Removing --flag 2 when building GSI vbmeta.img
With the support of enabling AVB on standalone partitions in libfs_avb, devices can boot GSI with dm-verity. No need to disable AVB anymore. Devices still can use the following command to disable AVB on device-specific vbmeta.img if needed: `fastboot flash --disable-verification vbmeta vbmeta.img` Bug: 130595457 Test: Tree Hugger Change-Id: I067dcda15f14f04428e0b60ce1f49227d61e4349
This commit is contained in:
parent
db57997c72
commit
2e2a7682ba
|
@ -28,16 +28,9 @@ BOARD_PRODUCTIMAGE_FILE_SYSTEM_TYPE :=
|
|||
BOARD_USES_METADATA_PARTITION := true
|
||||
|
||||
# Android Verified Boot (AVB):
|
||||
# Set AVB_VBMETA_IMAGE_FLAGS_VERIFICATION_DISABLED (--flags 2) in
|
||||
# vbmeta.img to disable AVB verification. Also set the rollback index
|
||||
# to zero, to prevent the device bootloader from updating the last seen
|
||||
# rollback index in the tamper-evident storage.
|
||||
#
|
||||
# To disable AVB for GSI, use the vbmeta.img and the GSI together.
|
||||
# To enable AVB for GSI, include the GSI public key into the device-specific
|
||||
# vbmeta.img.
|
||||
# Set the rollback index to zero, to prevent the device bootloader from
|
||||
# updating the last seen rollback index in the tamper-evident storage.
|
||||
BOARD_AVB_ROLLBACK_INDEX := 0
|
||||
BOARD_AVB_MAKE_VBMETA_IMAGE_ARGS += --flags 2
|
||||
|
||||
# Enable chain partition for system.
|
||||
BOARD_AVB_SYSTEM_KEY_PATH := external/avb/test/data/testkey_rsa2048.pem
|
||||
|
|
Loading…
Reference in New Issue