diff options
| author | Daniel Micay <daniel.micay@grapheneos.org> | 2023-06-27 22:47:07 -0400 |
|---|---|---|
| committer | Daniel Micay <daniel.micay@grapheneos.org> | 2023-06-27 22:49:40 -0400 |
| commit | 7bf9b2671667828d1553c92bf4f64cc749b74d0b (patch) | |
| tree | 29b48257e8075c720a0363d24f4f9523feaf31e6 /static/build.html | |
| parent | 5220461d573468da44f5b67a6903da8ff167b234 (diff) | |
drop legacy info on APEX components
Diffstat (limited to 'static/build.html')
| -rw-r--r-- | static/build.html | 31 |
1 files changed, 10 insertions, 21 deletions
diff --git a/static/build.html b/static/build.html index c8260be5..ce8c4531 100644 --- a/static/build.html +++ b/static/build.html @@ -28,6 +28,7 @@ <link rel="manifest" href="/manifest.webmanifest"/> <link rel="license" href="/LICENSE.txt"/> <link rel="me" href="https://grapheneos.social/@GrapheneOS"/> + {{js|/js/redirect.js}} </head> <body> <header> @@ -80,7 +81,7 @@ <ul> <li><a href="#migration-to-android-13">Migration to Android 13</a></li> <li><a href="#encrypting-keys">Encrypting keys</a></li> - <li><a href="#enabling-updatable-apex-components">Enabling updatable APEX components</a></li> + <li><a href="#apex-components">APEX components</a></li> </ul> </li> <li> @@ -606,27 +607,15 @@ cd ../..</pre> the keys in tmpfs to perform signing.</p> </section> - <section id="enabling-updatable-apex-components"> - <h4><a href="#enabling-updatable-apex-components">Enabling updatable APEX components</a></h4> + <section id="apex-components"> + <h4><a href="#apex-components">APEX components</a></h4> - <p>GrapheneOS uses the <code>TARGET_FLATTEN_APEX := true</code> format to - include APEX components as part of the base OS and disables support for - out-of-band APEX component updates. This reduces complexity and attack - surface along with simplifying key management since there aren't a bunch - of additional components to sign. GrapheneOS has no use for out-of-band - updates to APEX components since we update the OS for each device and - don't need partial out-of-band updates for portable components.</p> - - <p>APEX components that aren't flattened are a signed APK (used to verify - updates) with an embedded filesystem image signed with an AVB key (for - verified boot). Our release signing scripts has support for signing - non-flattened APEX components with the releasekey and AVB key for the - device. This secures it but wouldn't be usable for shipping out-of-band - updates to APEX components across multiple devices. You could switch to - using a single shared APEX APK signing key and AVB signing key. You'll - also need to add parameters for additional device-specific APEX components - not included in our release signing script which was set up based on the - Pixel 6 and Pixel 6 Pro.</p> + <p>GrapheneOS currently doesn't use out-of-date updates to APEX + components, so these are all signed with the OS releasekey and verified + boot key to avoid needing many extra pairs of keys. Each APEX needs an APK + signing key and verified boot signing key. If you want to ship out-of-band + updates to APEX components, you'll need to deal with this and you should + make a separate pair of keys for each one.</p> <p>Consult the upstream documentation on generating these keys. It will likely be covered here in the future, especially if non-flattened APEX |
