adlr@google.com | 3defe6a | 2009-12-04 20:57:17 +0000 | [diff] [blame] | 1 | // Copyright (c) 2009 The Chromium Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
| 5 | // Update file format: A delta update file contains all the deltas needed |
| 6 | // to update a system from one specific version to another specific |
| 7 | // version. The update format is represented by this struct pseudocode: |
| 8 | // struct delta_update_file { |
| 9 | // char magic[4] = "CrAU"; |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 10 | // uint32 file_format_version = 1; |
| 11 | // uint64 manifest_size; // Size of protobuf DeltaArchiveManifest |
| 12 | // // The Bzip2 compressed DeltaArchiveManifest |
| 13 | // char manifest[]; |
adlr@google.com | 3defe6a | 2009-12-04 20:57:17 +0000 | [diff] [blame] | 14 | // |
| 15 | // // Data blobs for files, no specific format. The specific offset |
| 16 | // // and length of each data blob is recorded in the DeltaArchiveManifest. |
| 17 | // struct { |
| 18 | // char data[]; |
| 19 | // } blobs[]; |
| 20 | // |
Andrew de los Reyes | 94f025d | 2010-08-16 17:17:27 -0700 | [diff] [blame^] | 21 | // // These two are not signed: |
| 22 | // uint64 signatures_message_size; |
| 23 | // char signatures_message[]; |
| 24 | // |
adlr@google.com | 3defe6a | 2009-12-04 20:57:17 +0000 | [diff] [blame] | 25 | // }; |
| 26 | |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 27 | // The DeltaArchiveManifest protobuf is an ordered list of InstallOperation |
| 28 | // objects. These objects are stored in a linear array in the |
| 29 | // DeltaArchiveManifest. Each operation is applied in order by the client. |
adlr@google.com | 3defe6a | 2009-12-04 20:57:17 +0000 | [diff] [blame] | 30 | |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 31 | // The DeltaArchiveManifest also contains the initial and final |
| 32 | // checksums for the device. |
adlr@google.com | 3defe6a | 2009-12-04 20:57:17 +0000 | [diff] [blame] | 33 | |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 34 | // The client will perform each InstallOperation in order, beginning even |
| 35 | // before the entire delta file is downloaded (but after at least the |
| 36 | // protobuf is downloaded). The types of operations are explained: |
| 37 | // - REPLACE: Replace the dst_extents on the drive with the attached data, |
| 38 | // zero padding out to block size. |
| 39 | // - REPLACE_BZ: bzip2-uncompress the attached data and write it into |
| 40 | // dst_extents on the drive, zero padding to block size. |
| 41 | // - MOVE: Copy the data in src_extents to dst_extents. Extents may overlap, |
| 42 | // so it may be desirable to read all src_extents data into memory before |
| 43 | // writing it out. |
| 44 | // - BSDIFF: Read src_length bytes from src_extents into memory, perform |
| 45 | // bspatch with attached data, write new data to dst_extents, zero padding |
| 46 | // to block size. |
adlr@google.com | 3defe6a | 2009-12-04 20:57:17 +0000 | [diff] [blame] | 47 | |
| 48 | package chromeos_update_engine; |
| 49 | |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 50 | // Data is packed into blocks on disk, always starting from the beginning |
| 51 | // of the block. If a file's data is too large for one block, it overflows |
| 52 | // into another block, which may or may not be the following block on the |
| 53 | // physical partition. An ordered list of extents is another |
| 54 | // representation of an ordered list of blocks. For example, a file stored |
| 55 | // in blocks 9, 10, 11, 2, 18, 12 (in that order) would be stored in |
| 56 | // extents { {9, 3}, {2, 1}, {18, 1}, {12, 1} } (in that order). |
| 57 | // In general, files are stored sequentially on disk, so it's more efficient |
| 58 | // to use extents to encode the block lists (this is effectively |
| 59 | // run-length encoding). |
| 60 | // A sentinel value (kuint64max) as the start block denotes a sparse-hole |
| 61 | // in a file whose block-length is specified by num_blocks. |
