installd.cpp revision eecb2d205366351af42fd0cd9e1a95de3980764e
1/* 2** Copyright 2008, The Android Open Source Project 3** 4** Licensed under the Apache License, Version 2.0 (the "License"); 5** you may not use this file except in compliance with the License. 6** You may obtain a copy of the License at 7** 8** http://www.apache.org/licenses/LICENSE-2.0 9** 10** Unless required by applicable law or agreed to in writing, software 11** distributed under the License is distributed on an "AS IS" BASIS, 12** WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13** See the License for the specific language governing permissions and 14** limitations under the License. 15*/ 16 17#include <fcntl.h> 18#include <selinux/android.h> 19#include <selinux/avc.h> 20#include <sys/capability.h> 21#include <sys/fsuid.h> 22#include <sys/prctl.h> 23#include <sys/socket.h> 24#include <sys/stat.h> 25 26#include <android-base/logging.h> 27#include <cutils/fs.h> 28#include <cutils/log.h> // TODO: Move everything to base::logging. 29#include <cutils/properties.h> 30#include <cutils/sockets.h> 31#include <private/android_filesystem_config.h> 32 33#include <commands.h> 34#include <globals.h> 35#include <installd_constants.h> 36#include <installd_deps.h> // Need to fill in requirements of commands. 37#include <utils.h> 38 39#ifndef LOG_TAG 40#define LOG_TAG "installd" 41#endif 42#define SOCKET_PATH "installd" 43 44#define BUFFER_MAX 1024 /* input buffer for commands */ 45#define TOKEN_MAX 16 /* max number of arguments in buffer */ 46#define REPLY_MAX 256 /* largest reply allowed */ 47 48namespace android { 49namespace installd { 50 51// Check that installd-deps sizes match cutils sizes. 52static_assert(kPropertyKeyMax == PROPERTY_KEY_MAX, "Size mismatch."); 53static_assert(kPropertyValueMax == PROPERTY_VALUE_MAX, "Size mismatch."); 54 55//////////////////////// 56// Plug-in functions. // 57//////////////////////// 58 59int get_property(const char *key, char *value, const char *default_value) { 60 return property_get(key, value, default_value); 61} 62 63// Compute the output path of 64bool calculate_oat_file_path(char path[PKG_PATH_MAX], 65 const char *oat_dir, 66 const char *apk_path, 67 const char *instruction_set) { 68 char *file_name_start; 69 char *file_name_end; 70 71 file_name_start = strrchr(apk_path, '/'); 72 if (file_name_start == NULL) { 73 ALOGE("apk_path '%s' has no '/'s in it\n", apk_path); 74 return false; 75 } 76 file_name_end = strrchr(apk_path, '.'); 77 if (file_name_end < file_name_start) { 78 ALOGE("apk_path '%s' has no extension\n", apk_path); 79 return false; 80 } 81 82 // Calculate file_name 83 int file_name_len = file_name_end - file_name_start - 1; 84 char file_name[file_name_len + 1]; 85 memcpy(file_name, file_name_start + 1, file_name_len); 86 file_name[file_name_len] = '\0'; 87 88 // <apk_parent_dir>/oat/<isa>/<file_name>.odex 89 snprintf(path, PKG_PATH_MAX, "%s/%s/%s.odex", oat_dir, instruction_set, file_name); 90 return true; 91} 92 93/* 94 * Computes the odex file for the given apk_path and instruction_set. 95 * /system/framework/whatever.jar -> /system/framework/oat/<isa>/whatever.odex 96 * 97 * Returns false if it failed to determine the odex file path. 98 */ 99bool calculate_odex_file_path(char path[PKG_PATH_MAX], 100 const char *apk_path, 101 const char *instruction_set) { 102 if (strlen(apk_path) + strlen("oat/") + strlen(instruction_set) 103 + strlen("/") + strlen("odex") + 1 > PKG_PATH_MAX) { 104 ALOGE("apk_path '%s' may be too long to form odex file path.\n", apk_path); 105 return false; 106 } 107 108 strcpy(path, apk_path); 109 char *end = strrchr(path, '/'); 110 if (end == NULL) { 111 ALOGE("apk_path '%s' has no '/'s in it?!