View Issue Details

IDProjectCategoryView StatusLast Update
0001970T99X171.00 SKB EagleSWpublic2024-09-04 14:55
Reporter(SW) Kerwin Chen Assigned To(ALTech) Sangmin Choi Due Date2024-07-26 00:00
PriorityhighSeveritys4-minorReproducibilityalways
Status closedResolutionfixed 
Summary0001970: Need to apply Amlogic Production patches to fix security vulnerability
DescriptionHi YK,

In 2024-03 Android Security Bulletin, there are 2 security vulnerabilities related to Amlogic platform.
https://source.android.com/docs/security/bulletin/2024-03-01

Amlogic already provide patches to fix these issues.
However, if we enable 'production mode', then Amlogic burning tool and fastboot will not support.
Only OTA could be used for FW upgrade.

It is heard that Intek already apply and enable production mode.
We want to make sure if SKB agree to apply and enable production for Eagle.
Thanks.
TagsNo tags attached.
Attach Tags

Users monitoring this issue

User List (ALTech) Jong-Hwa JUNG , (ALTech) JunGyu Kim , (ALTech) Sangmin Choi , (ALTech) SY Yoon , (ALTech) Wooshin Kang

Activities

(SW) Kerwin Chen

2024-07-04 09:25

developer  

image.png (52,637 bytes)   
image.png (52,637 bytes)   

(ALTech) Younkwang Jung

2024-07-04 10:31

developer   ~0016169

Hi Kerwin

I'll check the contents and update you.

>> Amlogic already provide patches to fix these issues.
=> Please let me know the amlogic patch files.

>> if we enable 'production mode', then Amlogic burning tool and fastboot will not support.
=> Please further explain what production mode is.

>> It is heard that Intek already apply and enable production mode
=> Did you hear this from Taiwan's Amlogic FAE?

Thank you
YK.Jung

(SW) Kerwin Chen

2024-07-04 13:44

developer   ~0016171

Hi YK,

>>Please let me know the amlogic patch files
=> will share patch files later

>>Please further explain what production mode is.
=> It is a flag used in uboot to make sure device security for Amlogic platforms.
In the CVE events, it is possible to get higher permission by uboot commands. (flashing binary images on some devices)
So Google asks Amlogic to disable console output, commands for production devices.

>>Did you hear this from Taiwan's Amlogic FAE?
=> Yes

(SW) Sam Yang

2024-07-04 14:33

developer   ~0016172

=> will share patch files later
=> "production_patch.zip"
production_patch.zip (13,789 bytes)

(ALTech) Younkwang Jung

2024-07-04 14:52

developer   ~0016173

Hi Kerwin

>> Amlogic burning tool and fastboot will not support.
  At here you said ,"fastboot will not support."
  fastboot is described in "Requirements for flashing GSI" at Google .
  I don't understand that fastboot is not supported.

>> Is there anything that could make a difference when customers use STB after applying this patch ?

Thank you
YK.Jung

(SW) Kerwin Chen

2024-07-04 15:13

developer   ~0016174

Hi YK,

Android VTS/GSI or debug need enable fastboot unlock function through --fastboot-write.
This means we need to build a sepcial bootload image.

(ALTech) Younkwang Jung

2024-07-04 15:22

developer   ~0016175

Hi Kerwin

I checked with Korea Amlogic FAE
This patch(#c16172) you mentioned is not applicable to our Smart3 system.
- Smart3's path is bootloader/uboot-repo/bl33/v2015 , AML_ATV_Q2S
- This patch(#c16172)'s patch is bootloader/uboot-repo/bl33/v2019 , Android S Hailstorm 5.2 SDK

Please check it again with Taiwan's Amlogic FAE

Thank you
YK.Jung

(SW) Kerwin Chen

2024-07-04 19:37

developer   ~0016180

Hi YK,

Acturally, Amlogic also provides patches for Uboot-2015.
The contents are almost the same.
image-2.png (35,131 bytes)   
image-2.png (35,131 bytes)   

(ALTech) Younkwang Jung

2024-07-05 11:06

developer   ~0016184

Hi Kerwin

I am checking whether production mode is applied to other manufacturers
and to check, please share the patch , if you have any documents, please attach them.

