FRG01B OTA enables a feature to undo custom recovery partitions

Discussion in 'Droid Labs' started by MotoCache1, Aug 22, 2010.

  1. MotoCache1
    Offline

    MotoCache1 Chief Droid Scientist

    Joined:
    Jun 30, 2010
    Messages:
    530
    Likes Received:
    1
    Trophy Points:
    18
    Ratings:
    +1
    Two days ago (8/20) over in the SBF to root/unroot topic I was helping a couple people troubleshoot a very strange problem they were having. The result of that troubleshooting led to a very interesting (and important) discovery. Perhaps this has already been discovered by someone else, but if it has, I've not seen it. This discovery may help resolve a lot of bizarre problems that are going on out there.

    Symptom:
    User successfully flashes a new image to the recovery partition (we'll say it is Clockwork for this example, but it could just as well be SPRecovery or any other recovery). They are able to boot into recovery and their custom recovery is shown as expected. When finished they boot the phone back to the OS. The next time they try to go into recovery, they find that the phone is now back to the stock recovery. Both users received FRG01B OTA and are unrooted. They attempted to install SPRecovery using my new "recovery only" SBF that does not touch the kernel (/boot) partition. This would also occur if they had rooted with EasyRoot and then used ROM Manager to flash Clockwork or SPRecovery on (tested on my phone after resolution was known). It was observed that their phones were reporting a boot loader version of 2C.7C whereas my phone (and the phone of everyone else who could not reproduce the problem) was 2C.6C.


    Outcome:
    It turns out that the FRG01B OTA package contains a new feature that I have decided to call "Flash Recovery Service" (hereinafter "FRS") after I dug through the OS and found the code that was responsible. FRS knows what the SHA1 hash (similar to an MD5 sum or hash) should be for the recovery partition. When you boot the OS, FRS checks the SHA1 hash of the recovery partition, and if it is not correct it "patches" it back to stock. Hence, you can change the recovery to whatever you want, but at the next boot of the OS it will change back.


    How to Fix It:
    Many aren't interested in the technical details of how it was isolated or how it works, and will stop after this section.

    To keep FRS from flashing your recovery partition back to stock on each boot of the OS, you need to rename or delete the /system/recovery-from-boot.p file so that FRS can't find it. There are many ways to do this. I will present two manual methods here which both require root.

    [I have built a method to fix this which does not require root and which will go ahead and root your phone in the process. I will be publishing that information soon and will update this post with a link when it is published.]

    Using Root Explorer:

    1. Navigate to /system
    2. Remount the partition r/w
    3. Delete the file or rename it recovery-from-boot.p.not (or whatever you want).
    4. Remount the partition r/o
    Using ADB:

    1. adb shell
    2. su
    3. mount -o remount,rw -t yaffs2 /dev/block/mtdblock4 /system
    4. cd /system
    5. mv recovery-from-boot.p recovery-from-boot.p.not (or "rm recovery-from-boot.p" if you want to delete it)
    6. mount -o remount,ro -t yaffs2 /dev/block/mtdblock4 /system

    [Remainder of this is not for folks who don't want to understand how any of this works.]

    Troubleshooting Highlights:
    Problem initially could not be duplicated on my Droid 1 even after flashing FRG01B on using the SBF. Flashing the FRG01B SBF onto my phone did not change the boot loader from 2C.6C to 2C.7C. I was ultimately able to get my phone to boot loader 2C.7C by flashing ESE81 on via SBF and then applying the FRG01B OTA (update.zip). Once I did that, I was able to reproduce the problem they were seeing. Since applying the FRG01B SBF did not exhibit the problem and applying the OTA update.zip did, my first effort at a crude fix was just to flash the SBF back on. This did get rid of the "feature" but did not change the boot loader back to 2C.6C. This told me that the boot loader had nothing to do with the issue. Then I sifted through the OTA update.zip file looking at what the code was doing and found the rest of the pieces of the puzzle.


    How Flash Recovery Service Works:
    Under FRG01B, in the init.rc file there appears something new that wasn't there in ESE81:

    Code:
    service flash_recovery /system/etc/install-recovery.sh
        oneshot
    
    Each time the OS boots it therefore runs /system/etc/install-recovery.sh.

    install-recovery.sh:
    Code:
    #!/system/bin/sh
    if ! applypatch -c MTD:recovery:2048:e341bb90b74f7eb644b7d72501be659ce229bb1b; then
      log -t recovery "Installing new recovery image"
      applypatch MTD:boot:2875392:d104d2ec84a2d0660e786c0fb8174bfacb4079d6 MTD:recovery 57de46b6424e717d68c9c3856b339271bc0e5980 3125248 d104d2ec84a2d0660e786c0fb8174bfacb4079d6:/system/recovery-from-boot.p
    else
      log -t recovery "Recovery image already installed"
    fi
    What this does it look at the first 2K block of the recovery partition image and take a SHA1 has of it. If the hash isn't the one shown then it calls "applypatch". Applypatch uses the first 2,875,392 bytes of the boot partition image (headers, kernel, and ramdisk) and the contents of /system/recovery-from-boot.p (a "diff" file) to mathematically reconstruct an image of the recovery partition. I went through this process myself and indeed ended up with a byte-perfect "stock" recovery image. Then the re-created stock recovery image is flashed to the recovery partition.

