installd.cpp revision e37d62803210f258ddb843c7d8d0494127069342
1/* 2** Copyright 2008, The Android Open Source Project 3** 4** Licensed under the Apache License, Version 2.0 (the "License"); 5** you may not use this file except in compliance with the License. 6** You may obtain a copy of the License at 7** 8** http://www.apache.org/licenses/LICENSE-2.0 9** 10** Unless required by applicable law or agreed to in writing, software 11** distributed under the License is distributed on an "AS IS" BASIS, 12** WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13** See the License for the specific language governing permissions and 14** limitations under the License. 15*/ 16 17#include <fcntl.h> 18#include <selinux/android.h> 19#include <selinux/avc.h> 20#include <sys/capability.h> 21#include <sys/fsuid.h> 22#include <sys/prctl.h> 23#include <sys/socket.h> 24#include <sys/stat.h> 25 26#include <android-base/logging.h> 27#include <cutils/fs.h> 28#include <cutils/log.h> // TODO: Move everything to base::logging. 29#include <cutils/properties.h> 30#include <cutils/sockets.h> 31#include <private/android_filesystem_config.h> 32 33#include <commands.h> 34#include <globals.h> 35#include <installd_constants.h> 36#include <installd_deps.h> // Need to fill in requirements of commands. 37#include <utils.h> 38 39#ifndef LOG_TAG 40#define LOG_TAG "installd" 41#endif 42#define SOCKET_PATH "installd" 43 44#define BUFFER_MAX 1024 /* input buffer for commands */ 45#define TOKEN_MAX 16 /* max number of arguments in buffer */ 46#define REPLY_MAX 256 /* largest reply allowed */ 47 48namespace android { 49namespace installd { 50 51// Check that installd-deps sizes match cutils sizes. 52static_assert(kPropertyKeyMax == PROPERTY_KEY_MAX, "Size mismatch."); 53static_assert(kPropertyValueMax == PROPERTY_VALUE_MAX, "Size mismatch."); 54 55//////////////////////// 56// Plug-in functions. // 57//////////////////////// 58 59int get_property(const char *key, char *value, const char *default_value) { 60 return property_get(key, value, default_value); 61} 62 63// Compute the output path of 64bool calculate_oat_file_path(char path[PKG_PATH_MAX], 65 const char *oat_dir, 66 const char *apk_path, 67 const char *instruction_set) { 68 char *file_name_start; 69 char *file_name_end; 70 71 file_name_start = strrchr(apk_path, '/'); 72 if (file_name_start == NULL) { 73 ALOGE("apk_path '%s' has no '/'s in it\n", apk_path); 74 return false; 75 } 76 file_name_end = strrchr(apk_path, '.'); 77 if (file_name_end < file_name_start) { 78 ALOGE("apk_path '%s' has no extension\n", apk_path); 79 return false; 80 } 81 82 // Calculate file_name 83 int file_name_len = file_name_end - file_name_start - 1; 84 char file_name[file_name_len + 1]; 85 memcpy(file_name, file_name_start + 1, file_name_len); 86 file_name[file_name_len] = '\0'; 87 88 // <apk_parent_dir>/oat/<isa>/<file_name>.odex 89 snprintf(path, PKG_PATH_MAX, "%s/%s/%s.odex", oat_dir, instruction_set, file_name); 90 return true; 91} 92 93/* 94 * Computes the odex file for the given apk_path and instruction_set. 95 * /system/framework/whatever.jar -> /system/framework/oat/<isa>/whatever.odex 96 * 97 * Returns false if it failed to determine the odex file path. 98 */ 99bool calculate_odex_file_path(char path[PKG_PATH_MAX], 100 const char *apk_path, 101 const char *instruction_set) { 102 if (strlen(apk_path) + strlen("oat/") + strlen(instruction_set) 103 + strlen("/") + strlen("odex") + 1 > PKG_PATH_MAX) { 104 ALOGE("apk_path '%s' may be too long to form odex file path.\n", apk_path); 105 return false; 106 } 107 108 strcpy(path, apk_path); 109 char *end = strrchr(path, '/'); 110 if (end == NULL) { 111 ALOGE("apk_path '%s' has no '/'s in it?!