502 event_log.Log('cr50_set_ro_hash')
503
Stimim Chenda9e62c2020-05-14 15:43:18 +0800504@Command('cr50_set_sn_bits_and_board_id',
505 _rma_mode_cmd_arg)
Yves Arrouyeb49b31e2019-03-06 21:51:52 -0800506def Cr50SetSnBitsAndBoardId(options):
Wei-Han Chen66357592020-01-14 15:15:37 +0800507 """Deprecated: use Cr50WriteFlashInfo instead."""
508 logging.warning('This function is renamed to Cr50WriteFlashInfo')
509 Cr50WriteFlashInfo(options)
510
511
Cheng-Han Yang40a19e22021-01-05 20:01:26 +0800512@Command('cr50_write_flash_info', _rma_mode_cmd_arg,
513 _replacement_mlb_mode_cmd_arg, _enable_zero_touch_cmd_arg)
Wei-Han Chen66357592020-01-14 15:15:37 +0800514def Cr50WriteFlashInfo(options):
Yves Arrouyeb49b31e2019-03-06 21:51:52 -0800515 """Set the serial number bits, board id and flags on the Cr50 chip."""
Stimim Chenc9fbdfc2020-05-21 17:00:53 +0800516 GetGooftool(options).Cr50WriteFlashInfo(
Cheng-Han Yang40a19e22021-01-05 20:01:26 +0800517 options.enable_zero_touch, options.rma_mode, options.replacement_mlb_mode)
Wei-Han Chen66357592020-01-14 15:15:37 +0800518 event_log.Log('cr50_write_flash_info')
519
520
521@Command('cr50_write_whitelabel_flags')
522def Cr50WriteWhitelabelFlags(options):
523 GetGooftool(options).Cr50WriteWhitelabelFlags()
524 event_log.Log('cr50_write_whitelabel_flags')
Shen-En Shihd078a7c2017-08-04 13:33:49 +0800525
526
Marco Chen20c885d2018-10-04 17:22:03 +0800527@Command('cr50_disable_factory_mode')
Marco Chen44a666d2018-07-13 21:01:50 +0800528def Cr50DisableFactoryMode(options):
Cheng-Han Yang08333af2017-12-18 17:22:38 +0800529 """Reset Cr50 state back to default state after RMA."""
Marco Chen44a666d2018-07-13 21:01:50 +0800530 return GetGooftool(options).Cr50DisableFactoryMode()
Cheng-Han Yang08333af2017-12-18 17:22:38 +0800531
532
Cheng-Han Yang40a19e22021-01-05 20:01:26 +0800533@Command('cr50_finalize', _no_write_protect_cmd_arg, _rma_mode_cmd_arg,
534 _replacement_mlb_mode_cmd_arg, _enable_zero_touch_cmd_arg)
Cheng-Han Yang663763b2020-09-15 20:46:23 +0800535def Cr50Finalize(options):
536 """Finalize steps for cr50."""
537 if options.no_write_protect:
538 logging.warning('SWWP is not enabled. Skip setting RO hash.')
539 elif options.rma_mode:
540 logging.warning('RMA mode. Skip setting RO hash.')
Cheng-Han Yang40a19e22021-01-05 20:01:26 +0800541 elif options.replacement_mlb_mode:
542 logging.warning('Replacement MLB mode. Skip setting RO hash.')
Cheng-Han Yang663763b2020-09-15 20:46:23 +0800543 else:
544 Cr50SetROHash(options)
545 Cr50WriteFlashInfo(options)
Cheng-Han Yang40a19e22021-01-05 20:01:26 +0800546 if not options.replacement_mlb_mode:
547 Cr50DisableFactoryMode(options)
Cheng-Han Yang663763b2020-09-15 20:46:23 +0800548
549
Earl Ou564a7872016-10-05 10:22:00 +0800550@Command('enable_release_partition',
551 CmdArg('--release_rootfs',
552 help=('path to the release rootfs device. If not specified, '
553 'the default (5th) partition will be used.')))
554def EnableReleasePartition(options):
555 """Enables a release image partition on the disk."""
556 GetGooftool(options).EnableReleasePartition(options.release_rootfs)
557
558
Shun-Hsing Oucdc64e12015-01-14 22:07:33 +0800559@Command('wipe_in_place',
560 CmdArg('--fast', action='store_true',
Shun-Hsing Ou8d3c40a2015-10-08 18:16:08 +0800561 help='use non-secure but faster wipe method.'),
Wei-Han Chenbe1355a2016-04-24 19:31:03 +0800562 _shopfloor_url_args_cmd_arg,
563 _station_ip_cmd_arg,
564 _station_port_cmd_arg,
Meng-Huan Yu7a4f0f52020-01-07 20:11:01 +0800565 _wipe_finish_token_cmd_arg,
566 _test_umount_cmd_arg)
Shun-Hsing Oucdc64e12015-01-14 22:07:33 +0800567def WipeInPlace(options):
568 """Start factory wipe directly without reboot."""
