property_service.cpp revision 929f4070767d1e4806c058849178afa13d9ded1e
1/* 2 * Copyright (C) 2007 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17#include <stdio.h> 18#include <stdlib.h> 19#include <unistd.h> 20#include <string.h> 21#include <ctype.h> 22#include <fcntl.h> 23#include <stdarg.h> 24#include <dirent.h> 25#include <limits.h> 26#include <errno.h> 27#include <sys/poll.h> 28 29#include <memory> 30 31#include <cutils/misc.h> 32#include <cutils/sockets.h> 33#include <cutils/multiuser.h> 34 35#define _REALLY_INCLUDE_SYS__SYSTEM_PROPERTIES_H_ 36#include <sys/_system_properties.h> 37 38#include <sys/socket.h> 39#include <sys/un.h> 40#include <sys/select.h> 41#include <sys/types.h> 42#include <netinet/in.h> 43#include <sys/mman.h> 44#include <private/android_filesystem_config.h> 45 46#include <selinux/selinux.h> 47#include <selinux/label.h> 48 49#include "property_service.h" 50#include "init.h" 51#include "util.h" 52#include "log.h" 53 54#define PERSISTENT_PROPERTY_DIR "/data/property" 55 56static int persistent_properties_loaded = 0; 57static bool property_area_initialized = false; 58 59static int property_set_fd = -1; 60 61struct workspace { 62 size_t size; 63 int fd; 64}; 65 66static workspace pa_workspace; 67 68void property_init() { 69 if (property_area_initialized) { 70 return; 71 } 72 73 property_area_initialized = true; 74 75 if (__system_property_area_init()) { 76 return; 77 } 78 79 pa_workspace.size = 0; 80 pa_workspace.fd = open(PROP_FILENAME, O_RDONLY | O_NOFOLLOW | O_CLOEXEC); 81 if (pa_workspace.fd == -1) { 82 ERROR("Failed to open %s: %s\n", PROP_FILENAME, strerror(errno)); 83 return; 84 } 85} 86 87static int check_mac_perms(const char *name, char *sctx) 88{ 89 if (is_selinux_enabled() <= 0) 90 return 1; 91 92 char *tctx = NULL; 93 int result = 0; 94 95 if (!sctx) 96 goto err; 97 98 if (!sehandle_prop) 99 goto err; 100 101 if (selabel_lookup(sehandle_prop, &tctx, name, 1) != 0) 102 goto err; 103 104 if (selinux_check_access(sctx, tctx, "property_service", "set", (void*) name) == 0) 105 result = 1; 106 107 freecon(tctx); 108 err: 109 return result; 110} 111 112static int check_control_mac_perms(const char *name, char *sctx) 113{ 114 /* 115 * Create a name prefix out of ctl.<service name> 116 * The new prefix allows the use of the existing 117 * property service backend labeling while avoiding 118 * mislabels based on true property prefixes. 119 */ 120 char ctl_name[PROP_VALUE_MAX+4]; 121 int ret = snprintf(ctl_name, sizeof(ctl_name), "ctl.%s", name); 122 123 if (ret < 0 || (size_t) ret >= sizeof(ctl_name)) 124 return 0; 125 126 return check_mac_perms(ctl_name, sctx); 127} 128 129/* 130 * Checks permissions for setting system properties. 131 * Returns 1 if uid allowed, 0 otherwise. 132 */ 133static int check_perms(const char *name, char *sctx) 134{ 135 if(!strncmp(name, "ro.", 3)) 136 name +=3; 137 138 return check_mac_perms(name, sctx); 139} 140 141int __property_get(const char *name, char *value) 142{ 143 return __system_property_get(name, value); 144} 145 146static void write_persistent_property(const char *name, const char *value) 147{ 148 char tempPath[PATH_MAX]; 149 char path[PATH_MAX]; 150 int fd; 151 152 snprintf(tempPath, sizeof(tempPath), "%s/.temp.XXXXXX", PERSISTENT_PROPERTY_DIR); 153 fd = mkstemp(tempPath); 154 if (fd < 0) { 155 ERROR("Unable to write persistent property to temp file %s: %s\n", tempPath, strerror(errno)); 156 return; 157 } 158 write(fd, value, strlen(value)); 159 fsync(fd); 160 close(fd); 161 162 snprintf(path, sizeof(path), "%s/%s", PERSISTENT_PROPERTY_DIR, name); 163 if (rename(tempPath, path)) { 