\n", apk_path); 112 return false; 113 } 114 const char *apk_end = apk_path + (end - path); // strrchr(apk_path, '/'); 115 116 strcpy(end + 1, "oat/"); // path = /system/framework/oat/\0 117 strcat(path, instruction_set); // path = /system/framework/oat/<isa>\0 118 strcat(path, apk_end); // path = /system/framework/oat/<isa>/whatever.jar\0 119 end = strrchr(path, '.'); 120 if (end == NULL) { 121 ALOGE("apk_path '%s' has no extension.\n", apk_path); 122 return false; 123 } 124 strcpy(end + 1, "odex"); 125 return true; 126} 127 128bool create_cache_path(char path[PKG_PATH_MAX], 129 const char *src, 130 const char *instruction_set) { 131 size_t srclen = strlen(src); 132 133 /* demand that we are an absolute path */ 134 if ((src == 0) || (src[0] != '/') || strstr(src,"..")) { 135 return false; 136 } 137 138 if (srclen > PKG_PATH_MAX) { // XXX: PKG_NAME_MAX? 139 return false; 140 } 141 142 size_t dstlen = 143 android_data_dir.len + 144 strlen(DALVIK_CACHE) + 145 1 + 146 strlen(instruction_set) + 147 srclen + 148 strlen(DALVIK_CACHE_POSTFIX) + 2; 149 150 if (dstlen > PKG_PATH_MAX) { 151 return false; 152 } 153 154 sprintf(path,"%s%s/%s/%s%s", 155 android_data_dir.path, 156 DALVIK_CACHE, 157 instruction_set, 158 src + 1, /* skip the leading / */ 159 DALVIK_CACHE_POSTFIX); 160 161 char* tmp = 162 path + 163 android_data_dir.len + 164 strlen(DALVIK_CACHE) + 165 1 + 166 strlen(instruction_set) + 1; 167 168 for(; *tmp; tmp++) { 169 if (*tmp == '/') { 170 *tmp = '@'; 171 } 172 } 173 174 return true; 175} 176 177 178static char* parse_null(char* arg) { 179 if (strcmp(arg, "!") == 0) { 180 return nullptr; 181 } else { 182 return arg; 183 } 184} 185 186static int do_ping(char **arg ATTRIBUTE_UNUSED, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 187{ 188 return 0; 189} 190 191static int do_create_app_data(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 192 /* const char *uuid, const char *pkgname, userid_t userid, int flags, 193 appid_t appid, const char* seinfo, int target_sdk_version */ 194 return create_app_data(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3]), 195 atoi(arg[4]), arg[5], atoi(arg[6])); 196} 197 198static int do_restorecon_app_data(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 199 /* const char* uuid, const char* pkgName, userid_t userid, int flags, 200 appid_t appid, const char* seinfo */ 201 return restorecon_app_data(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3]), atoi(arg[4]), arg[5]); 202} 203 204static int do_clear_app_data(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 205 /* const char *uuid, const char *pkgname, userid_t userid, int flags */ 206 return clear_app_data(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3])); 207} 208 209static int do_destroy_app_data(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 210 /* const char *uuid, const char *pkgname, userid_t userid, int flags */ 211 return destroy_app_data(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3])); 212} 213 214static int do_dexopt(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 215{ 216 /* apk_path, uid, pkgname, instruction_set, dexopt_needed, oat_dir, dexopt_flags, volume_uuid, 217 use_profiles */ 218 return dexopt(arg[0], atoi(arg[1]), arg[2], arg[3], atoi(arg[4]), 219 arg[5], atoi(arg[6]), parse_null(arg[7]), (atoi(arg[8]) == 0 ? false : true)); 220} 221 222static int do_mark_boot_complete(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 223{ 224 return mark_boot_complete(arg[0] /* instruction set */); 225} 226 227static int do_rm_dex(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 228{ 229 return rm_dex(arg[0], arg[1]); /* pkgname, instruction_set */ 230} 231 232static int do_free_cache(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) /* TODO int:free_size */ 233{ 234 return free_cache(parse_null(arg[0]), (int64_t)atoll(arg[1])); /* uuid, free_size */ 235} 236 237static int