569
Wei-Han Chenbe1355a2016-04-24 19:31:03 +0800570 GetGooftool(options).WipeInPlace(options.fast,
Wei-Han Chenbe1355a2016-04-24 19:31:03 +0800571 options.shopfloor_url,
572 options.station_ip,
573 options.station_port,
Meng-Huan Yu7a4f0f52020-01-07 20:11:01 +0800574 options.wipe_finish_token,
575 options.test_umount)
Mattias Nisslercca761b2015-04-15 21:53:04 +0200576
Wei-Han Chen7dc6d132016-04-06 11:11:53 +0800577@Command('wipe_init',
Wei-Han Chen0a3320e2016-04-23 01:32:07 +0800578 CmdArg('--wipe_args', help='arguments for clobber-state'),
579 CmdArg('--state_dev', help='path to stateful partition device'),
580 CmdArg('--root_disk', help='path to primary device'),
581 CmdArg('--old_root', help='path to old root'),
Wei-Han Chen0a3320e2016-04-23 01:32:07 +0800582 _shopfloor_url_args_cmd_arg,
Wei-Han Chenbe1355a2016-04-24 19:31:03 +0800583 _release_rootfs_cmd_arg,
584 _station_ip_cmd_arg,
585 _station_port_cmd_arg,
Wei-Han Chenf3924112019-02-25 14:52:58 +0800586 _wipe_finish_token_cmd_arg,
Meng-Huan Yu7a4f0f52020-01-07 20:11:01 +0800587 _keep_developer_mode_flag_after_clobber_state_cmd_arg,
588 _test_umount_cmd_arg)
Wei-Han Chen7dc6d132016-04-06 11:11:53 +0800589def WipeInit(options):
Wei-Han Chenf3924112019-02-25 14:52:58 +0800590 GetGooftool(options).WipeInit(
591 options.wipe_args,
592 options.shopfloor_url,
593 options.state_dev,
594 options.release_rootfs,
595 options.root_disk,
596 options.old_root,
597 options.station_ip,
598 options.station_port,
599 options.wipe_finish_token,
Meng-Huan Yu7a4f0f52020-01-07 20:11:01 +0800600 options.keep_developer_mode_flag_after_clobber_state,
601 options.test_umount)
Wei-Han Chen7dc6d132016-04-06 11:11:53 +0800602
Stimim Chen8aaa2952020-05-20 13:04:24 +0800603
Cheng Yueh14f50af2020-11-25 13:49:10 +0800604@Command(
605 'verify',
606 _hwid_status_list_cmd_arg,
607 _hwdb_path_cmd_arg,
608 _project_cmd_arg,
609 _probe_results_cmd_arg,
610 _hwid_cmd_arg,
611 _hwid_run_vpd_cmd_arg,
612 _hwid_vpd_data_file_cmd_arg,
613 _no_write_protect_cmd_arg,
614 _rma_mode_cmd_arg,
615 _cros_core_cmd_arg,
616 _has_ec_pubkey_cmd_arg,
617 _ec_pubkey_path_cmd_arg,
618 _ec_pubkey_hash_cmd_arg,
619 _release_rootfs_cmd_arg,
620 _firmware_path_cmd_arg,
621 _enforced_release_channels_cmd_arg,
622 _waive_list_cmd_arg,
623 _skip_list_cmd_arg,
624 _no_ectool_cmd_arg,
625 _enable_zero_touch_cmd_arg,
626 _cbi_eeprom_wp_status_cmd_arg,
627)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800628def Verify(options):
629 """Verifies if whole factory process is ready for finalization.
630
631 This routine performs all the necessary checks to make sure the
632 device is ready to be finalized, but does not modify state. These
633 checks include dev switch, firmware write protection switch, hwid,
634 system time, keys, and root file system.