\n", apk_path); 112 return false; 113 } 114 const char *apk_end = apk_path + (end - path); // strrchr(apk_path, '/'); 115 116 strcpy(end + 1, "oat/"); // path = /system/framework/oat/\0 117 strcat(path, instruction_set); // path = /system/framework/oat/<isa>\0 118 strcat(path, apk_end); // path = /system/framework/oat/<isa>/whatever.jar\0 119 end = strrchr(path, '.'); 120 if (end == NULL) { 121 ALOGE("apk_path '%s' has no extension.\n", apk_path); 122 return false; 123 } 124 strcpy(end + 1, "odex"); 125 return true; 126} 127 128bool create_cache_path(char path[PKG_PATH_MAX], 129 const char *src, 130 const char *instruction_set) { 131 size_t srclen = strlen(src); 132 133 /* demand that we are an absolute path */ 134 if ((src == 0) || (src[0] != '/') || strstr(src,"..")) { 135 return false; 136 } 137 138 if (srclen > PKG_PATH_MAX) { // XXX: PKG_NAME_MAX? 139 return false; 140 } 141 142 size_t dstlen = 143 android_data_dir.len + 144 strlen(DALVIK_CACHE) + 145 1 + 146 strlen(instruction_set) + 147 srclen + 148 strlen(DALVIK_CACHE_POSTFIX) + 2; 149 150 if (dstlen > PKG_PATH_MAX) { 151 return false; 152 } 153 154 sprintf(path,"%s%s/%s/%s%s", 155 android_data_dir.path, 156 DALVIK_CACHE, 157 instruction_set, 158 src + 1, /* skip the leading / */ 159 DALVIK_CACHE_POSTFIX); 160 161 char* tmp = 162 path + 163 android_data_dir.len + 164 strlen(DALVIK_CACHE) + 165 1 + 166 strlen(instruction_set) + 1; 167 168 for(; *tmp; tmp++) { 169 if (*tmp == '/') { 170 *tmp = '@'; 171 } 172 } 173 174 return true; 175} 176 177 178static char* parse_null(char* arg) { 179 if (strcmp(arg, "!") == 0) { 180 return nullptr; 181 } else { 182 return arg; 183 } 184} 185 186static int do_ping(char **arg ATTRIBUTE_UNUSED, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 187{ 188 return 0; 189} 190 191static int do_create_app_data(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 192 /* const char *uuid, const char *pkgname, userid_t userid, int flags, 193 appid_t appid, const char* seinfo, int target_sdk_version */ 194 return create_app_data(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3]), 195 atoi(arg[4]), arg[5], atoi(arg[6])); 196} 197 198static int do_restorecon_app_data(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 199 /* const char* uuid, const char* pkgName, userid_t userid, int flags, 200 appid_t appid, const char* seinfo */ 201 return restorecon_app_data(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3]), atoi(arg[4]), arg[5]); 202} 203 204static int do_clear_app_data(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 205 /* const char *uuid, const char *pkgname, userid_t userid, int flags */ 206 return clear_app_data(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3])); 207} 208 209static int do_destroy_app_data(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 210 /* const char *uuid, const char *pkgname, userid_t userid, int flags */ 211 return destroy_app_data(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3])); 212} 213 214static int do_dexopt(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 215{ 216 /* apk_path, uid, pkgname, instruction_set, dexopt_needed, oat_dir, dexopt_flags */ 217 return dexopt(arg[0], atoi(arg[1]), arg[2], arg[3], atoi(arg[4]), 218 arg[5], atoi(arg[6])); 219} 220 221static int do_mark_boot_complete(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 222{ 223 return mark_boot_complete(arg[0] /* instruction set */); 224} 225 226static int do_rm_dex(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 227{ 228 return rm_dex(arg[0], arg[1]); /* pkgname, instruction_set */ 229} 230 231static int do_free_cache(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) /* TODO int:free_size */ 232{ 233 return free_cache(parse_null(arg[0]), (int64_t)atoll(arg[1])); /* uuid, free_size */ 234} 235 236static int do_get_app_size(char **arg, char reply[REPLY_MAX]) { 237 int64_t codesize = 0; 238 int64_t datasize = 0; 239 int64_t cachesize = 0; 240 int64_t asecsize = 0; 241 int res = 0; 242 243 /* const char *uuid, const char *pkgname, userid_t userid, int flags, 244 const char *apkpath, const char *libdirpath, const char *fwdlock_apkpath, 245 const char *asecpath, const char *instruction_set */ 246 res = get_app_size(parse_null(arg[0]), arg[1], atoi(arg[2]), atoi(arg[3]), arg[4], arg[5], 247 arg[6], arg[7], arg[8], &codesize, &datasize, &cachesize, &asecsize); 248 249 /* 250 * Each int64_t can take up 22 characters printed out. Make sure it 251 * doesn't go over REPLY_MAX in the future. 