In addition, please check if it was received from the path below at FXN
git clone ssh://git@openlinux2.amlogic.com/s-amlogic/vendor/amlogic/tools/DroidlogicPatch
If it is different, please let me know the path of the patch you received.

Thank you
YK.Jung

(SW) Kerwin Chen

2024-07-05 14:49

developer   ~0016189

Hi YK,

For uboot-2015, I found it in git of Android R patches, not 's-amlogic/vendor/amlogic/tools/DroidlogicPatch'.
I attach here for reference.
BTW, I don't have document for it.
production_patch_R.tar (163,840 bytes)

(ALTech) Younkwang Jung

2024-07-11 12:34

developer   ~0016243

Hi Kerwin

The Jira below has been created.
https://jira.skbroadband.com/browse/AMANDROIDS-194
and it is said that it is already applied in INTEK.

I'll talk to SKB about applying it early next week.
Please let me know if there is any problem or different from the previous one after applying the patch.

Thank you
YK.Jung
image-3.png (93,343 bytes)   
image-3.png (93,343 bytes)   

(SW) Kerwin Chen

2024-07-11 15:03

developer   ~0016246

Hi YK,

Could you share QtoS patch to us ?
It seems Amlogic provide it on SKB JIRA.
We will try to apply and check the result.
Thanks!

(ALTech) Younkwang Jung

2024-07-11 15:32

developer   ~0016248

Hi Kerwin

I have attached a patch file
Please check it

Thank you
YK.Jung
v2015.zip (10,809 bytes)
image-4.png (62,990 bytes)   
image-4.png (62,990 bytes)   

(SW) Kerwin Chen

2024-07-11 15:54

developer   ~0016250

Hi Kinbay,

Please integrate and check the result.
Thanks!

(ALTech) Younkwang Jung

2024-07-17 14:14

developer   ~0016271

Hi Kinbay

I'd like to know the test result by this week.
What is your expected schedule?

Thank you
YK.Jung

(SW) Kinbay Wu

2024-07-17 15:32

developer   ~0016272

Hi YK
 
I tested an image with these patches.
The command "fastboot flashing unlock" will return the below message.
    FAILED (remote: 'missing partition name')
    fastboot: error: Command failed
It means the gsi can't flash by fastboot anymore.
 
We asked Amlogic if there was any other way to work around it.
They recommend building a special image for flash gsi.
That way need to check with Google/3PL because that is a different image.
 
Best Regards
Kinbay

(SW) Kinbay Wu

2024-07-18 11:58

developer   ~0016287

Last edited: 2024-07-18 11:59

Hi YK
 
For the special case.
Undefine "CONFIG_NO_FASTBOOT_FLASHING" to enable fastboot to unlock for flashing.
Then GSI can be flashing into STB.
Patch path: bootloader/uboot-repo/bl33/v2015
 
Best Regards
Kinbay
unlock_fastboot_flashing_for_gsi.diff (513 bytes)   
diff --git a/board/amlogic/configs/g12a_u212_v1.h b/board/amlogic/configs/g12a_u212_v1.h
index e68b39058b..b6858e2f18 100644
--- a/board/amlogic/configs/g12a_u212_v1.h
+++ b/board/amlogic/configs/g12a_u212_v1.h
@@ -46,7 +46,7 @@
 #define CONFIG_AML_PRODUCT_MODE 1 //
 #ifdef CONFIG_AML_PRODUCT_MODE
 #define CONFIG_SILENT_CONSOLE
-#define CONFIG_NO_FASTBOOT_FLASHING
+// #define CONFIG_NO_FASTBOOT_FLASHING
 #define CONFIG_USB_TOOL_ENTRY   "echo product mode"
 #define CONFIG_KNL_LOG_LEVEL    "loglevel=1"
 #else

(ALTech) Sangmin Choi

2024-07-18 13:36

developer   ~0016295

Hello, Kinbay,

Apply Amlogic Production patches -> can't flash the gsi
Apply Amlogic Production patches + undef CONFIG_NO_FASTBOOT_FLASHING -> can flash the gsi
Do I understand correctly?