do_get_app_size(char **arg, char reply[REPLY_MAX]) { 238 int64_t codesize = 0; 239 int64_t datasize = 0; 240 int64_t cachesize = 0; 241 int64_t asecsize = 0; 242 int res = 0; 243 244 /* const char *uuid, const char *pkgname, userid_t userid, int flags, 245 const char *apkpath, const char *libdirpath, const char *fwdlock_apkpath, 246 const char *asecpath, const char *instruction_set */ 247 res = get_app_size(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3]), arg[4], arg[5], 248 arg[6], arg[7], arg[8], &codesize, &datasize, &cachesize, &asecsize); 249 250 /* 251 * Each int64_t can take up 22 characters printed out. Make sure it 252 * doesn't go over REPLY_MAX in the future. 253 */ 254 snprintf(reply, REPLY_MAX, "%" PRId64 " %" PRId64 " %" PRId64 " %" PRId64, 255 codesize, datasize, cachesize, asecsize); 256 return res; 257} 258 259static int do_move_complete_app(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 260 /* const char* from_uuid, const char *to_uuid, const char *package_name, 261 const char *data_app_name, appid_t appid, const char* seinfo, 262 int target_sdk_version */ 263 return move_complete_app(parse_null(arg[0]), parse_null(arg[1]), arg[2], arg[3], 264 atoi(arg[4]), arg[5], atoi(arg[6])); 265} 266 267static int do_mk_user_config(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 268{ 269 return make_user_config(atoi(arg[0])); /* userid */ 270} 271 272static int do_rm_user(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 273{ 274 return delete_user(parse_null(arg[0]), atoi(arg[1])); /* uuid, userid */ 275} 276 277static int do_linklib(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 278{ 279 return linklib(parse_null(arg[0]), arg[1], arg[2], atoi(arg[3])); 280} 281 282static int do_idmap(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 283{ 284 return idmap(arg[0], arg[1], atoi(arg[2])); 285} 286 287static int do_create_oat_dir(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 288{ 289 /* oat_dir, instruction_set */ 290 return create_oat_dir(arg[0], arg[1]); 291} 292 293static int do_rm_package_dir(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 294{ 295 /* oat_dir */ 296 return rm_package_dir(arg[0]); 297} 298 299static int do_link_file(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 300{ 301 /* relative_path, from_base, to_base */ 302 return link_file(arg[0], arg[1], arg[2]); 303} 304 305struct cmdinfo { 306 const char *name; 307 unsigned numargs; 308 int (*func)(char **arg, char reply[REPLY_MAX]); 309}; 310 311struct cmdinfo cmds[] = { 312 { "ping", 0, do_ping }, 313 314 { "create_app_data", 7, do_create_app_data }, 315 { "restorecon_app_data", 6, do_restorecon_app_data }, 316 { "clear_app_data", 4, do_clear_app_data }, 317 { "destroy_app_data", 4, do_destroy_app_data }, 318 { "move_complete_app", 7, do_move_complete_app }, 319 { "get_app_size", 9, do_get_app_size }, 320 321 { "dexopt", 9, do_dexopt }, 322 { "markbootcomplete", 1, do_mark_boot_complete }, 323 { "rmdex", 2, do_rm_dex }, 324 { "freecache", 2, do_free_cache }, 325 { "linklib", 4, do_linklib }, 326 { "mkuserconfig", 1, do_mk_user_config }, 327 { "rmuser", 2, do_rm_user }, 328 { "idmap", 3, do_idmap }, 329 { "createoatdir", 2, do_create_oat_dir }, 330 { "rmpackagedir", 1, do_rm_package_dir }, 331 { "linkfile", 3, do_link_file }, 332}; 333 334static int readx(int s, void *_buf, int count) 335{ 336 char *buf = (char *) _buf; 337 int n = 0, r; 338 if (count < 0) return -1; 339 while (n < count) { 340 r = read(s, buf + n, count - n); 341 if (r < 0) { 342 if (errno == EINTR) continue; 343 ALOGE("read error: %s\n", strerror(errno)); 344 return -1; 345 } 346 if (r == 0) { 347 ALOGE("eof\n"); 348 return -1; /* EOF */ 349 } 350 n += r; 351 } 352 return 0; 353} 354 355static int writex(int s, const void *_buf, int count) 356{ 357 const char *buf = (const char *) _buf; 358 int n = 0, r; 359 if (count < 0) return -1; 360 while (n < count) { 361 r = write(s, buf + n, count - n); 362 if (r < 0) { 363 if (errno == EINTR) continue; 364 ALOGE("write error: %s\n", strerror(errno)); 365 return -1; 366 } 367 n += r; 368 } 369 return 0; 370} 371 372 373/* Tokenize the command buffer, locate a matching command, 374 * ensure that the required number of arguments are provided, 375 * call the function(), return the result. 