635 """
Andy Cheng7a76cb82012-11-19 18:08:19 +0800636
Hung-Te Lin6d827542012-07-19 11:50:41 +0800637 if not options.no_write_protect:
Ricky Lianga70a1202013-03-15 15:03:17 +0800638 VerifyWPSwitch(options)
Hung-Te Lindd708d42014-07-11 17:05:01 +0800639 VerifyManagementEngineLocked(options)
Cheng Yueh14f50af2020-11-25 13:49:10 +0800640 VerifyCBIEEPROMWPStatus(options)
Ting Shen129fa6f2016-09-02 12:22:24 +0800641 VerifyHWID(options)
Ricky Lianga70a1202013-03-15 15:03:17 +0800642 VerifySystemTime(options)
Pin-Yen Lin215b7542020-05-05 09:45:37 +0800643 if options.has_ec_pubkey:
Yilun Lin599833f2017-12-22 14:07:46 +0800644 VerifyECKey(options)
Philip Chen84c16262020-07-30 17:35:27 -0700645 if HasFpmcu():
646 VerifyFpKey(options)
Ricky Lianga70a1202013-03-15 15:03:17 +0800647 VerifyKeys(options)
648 VerifyRootFs(options)
Cheng-Yi Chiang676b5292013-06-18 12:05:33 +0800649 VerifyTPM(options)
Hung-Te Lin53c49402017-07-26 13:10:58 +0800650 VerifyVPD(options)
bowgotsai529139c2015-05-30 01:39:49 +0800651 VerifyReleaseChannel(options)
Wei-Han Chen0de7cfd2020-01-03 16:49:20 +0800652 VerifyCrosConfig(options)
Stimim Chen8aaa2952020-05-20 13:04:24 +0800653 VerifySnBits(options)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800654
Hung-Te Lin56b18402015-01-16 14:52:30 +0800655
Jon Salzfe9036f2014-01-16 14:11:23 +0800656@Command('untar_stateful_files')
Hung-Te Lin388bce22014-06-03 19:56:40 +0800657def UntarStatefulFiles(unused_options):
Jon Salzfe9036f2014-01-16 14:11:23 +0800658 """Untars stateful files from stateful_files.tar.xz on stateful partition.
659
660 If that file does not exist (which should only be R30 and earlier),
661 this is a no-op.
662 """
Hung-Te Lin2333f3f2016-08-24 17:56:48 +0800663 # Path to stateful partition on device.
664 device_stateful_path = '/mnt/stateful_partition'
665 tar_file = os.path.join(device_stateful_path, 'stateful_files.tar.xz')
Jon Salzfe9036f2014-01-16 14:11:23 +0800666 if os.path.exists(tar_file):
Hung-Te Lin2333f3f2016-08-24 17:56:48 +0800667 Spawn(['tar', 'xf', tar_file], cwd=device_stateful_path,
Jon Salzfe9036f2014-01-16 14:11:23 +0800668 log=True, check_call=True)
669 else:
670 logging.warning('No stateful files at %s', tar_file)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800671
Jon Salz40b9f822014-07-25 16:39:55 +0800672
673@Command('log_source_hashes')
Peter Shihfdf17682017-05-26 11:38:39 +0800674def LogSourceHashes(options):
Jon Salz40b9f822014-07-25 16:39:55 +0800675 """Logs hashes of source files in the factory toolkit."""
Peter Shihfdf17682017-05-26 11:38:39 +0800676 del options # Unused.
Jon Salze60307f2014-08-05 16:20:00 +0800677 # WARNING: The following line is necessary to validate the integrity
678 # of the factory software. Do not remove or modify it.
679 #
680 # 警告:此行会验证工厂软件的完整性,禁止删除或修改。
Wei-Han Chena5c01a02016-04-23 19:27:19 +0800681 factory_par = sys_utils.GetRunningFactoryPythonArchivePath()
682 if factory_par:
683 event_log.Log(
684 'source_hashes',
685 **file_utils.HashPythonArchive(factory_par))
686 else:
687 event_log.Log(
688 'source_hashes',
Peter Shihad166772017-05-31 11:36:17 +0800689 **file_utils.HashSourceTree(os.path.join(paths.FACTORY_DIR, 'py')))
Jon Salz40b9f822014-07-25 16:39:55 +0800690
691
Tammo Spalink86a61c62012-05-25 15:10:35 +0800692@Command('log_system_details')
Peter Shihfdf17682017-05-26 11:38:39 +0800693def LogSystemDetails(options):
Tammo Spalink86a61c62012-05-25 15:10:35 +0800694 """Write miscellaneous system details to the event log."""
Andy Cheng7a76cb82012-11-19 18:08:19 +0800695
Ricky Liang43b879b2014-02-24 11:36:55 +0800696 event_log.Log('system_details', **GetGooftool(options).GetSystemDetails())
Tammo Spalink86a61c62012-05-25 15:10:35 +0800697
698
Jon Salza88b83b2013-05-27 20:00:35 +0800699def CreateReportArchiveBlob(*args, **kwargs):
700 """Creates a report archive and returns it as a blob.
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800701
Jon Salza88b83b2013-05-27 20:00:35 +0800702 Args:
703 See CreateReportArchive.
Andy Cheng7a76cb82012-11-19 18:08:19 +0800704
Jon Salza88b83b2013-05-27 20:00:35 +0800705 Returns:
Yilin Yange02d5722019-10-23 11:07:36 +0800706 An xmlrpc.client.Binary object containing a .tar.xz file.