I wonder if there is any special step when I flash the gsi.

Thank you.
Sangmin Choi.

(SW) Kinbay Wu

2024-07-18 13:45

developer   ~0016296

Hi Sangmin

Apply Amlogic Production patches -> can't flash the gsi
Apply Amlogic Production patches + undef CONFIG_NO_FASTBOOT_FLASHING -> can flash the gsi
Do I understand correctly?
=> Yes.

I wonder if there is any special step when I flash the gsi.
=> No need just need to use the special user build image.

Best Regards
Kinbay

(ALTech) Sangmin Choi

2024-07-18 14:10

developer   ~0016297

Hello, Kinbay,

I wonder if there is any special step when I flash the gsi.
=> No need just need to use the special user build image.
==> Do you prepare the user image for CTS and user image for CTS-on-GSI ? Could you please let me know the steps when you run the Google xTS ?

Thank you.
Sangmin Choi.

(SW) Kinbay Wu

2024-07-18 15:04

developer   ~0016298

Hi Sangmin
 
I uploaded the two user build images to FTP.
ftp://altserver01.duckdns.org/release_by_fxn/tmp/mantis1970/

[usb_bfx-at100_V15.542.906t2_SU.zip] is a normal user build:
      apply production patches => It can't flash the gsi.
[usb_bfx-at100_V15.542.906t3_SU.zip] is a special user build:
      apply production patches + undef CONFIG_NO_FASTBOOT_FLASHING => It can flash the gsi.
 
I only tested the images to flash the gsi process, not have time to run fully Google xTS yet.
If any problem let me know thanks
 
Best Regards
Kinbay

(SW) Kinbay Wu

2024-07-22 17:49

developer   ~0016320

Hi Sangmin, YK
FYI

I ask 3PL about the special user build image for flash the gsi.
They are feedback that is OK.

Best Regards
Kinbay

(ALTech) Younkwang Jung

2024-07-23 08:04

developer   ~0016322

Hi Kinbay

I tried to apply the patch(#c16248), but an error was occurring.
I think you also modified the patch when applying it.
Please share the "apply production patches "applied to #c16298.

Thank you
YK.Jung

(SW) Kinbay Wu

2024-07-23 09:03

developer   ~0016323

Hi YK
 
Attached is production patches as I use it.
If any questions let me know. Thanks.
 
Best Regards
Kinbay

(ALTech) Younkwang Jung

2024-07-24 09:42

developer   ~0016330

Hi Kinbay

The production patch is different.
I have attached the production patch I received from AML KOR.
- #c16248 ( https://jira.skbroadband.com/browse/AMANDROIDS-194 )

Please check which one is correct.

Thank you
YK.Jung

(SW) Kinbay Wu

2024-07-26 08:59

developer   ~0016337

Hi YK
 
I have modified the patches based on your v2015 from #c16248
BTW, That is the same as v2015 in production_patch_R.tar from #c16189
 
If any questions let me know.
 
Thanks
Kinbay

(ALTech) Wooshin Kang

2024-07-29 09:08

developer   ~0016339

Hi Kinbay,

Did you finish google test using firmware included this patch ?
Please update your status.

Thanks

(SW) Kinbay Wu

2024-08-01 15:15

developer   ~0016372

Hi Wooshin
 
I let the SQA team start the Google test yesterday.
If they complete the test, I will inform you.
 
BR,
Kinbay

(SW) Kinbay Wu

2024-08-09 11:23

developer   ~0016441

Hi Wooshin
 
We finish the full Google xTS 906t2 & 906t3 for production mode.
There is no issue found.
 
BR,
Kinbay

(ALTech) Sangmin Choi

2024-08-09 12:00

developer   ~0016442

Hello, Kinbay,

Could you please guide us any difference when I run the Google xTS with the firmware which is applied Amlogic production patches?

Did you flash the firmware using Amlogic burning tool?