376 */ 377static int execute(int s, char cmd[BUFFER_MAX]) 378{ 379 char reply[REPLY_MAX]; 380 char *arg[TOKEN_MAX+1]; 381 unsigned i; 382 unsigned n = 0; 383 unsigned short count; 384 int ret = -1; 385 386 // ALOGI("execute('%s')\n", cmd); 387 388 /* default reply is "" */ 389 reply[0] = 0; 390 391 /* n is number of args (not counting arg[0]) */ 392 arg[0] = cmd; 393 while (*cmd) { 394 if (isspace(*cmd)) { 395 *cmd++ = 0; 396 n++; 397 arg[n] = cmd; 398 if (n == TOKEN_MAX) { 399 ALOGE("too many arguments\n"); 400 goto done; 401 } 402 } 403 if (*cmd) { 404 cmd++; 405 } 406 } 407 408 for (i = 0; i < sizeof(cmds) / sizeof(cmds[0]); i++) { 409 if (!strcmp(cmds[i].name,arg[0])) { 410 if (n != cmds[i].numargs) { 411 ALOGE("%s requires %d arguments (%d given)\n", 412 cmds[i].name, cmds[i].numargs, n); 413 } else { 414 ret = cmds[i].func(arg + 1, reply); 415 } 416 goto done; 417 } 418 } 419 ALOGE("unsupported command '%s'\n", arg[0]); 420 421done: 422 if (reply[0]) { 423 n = snprintf(cmd, BUFFER_MAX, "%d %s", ret, reply); 424 } else { 425 n = snprintf(cmd, BUFFER_MAX, "%d", ret); 426 } 427 if (n > BUFFER_MAX) n = BUFFER_MAX; 428 count = n; 429 430 // ALOGI("reply: '%s'\n", cmd); 431 if (writex(s, &count, sizeof(count))) return -1; 432 if (writex(s, cmd, count)) return -1; 433 return 0; 434} 435 436bool initialize_globals() { 437 const char* data_path = getenv("ANDROID_DATA"); 438 if (data_path == nullptr) { 439 ALOGE("Could not find ANDROID_DATA"); 440 return false; 441 } 442 const char* root_path = getenv("ANDROID_ROOT"); 443 if (root_path == nullptr) { 444 ALOGE("Could not find ANDROID_ROOT"); 445 return false; 446 } 447 448 return init_globals_from_data_and_root(data_path, root_path); 449} 450 451static int initialize_directories() { 452 int res = -1; 453 454 // Read current filesystem layout version to handle upgrade paths 455 char version_path[PATH_MAX]; 456 snprintf(version_path, PATH_MAX, "%s.layout_version", android_data_dir.path); 457 458 int oldVersion; 459 if (fs_read_atomic_int(version_path, &oldVersion) == -1) { 460 oldVersion = 0; 461 } 462 int version = oldVersion; 463 464 if (version < 2) { 465 SLOGD("Assuming that device has multi-user storage layout; upgrade no longer supported"); 466 version = 2; 467 } 468 469 if (ensure_config_user_dirs(0) == -1) { 470 ALOGE("Failed to setup misc for user 0"); 471 goto fail; 472 } 473 474 if (version == 2) { 475 ALOGD("Upgrading to /data/misc/user directories"); 476 477 char misc_dir[PATH_MAX]; 478 snprintf(misc_dir, PATH_MAX, "%smisc", android_data_dir.path); 479 480 char keychain_added_dir[PATH_MAX]; 481 snprintf(keychain_added_dir, PATH_MAX, "%s/keychain/cacerts-added", misc_dir); 482 483 char keychain_removed_dir[PATH_MAX]; 484 snprintf(keychain_removed_dir, PATH_MAX, "%s/keychain/cacerts-removed", misc_dir); 485 486 DIR *dir; 487 struct dirent *dirent; 488 dir = opendir("/data/user"); 489 if (dir != NULL) { 490 while ((dirent = readdir(dir))) { 491 const char *name = dirent->d_name; 492 493 // skip "." and ".." 