164 unlink(tempPath); 165 ERROR("Unable to rename persistent property file %s to %s\n", tempPath, path); 166 } 167} 168 169static bool is_legal_property_name(const char* name, size_t namelen) 170{ 171 size_t i; 172 if (namelen >= PROP_NAME_MAX) return false; 173 if (namelen < 1) return false; 174 if (name[0] == '.') return false; 175 if (name[namelen - 1] == '.') return false; 176 177 /* Only allow alphanumeric, plus '.', '-', or '_' */ 178 /* Don't allow ".." to appear in a property name */ 179 for (i = 0; i < namelen; i++) { 180 if (name[i] == '.') { 181 // i=0 is guaranteed to never have a dot. See above. 182 if (name[i-1] == '.') return false; 183 continue; 184 } 185 if (name[i] == '_' || name[i] == '-') continue; 186 if (name[i] >= 'a' && name[i] <= 'z') continue; 187 if (name[i] >= 'A' && name[i] <= 'Z') continue; 188 if (name[i] >= '0' && name[i] <= '9') continue; 189 return false; 190 } 191 192 return true; 193} 194 195static int property_set_impl(const char* name, const char* value) { 196 size_t namelen = strlen(name); 197 size_t valuelen = strlen(value); 198 199 if (!is_legal_property_name(name, namelen)) return -1; 200 if (valuelen >= PROP_VALUE_MAX) return -1; 201 202 prop_info* pi = (prop_info*) __system_property_find(name); 203 204 if(pi != 0) { 205 /* ro.* properties may NEVER be modified once set */ 206 if(!strncmp(name, "ro.", 3)) return -1; 207 208 __system_property_update(pi, value, valuelen); 209 } else { 210 int rc = __system_property_add(name, namelen, value, valuelen); 211 if (rc < 0) { 212 return rc; 213 } 214 } 215 /* If name starts with "net." treat as a DNS property. */ 216 if (strncmp("net.", name, strlen("net.")) == 0) { 217 if (strcmp("net.change", name) == 0) { 218 return 0; 219 } 220 /* 221 * The 'net.change' property is a special property used track when any 222 * 'net.*' property name is updated. It is _ONLY_ updated here. Its value 223 * contains the last updated 'net.*' property. 224 */ 225 property_set("net.change", name); 226 } else if (persistent_properties_loaded && 227 strncmp("persist.", name, strlen("persist.")) == 0) { 228 /* 229 * Don't write properties to disk until after we have read all default properties 230 * to prevent them from being overwritten by default values. 231 */ 232 write_persistent_property(name, value); 233 } else if (strcmp("selinux.reload_policy", name) == 0 && 234 strcmp("1", value) == 0) { 235 selinux_reload_policy(); 236 } 237 property_changed(name, value); 238 return 0; 239} 240 241int property_set(const char* name, const char* value) { 242 int rc = property_set_impl(name, value); 243 if (rc == -1) { 244 ERROR("property_set(\"%s\", \"%s\") failed\n", name, value); 245 } 246 return rc; 247} 248 249static void handle_property_set_fd() 250{ 251 prop_msg msg; 252 int s; 253 int r; 254 struct ucred cr; 255 struct sockaddr_un addr; 256 socklen_t addr_size = sizeof(addr); 257 socklen_t cr_size = sizeof(cr); 258 char * source_ctx = NULL; 259 struct pollfd ufds[1]; 260 const int timeout_ms = 2 * 1000; /* Default 2 sec timeout for caller to send property. */ 261 int nr; 262 263 if ((s = accept(property_set_fd, (struct sockaddr *) &addr, &addr_size)) < 0) { 264 return; 265 } 266 267 /* Check socket options here */ 268 if (getsockopt(s, SOL_SOCKET, SO_PEERCRED, &cr, &cr_size) < 0) { 269 close(s); 270 ERROR("Unable to receive socket options\n"); 271 return; 272 } 273 274 ufds[0].fd = s; 275 ufds[0].events = POLLIN; 276 ufds[0].revents = 0; 277 nr = TEMP_FAILURE_RETRY(poll(ufds, 1, timeout_ms)); 278 if (nr == 0) { 279 ERROR("sys_prop: timeout waiting for uid=%d to send property message.