summaryrefslogtreecommitdiff
path: root/static
diff options
context:
space:
mode:
authorDaniel Micay <daniel.micay@grapheneos.org>2023-06-27 22:47:07 -0400
committerDaniel Micay <daniel.micay@grapheneos.org>2023-06-27 22:49:40 -0400
commit7bf9b2671667828d1553c92bf4f64cc749b74d0b (patch)
tree29b48257e8075c720a0363d24f4f9523feaf31e6 /static
parent5220461d573468da44f5b67a6903da8ff167b234 (diff)
drop legacy info on APEX components
Diffstat (limited to 'static')
-rw-r--r--static/build.html31
-rw-r--r--static/js/redirect.js2
2 files changed, 12 insertions, 21 deletions
diff --git a/static/build.html b/static/build.html
index c8260be5..ce8c4531 100644
--- a/static/build.html
+++ b/static/build.html
@@ -28,6 +28,7 @@
<link rel="manifest" href="/manifest.webmanifest"/>
<link rel="license" href="/LICENSE.txt"/>
<link rel="me" href="https://grapheneos.social/@GrapheneOS"/>
+ {{js|/js/redirect.js}}
</head>
<body>
<header>
@@ -80,7 +81,7 @@
<ul>
<li><a href="#migration-to-android-13">Migration to Android 13</a></li>
<li><a href="#encrypting-keys">Encrypting keys</a></li>
- <li><a href="#enabling-updatable-apex-components">Enabling updatable APEX components</a></li>
+ <li><a href="#apex-components">APEX components</a></li>
</ul>
</li>
<li>
@@ -606,27 +607,15 @@ cd ../..</pre>
the keys in tmpfs to perform signing.</p>
</section>
- <section id="enabling-updatable-apex-components">
- <h4><a href="#enabling-updatable-apex-components">Enabling updatable APEX components</a></h4>
+ <section id="apex-components">
+ <h4><a href="#apex-components">APEX components</a></h4>
- <p>GrapheneOS uses the <code>TARGET_FLATTEN_APEX := true</code> format to
- include APEX components as part of the base OS and disables support for
- out-of-band APEX component updates. This reduces complexity and attack
- surface along with simplifying key management since there aren't a bunch
- of additional components to sign. GrapheneOS has no use for out-of-band
- updates to APEX components since we update the OS for each device and
- don't need partial out-of-band updates for portable components.</p>
-
- <p>APEX components that aren't flattened are a signed APK (used to verify
- updates) with an embedded filesystem image signed with an AVB key (for
- verified boot). Our release signing scripts has support for signing
- non-flattened APEX components with the releasekey and AVB key for the
- device. This secures it but wouldn't be usable for shipping out-of-band
- updates to APEX components across multiple devices. You could switch to
- using a single shared APEX APK signing key and AVB signing key. You'll
- also need to add parameters for additional device-specific APEX components
- not included in our release signing script which was set up based on the
- Pixel 6 and Pixel 6 Pro.</p>
+ <p>GrapheneOS currently doesn't use out-of-date updates to APEX
+ components, so these are all signed with the OS releasekey and verified
+ boot key to avoid needing many extra pairs of keys. Each APEX needs an APK
+ signing key and verified boot signing key. If you want to ship out-of-band
+ updates to APEX components, you'll need to deal with this and you should
+ make a separate pair of keys for each one.</p>
<p>Consult the upstream documentation on generating these keys. It will
likely be covered here in the future, especially if non-flattened APEX
diff --git a/static/js/redirect.js b/static/js/redirect.js
index 3e43d8d7..8bc575e0 100644
--- a/static/js/redirect.js
+++ b/static/js/redirect.js
@@ -24,6 +24,8 @@ const redirects = new Map([
["/install/cli#fastboot-as-non-root", "/install/cli#flashing-as-non-root"],
["/install/web#fastboot-as-non-root", "/install/web#flashing-as-non-root"],
+ ["/build#enabling-updatable-apex-components", "/build#apex-components"],
+
// legacy devices
["/releases#marlin-stable", "/faq#legacy-devices"],
["/releases#marlin-beta", "/faq#legacy-devices"],