    By making the diff file (recovery-from-boot.p) unavailable the applypatch can't run and it has no choice but to leave the recovery partition "as is". It will still put an entry in the system log each time you boot that says "Installing new recovery image", but it won't actually be able to do it. If you want, you can also rename or delete the /system/etc/install-recovery.sh file and then it won't even try. In my instructions I don't have you do that just because if you ever want to re-enable it, it's easier if you've only renamed the .p file and just have to rename it back.

    Interestingly, even though the version of FRG01B in the SBF does not exhibit the FRS feature, it does contain it. The "service" commands are included in the init.rc in the FRG01B SBF, but interestingly the /system/recovery-from-boot.p and /system/etc/install-recovery.sh files are not. So, the service tries to run but doesn't because the files it needs aren't there.

    I have dissected the ramdisk out of the ESE81 kernel (where the init.rc file is located) and ESE81 did not have this "service".

    That was a fun one. :)

    [Edited to add: If you flash a custom ROM or kernel that will also kill the FRS. Since the applypatch command uses data from the boot image coupled with the recovery-from-boot.p file, if the boot image doesn't match the SHA1 hash the applypatch will abort as well. This may be why fewer people have noticed -- many of the people who root also put on a custom ROM or kernel shortly thereafter. In some further looking through prior OTA's, the recovery-from-boot.p and install-recovery.sh files were actually in the ESE81 OTA too. The "service" wasn't in the init.rc, but presumably they got kicked off a different way (and it isn't worth going back and figuring out what that way was at the moment).

    If you go back far enough there used to be a recovery.img in /system that got flashed in on each reboot. So it seems like this scheme has been around in some form for a long time. I'd bet that with each new OTA there is a round of people having strange problems putting on a custom recovery and having it revert, and they somehow get it fixed and everyone forgets about it. I did some searches and found several such posts here. I read them grinning because everyone is confounded as to how you could flash on a recovery and have it just disappear and go back to stock. Eventually the OP magically fixes it but they don't know how. Usually how they fixed it was by flashing in the recovery within ROM Manager and flashing in a ROM within ROM Manager at the same time. That replaces the boot image with one with a "wrong" SHA1 signature and voila the recovery partition stops reverting. Of course they don't know that was why. Anyway, these discoveries certainly make the presence of this feature in the 2.2 OTA a lot less insidious. It's still important that everyone understand it so they can avoid all the thrashing around trying to solve some odd problem of their recovery not "sticking". I'd still like to know why the boot loader needed to change from 2C.6C to 2C.7C. That probably worries me more than the FRS.]
  2. Corinacakes
    Offline

    Corinacakes DF Super Moderator Theme Developer

    Joined:
    Nov 17, 2009
    Messages:
    5,031
    Likes Received:
    3
    Trophy Points:
    153
    Location:
    Maine
    Ratings:
    +3
    Great discovery and writeup!!!!!!
  3. gavron
    Online

    gavron Guest

    Top Poster Of Month

    Ratings:
    +0
    Nicely done!!! Very well annotated! :)
    E
  4. cupfulloflol
    Offline

    cupfulloflol Senior Member

    Joined:
    Dec 5, 2009
    Messages:
    1,898
    Likes Received:
    22
    Trophy Points:
    68
    Ratings:
    +23
    Those sly and persistent devils.

    Good writeup. :)
  5. k3mist
    Offline

    k3mist New Member

    Joined:
    Aug 22, 2010
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    1
    Ratings:
    +0
    I decided to root my phone for the first time ever yesterday after the 2.2 update because of amazon and visual voice mail constantly running in the background even after you kill them over and over. Seriously retarded.

