blob: a8d648917b080f89d067945499fc9bb365de8da0 [file] [log] [blame]
Mårten Kongstad02751232018-04-27 13:16:32 +02001/*
2 * Copyright (C) 2018 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
Ryan Mitchell52e1f7a2019-04-12 12:31:42 -070017#include "idmap2d/Idmap2Service.h"
18
Mårten Kongstad02751232018-04-27 13:16:32 +020019#include <sys/stat.h> // umask
20#include <sys/types.h> // umask
Mårten Kongstad02751232018-04-27 13:16:32 +020021
22#include <cerrno>
23#include <cstring>
Ryan Mitchell6a2ca782021-01-19 13:51:15 -080024#include <filesystem>
Mårten Kongstad02751232018-04-27 13:16:32 +020025#include <fstream>
26#include <memory>
27#include <ostream>
28#include <string>
Mårten Kongstad1195a6b2021-05-11 12:57:01 +000029#include <utility>
30#include <vector>
Mårten Kongstad02751232018-04-27 13:16:32 +020031
32#include "android-base/macros.h"
Mårten Kongstadd10d06d2019-01-07 17:26:25 -080033#include "android-base/stringprintf.h"
Mårten Kongstad1da49dc2019-01-14 10:03:53 +010034#include "binder/IPCThreadState.h"
Mårten Kongstad02751232018-04-27 13:16:32 +020035#include "idmap2/BinaryStreamVisitor.h"
36#include "idmap2/FileUtils.h"
37#include "idmap2/Idmap.h"
Mårten Kongstad99ae8982021-05-10 11:00:17 +000038#include "idmap2/PrettyPrintVisitor.h"
Ryan Mitchella7070132020-05-13 14:17:52 -070039#include "idmap2/Result.h"
Mårten Kongstad4cbb0072018-11-30 16:22:05 +010040#include "idmap2/SysTrace.h"
Mårten Kongstad02751232018-04-27 13:16:32 +020041
Mårten Kongstad1da49dc2019-01-14 10:03:53 +010042using android::IPCThreadState;
Ryan Mitchella7070132020-05-13 14:17:52 -070043using android::base::StringPrintf;
Mårten Kongstad02751232018-04-27 13:16:32 +020044using android::binder::Status;
45using android::idmap2::BinaryStreamVisitor;
Ryan Mitchell6a2ca782021-01-19 13:51:15 -080046using android::idmap2::FabricatedOverlay;
47using android::idmap2::FabricatedOverlayContainer;
Mårten Kongstad02751232018-04-27 13:16:32 +020048using android::idmap2::Idmap;
49using android::idmap2::IdmapHeader;
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -080050using android::idmap2::OverlayResourceContainer;
Mårten Kongstad99ae8982021-05-10 11:00:17 +000051using android::idmap2::PrettyPrintVisitor;
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -080052using android::idmap2::TargetResourceContainer;
Mårten Kongstad1da49dc2019-01-14 10:03:53 +010053using android::idmap2::utils::kIdmapCacheDir;
Mårten Kongstadb8779022018-11-29 09:53:17 +010054using android::idmap2::utils::kIdmapFilePermissionMask;
Ryan Mitchell6a2ca782021-01-19 13:51:15 -080055using android::idmap2::utils::RandomStringForPath;
Mårten Kongstad1da49dc2019-01-14 10:03:53 +010056using android::idmap2::utils::UidHasWriteAccessToPath;
Mårten Kongstad02751232018-04-27 13:16:32 +020057
Winson62ac8b52019-12-04 08:36:48 -080058using PolicyBitmask = android::ResTable_overlayable_policy_header::PolicyBitmask;
59
Mårten Kongstad02751232018-04-27 13:16:32 +020060namespace {
61
Ryan Mitchell7d53f192020-04-24 17:45:25 -070062constexpr const char* kFrameworkPath = "/system/framework/framework-res.apk";
63
Mårten Kongstad02751232018-04-27 13:16:32 +020064Status ok() {
65 return Status::ok();
66}
67
68Status error(const std::string& msg) {
69 LOG(ERROR) << msg;
70 return Status::fromExceptionCode(Status::EX_NONE, msg.c_str());
71}
72
Mårten Kongstadd10d06d2019-01-07 17:26:25 -080073PolicyBitmask ConvertAidlArgToPolicyBitmask(int32_t arg) {
74 return static_cast<PolicyBitmask>(arg);
75}
Ryan Mitchell6a2ca782021-01-19 13:51:15 -080076
Mårten Kongstad02751232018-04-27 13:16:32 +020077} // namespace
78
Mårten Kongstad0eba72a2018-11-29 08:23:14 +010079namespace android::os {
Mårten Kongstad02751232018-04-27 13:16:32 +020080
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -080081Status Idmap2Service::getIdmapPath(const std::string& overlay_path,
Mårten Kongstad02751232018-04-27 13:16:32 +020082 int32_t user_id ATTRIBUTE_UNUSED, std::string* _aidl_return) {
83 assert(_aidl_return);
