native_loader.cpp revision 3150fa25140fd5e2d66569841bd8e8eba07adb27
1/* 2 * Copyright (C) 2015 The Android Open Source Project 3 * 4 * Licensed under the Apache License, Version 2.0 (the "License"); 5 * you may not use this file except in compliance with the License. 6 * You may obtain a copy of the License at 7 * 8 * http://www.apache.org/licenses/LICENSE-2.0 9 * 10 * Unless required by applicable law or agreed to in writing, software 11 * distributed under the License is distributed on an "AS IS" BASIS, 12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13 * See the License for the specific language governing permissions and 14 * limitations under the License. 15 */ 16 17#include "nativeloader/native_loader.h" 18#include "ScopedUtfChars.h" 19 20#include <dlfcn.h> 21#ifdef __ANDROID__ 22#include <android/dlext.h> 23#include "cutils/properties.h" 24#define LOG_TAG "libnativeloader" 25#include "log/log.h" 26#endif 27 28#include <algorithm> 29#include <vector> 30#include <string> 31#include <mutex> 32 33#include "android-base/file.h" 34#include "android-base/macros.h" 35#include "android-base/strings.h" 36 37namespace android { 38 39#if defined(__ANDROID__) 40static constexpr const char* kPublicNativeLibrariesSystemConfig = "/system/etc/public.libraries.txt"; 41static constexpr const char* kPublicNativeLibrariesVendorConfig = "/vendor/etc/public.libraries.txt"; 42 43class LibraryNamespaces { 44 public: 45 LibraryNamespaces() : initialized_(false) { } 46 47 android_namespace_t* Create(JNIEnv* env, 48 jobject class_loader, 49 bool is_shared, 50 jstring java_library_path, 51 jstring java_permitted_path, 52 int32_t target_sdk_version) { 53 ScopedUtfChars library_path(env, java_library_path); 54 55 std::string permitted_path; 56 if (java_permitted_path != nullptr) { 57 ScopedUtfChars path(env, java_permitted_path); 58 permitted_path = path.c_str(); 59 } else { 60 // (http://b/27588281) This is a workaround for apps using custom 61 // classloaders and calling System.load() with an absolute path which 62 // is outside of the classloader library search path. 63 // 64 // This part effectively allows such a classloader to access anything 65 // under /data 66 permitted_path = "/data"; 67 } 68 69 if (!initialized_ && !InitPublicNamespace(library_path.c_str(), target_sdk_version)) { 70 return nullptr; 71 } 72 73 android_namespace_t* ns = FindNamespaceByClassLoader(env, class_loader); 74 75 LOG_ALWAYS_FATAL_IF(ns != nullptr, 76 "There is already a namespace associated with this classloader"); 77 78 uint64_t namespace_type = ANDROID_NAMESPACE_TYPE_ISOLATED; 79 if (is_shared) { 80 namespace_type |= ANDROID_NAMESPACE_TYPE_SHARED; 81 } 82 83 ns = android_create_namespace("classloader-namespace", 84 nullptr, 85 library_path.c_str(), 86 namespace_type, 87 !permitted_path.empty() ? 88 permitted_path.c_str() : 89 nullptr); 90 91 if (ns != nullptr) { 92 namespaces_.push_back(std::make_pair(env->NewWeakGlobalRef(class_loader), ns)); 93 } 94 95 return ns; 96 } 97 98 android_namespace_t* FindNamespaceByClassLoader(JNIEnv* env, jobject class_loader) { 99 auto it = std::find_if(namespaces_.begin(), namespaces_.end(), 100 [&](const std::pair<jweak, android_namespace_t*>& value) { 101 return env->IsSameObject(value.first, class_loader); 102 }); 103 return it != namespaces_.end() ? it->second : nullptr; 104 } 105 106 void Initialize() { 107 std::vector<std::string> sonames; 108 109 LOG_ALWAYS_FATAL_IF(!ReadConfig(kPublicNativeLibrariesSystemConfig, &sonames), 110 "Error reading public native library list from \"%s\": %s", 111 kPublicNativeLibrariesSystemConfig, strerror(errno)); 112 // This file is optional, quietly ignore if the file does not exist. 113 ReadConfig(kPublicNativeLibrariesVendorConfig, &sonames); 114 115 // android_init_namespaces() expects all the public libraries 116 // to be loaded so that they can be found by soname alone. 117 // 118 // TODO(dimitry): this is a bit misleading since we do not know 119 // if the vendor public library is going to be opened from /vendor/lib 120 // we might as well end up loading them from /system/lib 121 // For now we rely on CTS test to catch things like this but 122 // it should probably be addressed in the future. 