Jon Salza88b83b2013-05-27 20:00:35 +0800707 """
Wei-Han Chen47416612016-09-14 17:41:52 +0800708 report_archive = CreateReportArchive(*args, **kwargs)
709 try:
Yilin Yangf6994c22019-12-09 16:17:21 +0800710 return xmlrpc.client.Binary(
711 file_utils.ReadFile(report_archive, encoding=None))
Wei-Han Chen47416612016-09-14 17:41:52 +0800712 finally:
713 os.unlink(report_archive)
Jon Salza88b83b2013-05-27 20:00:35 +0800714
715
716def CreateReportArchive(device_sn=None, add_file=None):
717 """Creates a report archive in a temporary directory.
718
719 Args:
720 device_sn: The device serial number (optional).
721 add_file: A list of files to add (optional).
722
723 Returns:
724 Path to the archive.
725 """
Philip Chen6ada02c2019-11-04 19:41:54 +0000726 # Flush Testlog data to DATA_TESTLOG_DIR before creating a report archive.
727 result, reason = state.GetInstance().FlushTestlog(
728 uplink=False, local=True, timeout=10)
729 if not result:
730 logging.warning('Failed to flush testlog data: %s', reason)
731
Hung-Te Lin6bd16472012-06-20 16:26:47 +0800732 def NormalizeAsFileName(token):
733 return re.sub(r'\W+', '', token).strip()
Jon Salza88b83b2013-05-27 20:00:35 +0800734
735 target_name = '%s%s.tar.xz' % (
736 time.strftime('%Y%m%dT%H%M%SZ',
737 time.gmtime()),
Hung-Te Lin56b18402015-01-16 14:52:30 +0800738 ('' if device_sn is None else
739 '_' + NormalizeAsFileName(device_sn)))
Tammo Spalink86a61c62012-05-25 15:10:35 +0800740 target_path = os.path.join(gettempdir(), target_name)
Jon Salza88b83b2013-05-27 20:00:35 +0800741
Tammo Spalink86a61c62012-05-25 15:10:35 +0800742 # Intentionally ignoring dotfiles in EVENT_LOG_DIR.
Pi-Hsun Shih1f569a72019-12-26 11:23:56 +0800743 tar_cmd = 'cd %s ; tar cJf %s * -C /' % (event_log.EVENT_LOG_DIR, target_path)
Jongpil Jung23355a92019-12-31 14:38:29 +0900744 tar_files = [paths.FACTORY_LOG_PATH, paths.DATA_TESTLOG_DIR]
745 if add_file:
746 tar_files = tar_files + add_file
Pi-Hsun Shih1f569a72019-12-26 11:23:56 +0800747 for f in tar_files:
748 # Require absolute paths since we use -C / to change current directory to
749 # root.
750 if not f.startswith('/'):
751 raise Error('Not an absolute path: %s' % f)
752 if not os.path.exists(f):
753 raise Error('File does not exist: %s' % f)
754 tar_cmd += ' %s' % pipes.quote(f[1:])
Tammo Spalink86a61c62012-05-25 15:10:35 +0800755 cmd_result = Shell(tar_cmd)
Jon Salzff88c022012-11-03 12:19:58 +0800756
Hung-Te Lin3756c432020-01-16 11:30:46 +0800757 if cmd_result.status == 1:
758 # tar returns 1 when some files were changed during archiving,
759 # but that is expected for log files so should ignore such failure
760 # if the archive looks good.
Pi-Hsun Shih1f569a72019-12-26 11:23:56 +0800761 Spawn(['tar', 'tJf', target_path], check_call=True, log=True,
Jon Salzff88c022012-11-03 12:19:58 +0800762 ignore_stdout=True)
763 elif not cmd_result.success:
Tammo Spalink86a61c62012-05-25 15:10:35 +0800764 raise Error('unable to tar event logs, cmd %r failed, stderr: %r' %
765 (tar_cmd, cmd_result.stderr))
Jon Salzff88c022012-11-03 12:19:58 +0800766
Jon Salza88b83b2013-05-27 20:00:35 +0800767 return target_path
768
769_upload_method_cmd_arg = CmdArg(
770 '--upload_method', metavar='METHOD:PARAM',
771 help=('How to perform the upload. METHOD should be one of '
Kevin Line4c64de2019-11-22 15:28:34 +0800772 '{ftp, shopfloor, ftps, cpfe, smb}.'))
Cheng-Han Yang31a3bd92018-08-23 19:04:04 +0800773_upload_max_retry_times_arg = CmdArg(
774 '--upload_max_retry_times', type=int, default=0,
775 help='Number of tries to upload. 0 to retry infinitely.')