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -080084 SYSTRACE << "Idmap2Service::getIdmapPath " << overlay_path;
85 *_aidl_return = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path);
Mårten Kongstad02751232018-04-27 13:16:32 +020086 return ok();
87}
88
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -080089Status Idmap2Service::removeIdmap(const std::string& overlay_path, int32_t user_id ATTRIBUTE_UNUSED,
90 bool* _aidl_return) {
Mårten Kongstad02751232018-04-27 13:16:32 +020091 assert(_aidl_return);
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -080092 SYSTRACE << "Idmap2Service::removeIdmap " << overlay_path;
Mårten Kongstad1da49dc2019-01-14 10:03:53 +010093 const uid_t uid = IPCThreadState::self()->getCallingUid();
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -080094 const std::string idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path);
Mårten Kongstad1da49dc2019-01-14 10:03:53 +010095 if (!UidHasWriteAccessToPath(uid, idmap_path)) {
96 *_aidl_return = false;
97 return error(base::StringPrintf("failed to unlink %s: calling uid %d lacks write access",
98 idmap_path.c_str(), uid));
99 }
Mårten Kongstadb8779022018-11-29 09:53:17 +0100100 if (unlink(idmap_path.c_str()) != 0) {
Mårten Kongstad02751232018-04-27 13:16:32 +0200101 *_aidl_return = false;
102 return error("failed to unlink " + idmap_path + ": " + strerror(errno));
103 }
Mårten Kongstadb8779022018-11-29 09:53:17 +0100104 *_aidl_return = true;
105 return ok();
Mårten Kongstad02751232018-04-27 13:16:32 +0200106}
107
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800108Status Idmap2Service::verifyIdmap(const std::string& target_path, const std::string& overlay_path,
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800109 const std::string& overlay_name, int32_t fulfilled_policies,
110 bool enforce_overlayable, int32_t user_id ATTRIBUTE_UNUSED,
111 bool* _aidl_return) {
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800112 SYSTRACE << "Idmap2Service::verifyIdmap " << overlay_path;
Mårten Kongstadef0695d2018-12-04 14:36:48 +0100113 assert(_aidl_return);
Ryan Mitchell038a2842020-06-08 14:41:07 -0700114
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800115 const std::string idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path);
Mårten Kongstadef0695d2018-12-04 14:36:48 +0100116 std::ifstream fin(idmap_path);
117 const std::unique_ptr<const IdmapHeader> header = IdmapHeader::FromBinaryStream(fin);
118 fin.close();
hg.choia3a68132020-01-15 17:12:48 +0900119 if (!header) {
120 *_aidl_return = false;
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800121 LOG(WARNING) << "failed to parse idmap header of '" << idmap_path << "'";
122 return ok();
hg.choia3a68132020-01-15 17:12:48 +0900123 }
124
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800125 const auto target = GetTargetContainer(target_path);
126 if (!target) {
Ryan Mitchella7070132020-05-13 14:17:52 -0700127 *_aidl_return = false;
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800128 LOG(WARNING) << "failed to load target '" << target_path << "'";
129 return ok();
130 }
131
132 const auto overlay = OverlayResourceContainer::FromPath(overlay_path);
133 if (!overlay) {
134 *_aidl_return = false;
135 LOG(WARNING) << "failed to load overlay '" << overlay_path << "'";
136 return ok();
Ryan Mitchella7070132020-05-13 14:17:52 -0700137 }
138
139 auto up_to_date =
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800140 header->IsUpToDate(*GetPointer(*target), **overlay, overlay_name,
Ryan Mitchell038a2842020-06-08 14:41:07 -0700141 ConvertAidlArgToPolicyBitmask(fulfilled_policies), enforce_overlayable);
Ryan Mitchella7070132020-05-13 14:17:52 -0700142
Ryan Mitchell038a2842020-06-08 14:41:07 -0700143 *_aidl_return = static_cast<bool>(up_to_date);
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800144 if (!up_to_date) {
145 LOG(WARNING) << "idmap '" << idmap_path
146 << "' not up to date : " << up_to_date.GetErrorMessage();
