Secure upgrade: Difference between revisions

From OLPC
Jump to navigation Jump to search
(update to 8.2 build 767)
 
(8 intermediate revisions by 3 users not shown)
Line 1: Line 1:
<noinclude>{{OLPC}}{{Translations}}
<noinclude>{{OLPC}}{{Translations}}
{{obsolete|link=each release's [[Release notes]] have instructions for upgrading to it}}
{{merge|Clean-install procedure}}
This page describes how to reinstall the operating system of a secured laptop, whether it is unactivated (fresh from the factory) or already activated.
This page describes how to reinstall the operating system of a secured laptop, whether it is unactivated (fresh from the factory) or already activated.


Line 27: Line 27:
* To download those files, plug the USB flash drive into another computer that is connected to the Internet. Right-click (Ctrl-click for Mac) on each of the above two URLs in the browser and choose "Save Target As" ("Save Link As" for Firefox). Save both files to the USB flash drive. Eject/Remove the USB flash drive, and unplug it.
* To download those files, plug the USB flash drive into another computer that is connected to the Internet. Right-click (Ctrl-click for Mac) on each of the above two URLs in the browser and choose "Save Target As" ("Save Link As" for Firefox). Save both files to the USB flash drive. Eject/Remove the USB flash drive, and unplug it.


The first file is about 209KiB, and the second file is quite large (about 324 MiB), which might take a while to download.
The first file is about 154Kb, and the second file is quite large (about 233 Mb), which might take a while to download.


After you have finished this step, there should be two files on the USB flash drive, the fs.zip file, and the img file.
After you have finished this step, there should be two files on the USB flash drive, the fs.zip file, and the img file.
Line 51: Line 51:


===== Install activities =====
===== Install activities =====
No activities are included in some versions of the OLPC software. Follow these instructions to install basic activities on release 8.1.0 and 8.1.1.
No activities are included in some versions of the OLPC software. Follow these instructions to install basic activities on release 8.1.0, 8.1.1 and 8.2.0.


# Power off the XO
# Power off the XO
Line 72: Line 72:
16. If the screen says something that begins with
16. If the screen says something that begins with


OLPC build 703
OLPC build 767


then we are one step closer to finishing the upgrade process!
then we are one step closer to finishing the upgrade process!
Line 78: Line 78:
17. Go to Home view and mouse over the XO guy in the center.
17. Go to Home view and mouse over the XO guy in the center.


18. Select the "Shutdown" option to power off the machine. Now you should be able to power it up as usual, with build 703.
18. Select the "Shutdown" option to power off the machine. Now you should be able to power it up as usual, with build 767.


<noinclude>
<noinclude>
Line 90: Line 90:


# Get to a terminal on the laptop, and type: ls /security
# Get to a terminal on the laptop, and type: ls /security
#* ''On XO-1 this requires root permissions. Press the Ctrl+Alt+[[Image:Mesh key f1 small.png]] keys together to get to the console, log in as root and then enter the command above as stated.''
#* ''On XO-1 this requires root permissions. See [[Console]] for how to get them.
#* If there is a lease.sig file, you will want to save this lease before re-flashing the laptop.
#* If there is a lease.sig file, you will want to save this lease before re-flashing the laptop.
#*# To do so, insert a USB stick, wait for it to mount, and then type: cp /security/lease.sig /media/{name_of_usb_stick}
#*# To do so, insert a USB stick, wait for it to mount, and then type: cp /security/lease.sig /media/{name_of_usb_stick}
Line 118: Line 118:
===Upgrading to an '''Unsigned''' Image by disabling security===
===Upgrading to an '''Unsigned''' Image by disabling security===


To put an ''unsigned image'' (not a stable release), you will first need to disable activation security. In a country deployment, this may make your laptop more vulnerable to theft &mdash; but it's assumed that if you're running a unstable build you're a developer and willing to take the risk.
To put an ''unsigned image'' (not a stable release), you may first need to disable activation security. In a country deployment, this may make your laptop more vulnerable to theft &mdash; but it's assumed that if you're running a unstable build you're a developer and willing to take the risk.