I think there are three firmwares to run Google xTS.
1. user build
2. user build + undef CONFIG_NO_FASTBOOT_FLASHING
3. userdebug build
So, should the fingerprint of firmware #1 and firmware #2 is different?
If yes, the fingerprint of CTS report and CTS-on-GSI report will be different. Is it okay to get the certification?

Please let me know even there is any small different things.

Thank you.
Sangmin Choi.

(SW) Kinbay Wu

2024-08-09 15:38

developer   ~0016444

Hi Sangmin Choi
 
Could you please guide us any difference when I run the Google xTS with the firmware which is applied Amlogic production patches?
=> No difference, only you need to use a different image to flash the gsi.
 
Did you flash the firmware using Amlogic burning tool?
=> Can't use the Amlogic's burning tool after applying the production patches. Must use OTA image to burning.
 
So, should the fingerprint of firmware #1 and firmware #2 is different?
=> No, these two images will have the same fingerprint.
 
BR,
Kinbay

(ALTech) Younkwang Jung

2024-08-13 13:02

developer   ~0016455

Hi Kinbay

The BMT of the Smart3 UI542c(CUG model) is in progress right now. ( BMT : ~ Aug/26th)
we have to get Google approval after BMT ends. ( Google approval : ~ Aug / 29th or 30th )

Does this patch must be included in the UI542c FW that needs to be approved by Google this time?
In other words , is there no problem with Google approval even if we don't include this patch?
Please check it

Thank you
YK.Jung

(SW) Kinbay Wu

2024-08-13 15:38

developer   ~0016457

Hi YK
 
Google has not set a deadline for including these patches.
Amlogic is asking us to apply ASAP.
 
So I think this time, it's not a problem to get Google's approval without these patches.

BR,
Kinbay

(ALTech) Younkwang Jung

2024-08-20 12:02

developer   ~0016494

Hi Kinbay

Please apply this production patchs to Smart3 UI543 branch and use the "[AMANDROIDS-194]" for prefix of commit message.
and I will let you know if any issues are observed during the verification later.

Thank you
YK.Jung

(SW) Kinbay Wu

2024-08-20 15:06

developer   ~0016500

Hi YK,
 
Push done.
Please check it.
 
---
0bfb678f | bootable/recovery | [AMANDROIDS-194] [MT-1970] recovery: add condition to check if get the aml script val
b887e96 | vendor/amlogic/common/pre_submit_for_google | [AMANDROIDS-194] [MT-1970] recovery: add condition to check if get the aml script val
c4e80a96a33f | common | [AMANDROIDS-194] [MT-1970] Common: Kernel reserved memory info. [1/1]
7117cda256 | bootloader/uboot-repo/bl33/v2015 | [AMANDROIDS-194] [MT-1970] BL33: Uboot 2015 Security Mode Configuration [1/1]
1985088afa | bootloader/uboot-repo/bl33/v2015 | [AMANDROIDS-194] [MT-1970] production_patch: Update production patch according to lat
---
 
BR,
Kinbay

(ALTech) Sangmin Choi

2024-08-28 13:39

developer   ~0016593

Hello, Kinbay,

We have complete the Google test using the firmware you shared and there is no issue.
[usb_bfx-at100_V15.542.906t2_SU.zip] is a normal user build:
[usb_bfx-at100_V15.542.906t3_SU.zip] is a special user build:

For my understanding, when I upgrade the STB using usb_bfx-at100_V15.542.906t2_SU.zip, flashing GSI is not possible. Am I right?
But, I can flash the GSI.

Could you please check it?

Thank you.
Sangmin Choi.

(SW) Kinbay Wu

2024-08-28 15:38

developer   ~0016595

Hi Sangmin
 
I double-confirmed that the t2 version can't flash the gsi.
You can go into fastboot but the start from "fastboot flashing unlock" will fail.
I force continues to go through the "flash system" command will fail too.
Please check it.
 
BR,
Kinbay
image-5.png (183,887 bytes)   
image-5.png (183,887 bytes)   

(ALTech) Sangmin Choi

2024-08-28 16:09

developer   ~0016596

Hello, Kinbay,

I attached the captured image of command, flashing gsi is possible.
It's really weird.