252 */ 253 snprintf(reply, REPLY_MAX, "%" PRId64 " %" PRId64 " %" PRId64 " %" PRId64, 254 codesize, datasize, cachesize, asecsize); 255 return res; 256} 257 258static int do_move_complete_app(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) { 259 /* const char* from_uuid, const char *to_uuid, const char *package_name, 260 const char *data_app_name, appid_t appid, const char* seinfo, 261 int target_sdk_version */ 262 return move_complete_app(parse_null(arg[0]), parse_null(arg[1]), arg[2], arg[3], 263 atoi(arg[4]), arg[5], atoi(arg[6])); 264} 265 266static int do_mk_user_config(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 267{ 268 return make_user_config(atoi(arg[0])); /* userid */ 269} 270 271static int do_rm_user(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 272{ 273 return delete_user(parse_null(arg[0]), atoi(arg[1])); /* uuid, userid */ 274} 275 276static int do_movefiles(char **arg ATTRIBUTE_UNUSED, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 277{ 278 return movefiles(); 279} 280 281static int do_linklib(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 282{ 283 return linklib(parse_null(arg[0]), arg[1], arg[2], atoi(arg[3])); 284} 285 286static int do_idmap(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 287{ 288 return idmap(arg[0], arg[1], atoi(arg[2])); 289} 290 291static int do_create_oat_dir(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 292{ 293 /* oat_dir, instruction_set */ 294 return create_oat_dir(arg[0], arg[1]); 295} 296 297static int do_rm_package_dir(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 298{ 299 /* oat_dir */ 300 return rm_package_dir(arg[0]); 301} 302 303static int do_link_file(char **arg, char reply[REPLY_MAX] ATTRIBUTE_UNUSED) 304{ 305 /* relative_path, from_base, to_base */ 306 return link_file(arg[0], arg[1], arg[2]); 307} 308 309struct cmdinfo { 310 const char *name; 311 unsigned numargs; 312 int (*func)(char **arg, char reply[REPLY_MAX]); 313}; 314 315struct cmdinfo cmds[] = { 316 { "ping", 0, do_ping }, 317 318 { "create_app_data", 7, do_create_app_data }, 319 { "restorecon_app_data", 6, do_restorecon_app_data }, 320 { "clear_app_data", 4, do_clear_app_data }, 321 { "destroy_app_data", 4, do_destroy_app_data }, 322 { "move_complete_app", 7, do_move_complete_app }, 323 { "get_app_size", 9, do_get_app_size }, 324 325 { "dexopt", 7, do_dexopt }, 326 { "markbootcomplete", 1, do_mark_boot_complete }, 327 { "rmdex", 2, do_rm_dex }, 328 { "freecache", 2, do_free_cache }, 329 { "movefiles", 0, do_movefiles }, 330 { "linklib", 4, do_linklib }, 331 { "mkuserconfig", 1, do_mk_user_config }, 332 { "rmuser", 2, do_rm_user }, 333 { "idmap", 3, do_idmap }, 334 { "createoatdir", 2, do_create_oat_dir }, 335 { "rmpackagedir", 1, do_rm_package_dir }, 336 { "linkfile", 3, do_link_file }, 337}; 338 339static int readx(int s, void *_buf, int count) 340{ 341 char *buf = (char *) _buf; 342 int n = 0, r; 343 if (count < 0) return -1; 344 while (n < count) { 345 r = read(s, buf + n, count - n); 346 if (r < 0) { 347 if (errno == EINTR) continue; 348 ALOGE("read error: %s\n", strerror(errno)); 349 return -1; 350 } 351 if (r == 0) { 352 ALOGE("eof\n"); 353 return -1; /* EOF */ 354 } 355 n += r; 356 } 357 return 0; 358} 359 360static int writex(int s, const void *_buf, int count) 361{ 362 const char *buf = (const char *) _buf; 363 int n = 0, r; 364 if (count < 0) return -1; 365 while (n < count) { 366 r = write(s, buf + n, count - n); 367 if (r < 0) { 368 if (errno == EINTR) continue; 369 ALOGE("write error: %s\n", strerror(errno)); 370 return -1; 371 } 372 n += r; 373 } 374 return 0; 375} 376 377 378/* Tokenize the command buffer, locate a matching command, 379 * ensure that the required number of arguments are provided, 380 * call the function(), return the result. 