Cheng-Han Yang3d4b0c02018-08-23 18:24:14 +0800776_upload_retry_interval_arg = CmdArg(
777 '--upload_retry_interval', type=int, default=None,
Cheng-Han Yang31a3bd92018-08-23 19:04:04 +0800778 help='Retry interval in seconds.')
Cheng-Han Yangc1697e22018-08-24 15:22:39 +0800779_upload_allow_fail_arg = CmdArg(
780 '--upload_allow_fail', action='store_true',
781 help='Continue finalize if report upload fails.')
Jon Salza88b83b2013-05-27 20:00:35 +0800782_add_file_cmd_arg = CmdArg(
783 '--add_file', metavar='FILE', action='append',
784 help='Extra file to include in report (must be an absolute path)')
785
Hung-Te Lin56b18402015-01-16 14:52:30 +0800786
Jon Salza88b83b2013-05-27 20:00:35 +0800787@Command('upload_report',
788 _upload_method_cmd_arg,
Cheng-Han Yang31a3bd92018-08-23 19:04:04 +0800789 _upload_max_retry_times_arg,
Cheng-Han Yang3d4b0c02018-08-23 18:24:14 +0800790 _upload_retry_interval_arg,
Cheng-Han Yangc1697e22018-08-24 15:22:39 +0800791 _upload_allow_fail_arg,
Jon Salza88b83b2013-05-27 20:00:35 +0800792 _add_file_cmd_arg)
793def UploadReport(options):
794 """Create a report containing key device details."""
Yong Hong65bda312018-12-13 20:05:58 +0800795 ro_vpd = vpd.VPDTool().GetAllData(partition=vpd.VPD_READONLY_PARTITION_NAME)
Jon Salza88b83b2013-05-27 20:00:35 +0800796 device_sn = ro_vpd.get('serial_number', None)
797 if device_sn is None:
798 logging.warning('RO_VPD missing device serial number')
Chun-Ta Lin53cbbd52016-06-08 21:42:19 +0800799 device_sn = 'MISSING_SN_' + time_utils.TimedUUID()
chuntsena6da2be2019-08-14 17:11:55 +0800800 target_path = CreateReportArchive(device_sn, options.add_file)
Jon Salza88b83b2013-05-27 20:00:35 +0800801
Tammo Spalink86a61c62012-05-25 15:10:35 +0800802 if options.upload_method is None or options.upload_method == 'none':
803 logging.warning('REPORT UPLOAD SKIPPED (report left at %s)', target_path)
804 return
805 method, param = options.upload_method.split(':', 1)
Cheng-Han Yang3d4b0c02018-08-23 18:24:14 +0800806
807 if options.upload_retry_interval is not None:
808 retry_interval = options.upload_retry_interval
809 else:
810 retry_interval = report_upload.DEFAULT_RETRY_INTERVAL
811
Tammo Spalink86a61c62012-05-25 15:10:35 +0800812 if method == 'shopfloor':
You-Cheng Syuf0f4be12017-12-05 16:33:53 +0800813 report_upload.ShopFloorUpload(
814 target_path, param,
Cheng-Han Yang3d4b0c02018-08-23 18:24:14 +0800815 'GRT' if options.command_name == 'finalize' else None,
Cheng-Han Yang31a3bd92018-08-23 19:04:04 +0800816 max_retry_times=options.upload_max_retry_times,
Cheng-Han Yangc1697e22018-08-24 15:22:39 +0800817 retry_interval=retry_interval,
818 allow_fail=options.upload_allow_fail)
Tammo Spalink86a61c62012-05-25 15:10:35 +0800819 elif method == 'ftp':
Cheng-Han Yang3d4b0c02018-08-23 18:24:14 +0800820 report_upload.FtpUpload(target_path, 'ftp:' + param,
Cheng-Han Yang31a3bd92018-08-23 19:04:04 +0800821 max_retry_times=options.upload_max_retry_times,
Cheng-Han Yangc1697e22018-08-24 15:22:39 +0800822 retry_interval=retry_interval,
823 allow_fail=options.upload_allow_fail)
Tammo Spalink86a61c62012-05-25 15:10:35 +0800824 elif method == 'ftps':
Cheng-Han Yang3d4b0c02018-08-23 18:24:14 +0800825 report_upload.CurlUrlUpload(target_path, '--ftp-ssl-reqd ftp:%s' % param,
Cheng-Han Yang31a3bd92018-08-23 19:04:04 +0800826 max_retry_times=options.upload_max_retry_times,
Cheng-Han Yangc1697e22018-08-24 15:22:39 +0800827 retry_interval=retry_interval,
828 allow_fail=options.upload_allow_fail)
Tammo Spalink86a61c62012-05-25 15:10:35 +0800829 elif method == 'cpfe':
Cheng-Han Yang3d4b0c02018-08-23 18:24:14 +0800830 report_upload.CpfeUpload(target_path, pipes.quote(param),
Cheng-Han Yang31a3bd92018-08-23 19:04:04 +0800831 max_retry_times=options.upload_max_retry_times,
Cheng-Han Yangc1697e22018-08-24 15:22:39 +0800832 retry_interval=retry_interval,
833 allow_fail=options.upload_allow_fail)
Kevin Line4c64de2019-11-22 15:28:34 +0800834 elif method == 'smb':
835 # param should be in form: <dest_path>.
