Parsing and re-packing Android boot.img/vbmeta.img/payload.bin, supporting Android 13 preview
You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 
Go to file
cfig 32139203e7
fix several critial bug
details
 - code refine
 "In Kotlin 1.3, it is now possible to capture the when subject into variable"
 - fix gradle version checking bug: now we can handle versions like "5.4-rc-1" and "5.4"
 - removed unwanted import of "UnImplNode"
 - add Struct3 doc
6 years ago
avb mass update 6 years ago
bbootimg fix several critial bug 6 years ago
boot_signer replace AOSP bouncycastle with upstream bcprov-jdk15on:1.57 7 years ago
doc fix several critial bug 6 years ago
gradle/wrapper upgrade build 6 years ago
mkbootfs
security
src update integrationTest for android Q preview 6 years ago
tools replace AOSP bouncycastle with upstream bcprov-jdk15on:1.57 7 years ago
.gitattributes
.gitignore
.gitmodules add submodule for integrationTest resources 6 years ago
.travis.yml
LICENSE.md
README.md update integrationTest for android Q preview 6 years ago
build.gradle fix several critial bug 6 years ago
gradlew upgrade build 6 years ago
gradlew.bat upgrade build 6 years ago
integrationTest.py update integrationTest for android Q preview 6 years ago
settings.gradle replace AOSP bouncycastle with upstream bcprov-jdk15on:1.57 7 years ago
short.md

README.md

Android_boot_image_editor

Build Status License

This tool focuses on editing Android boot.img(also recovery.img, recovery-two-step.img and vbmeta.img).

1. Prerequisite

1.1 Host OS requirement:

Linux or Mac. Also need python 2.x and jdk 8.

1.2 Target Android requirement:

(1) Target boot.img MUST follows AOSP verified boot flow, either Boot image signature in VBoot 1.0 or AVB HASH footer in VBoot 2.0.

Supported images:

  • boot.img
  • recovery.img
  • recovery-two-step.img
  • vbmeta.img

(2) These utilities are known to work for Nexus/Pixel boot.img for the following Android releases:

  • AOSP master
  • Lollipop (5.0) - Q preview

2. Usage

Put your boot.img to current directory, then start gradle 'unpack' task:

cp <original_boot_image> boot.img
./gradlew unpack

Your get the flattened kernel and /root filesystem under ./build/unzip_boot:

build/unzip_boot/
├── boot.img.avb.json (AVB only)
├── bootimg.json (boot image info)
├── kernel
├── second       (2nd bootloader, if exists)
├── dtb          (dtb, if exists)
├── dtbo         (dtbo, if exists)
└── root

Then you can edit the actual file contents, like rootfs or kernel. Now, pack the boot.img again

./gradlew pack

You get the repacked boot.img at $(CURDIR):

boot.img.signed

If you are working with recovery.img

If you are working with recovery.img, the steps are similar:

cp <original_recovery_image> recovery.img
./gradlew unpack
./gradlew pack

And you get recovery.img.signed

3. example & test

An example boot.img has been placed at src/test/resources/boot.img, which is extracted from Nexus 5x(code: bullhead) factory images from Google, you can take it as a quick start.

4. boot.img layout

Read layout of Android boot.img. We now support both VB 1.0 and AVB 2.0 layouts.

5. compatible devices

Device Model Manufacturer Compatible Android Version Note
Pixel 3 (blueline) Google Y Q preview (qpp2.190228.023,
2019)
more ...
Pixel XL (marlin) HTC Y 9.0.0 (PPR2.180905.006,
Sep 2018)
more ...
Z18(NX606J) ZTE Y 8.1.0 more...
Nexus 9 (volantis/flounder) HTC Y(with some tricks) 7.1.1 (N9F27M, Oct 2017) tricks
Nexus 5x (bullhead) LG Y 6.0.0_r12 (MDA89E)
Moto X (2013) T-Mobile Motorola N

6. References

boot_signer https://android.googlesource.com/platform/system/extras

bouncycastle https://android.googlesource.com/platform/external/bouncycastle

cpio / fs_config https://android.googlesource.com/platform/system/core

AVB https://android.googlesource.com/platform/external/avb/

mkbootimg https://android.googlesource.com/platform/system/core/+/master/mkbootimg/

Android version list https://source.android.com/source/build-numbers.html