381 */ 382static int execute(int s, char cmd[BUFFER_MAX]) 383{ 384 char reply[REPLY_MAX]; 385 char *arg[TOKEN_MAX+1]; 386 unsigned i; 387 unsigned n = 0; 388 unsigned short count; 389 int ret = -1; 390 391 // ALOGI("execute('%s')\n", cmd); 392 393 /* default reply is "" */ 394 reply[0] = 0; 395 396 /* n is number of args (not counting arg[0]) */ 397 arg[0] = cmd; 398 while (*cmd) { 399 if (isspace(*cmd)) { 400 *cmd++ = 0; 401 n++; 402 arg[n] = cmd; 403 if (n == TOKEN_MAX) { 404 ALOGE("too many arguments\n"); 405 goto done; 406 } 407 } 408 if (*cmd) { 409 cmd++; 410 } 411 } 412 413 for (i = 0; i < sizeof(cmds) / sizeof(cmds[0]); i++) { 414 if (!strcmp(cmds[i].name,arg[0])) { 415 if (n != cmds[i].numargs) { 416 ALOGE("%s requires %d arguments (%d given)\n", 417 cmds[i].name, cmds[i].numargs, n); 418 } else { 419 ret = cmds[i].func(arg + 1, reply); 420 } 421 goto done; 422 } 423 } 424 ALOGE("unsupported command '%s'\n", arg[0]); 425 426done: 427 if (reply[0]) { 428 n = snprintf(cmd, BUFFER_MAX, "%d %s", ret, reply); 429 } else { 430 n = snprintf(cmd, BUFFER_MAX, "%d", ret); 431 } 432 if (n > BUFFER_MAX) n = BUFFER_MAX; 433 count = n; 434 435 // ALOGI("reply: '%s'\n", cmd); 436 if (writex(s, &count, sizeof(count))) return -1; 437 if (writex(s, cmd, count)) return -1; 438 return 0; 439} 440 441bool initialize_globals() { 442 const char* data_path = getenv("ANDROID_DATA"); 443 if (data_path == nullptr) { 444 ALOGE("Could not find ANDROID_DATA"); 445 return false; 446 } 447 const char* root_path = getenv("ANDROID_ROOT"); 448 if (root_path == nullptr) { 449 ALOGE("Could not find ANDROID_ROOT"); 450 return false; 451 } 452 453 return init_globals_from_data_and_root(data_path, root_path); 454} 455 456static int initialize_directories() { 457 int res = -1; 458 459 // Read current filesystem layout version to handle upgrade paths 460 char version_path[PATH_MAX]; 461 snprintf(version_path, PATH_MAX, "%s.layout_version", android_data_dir.path); 462 463 int oldVersion; 464 if (fs_read_atomic_int(version_path, &oldVersion) == -1) { 465 oldVersion = 0; 466 } 467 int version = oldVersion; 468 469 if (version < 2) { 470 SLOGD("Assuming that device has multi-user storage layout; upgrade no longer supported"); 471 version = 2; 472 } 473 474 if (ensure_config_user_dirs(0) == -1) { 475 ALOGE("Failed to setup misc for user 0"); 476 goto fail; 477 } 478 479 if (version == 2) { 480 ALOGD("Upgrading to /data/misc/user directories"); 481 482 char misc_dir[PATH_MAX]; 483 snprintf(misc_dir, PATH_MAX, "%smisc", android_data_dir.path); 484 485 char keychain_added_dir[PATH_MAX]; 486 snprintf(keychain_added_dir, PATH_MAX, "%s/keychain/cacerts-added", misc_dir); 487 488 char keychain_removed_dir[PATH_MAX]; 489 snprintf(keychain_removed_dir, PATH_MAX, "%s/keychain/cacerts-removed", misc_dir); 490 491 DIR *dir; 492 struct dirent *dirent; 493 dir = opendir("/data/user"); 494 if (dir != NULL) { 495 while ((dirent = readdir(dir))) { 496 const char *name = dirent->d_name; 497 498 // skip "." and ".." 