123 for (const auto& soname : sonames) { 124 dlopen(soname.c_str(), RTLD_NOW | RTLD_NODELETE); 125 } 126 127 public_libraries_ = base::Join(sonames, ':'); 128 } 129 130 private: 131 bool ReadConfig(const std::string& configFile, std::vector<std::string>* sonames) { 132 // Read list of public native libraries from the config file. 133 std::string file_content; 134 if(!base::ReadFileToString(configFile, &file_content)) { 135 return false; 136 } 137 138 std::vector<std::string> lines = base::Split(file_content, "\n"); 139 140 for (const auto& line : lines) { 141 auto trimmed_line = base::Trim(line); 142 if (trimmed_line[0] == '#' || trimmed_line.empty()) { 143 continue; 144 } 145 146 sonames->push_back(trimmed_line); 147 } 148 149 return true; 150 } 151 152 bool InitPublicNamespace(const char* library_path, int32_t target_sdk_version) { 153 std::string publicNativeLibraries = public_libraries_; 154 155 UNUSED(target_sdk_version); 156 // (http://b/25844435) - Some apps call dlopen from generated code (mono jited 157 // code is one example) unknown to linker in which case linker uses anonymous 158 // namespace. The second argument specifies the search path for the anonymous 159 // namespace which is the library_path of the classloader. 160 initialized_ = android_init_namespaces(publicNativeLibraries.c_str(), library_path); 161 162 return initialized_; 163 } 164 165 bool initialized_; 166 std::vector<std::pair<jweak, android_namespace_t*>> namespaces_; 167 std::string public_libraries_; 168 169 170 DISALLOW_COPY_AND_ASSIGN(LibraryNamespaces); 171}; 172 173static std::mutex g_namespaces_mutex; 174static LibraryNamespaces* g_namespaces = new LibraryNamespaces; 175 176static bool namespaces_enabled(uint32_t target_sdk_version) { 177 return target_sdk_version > 0; 178} 179#endif 180 181void InitializeNativeLoader() { 182#if defined(__ANDROID__) 183 std::lock_guard<std::mutex> guard(g_namespaces_mutex); 184 g_namespaces->Initialize(); 185#endif 186} 187 188 189jstring CreateClassLoaderNamespace(JNIEnv* env, 190 int32_t target_sdk_version, 191 jobject class_loader, 192 bool is_shared, 193 jstring library_path, 194 jstring permitted_path) { 195#if defined(__ANDROID__) 196 if (!namespaces_enabled(target_sdk_version)) { 197 return nullptr; 198 } 199 200 std::lock_guard<std::mutex> guard(g_namespaces_mutex); 201 android_namespace_t* ns = g_namespaces->Create(env, 202 class_loader, 203 is_shared, 204 library_path, 205 permitted_path, 206 target_sdk_version); 207 if (ns == nullptr) { 208 return env->NewStringUTF(dlerror()); 209 } 210#else 211 UNUSED(env, target_sdk_version, class_loader, is_shared, 212 library_path, permitted_path); 213#endif 214 return nullptr; 215} 216 217void* OpenNativeLibrary(JNIEnv* env, 218 int32_t target_sdk_version, 219 const char* path, 220 jobject class_loader, 221 jstring library_path) { 222#if defined(__ANDROID__) 223 if (!namespaces_enabled(target_sdk_version) || class_loader == nullptr) { 224 return dlopen(path, RTLD_NOW); 225 } 226 227 std::lock_guard<std::mutex> guard(g_namespaces_mutex); 228 android_namespace_t* ns = g_namespaces->FindNamespaceByClassLoader(env, class_loader); 229 230 if (ns == nullptr) { 231 // This is the case where the classloader was not created by ApplicationLoaders 232 // In this case we create an isolated not-shared namespace for it. 233 ns = g_namespaces->Create(env, class_loader, false, library_path, nullptr, target_sdk_version); 234 if (ns == nullptr) { 235 return nullptr; 236 } 237 } 238 239 android_dlextinfo extinfo; 240 extinfo.flags = ANDROID_DLEXT_USE_NAMESPACE; 241 extinfo.library_namespace = ns; 242 243 return android_dlopen_ext(path, RTLD_NOW, &extinfo); 244#else 245 UNUSED(env, target_sdk_version, class_loader, library_path); 246 return dlopen(path, RTLD_NOW); 247#endif 248} 249 250#if defined(__ANDROID__) 251android_namespace_t* FindNamespaceByClassLoader(JNIEnv* env, jobject class_loader) { 252 std::lock_guard<std::mutex> guard(g_namespaces_mutex); 253 return g_namespaces->FindNamespaceByClassLoader(env, class_loader); 254} 255#endif 256 257}; // android namespace 258