Thank you.
Sangmin Choi.
flash_gsi.png (615,817 bytes)

(SW) Kinbay Wu

2024-08-28 16:46

developer   ~0016597

Hi Sangmin

I'm flashing the image with the AML flash tool.
Can you try to use it?

BR,
Kinbay

(ALTech) Sangmin Choi

2024-08-28 17:03

developer   ~0016598

Hello, Kinbay,

I'm flashing the image with the AML flash tool.
Can you try to use it?
-> Can I know why do you request it?

Thank you.
Sangmin Choi.

(ALTech) Sangmin Choi

2024-08-30 12:42

developer   ~0016616

Hello, Kinbay,

I flashed the firmware using AML flash tool.
And, I can't flash the gsi.

So, I upgraded using USB image, but also I can't flash the gsi anymore.

I can't reproduce it anymore, but I don't know there is any problem or not.

How about your opinion?

Thank you.
Sangmin Choi.

(ALTech) Sangmin Choi

2024-09-03 08:46

developer   ~0016628

Hello, Kinbay,

Could you please check my comment?

Thank you.
Sangmin Choi.

(SW) Kinbay Wu

2024-09-03 09:11

developer   ~0016629

Hi Sangmin
 
You can try to do a factory reset after flash.
 
BR,
Kinbay

(ALTech) Sangmin Choi

2024-09-03 09:36

developer   ~0016631

Hello, Kinbay,

I'm sorry but I don't know what is your point.

Does the factory reset affect the above result?

Why did you request that flash the image using AML burning tool?
Is there any difference with flash the image by USB and flash the image by AML burning tool?

Thank you.
Sangmin Choi.

(ALTech) Sangmin Choi

2024-09-04 14:55

developer   ~0016658

Hello, Kinbay,

Flashing GSI is just related with lock flag, it's not an issue.
I close this issue.

Thank you.
Sangmin Choi.