147 }
148 return ok();
Mårten Kongstadef0695d2018-12-04 14:36:48 +0100149}
150
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800151Status Idmap2Service::createIdmap(const std::string& target_path, const std::string& overlay_path,
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800152 const std::string& overlay_name, int32_t fulfilled_policies,
153 bool enforce_overlayable, int32_t user_id ATTRIBUTE_UNUSED,
Jooyung Han16bac852020-08-10 12:53:14 +0900154 std::optional<std::string>* _aidl_return) {
Mårten Kongstad02751232018-04-27 13:16:32 +0200155 assert(_aidl_return);
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800156 SYSTRACE << "Idmap2Service::createIdmap " << target_path << " " << overlay_path;
Jooyung Han605e39f2020-01-23 13:29:22 +0900157 _aidl_return->reset();
Mårten Kongstad02751232018-04-27 13:16:32 +0200158
Mårten Kongstadd10d06d2019-01-07 17:26:25 -0800159 const PolicyBitmask policy_bitmask = ConvertAidlArgToPolicyBitmask(fulfilled_policies);
160
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800161 const std::string idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path);
Mårten Kongstad1da49dc2019-01-14 10:03:53 +0100162 const uid_t uid = IPCThreadState::self()->getCallingUid();
163 if (!UidHasWriteAccessToPath(uid, idmap_path)) {
164 return error(base::StringPrintf("will not write to %s: calling uid %d lacks write accesss",
165 idmap_path.c_str(), uid));
166 }
167
Ryan Mitchellb49cb5e2021-02-10 11:27:29 -0800168 // idmap files are mapped with mmap in libandroidfw. Deleting and recreating the idmap guarantees
169 // that existing memory maps will continue to be valid and unaffected. The file must be deleted
170 // before attempting to create the idmap, so that if idmap creation fails, the overlay will no
171 // longer be usable.
172 unlink(idmap_path.c_str());
173
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800174 const auto target = GetTargetContainer(target_path);
175 if (!target) {
176 return error("failed to load target '%s'" + target_path);
Mårten Kongstad02751232018-04-27 13:16:32 +0200177 }
178
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800179 const auto overlay = OverlayResourceContainer::FromPath(overlay_path);
180 if (!overlay) {
181 return error("failed to load apk overlay '%s'" + overlay_path);
Mårten Kongstad02751232018-04-27 13:16:32 +0200182 }
183
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800184 const auto idmap = Idmap::FromContainers(*GetPointer(*target), **overlay, overlay_name,
185 policy_bitmask, enforce_overlayable);
Mårten Kongstad02751232018-04-27 13:16:32 +0200186 if (!idmap) {
Mårten Kongstadce424902019-03-01 08:35:37 +0100187 return error(idmap.GetErrorMessage());
Mårten Kongstad02751232018-04-27 13:16:32 +0200188 }
189
Mårten Kongstadb8779022018-11-29 09:53:17 +0100190 umask(kIdmapFilePermissionMask);
Mårten Kongstad02751232018-04-27 13:16:32 +0200191 std::ofstream fout(idmap_path);
192 if (fout.fail()) {
193 return error("failed to open idmap path " + idmap_path);
194 }
Ryan Mitchella9093052020-03-26 17:15:01 -0700195
Mårten Kongstad02751232018-04-27 13:16:32 +0200196 BinaryStreamVisitor visitor(fout);
Mårten Kongstadce424902019-03-01 08:35:37 +0100197 (*idmap)->accept(&visitor);
Mårten Kongstad02751232018-04-27 13:16:32 +0200198 fout.close();
199 if (fout.fail()) {
Ryan Mitchella9093052020-03-26 17:15:01 -0700200 unlink(idmap_path.c_str());
Mårten Kongstad02751232018-04-27 13:16:32 +0200201 return error("failed to write to idmap path " + idmap_path);
202 }
203
Jooyung Han16bac852020-08-10 12:53:14 +0900204 *_aidl_return = idmap_path;
Mårten Kongstad02751232018-04-27 13:16:32 +0200205 return ok();
206}
207
Ryan Mitchell2ed8bfa2021-01-08 13:34:28 -0800208idmap2::Result<Idmap2Service::TargetResourceContainerPtr> Idmap2Service::GetTargetContainer(
209 const std::string& target_path) {
210 if (target_path == kFrameworkPath) {
211 if (framework_apk_cache_ == nullptr) {
212 // Initialize the framework APK cache.