836 report_upload.SmbUpload(target_path, 'smb:' + param,
837 max_retry_times=options.upload_max_retry_times,
838 retry_interval=retry_interval,
839 allow_fail=options.upload_allow_fail)
Tammo Spalink86a61c62012-05-25 15:10:35 +0800840 else:
Peter Shihbf6f22b2018-02-26 14:05:28 +0800841 raise Error('unknown report upload method %r' % method)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800842
843
Cheng Yueh14f50af2020-11-25 13:49:10 +0800844@Command(
845 'finalize',
846 CmdArg('--fast', action='store_true',
847 help='use non-secure but faster wipe method.'),
848 _no_ectool_cmd_arg,
849 _shopfloor_url_args_cmd_arg,
850 _hwdb_path_cmd_arg,
851 _hwid_status_list_cmd_arg,
852 _upload_method_cmd_arg,
853 _upload_max_retry_times_arg,
854 _upload_retry_interval_arg,
855 _upload_allow_fail_arg,
856 _add_file_cmd_arg,
857 _probe_results_cmd_arg,
858 _hwid_cmd_arg,
859 _hwid_run_vpd_cmd_arg,
860 _hwid_vpd_data_file_cmd_arg,
861 _no_write_protect_cmd_arg,
862 _rma_mode_cmd_arg,
Cheng-Han Yang40a19e22021-01-05 20:01:26 +0800863 _replacement_mlb_mode_cmd_arg,
Cheng Yueh14f50af2020-11-25 13:49:10 +0800864 _cros_core_cmd_arg,
865 _has_ec_pubkey_cmd_arg,
866 _ec_pubkey_path_cmd_arg,
867 _ec_pubkey_hash_cmd_arg,
868 _release_rootfs_cmd_arg,
869 _firmware_path_cmd_arg,
870 _enforced_release_channels_cmd_arg,
871 _station_ip_cmd_arg,
872 _station_port_cmd_arg,
873 _wipe_finish_token_cmd_arg,
874 _rlz_embargo_end_date_offset_cmd_arg,
875 _waive_list_cmd_arg,
876 _skip_list_cmd_arg,
877 _no_generate_mfg_date_cmd_arg,
878 _enable_zero_touch_cmd_arg,
879 _cbi_eeprom_wp_status_cmd_arg,
880)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800881def Finalize(options):
882 """Verify system readiness and trigger transition into release state.
883
Jon Salzaa3a30e2013-05-15 15:56:28 +0800884 This routine does the following:
885 - Verifies system state (see verify command)
Jon Salzfe9036f2014-01-16 14:11:23 +0800886 - Untars stateful_files.tar.xz, if it exists, in the stateful partition, to
887 initialize files such as the CRX cache
Jon Salzaa3a30e2013-05-15 15:56:28 +0800888 - Modifies firmware bitmaps to match locale
889 - Clears all factory-friendly flags from the GBB
890 - Removes factory-specific entries from RW_VPD (factory.*)
891 - Enables firmware write protection (cannot rollback after this)
Marco Chenecee04f2019-02-15 22:24:24 +0800892 - Initialize Fpmcu entropy
Jon Salzaa3a30e2013-05-15 15:56:28 +0800893 - Uploads system logs & reports
Earl Ou51182222016-09-09 12:16:48 +0800894 - Wipes the testing kernel, rootfs, and stateful partition
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800895 """
Cheng-Han Yang40a19e22021-01-05 20:01:26 +0800896 if options.replacement_mlb_mode:
897 # Replacement MLB mode only do cr50 finalize.
898 Cr50Finalize(options)
899 LogSourceHashes(options)
900 LogSystemDetails(options)
901 UploadReport(options)
902 return
903
Wei-Han Cheneb4f9a22018-03-09 14:52:23 +0800904 if not options.rma_mode:
905 # Write VPD values related to RLZ ping into VPD.