See [[Activation_and_developer_keys#How_to_tell_if_your_laptop_is_secured|how to check]] if it is locked, [[Activation_and_developer_keys#Getting_a_developer_key|how to get]] a developer key, [[Activation_and_developer_keys#Using_a_developer_key|how to use]] a developer key, and [[Activation_and_developer_keys#Disabling_the_security_system|how to unlock]] permanently. For groups of laptops, use the [[collection stick]] then an [[collection stick#unlock stick|unlock stick]].
First, disable security on the laptop:

# Create a folder '''security''' on the top-level of your USB stick and place your develop.sig in this folder. Go to the [[Activation and Developer Keys]] page for details on how to get a develop.sig developer key
# Plug in the USB key and boot
# Immediately hit the "X" Escape key
# At the firmware '''ok''' prompt, type '''disable-security''' The XO should reboot. Pay attention to the messages given; you may have to repeat these two steps. Leave in the USB key.


Now, you can follow the normal "developer upgrade" instructions, using either [[Olpc-update|olpc-update]] or this OFW technique:
Now, you can follow the normal "developer upgrade" instructions, using either [[Olpc-update|olpc-update]] or this OFW technique:


# Create a USB stick with the files '''os{number}.img''' and '''os{number}.img.crc''' on the disk in the top-level directory. (We recommend that you use a "factory-formatted" USB stick.) (Note that the 'fs.zip' file is used only for 'secure' upgrade, not for this process, and does not exist for unstable builds.)
# Create a USB drive with the files '''os{number}.img''' and '''os{number}.crc''' on the disk in the top-level directory.
# Boot the laptop. OFW will prompt you to hit "Escape" (the X key in the upper-left) to interrupt the boot process. Do so!
# Boot the laptop. OFW will prompt you to hit "Escape" (the X key in the upper-left) to interrupt the boot process. Do so!
# At the firmware '''ok''' prompt, type '''copy-nand disk:\os{number}.img'''. The XO should reboot once it is finished.
# At the firmware '''ok''' prompt, type '''copy-nand u:\os{number}.img'''. The XO should reboot once it is finished.
# Beware: these instructions may change in the future as we transition to a [[Customization key]] process.


You can re-enable security in the future if you want to return to signed builds by typing 'enable-security' at the OFW '''ok''' prompt. (Again, pay attention to what OFW says; you may need to do this twice.)
You can re-enable security in the future if you want to return to signed builds by typing 'enable-security' at the OFW '''ok''' prompt. (Again, pay attention to what OFW says; you may need to do this twice.)

Latest revision as of 06:11, 3 January 2014

  This page is monitored by the OLPC team.
  english | español HowTo [ID# 294574]  +/-  


542-stopicon.png This page has a more up-to-date location: each release's Release notes have instructions for upgrading to it

This page describes how to reinstall the operating system of a secured laptop, whether it is unactivated (fresh from the factory) or already activated.

This process destroys all the data on the laptop, wiping out all user data, and resetting the laptop to booting from a new, standard, signed operating system build. Please use olpc-update if you wish to keep your data.

Steps for secured upgrade, in plain English

  For the general public


0. Before performing the upgrade, please note that EVERYTHING previously created will be deleted!

1. Read release notes for your target release!

Activities must be installed separately.

2. You need a formatted USB flash drive that is larger than 325 MB, and it is better that you format it before copying any files over.

3. To install build 767 (Release 8.2.0) download the following two files from the Internet and put them on the USB flash drive:

http://download.laptop.org/xo-1/os/official/767/jffs2/fs.zip

http://download.laptop.org/xo-1/os/official/767/jffs2/os767.img

  • To download those files, plug the USB flash drive into another computer that is connected to the Internet. Right-click (Ctrl-click for Mac) on each of the above two URLs in the browser and choose "Save Target As" ("Save Link As" for Firefox). Save both files to the USB flash drive. Eject/Remove the USB flash drive, and unplug it.

The first file is about 154Kb, and the second file is quite large (about 233 Mb), which might take a while to download.

After you have finished this step, there should be two files on the USB flash drive, the fs.zip file, and the img file.

4. Make sure the XO laptop is OFF. Make sure that the battery is installed, and that you have external (AC) power plugged in as well. Plug in the USB flash drive, and do not unplug it until instructed.

5. With the USB flash drive inserted, power up the laptop while holding down ALL four game buttons on the right side of screen (the four buttons above the power button, and they are marked with O, V, X, and square). Please be sure to press all of them firmly; use two thumbs if that helps.

6. When the screen says 'release the game key to continue', release all four buttons.

7. You will see arrays of colored grids running on the screen. We are now re-writing the laptop with the new operating system.

8. Once done with re-writing, the laptop will reboot itself.

9. Next, the laptop may update the firmware, if necessary, and reboot itself. It will insist on being plugged in and having a battery present if it needs to update the firmware. (You don't have to do anything; just watch.)