\n", cr.uid); 280 close(s); 281 return; 282 } else if (nr < 0) { 283 ERROR("sys_prop: error waiting for uid=%d to send property message: %s\n", cr.uid, strerror(errno)); 284 close(s); 285 return; 286 } 287 288 r = TEMP_FAILURE_RETRY(recv(s, &msg, sizeof(msg), MSG_DONTWAIT)); 289 if(r != sizeof(prop_msg)) { 290 ERROR("sys_prop: mis-match msg size received: %d expected: %zu: %s\n", 291 r, sizeof(prop_msg), strerror(errno)); 292 close(s); 293 return; 294 } 295 296 switch(msg.cmd) { 297 case PROP_MSG_SETPROP: 298 msg.name[PROP_NAME_MAX-1] = 0; 299 msg.value[PROP_VALUE_MAX-1] = 0; 300 301 if (!is_legal_property_name(msg.name, strlen(msg.name))) { 302 ERROR("sys_prop: illegal property name. Got: \"%s\"\n", msg.name); 303 close(s); 304 return; 305 } 306 307 getpeercon(s, &source_ctx); 308 309 if(memcmp(msg.name,"ctl.",4) == 0) { 310 // Keep the old close-socket-early behavior when handling 311 // ctl.* properties. 312 close(s); 313 if (check_control_mac_perms(msg.value, source_ctx)) { 314 handle_control_message((char*) msg.name + 4, (char*) msg.value); 315 } else { 316 ERROR("sys_prop: Unable to %s service ctl [%s] uid:%d gid:%d pid:%d\n", 317 msg.name + 4, msg.value, cr.uid, cr.gid, cr.pid); 318 } 319 } else { 320 if (check_perms(msg.name, source_ctx)) { 321 property_set((char*) msg.name, (char*) msg.value); 322 } else { 323 ERROR("sys_prop: permission denied uid:%d name:%s\n", 324 cr.uid, msg.name); 325 } 326 327 // Note: bionic's property client code assumes that the 328 // property server will not close the socket until *AFTER* 329 // the property is written to memory. 330 close(s); 331 } 332 freecon(source_ctx); 333 break; 334 335 default: 336 close(s); 337 break; 338 } 339} 340 341void get_property_workspace(int *fd, int *sz) 342{ 343 *fd = pa_workspace.fd; 344 *sz = pa_workspace.size; 345} 346 347static void load_properties_from_file(const char *, const char *); 348 349/* 350 * Filter is used to decide which properties to load: NULL loads all keys, 351 * "ro.foo.*" is a prefix match, and "ro.foo.bar" is an exact match. 352 */ 353static void load_properties(char *data, const char *filter) 354{ 355 char *key, *value, *eol, *sol, *tmp, *fn; 356 size_t flen = 0; 357 358 if (filter) { 359 flen = strlen(filter); 360 } 361 362 sol = data; 363 while ((eol = strchr(sol, '\n'))) { 364 key = sol; 365 *eol++ = 0; 366 sol = eol; 367 368 while (isspace(*key)) key++; 369 if (*key == '#') continue; 370 371 tmp = eol - 2; 372 while ((tmp > key) && isspace(*tmp)) *tmp-- = 0; 373 374 if (!strncmp(key, "import ", 7) && flen == 0) { 375 fn = key + 7; 376 while (isspace(*fn)) fn++; 377 378 key = strchr(fn, ' '); 379 if (key) { 380 *key++ = 0; 381 while (isspace(*key)) key++; 382 } 383 384 load_properties_from_file(fn, key); 385 386 } else { 387 value = strchr(key, '='); 388 if (!value) continue; 389 *value++ = 0; 390 391 tmp = value - 2; 392 while ((tmp > key) && isspace(*tmp)) *tmp-- = 0; 393 394 while (isspace(*value)) value++; 395 396 if (flen > 0) { 397 if (filter[flen - 1] == '*') { 398 if (strncmp(key, filter, flen - 1)) continue; 399 } else { 400 if (strcmp(key, filter)) continue; 401 } 402 } 403 404 property_set(key, value); 405 } 406 } 407} 408 409/* 410 * Filter is used to decide which properties to load: NULL loads all keys, 411 * "ro.foo.*" is a prefix match, and "ro.foo.bar" is an exact match. 412 */ 413static void load_properties_from_file(const char* filename, const char* filter) { 414 Timer t; 415 std::string data; 416 if (read_file(filename, &data)) { 417 load_properties(&data[0], filter); 418 } 419 NOTICE("(Loading properties from %s took %.2fs.)