494 if (name[0] == '.') { 495 if (name[1] == 0) continue; 496 if ((name[1] == '.') && (name[2] == 0)) continue; 497 } 498 499 uint32_t user_id = atoi(name); 500 501 // /data/misc/user/<user_id> 502 if (ensure_config_user_dirs(user_id) == -1) { 503 goto fail; 504 } 505 506 char misc_added_dir[PATH_MAX]; 507 snprintf(misc_added_dir, PATH_MAX, "%s/user/%s/cacerts-added", misc_dir, name); 508 509 char misc_removed_dir[PATH_MAX]; 510 snprintf(misc_removed_dir, PATH_MAX, "%s/user/%s/cacerts-removed", misc_dir, name); 511 512 uid_t uid = multiuser_get_uid(user_id, AID_SYSTEM); 513 gid_t gid = uid; 514 if (access(keychain_added_dir, F_OK) == 0) { 515 if (copy_dir_files(keychain_added_dir, misc_added_dir, uid, gid) != 0) { 516 ALOGE("Some files failed to copy"); 517 } 518 } 519 if (access(keychain_removed_dir, F_OK) == 0) { 520 if (copy_dir_files(keychain_removed_dir, misc_removed_dir, uid, gid) != 0) { 521 ALOGE("Some files failed to copy"); 522 } 523 } 524 } 525 closedir(dir); 526 527 if (access(keychain_added_dir, F_OK) == 0) { 528 delete_dir_contents(keychain_added_dir, 1, 0); 529 } 530 if (access(keychain_removed_dir, F_OK) == 0) { 531 delete_dir_contents(keychain_removed_dir, 1, 0); 532 } 533 } 534 535 version = 3; 536 } 537 538 // Persist layout version if changed 539 if (version != oldVersion) { 540 if (fs_write_atomic_int(version_path, version) == -1) { 541 ALOGE("Failed to save version to %s: %s", version_path, strerror(errno)); 542 goto fail; 543 } 544 } 545 546 // Success! 547 res = 0; 548 549fail: 550 return res; 551} 552 553static int log_callback(int type, const char *fmt, ...) { 554 va_list ap; 555 int priority; 556 557 switch (type) { 558 case SELINUX_WARNING: 559 priority = ANDROID_LOG_WARN; 560 break; 561 case SELINUX_INFO: 562 priority = ANDROID_LOG_INFO; 563 break; 564 default: 565 priority = ANDROID_LOG_ERROR; 566 break; 567 } 568 va_start(ap, fmt); 569 LOG_PRI_VA(priority, "SELinux", fmt, ap); 570 va_end(ap); 571 return 0; 572} 573 574static int installd_main(const int argc ATTRIBUTE_UNUSED, char *argv[]) { 575 char buf[BUFFER_MAX]; 576 struct sockaddr addr; 577 socklen_t alen; 578 int lsocket, s; 579 int selinux_enabled = (is_selinux_enabled() > 0); 580 581 setenv("ANDROID_LOG_TAGS", "*:v", 1); 582 android::base::InitLogging(argv); 583 584 ALOGI("installd firing up\n"); 585 586 union selinux_callback cb; 587 cb.func_log = log_callback; 588 selinux_set_callback(SELINUX_CB_LOG, cb); 589 590 if (!initialize_globals()) { 591 ALOGE("Could not initialize globals; exiting.\n"); 592 exit(1); 593 } 594 595 if (initialize_directories() < 0) { 596 ALOGE("Could not create directories; exiting.\n"); 597 exit(1); 598 } 599 600 if (selinux_enabled && selinux_status_open(true) < 0) { 601 ALOGE("Could not open selinux status; exiting.\n"); 602 exit(1); 603 } 604 605 lsocket = android_get_control_socket(SOCKET_PATH); 606 if (lsocket < 0) { 607 ALOGE("Failed to get socket from environment: %s\n", strerror(errno)); 608 exit(1); 609 } 610 if (listen(lsocket, 5)) { 611 ALOGE("Listen on socket failed: %s\n", strerror(errno)); 612 exit(1); 613 } 614 fcntl(lsocket, F_SETFD, FD_CLOEXEC); 615 616 for (;;) { 617 alen = sizeof(addr); 618 s = accept(lsocket, &addr, &alen); 619 if (s < 0) { 620 ALOGE("Accept failed: %s\n", strerror(errno)); 621 continue; 622 } 623 fcntl(s, F_SETFD, FD_CLOEXEC); 624 625 ALOGI("new connection\n"); 626 for (;;) { 627 unsigned short count; 628 if (readx(s, &count, sizeof(count))) { 629 ALOGE("failed to read size\n"); 630 break; 631 } 632 if ((count < 1) || (count >= BUFFER_MAX)) { 633 ALOGE("invalid size %d\n", count); 634 break; 635 } 636 if (readx(s, buf, count)) { 637 ALOGE("failed to read command\n"); 638 break; 639 } 640 buf[count] = 0; 641 if (selinux_enabled && selinux_status_updated() > 0) { 642 selinux_android_seapp_context_reload(); 643 } 644 if (execute(s, buf)) break; 645 } 646 ALOGI("closing connection\n"); 647 close(s); 648 } 649 650 return 0; 651} 652 653} // namespace installd 654} // namespace android 655 656int main(const int argc, char *argv[]) { 657 return android::installd::installd_main(argc, argv); 658} 659