adlr@google.com | 3defe6a | 2009-12-04 20:57:17 +0000 | [diff] [blame] | 62 | |
Andrew de los Reyes | 94f025d | 2010-08-16 17:17:27 -0700 | [diff] [blame^] | 63 | // Signatures: Updates may be signed by the OS vendor. The client verifies |
| 64 | // an update's signature by hashing the entire download. The section of the |
| 65 | // download the contains the signature is at the end of the file, so when |
| 66 | // signing a file, only the part up to the signature part is signed. |
| 67 | // Then, the client looks inside the download's Signatures message for a |
| 68 | // Signature message that it knows how to handle. Generally, a client will |
| 69 | // only know how to handle one type of signature, but an update may contain |
| 70 | // many signatures to support many different types of client. Then client |
| 71 | // selects a Signature message and uses that, along with a known public key, |
| 72 | // to verify the download. The public key is expected to be part of the |
| 73 | // client. |
| 74 | |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 75 | message Extent { |
| 76 | optional uint64 start_block = 1; |
| 77 | optional uint64 num_blocks = 2; |
adlr@google.com | 3defe6a | 2009-12-04 20:57:17 +0000 | [diff] [blame] | 78 | } |
| 79 | |
Andrew de los Reyes | 94f025d | 2010-08-16 17:17:27 -0700 | [diff] [blame^] | 80 | message Signatures { |
| 81 | message Signature { |
| 82 | optional uint32 version = 1; |
| 83 | optional string data = 2; |
| 84 | } |
| 85 | repeated Signature signatures = 1; |
| 86 | } |
| 87 | |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 88 | message DeltaArchiveManifest { |
| 89 | message InstallOperation { |
| 90 | enum Type { |
| 91 | REPLACE = 0; // Replace destination extents w/ attached data |
| 92 | REPLACE_BZ = 1; // Replace destination extents w/ attached bzipped data |
| 93 | MOVE = 2; // Move source extents to destination extents |
| 94 | BSDIFF = 3; // The data is a bsdiff binary diff |
| 95 | } |
| 96 | required Type type = 1; |
| 97 | // The offset into the delta file (after the protobuf) |
| 98 | // where the data (if any) is stored |
| 99 | optional uint32 data_offset = 2; |
| 100 | // The length of the data in the delta file |
| 101 | optional uint32 data_length = 3; |
| 102 | |
| 103 | // Ordered list of extents that are read from (if any) and written to. |
| 104 | repeated Extent src_extents = 4; |
| 105 | // Byte length of src, not necessarily block aligned. It's only used for |
| 106 | // BSDIFF, because we need to pass that external program the number |
| 107 | // of bytes to read from the blocks we pass it. |
| 108 | optional uint64 src_length = 5; |
| 109 | |
| 110 | repeated Extent dst_extents = 6; |
| 111 | // byte length of dst, not necessarily block aligned. It's only used for |
| 112 | // BSDIFF, because we need to fill in the rest of the last block |
| 113 | // that bsdiff writes with '\0' bytes. |
| 114 | optional uint64 dst_length = 7; |
| 115 | } |
| 116 | repeated InstallOperation install_operations = 1; |
Andrew de los Reyes | f4c7ef1 | 2010-04-30 10:37:00 -0700 | [diff] [blame] | 117 | repeated InstallOperation kernel_install_operations = 2; |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 118 | |
| 119 | // (At time of writing) usually 4096 |
Andrew de los Reyes | f4c7ef1 | 2010-04-30 10:37:00 -0700 | [diff] [blame] | 120 | optional uint32 block_size = 3 [default = 4096]; |
Andrew de los Reyes | 94f025d | 2010-08-16 17:17:27 -0700 | [diff] [blame^] | 121 | |
| 122 | // If signatures are present, the offset into the blobs, generally |
| 123 | // tacked onto the end of the file. We use an offset rather than |
| 124 | // a bool to allow for more flexibility in future file formats. |
| 125 | // If this is absent, it means signatures aren't supported in this |
| 126 | // file. |
| 127 | optional uint64 signatures_offset = 4; |
Andrew de los Reyes | 1e338b8 | 2010-01-22 14:57:27 -0800 | [diff] [blame] | 128 | } |