\n", filename, t.duration()); 420} 421 422static void load_persistent_properties() { 423 persistent_properties_loaded = 1; 424 425 std::unique_ptr<DIR, int(*)(DIR*)> dir(opendir(PERSISTENT_PROPERTY_DIR), closedir); 426 if (!dir) { 427 ERROR("Unable to open persistent property directory \"%s\": %s\n", 428 PERSISTENT_PROPERTY_DIR, strerror(errno)); 429 return; 430 } 431 432 struct dirent* entry; 433 while ((entry = readdir(dir.get())) != NULL) { 434 if (strncmp("persist.", entry->d_name, strlen("persist."))) { 435 continue; 436 } 437 if (entry->d_type != DT_REG) { 438 continue; 439 } 440 441 // Open the file and read the property value. 442 int fd = openat(dirfd(dir.get()), entry->d_name, O_RDONLY | O_NOFOLLOW); 443 if (fd == -1) { 444 ERROR("Unable to open persistent property file \"%s\": %s\n", 445 entry->d_name, strerror(errno)); 446 continue; 447 } 448 449 struct stat sb; 450 if (fstat(fd, &sb) == -1) { 451 ERROR("fstat on property file \"%s\" failed: %s\n", entry->d_name, strerror(errno)); 452 close(fd); 453 continue; 454 } 455 456 // File must not be accessible to others, be owned by root/root, and 457 // not be a hard link to any other file. 458 if (((sb.st_mode & (S_IRWXG | S_IRWXO)) != 0) || (sb.st_uid != 0) || (sb.st_gid != 0) || 459 (sb.st_nlink != 1)) { 460 ERROR("skipping insecure property file %s (uid=%u gid=%u nlink=%u mode=%o)\n", 461 entry->d_name, (unsigned int)sb.st_uid, (unsigned int)sb.st_gid, 462 (unsigned int)sb.st_nlink, sb.st_mode); 463 close(fd); 464 continue; 465 } 466 467 char value[PROP_VALUE_MAX]; 468 int length = read(fd, value, sizeof(value) - 1); 469 if (length >= 0) { 470 value[length] = 0; 471 property_set(entry->d_name, value); 472 } else { 473 ERROR("Unable to read persistent property file %s: %s\n", 474 entry->d_name, strerror(errno)); 475 } 476 close(fd); 477 } 478} 479 480void property_load_boot_defaults() { 481 load_properties_from_file(PROP_PATH_RAMDISK_DEFAULT, NULL); 482} 483 484bool properties_initialized() { 485 return property_area_initialized; 486} 487 488static void load_override_properties() { 489 if (ALLOW_LOCAL_PROP_OVERRIDE) { 490 char debuggable[PROP_VALUE_MAX]; 491 int ret = property_get("ro.debuggable", debuggable); 492 if (ret && (strcmp(debuggable, "1") == 0)) { 493 load_properties_from_file(PROP_PATH_LOCAL_OVERRIDE, NULL); 494 } 495 } 496} 497 498/* When booting an encrypted system, /data is not mounted when the 499 * property service is started, so any properties stored there are 500 * not loaded. Vold triggers init to load these properties once it 501 * has mounted /data. 502 */ 503void load_persist_props(void) { 504 load_override_properties(); 505 /* Read persistent properties after all default values have been loaded. */ 506 load_persistent_properties(); 507} 508 509void load_all_props() { 510 load_properties_from_file(PROP_PATH_SYSTEM_BUILD, NULL); 511 load_properties_from_file(PROP_PATH_VENDOR_BUILD, NULL); 512 load_properties_from_file(PROP_PATH_BOOTIMAGE_BUILD, NULL); 513 load_properties_from_file(PROP_PATH_FACTORY, "ro.*"); 514 515 load_override_properties(); 516 517 /* Read persistent properties after all default values have been loaded. */ 518 load_persistent_properties(); 519} 520 521void start_property_service() { 522 property_set_fd = create_socket(PROP_SERVICE_NAME, SOCK_STREAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 523 0666, 0, 0, NULL); 524 if (property_set_fd == -1) { 525 ERROR("start_property_service socket creation failed: %s\n", strerror(errno)); 526 exit(1); 527 } 528 529 listen(property_set_fd, 8); 530 531 register_epoll_handler(property_set_fd, handle_property_set_fd); 532} 533