906 GetGooftool(options).WriteVPDForRLZPing(options.embargo_offset)
chuntsenaf1232f2019-03-20 15:45:54 +0800907 if options.generate_mfg_date:
908 GetGooftool(options).WriteVPDForMFGDate()
Cheng-Han Yang663763b2020-09-15 20:46:23 +0800909 Cr50Finalize(options)
Marco Chen9d0631c2018-08-31 10:52:44 +0800910 Verify(options)
Jon Salz40b9f822014-07-25 16:39:55 +0800911 LogSourceHashes(options)
Jon Salzfe9036f2014-01-16 14:11:23 +0800912 UntarStatefulFiles(options)
Chih-Yu Huang714dbc42015-07-21 16:42:16 +0800913 if options.cros_core:
914 logging.info('SetFirmwareBitmapLocale is skipped for ChromeOS Core device.')
915 else:
916 SetFirmwareBitmapLocale(options)
Jon Salzaa3a30e2013-05-15 15:56:28 +0800917 ClearFactoryVPDEntries(options)
Mattias Nisslercca761b2015-04-15 21:53:04 +0200918 GenerateStableDeviceSecret(options)
Shen-En Shih3e079b22017-09-11 05:43:09 -0700919 ClearGBBFlags(options)
Hung-Te Lin6d827542012-07-19 11:50:41 +0800920 if options.no_write_protect:
Pi-Hsun Shih1f569a72019-12-26 11:23:56 +0800921 logging.warning('WARNING: Firmware Write Protection is SKIPPED.')
Andy Cheng0465d132013-03-20 12:12:06 +0800922 event_log.Log('wp', fw='both', status='skipped')
Hung-Te Lin6d827542012-07-19 11:50:41 +0800923 else:
Wei-Han Chenba21f512016-10-14 18:52:33 +0800924 EnableFwWp(options)
Marco Chenecee04f2019-02-15 22:24:24 +0800925 FpmcuInitializeEntropy(options)
Jon Salza0f58e02012-05-29 19:33:39 +0800926 LogSystemDetails(options)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800927 UploadReport(options)
Earl Ou51182222016-09-09 12:16:48 +0800928
929 event_log.Log('wipe_in_place')
930 wipe_args = []
Earl Ou51182222016-09-09 12:16:48 +0800931 if options.shopfloor_url:
932 wipe_args += ['--shopfloor_url', options.shopfloor_url]
933 if options.fast:
934 wipe_args += ['--fast']
935 if options.station_ip:
936 wipe_args += ['--station_ip', options.station_ip]
937 if options.station_port:
938 wipe_args += ['--station_port', options.station_port]
939 if options.wipe_finish_token:
940 wipe_args += ['--wipe_finish_token', options.wipe_finish_token]
941 ExecFactoryPar('gooftool', 'wipe_in_place', *wipe_args)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800942
943
Ting Shen129fa6f2016-09-02 12:22:24 +0800944@Command('verify_hwid',
945 _probe_results_cmd_arg,
946 _hwdb_path_cmd_arg,
947 _hwid_cmd_arg,
Yong Hong68a0e0d2017-12-20 19:06:54 +0800948 _hwid_run_vpd_cmd_arg,
949 _hwid_vpd_data_file_cmd_arg,
Ting Shen129fa6f2016-09-02 12:22:24 +0800950 _rma_mode_cmd_arg)
951def VerifyHWID(options):
Ricky Liangc662be32013-12-24 11:50:23 +0800952 """A simple wrapper that calls out to HWID utils to verify version 3 HWID.
Ricky Liang53390232013-03-08 15:37:57 +0800953
Ricky Liangc662be32013-12-24 11:50:23 +0800954 This is mainly for Gooftool to verify v3 HWID during finalize. For testing
955 and development purposes, please use `hwid` command.
Ricky Liang53390232013-03-08 15:37:57 +0800956 """
Yong Hongada8e0e2018-01-04 16:36:21 +0800957 database = GetGooftool(options).db
Yong Hong68a0e0d2017-12-20 19:06:54 +0800958
Yong Hongada8e0e2018-01-04 16:36:21 +0800959 encoded_string = options.hwid or GetGooftool(options).ReadHWID()
960
961 probed_results = hwid_utils.GetProbedResults(infile=options.probe_results)
Yong Hong2c39bf22018-01-24 22:24:11 +0800962 device_info = hwid_utils.GetDeviceInfo()
Yong Hong65bda312018-12-13 20:05:58 +0800963 vpd_data = hwid_utils.GetVPDData(run_vpd=options.hwid_run_vpd,
964 infile=options.hwid_vpd_data_file)
Ricky Liang53390232013-03-08 15:37:57 +0800965
Hung-Te Lin11052952015-03-18 13:48:59 +0800966 event_log.Log('probed_results', probed_results=FilterDict(probed_results))
Ricky Liang53390232013-03-08 15:37:57 +0800967
Yong Hong2c39bf22018-01-24 22:24:11 +0800968 hwid_utils.VerifyHWID(database, encoded_string, probed_results,
Yong Hong65bda312018-12-13 20:05:58 +0800969 device_info, vpd_data, options.rma_mode)
Ricky Liang53390232013-03-08 15:37:57 +0800970
Ricky Liangc662be32013-12-24 11:50:23 +0800971 event_log.Log('verified_hwid', hwid=encoded_string)
Ricky Liang53390232013-03-08 15:37:57 +0800972
973
henryhsu44d793a2013-07-20 00:07:38 +0800974@Command('get_firmware_hash',
Marco Chence70b132018-05-03 23:43:39 +0800975 CmdArg('--file', required=True, metavar='FILE', help='Firmware File.'))