    I was in a bad situation with my droid1 because of this recovery issue just about an hour ago (playing with stuff already). I still could get into stock recovery but I don't have a windows PC anywhere in the house, so no RSDLite for me. Luckily, I found the full system update on this forum, put it on the sdcard and was able to run update.zip and from there, re-rooted, flashed, restored from backup. And obviously, thanks to the OP, I do not have to go through that again :)



    http://www.droidforums.net/forum/dr...yo-rollout-thread-version2-95.html#post747069
  6. beneharris
    Offline

    beneharris Member

    Joined:
    Dec 27, 2009
    Messages:
    318
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    portland
    Ratings:
    +0
    ok this one is sweet too. this should be considered for a sticky also.

    or at least in someone's sig so that its easy to find!
  7. Se7enLC
    Offline

    Se7enLC Active Member

    Joined:
    Nov 16, 2009
    Messages:
    1,263
    Likes Received:
    0
    Trophy Points:
    36
    Ratings:
    +0
    Isn't this old news? 2.0, 2.0.1 and 2.1 all did that, too - on boot, it would run install-recovery.sh and re-install the stock recovery image.
  8. MotoCache1
    Offline

    MotoCache1 Chief Droid Scientist

    Joined:
    Jun 30, 2010
    Messages:
    530
    Likes Received:
    1
    Trophy Points:
    18
    Ratings:
    +1
    Check the "Edited to Add" block toward the bottom. Apparently the concept has been implemented in the various builds, but not necessarily always functional. My stock ESE81 didn't exhibit the behavior, and the FRG01B SBF image has the service but not the script or the .p file in it.

    Even if it is old news, judging by posts here over the last year+ very few people were aware of it and it has caused (and continues to cause) quite a bit of confusion. At least now it's documented. :)
  9. gavron
    Online

    gavron Guest

    Top Poster Of Month

    Ratings:
    +0
    I don't know. Nobody in real life runs these OTA builds. Everybody I know runs a custom ROM and enjoys the features of free WiFi tether, etc.

    It's only on the net that some people apparently think they should stick with OTA. Their experience is what has led to this thread.

    E
  10. Tallica
    Offline

    Tallica Premium Member Rescue Squad Premium Member

    Joined:
    Mar 17, 2010
    Messages:
    3,259
    Likes Received:
    1
    Trophy Points:
    101
    Location:
    Middleboro, MA
    Ratings:
    +1
    You couldn't be more wrong. 99% of people with these phones run them stock and have no idea what root or a custom Rom is.

    Only about 1% of android users root their phones.
  11. Tallica
    Offline

    Tallica Premium Member Rescue Squad Premium Member

    Joined:
    Mar 17, 2010
    Messages:
    3,259
    Likes Received:
    1
    Trophy Points:
    101
    Location:
    Middleboro, MA
    Ratings:
    +1
    Great Job Moto, you're making our job eaiser!:)
  12. gavron
    Online

    gavron Guest

    Top Poster Of Month

    Ratings:
    +0
    Let me clarify.

    Of the people who post here that they are rooted, the majority run custom ROMs.

    I'm sorry that wasn't clear from my first post.

    Stop making up fake statistics.

    And by that I mean _now_.

    E
  13. Tallica
    Offline

    Tallica Premium Member Rescue Squad Premium Member

    Joined:
    Mar 17, 2010
    Messages:
    3,259
    Likes Received:
    1
    Trophy Points:
    101
    Location:
    Middleboro, MA
    Ratings:
    +1
    I might have exagerated a bit, but not much.

    And let me clairfy, everyday I see tons of cases of people have applied the 2.2 OTA before even knowing this site exists. Then they come here and root without knowing what they are doing, when the phone is messed up, who do they call....the RS!

    So what Moto has done here, is not only useful but infinitly valuable to the RS.

    Again I say, Great job Moto!
  14. gavron
    Online

    gavron Guest

    Top Poster Of Month

    Ratings:
    +0
    Yes, Moto has helped a lot! Already I have referred two people (one who started a thread, and one who asked me in a bar last night :) to Moto's comment.

    Kudos to you, Moto.

    E
  15. tdweng
    Offline

    tdweng Member

    Joined:
    Jun 10, 2010
    Messages:
    37
    Likes Received:
    0
    Trophy Points:
    6
    Ratings:
    +0
    MotoCache, i not sure if you tried or heard of this app, but i use it all the time and it is way easier then using ADB commands or root explorer to get to any folders that require root access. It is called droid explorer and installs on your PC. Once you have it installed all you should have to do is plug your phone in and then open the app, then it is will look like your normal windows explorer and you can get at any folder you want on your phone to push files and delete as needed. It has many other features as well, but that is what i use it for now. Works great on XP, have had issues getting it work on windows 7, have not tried it in awhile so they may have solved some of those issues now.

    Droid Explorer
Search tags for this page
cant delete install-recovery.sh
,
cant use restore options
,
custom backup list stock rom?
,

droid frs

,
install-recovery.sh
,
install-recovery.sh file isn't deleting
,

service flash recovery /system/etc/install-recovery.sh

,
undo phone flash
,
undo restore huawei