213 auto target = TargetResourceContainer::FromPath(target_path);
214 if (!target) {
215 return target.GetError();
216 }
217 framework_apk_cache_ = std::move(*target);
218 }
219 return {framework_apk_cache_.get()};
220 }
221
222 auto target = TargetResourceContainer::FromPath(target_path);
223 if (!target) {
224 return target.GetError();
225 }
226 return {std::move(*target)};
227}
228
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800229Status Idmap2Service::createFabricatedOverlay(
230 const os::FabricatedOverlayInternal& overlay,
231 std::optional<os::FabricatedOverlayInfo>* _aidl_return) {
232 idmap2::FabricatedOverlay::Builder builder(overlay.packageName, overlay.overlayName,
233 overlay.targetPackageName);
234 if (!overlay.targetOverlayable.empty()) {
235 builder.SetOverlayable(overlay.targetOverlayable);
236 }
237
238 for (const auto& res : overlay.entries) {
239 builder.SetResourceValue(res.resourceName, res.dataType, res.data);
240 }
241
242 // Generate the file path of the fabricated overlay and ensure it does not collide with an
243 // existing path. Re-registering a fabricated overlay will always result in an updated path.
244 std::string path;
245 std::string file_name;
246 do {
247 constexpr size_t kSuffixLength = 4;
248 const std::string random_suffix = RandomStringForPath(kSuffixLength);
249 file_name = StringPrintf("%s-%s-%s.frro", overlay.packageName.c_str(),
250 overlay.overlayName.c_str(), random_suffix.c_str());
251 path = StringPrintf("%s/%s", kIdmapCacheDir, file_name.c_str());
252
253 // Invoking std::filesystem::exists with a file name greater than 255 characters will cause this
254 // process to abort since the name exceeds the maximum file name size.
255 const size_t kMaxFileNameLength = 255;
256 if (file_name.size() > kMaxFileNameLength) {
257 return error(
258 base::StringPrintf("fabricated overlay file name '%s' longer than %zu characters",
259 file_name.c_str(), kMaxFileNameLength));
260 }
261 } while (std::filesystem::exists(path));
262
263 const uid_t uid = IPCThreadState::self()->getCallingUid();
264 if (!UidHasWriteAccessToPath(uid, path)) {
265 return error(base::StringPrintf("will not write to %s: calling uid %d lacks write access",
266 path.c_str(), uid));
267 }
268
Mårten Kongstada384fb72021-05-10 08:34:54 +0000269 const auto frro = builder.Build();
270 if (!frro) {
271 return error(StringPrintf("failed to serialize '%s:%s': %s", overlay.packageName.c_str(),
272 overlay.overlayName.c_str(), frro.GetErrorMessage().c_str()));
273 }
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800274 // Persist the fabricated overlay.
