Skip to content

Packaged DTBO has a correct payload but a different digest

scope: device:google-taimen · severity: trap · confidence: proven · subsystem: boot

Symptom — The Taimen DTBO source appears correct, but the packaged /boot/dtbo.img fails the image export’s exact digest check.

Cause — mkdtboimg cfg_create writes the 364-byte DTBO table and pads the file to its 2048-byte page size. The header’s total-size field is big-endian: d7 b7 ab 1e 00 00 01 6c starts with the magic and declares 364 bytes. Reading that field with a native-endian od -tu4 produced 1,812,004,864 on the little-endian build host and once made a sparse file of that size.

What to do — Keep the table bytes declared by the header, parse its size as big-endian, and reject an invalid magic or size before packaging. Check the APK’s extracted DTBO length and SHA-256, not only the DTS or build log.