Issue History

Date Modified Username Field Change
2024-07-04 09:25 (SW) Kerwin Chen New Issue
2024-07-04 09:25 (SW) Kerwin Chen Status new => assigned
2024-07-04 09:25 (SW) Kerwin Chen Assigned To => (ALTech) Younkwang Jung
2024-07-04 09:25 (SW) Kerwin Chen File Added: image.png
2024-07-04 10:28 (ALTech) Younkwang Jung Issue Monitored: (ALTech) SY Yoon
2024-07-04 10:28 (ALTech) Younkwang Jung Issue Monitored: (ALTech) JunGyu Kim
2024-07-04 10:28 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Wooshin Kang
2024-07-04 10:28 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Sangmin Choi
2024-07-04 10:28 (ALTech) Younkwang Jung Issue Monitored: (ALTech) Jong-Hwa JUNG
2024-07-04 10:31 (ALTech) Younkwang Jung Note Added: 0016169
2024-07-04 13:44 (SW) Kerwin Chen Note Added: 0016171
2024-07-04 14:33 (SW) Sam Yang Note Added: 0016172
2024-07-04 14:33 (SW) Sam Yang File Added: production_patch.zip
2024-07-04 14:52 (ALTech) Younkwang Jung Note Added: 0016173
2024-07-04 15:13 (SW) Kerwin Chen Note Added: 0016174
2024-07-04 15:22 (ALTech) Younkwang Jung Note Added: 0016175
2024-07-04 19:37 (SW) Kerwin Chen Note Added: 0016180
2024-07-04 19:37 (SW) Kerwin Chen File Added: image-2.png
2024-07-05 11:06 (ALTech) Younkwang Jung Note Added: 0016184
2024-07-05 14:49 (SW) Kerwin Chen Note Added: 0016189
2024-07-05 14:49 (SW) Kerwin Chen File Added: production_patch_R.tar
2024-07-11 12:34 (ALTech) Younkwang Jung Note Added: 0016243
2024-07-11 12:34 (ALTech) Younkwang Jung File Added: image-3.png
2024-07-11 15:03 (SW) Kerwin Chen Note Added: 0016246
2024-07-11 15:32 (ALTech) Younkwang Jung Note Added: 0016248
2024-07-11 15:32 (ALTech) Younkwang Jung File Added: v2015.zip
2024-07-11 15:32 (ALTech) Younkwang Jung File Added: image-4.png
2024-07-11 15:54 (SW) Kerwin Chen Note Added: 0016250
2024-07-11 15:54 (SW) Kerwin Chen Assigned To (ALTech) Younkwang Jung => (SW) Kinbay Wu
2024-07-17 14:14 (ALTech) Younkwang Jung Note Added: 0016271
2024-07-17 15:32 (SW) Kinbay Wu Note Added: 0016272
2024-07-18 11:58 (SW) Kinbay Wu Note Added: 0016287
2024-07-18 11:58 (SW) Kinbay Wu File Added: unlock_fastboot_flashing_for_gsi.diff
2024-07-18 11:59 (SW) Kinbay Wu Note Edited: 0016287
2024-07-18 13:36 (ALTech) Sangmin Choi Note Added: 0016295
2024-07-18 13:45 (SW) Kinbay Wu Note Added: 0016296
2024-07-18 14:10 (ALTech) Sangmin Choi Note Added: 0016297
2024-07-18 15:04 (SW) Kinbay Wu Note Added: 0016298
2024-07-22 17:49 (SW) Kinbay Wu Note Added: 0016320
2024-07-23 08:04 (ALTech) Younkwang Jung Note Added: 0016322
2024-07-23 09:03 (SW) Kinbay Wu Note Added: 0016323
2024-07-23 09:03 (SW) Kinbay Wu File Added: production_patch_kbfix.zip
2024-07-24 09:42 (ALTech) Younkwang Jung Note Added: 0016330
2024-07-26 08:59 (SW) Kinbay Wu Note Added: 0016337
2024-07-29 09:08 (ALTech) Wooshin Kang Note Added: 0016339
2024-08-01 15:15 (SW) Kinbay Wu Note Added: 0016372
2024-08-09 11:23 (SW) Kinbay Wu Note Added: 0016441
2024-08-09 12:00 (ALTech) Sangmin Choi Note Added: 0016442
2024-08-09 15:38 (SW) Kinbay Wu Note Added: 0016444
2024-08-13 13:02 (ALTech) Younkwang Jung Note Added: 0016455
2024-08-13 15:38 (SW) Kinbay Wu Note Added: 0016457
2024-08-20 12:02 (ALTech) Younkwang Jung Note Added: 0016494
2024-08-20 15:06 (SW) Kinbay Wu Note Added: 0016500
2024-08-28 13:39 (ALTech) Sangmin Choi Note Added: 0016593
2024-08-28 15:38 (SW) Kinbay Wu Note Added: 0016595
2024-08-28 15:38 (SW) Kinbay Wu File Added: image-5.png
2024-08-28 16:09 (ALTech) Sangmin Choi Note Added: 0016596
2024-08-28 16:09 (ALTech) Sangmin Choi File Added: flash_gsi.png
2024-08-28 16:46 (SW) Kinbay Wu Note Added: 0016597
2024-08-28 17:03 (ALTech) Sangmin Choi Note Added: 0016598
2024-08-30 12:42 (ALTech) Sangmin Choi Note Added: 0016616
2024-09-03 08:46 (ALTech) Sangmin Choi Note Added: 0016628
2024-09-03 09:11 (SW) Kinbay Wu Note Added: 0016629
2024-09-03 09:36 (ALTech) Sangmin Choi Note Added: 0016631
2024-09-04 14:55 (ALTech) Sangmin Choi Note Added: 0016658
2024-09-04 14:55 (ALTech) Sangmin Choi Assigned To (SW) Kinbay Wu => (ALTech) Sangmin Choi
2024-09-04 14:55 (ALTech) Sangmin Choi Status assigned => closed
2024-09-04 14:55 (ALTech) Sangmin Choi Resolution open => fixed