275 umask(kIdmapFilePermissionMask);
276 std::ofstream fout(path);
277 if (fout.fail()) {
278 return error("failed to open frro path " + path);
279 }
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800280 auto result = frro->ToBinaryStream(fout);
281 if (!result) {
282 unlink(path.c_str());
283 return error("failed to write to frro path " + path + ": " + result.GetErrorMessage());
284 }
285 if (fout.fail()) {
286 unlink(path.c_str());
287 return error("failed to write to frro path " + path);
288 }
289
290 os::FabricatedOverlayInfo out_info;
291 out_info.packageName = overlay.packageName;
292 out_info.overlayName = overlay.overlayName;
293 out_info.targetPackageName = overlay.targetPackageName;
294 out_info.targetOverlayable = overlay.targetOverlayable;
295 out_info.path = path;
296 *_aidl_return = out_info;
297 return ok();
298}
299
Ryan Mitchellb887f682021-07-15 10:43:42 -0700300Status Idmap2Service::acquireFabricatedOverlayIterator() {
301 if (frro_iter_.has_value()) {
302 LOG(WARNING) << "active ffro iterator was not previously released";
303 }
304 frro_iter_ = std::filesystem::directory_iterator(kIdmapCacheDir);
305 return ok();
306}
307
308Status Idmap2Service::releaseFabricatedOverlayIterator() {
309 if (!frro_iter_.has_value()) {
310 LOG(WARNING) << "no active ffro iterator to release";
311 }
312 return ok();
313}
314
315Status Idmap2Service::nextFabricatedOverlayInfos(
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800316 std::vector<os::FabricatedOverlayInfo>* _aidl_return) {
Ryan Mitchellb887f682021-07-15 10:43:42 -0700317 constexpr size_t kMaxEntryCount = 100;
318 if (!frro_iter_.has_value()) {
319 return error("no active frro iterator");
320 }
321
322 size_t count = 0;
323 auto& entry_iter = *frro_iter_;
324 auto entry_iter_end = end(*frro_iter_);
325 for (; entry_iter != entry_iter_end && count < kMaxEntryCount; ++entry_iter) {
326 auto& entry = *entry_iter;
327 if (!entry.is_regular_file() || !android::IsFabricatedOverlay(entry.path())) {
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800328 continue;
329 }
330
331 const auto overlay = FabricatedOverlayContainer::FromPath(entry.path());
332 if (!overlay) {
Ryan Mitchellb887f682021-07-15 10:43:42 -0700333 LOG(WARNING) << "Failed to open '" << entry.path() << "': " << overlay.GetErrorMessage();
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800334 continue;
335 }
336
337 const auto info = (*overlay)->GetManifestInfo();
338 os::FabricatedOverlayInfo out_info;
339 out_info.packageName = info.package_name;
340 out_info.overlayName = info.name;
341 out_info.targetPackageName = info.target_package;
342 out_info.targetOverlayable = info.target_name;
343 out_info.path = entry.path();
344 _aidl_return->emplace_back(std::move(out_info));
Ryan Mitchellb887f682021-07-15 10:43:42 -0700345 count++;
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800346 }
Ryan Mitchell6a2ca782021-01-19 13:51:15 -0800347 return ok();
348}
349
350binder::Status Idmap2Service::deleteFabricatedOverlay(const std::string& overlay_path,
351 bool* _aidl_return) {
352 SYSTRACE << "Idmap2Service::deleteFabricatedOverlay " << overlay_path;
353 const uid_t uid = IPCThreadState::self()->getCallingUid();
354
355 if (!UidHasWriteAccessToPath(uid, overlay_path)) {
356 *_aidl_return = false;
357 return error(base::StringPrintf("failed to unlink %s: calling uid %d lacks write access",
358 overlay_path.c_str(), uid));
359 }
360
361 const std::string idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path);
362 if (!UidHasWriteAccessToPath(uid, idmap_path)) {
363 *_aidl_return = false;
364 return error(base::StringPrintf("failed to unlink %s: calling uid %d lacks write access",
365 idmap_path.c_str(), uid));
366 }
367
368 if (unlink(overlay_path.c_str()) != 0) {
369 *_aidl_return = false;
370 return error("failed to unlink " + overlay_path + ": " + strerror(errno));
371 }
372
373 if (unlink(idmap_path.c_str()) != 0) {
374 *_aidl_return = false;
375 return error("failed to unlink " + idmap_path + ": " + strerror(errno));
376 }
377
378 *_aidl_return = true;
379 return ok();
380}
381
Mårten Kongstad99ae8982021-05-10 11:00:17 +0000382binder::Status Idmap2Service::dumpIdmap(const std::string& overlay_path,
383 std::string* _aidl_return) {
384 assert(_aidl_return);
385
386 const auto idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path);
387 std::ifstream fin(idmap_path);
388 const auto idmap = Idmap::FromBinaryStream(fin);
389 fin.close();
390 if (!idmap) {
391 return error(idmap.GetErrorMessage());
392 }
393
394 std::stringstream stream;
395 PrettyPrintVisitor visitor(stream);
396 (*idmap)->accept(&visitor);
397 *_aidl_return = stream.str();
398
399 return ok();
400}
401
Mårten Kongstad0eba72a2018-11-29 08:23:14 +0100402} // namespace android::os