499 if (name[0] == '.') { 500 if (name[1] == 0) continue; 501 if ((name[1] == '.') && (name[2] == 0)) continue; 502 } 503 504 uint32_t user_id = atoi(name); 505 506 // /data/misc/user/<user_id> 507 if (ensure_config_user_dirs(user_id) == -1) { 508 goto fail; 509 } 510 511 char misc_added_dir[PATH_MAX]; 512 snprintf(misc_added_dir, PATH_MAX, "%s/user/%s/cacerts-added", misc_dir, name); 513 514 char misc_removed_dir[PATH_MAX]; 515 snprintf(misc_removed_dir, PATH_MAX, "%s/user/%s/cacerts-removed", misc_dir, name); 516 517 uid_t uid = multiuser_get_uid(user_id, AID_SYSTEM); 518 gid_t gid = uid; 519 if (access(keychain_added_dir, F_OK) == 0) { 520 if (copy_dir_files(keychain_added_dir, misc_added_dir, uid, gid) != 0) { 521 ALOGE("Some files failed to copy"); 522 } 523 } 524 if (access(keychain_removed_dir, F_OK) == 0) { 525 if (copy_dir_files(keychain_removed_dir, misc_removed_dir, uid, gid) != 0) { 526 ALOGE("Some files failed to copy"); 527 } 528 } 529 } 530 closedir(dir); 531 532 if (access(keychain_added_dir, F_OK) == 0) { 533 delete_dir_contents(keychain_added_dir, 1, 0); 534 } 535 if (access(keychain_removed_dir, F_OK) == 0) { 536 delete_dir_contents(keychain_removed_dir, 1, 0); 537 } 538 } 539 540 version = 3; 541 } 542 543 // Persist layout version if changed 544 if (version != oldVersion) { 545 if (fs_write_atomic_int(version_path, version) == -1) { 546 ALOGE("Failed to save version to %s: %s", version_path, strerror(errno)); 547 goto fail; 548 } 549 } 550 551 // Success! 552 res = 0; 553 554fail: 555 return res; 556} 557 558static int log_callback(int type, const char *fmt, ...) { 559 va_list ap; 560 int priority; 561 562 switch (type) { 563 case SELINUX_WARNING: 564 priority = ANDROID_LOG_WARN; 565 break; 566 case SELINUX_INFO: 567 priority = ANDROID_LOG_INFO; 568 break; 569 default: 570 priority = ANDROID_LOG_ERROR; 571 break; 572 } 573 va_start(ap, fmt); 574 LOG_PRI_VA(priority, "SELinux", fmt, ap); 575 va_end(ap); 576 return 0; 577} 578 579static int installd_main(const int argc ATTRIBUTE_UNUSED, char *argv[]) { 580 char buf[BUFFER_MAX]; 581 struct sockaddr addr; 582 socklen_t alen; 583 int lsocket, s; 584 int selinux_enabled = (is_selinux_enabled() > 0); 585 586 setenv("ANDROID_LOG_TAGS", "*:v", 1); 587 android::base::InitLogging(argv); 588 589 ALOGI("installd firing up\n"); 590 591 union selinux_callback cb; 592 cb.func_log = log_callback; 593 selinux_set_callback(SELINUX_CB_LOG, cb); 594 595 if (!initialize_globals()) { 596 ALOGE("Could not initialize globals; exiting.\n"); 597 exit(1); 598 } 599 600 if (initialize_directories() < 0) { 601 ALOGE("Could not create directories; exiting.\n"); 602 exit(1); 603 } 604 605 if (selinux_enabled && selinux_status_open(true) < 0) { 606 ALOGE("Could not open selinux status; exiting.\n"); 607 exit(1); 608 } 609 610 lsocket = android_get_control_socket(SOCKET_PATH); 611 if (lsocket < 0) { 612 ALOGE("Failed to get socket from environment: %s\n", strerror(errno)); 613 exit(1); 614 } 615 if (listen(lsocket, 5)) { 616 ALOGE("Listen on socket failed: %s\n", strerror(errno)); 617 exit(1); 618 } 619 fcntl(lsocket, F_SETFD, FD_CLOEXEC); 620 621 for (;;) { 622 alen = sizeof(addr); 623 s = accept(lsocket, &addr, &alen); 624 if (s < 0) { 625 ALOGE("Accept failed: %s\n", strerror(errno)); 626 continue; 627 } 628 fcntl(s, F_SETFD, FD_CLOEXEC); 629 630 ALOGI("new connection\n"); 631 for (;;) { 632 unsigned short count; 633 if (readx(s, &count, sizeof(count))) { 634 ALOGE("failed to read size\n"); 635 break; 636 } 637 if ((count < 1) || (count >= BUFFER_MAX)) { 638 ALOGE("invalid size %d\n", count); 639 break; 640 } 641 if (readx(s, buf, count)) { 642 ALOGE("failed to read command\n"); 643 break; 644 } 645 buf[count] = 0; 646 if (selinux_enabled && selinux_status_updated() > 0) { 647 selinux_android_seapp_context_reload(); 648 } 649 if (execute(s, buf)) break; 650 } 651 ALOGI("closing connection\n"); 652 close(s); 653 } 654 655 return 0; 656} 657 658} // namespace installd 659} // namespace android 660 661int main(const int argc, char *argv[]) { 662 return android::installd::installd_main(argc, argv); 663} 664