10. After you're done with the update, the laptop will boot to the prompt for your preferred user name. You can now remove the USB flash drive, and it is no longer needed.

Install activities

No activities are included in some versions of the OLPC software. Follow these instructions to install basic activities on release 8.1.0, 8.1.1 and 8.2.0.

  1. Power off the XO
  2. Remove the "fs.zip" file from your flash drive.
  3. Download the activity pack and unzip it to the flash drive (NOT a subdirectory).
  4. Insert the USB flash drive and boot the XO. It will display text on a black screen as the activities are installed, after which it will power off.
  5. Remove the USB flash drive.

Verify your update

12. Go to the Terminal activity (click on the taskbar icon Activity-terminal.svg)

  • The screen should say something like [olpc@xo-05-2D-2F ~]$
  • The numbers don't matter, but be sure that you type things after the $ sign.

14. Type the following to check which version you XO is running:

  cat /etc/issue

15. Press the Enter key

16. If the screen says something that begins with

  OLPC build 767

then we are one step closer to finishing the upgrade process!

17. Go to Home view and mouse over the XO guy in the center.

18. Select the "Shutdown" option to power off the machine. Now you should be able to power it up as usual, with build 767.


Make sure you won't lose your activation lease

G1G1 recipients do not need a lease, and should skip this section.

(Here we check to see whether your laptop has the ak flag set or an activation lease. This doesn't work if your laptop won't boot, so if you're doing this upgrade to get your laptop to start booting again, just proceed to the next section and do the upgrade.)

  1. Get to a terminal on the laptop, and type: ls /security
    • On XO-1 this requires root permissions. See Console for how to get them.
    • If there is a lease.sig file, you will want to save this lease before re-flashing the laptop.
      1. To do so, insert a USB stick, wait for it to mount, and then type: cp /security/lease.sig /media/{name_of_usb_stick}
      2. Then, switch to the home view, go to the journal, mouse over the USB icon, and click unmount.
      3. Remove the USB stick from the USB slot, but make sure the lease.sig file is stored on it. You will have to boot the laptop with this USB stick inserted after the upgrade.
    • If there is no lease.sig file, your manufacturing data is probably set for pre-activation, and you probably don't need to do anything.
    • If you want to check that this is in fact true, in a terminal, type: ls /ofw/mfg-data/
    • If there is an 'ak' there, then the laptop is pre-activated.

Upgrade a Secured Laptop with a Signed Image

To put the latest signed image (stable build) on the laptop, follow these steps:

  1. Create a USB stick with the files os{number}.img and fs.zip on the disk in the top-level directory. (We recommend that you use a "factory-formatted" USB stick.)
  2. With the USB stick inserted into your XO, and the battery installed, and AC power plugged in, power up the laptop while holding down all four game buttons on the right side of screen.
  3. When prompted to release the game keys, do so.
    • This will re-write the internal flash memory image.
  4. Once done with this re-flash, the laptop will reboot itself.
  5. Next, the laptop may update the boot firmware, if necessary, and reboot itself.
  6. After you're done with the upgrade(s), the laptop will either boot to the prompt you for a name. (If the laptop is not activated, it will fail to boot; all G1G1 laptops are shipped activated.)
  7. From the Terminal activity check that the laptop is at the version you wanted by typing the command:
cat /etc/issue

(If your laptop failed to boot, insert the USB stick with lease.sig on it, and boot the laptop. This can be the same USB stick you used in Step 1 above. This should get you to the prompt for a name.)

Upgrading to an Unsigned Image by disabling security

To put an unsigned image (not a stable release), you may first need to disable activation security. In a country deployment, this may make your laptop more vulnerable to theft — but it's assumed that if you're running a unstable build you're a developer and willing to take the risk.

See how to check if it is locked, how to get a developer key, how to use a developer key, and how to unlock permanently. For groups of laptops, use the collection stick then an unlock stick.

Now, you can follow the normal "developer upgrade" instructions, using either olpc-update or this OFW technique:

  1. Create a USB drive with the files os{number}.img and os{number}.crc on the disk in the top-level directory.
  2. Boot the laptop. OFW will prompt you to hit "Escape" (the X key in the upper-left) to interrupt the boot process. Do so!
  3. At the firmware ok prompt, type copy-nand u:\os{number}.img. The XO should reboot once it is finished.

You can re-enable security in the future if you want to return to signed builds by typing 'enable-security' at the OFW ok prompt. (Again, pay attention to what OFW says; you may need to do this twice.)