henryhsu44d793a2013-07-20 00:07:38 +0800976def GetFirmwareHash(options):
henryhsuf6f835c2013-07-20 20:49:25 +0800977 """Get firmware hash from a file"""
henryhsu44d793a2013-07-20 00:07:38 +0800978 if os.path.exists(options.file):
Cheng-Han Yang2c668ae2018-04-18 22:31:07 +0800979 value_dict = chromeos_firmware.CalculateFirmwareHashes(options.file)
Yilin Yang879fbda2020-05-14 13:52:30 +0800980 for key, value in value_dict.items():
Yilin Yang71e39412019-09-24 09:26:46 +0800981 print(' %s: %s' % (key, value))
henryhsu44d793a2013-07-20 00:07:38 +0800982 else:
983 raise Error('File does not exist: %s' % options.file)
984
henryhsuf6f835c2013-07-20 20:49:25 +0800985
Philip Chen04fb90b2019-11-06 12:10:33 -0800986@Command('fpmcu_initialize_entropy')
Marco Chenecee04f2019-02-15 22:24:24 +0800987def FpmcuInitializeEntropy(options):
988 """Initialze entropy of FPMCU."""
Philip Chen04fb90b2019-11-06 12:10:33 -0800989
990 if HasFpmcu():
Marco Chenecee04f2019-02-15 22:24:24 +0800991 GetGooftool(options).FpmcuInitializeEntropy()
Philip Chen04fb90b2019-11-06 12:10:33 -0800992 else:
993 logging.info('No FPS on this board.')
Marco Chenecee04f2019-02-15 22:24:24 +0800994
995
Peter Shihfdf17682017-05-26 11:38:39 +0800996def main():
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800997 """Run sub-command specified by the command line args."""
Andy Cheng7a76cb82012-11-19 18:08:19 +0800998
Tammo Spalink9a96b8a2012-04-03 11:10:41 +0800999 options = ParseCmdline(
Ting Shen129fa6f2016-09-02 12:22:24 +08001000 'Perform Google required factory tests.',
Tammo Spalink9a96b8a2012-04-03 11:10:41 +08001001 CmdArg('-l', '--log', metavar='PATH',
1002 help='Write logs to this file.'),
Jon Salza4bea382012-10-29 13:00:34 +08001003 CmdArg('--suppress-event-logs', action='store_true',
1004 help='Suppress event logging.'),
Wei-Han Chenaff56232016-04-16 09:17:59 +08001005 CmdArg('--phase', default=None,
1006 help=('override phase for phase checking (defaults to the current '
1007 'as returned by the "factory phase" command)')),
Wei-Han Chenb34bdff2019-09-26 13:07:50 +08001008 VERBOSITY_CMD_ARG)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +08001009 SetupLogging(options.verbosity, options.log)
Andy Cheng0465d132013-03-20 12:12:06 +08001010 event_log.SetGlobalLoggerDefaultPrefix('gooftool')
1011 event_log.GetGlobalLogger().suppress = options.suppress_event_logs
Tammo Spalink9a96b8a2012-04-03 11:10:41 +08001012 logging.debug('gooftool options: %s', repr(options))
Wei-Han Chenaff56232016-04-16 09:17:59 +08001013
1014 phase.OverridePhase(options.phase)
Tammo Spalink9a96b8a2012-04-03 11:10:41 +08001015 try:
1016 logging.debug('GOOFTOOL command %r', options.command_name)
1017 options.command(options)
1018 logging.info('GOOFTOOL command %r SUCCESS', options.command_name)
Peter Shih6674ecf2018-03-29 14:04:57 +08001019 except Error as e:
Tammo Spalink9a96b8a2012-04-03 11:10:41 +08001020 logging.exception(e)
1021 sys.exit('GOOFTOOL command %r ERROR: %s' % (options.command_name, e))
Peter Shih6674ecf2018-03-29 14:04:57 +08001022 except Exception as e:
Tammo Spalink9a96b8a2012-04-03 11:10:41 +08001023 logging.exception(e)
1024 sys.exit('UNCAUGHT RUNTIME EXCEPTION %s' % e)
1025
1026
1027if __name__ == '__main__':
Peter Shihfdf17682017-05-26 11:38:39 +08001028 main()