| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 1 | /* | 
|  | 2 | * Copyright (C) 2018 The Android Open Source Project | 
|  | 3 | * | 
|  | 4 | * Licensed under the Apache License, Version 2.0 (the "License"); | 
|  | 5 | * you may not use this file except in compliance with the License. | 
|  | 6 | * You may obtain a copy of the License at | 
|  | 7 | * | 
|  | 8 | *      http://www.apache.org/licenses/LICENSE-2.0 | 
|  | 9 | * | 
|  | 10 | * Unless required by applicable law or agreed to in writing, software | 
|  | 11 | * distributed under the License is distributed on an "AS IS" BASIS, | 
|  | 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | 
|  | 13 | * See the License for the specific language governing permissions and | 
|  | 14 | * limitations under the License. | 
|  | 15 | */ | 
|  | 16 |  | 
| Ryan Mitchell | 52e1f7a | 2019-04-12 12:31:42 -0700 | [diff] [blame] | 17 | #include "idmap2d/Idmap2Service.h" | 
|  | 18 |  | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 19 | #include <sys/stat.h>   // umask | 
|  | 20 | #include <sys/types.h>  // umask | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 21 |  | 
|  | 22 | #include <cerrno> | 
|  | 23 | #include <cstring> | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 24 | #include <filesystem> | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 25 | #include <fstream> | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 26 | #include <limits> | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 27 | #include <memory> | 
|  | 28 | #include <ostream> | 
|  | 29 | #include <string> | 
| Mårten Kongstad | 1195a6b | 2021-05-11 12:57:01 +0000 | [diff] [blame] | 30 | #include <utility> | 
|  | 31 | #include <vector> | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 32 |  | 
|  | 33 | #include "android-base/macros.h" | 
| Mårten Kongstad | d10d06d | 2019-01-07 17:26:25 -0800 | [diff] [blame] | 34 | #include "android-base/stringprintf.h" | 
| Mårten Kongstad | 1da49dc | 2019-01-14 10:03:53 +0100 | [diff] [blame] | 35 | #include "binder/IPCThreadState.h" | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 36 | #include "idmap2/BinaryStreamVisitor.h" | 
|  | 37 | #include "idmap2/FileUtils.h" | 
|  | 38 | #include "idmap2/Idmap.h" | 
| Mårten Kongstad | 99ae898 | 2021-05-10 11:00:17 +0000 | [diff] [blame] | 39 | #include "idmap2/PrettyPrintVisitor.h" | 
| Ryan Mitchell | a707013 | 2020-05-13 14:17:52 -0700 | [diff] [blame] | 40 | #include "idmap2/Result.h" | 
| Mårten Kongstad | 4cbb007 | 2018-11-30 16:22:05 +0100 | [diff] [blame] | 41 | #include "idmap2/SysTrace.h" | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 42 |  | 
| Ryan Mitchell | a707013 | 2020-05-13 14:17:52 -0700 | [diff] [blame] | 43 | using android::base::StringPrintf; | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 44 | using android::binder::Status; | 
|  | 45 | using android::idmap2::BinaryStreamVisitor; | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 46 | using android::idmap2::FabricatedOverlayContainer; | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 47 | using android::idmap2::Idmap; | 
|  | 48 | using android::idmap2::IdmapHeader; | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 49 | using android::idmap2::OverlayResourceContainer; | 
| Mårten Kongstad | 99ae898 | 2021-05-10 11:00:17 +0000 | [diff] [blame] | 50 | using android::idmap2::PrettyPrintVisitor; | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 51 | using android::idmap2::TargetResourceContainer; | 
| Mårten Kongstad | 1da49dc | 2019-01-14 10:03:53 +0100 | [diff] [blame] | 52 | using android::idmap2::utils::kIdmapCacheDir; | 
| Mårten Kongstad | b877902 | 2018-11-29 09:53:17 +0100 | [diff] [blame] | 53 | using android::idmap2::utils::kIdmapFilePermissionMask; | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 54 | using android::idmap2::utils::RandomStringForPath; | 
| Mårten Kongstad | 1da49dc | 2019-01-14 10:03:53 +0100 | [diff] [blame] | 55 | using android::idmap2::utils::UidHasWriteAccessToPath; | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 56 |  | 
| Winson | 62ac8b5 | 2019-12-04 08:36:48 -0800 | [diff] [blame] | 57 | using PolicyBitmask = android::ResTable_overlayable_policy_header::PolicyBitmask; | 
|  | 58 |  | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 59 | namespace { | 
|  | 60 |  | 
| Ryan Mitchell | 7d53f19 | 2020-04-24 17:45:25 -0700 | [diff] [blame] | 61 | constexpr const char* kFrameworkPath = "/system/framework/framework-res.apk"; | 
|  | 62 |  | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 63 | Status ok() { | 
|  | 64 | return Status::ok(); | 
|  | 65 | } | 
|  | 66 |  | 
|  | 67 | Status error(const std::string& msg) { | 
|  | 68 | LOG(ERROR) << msg; | 
|  | 69 | return Status::fromExceptionCode(Status::EX_NONE, msg.c_str()); | 
|  | 70 | } | 
|  | 71 |  | 
| Mårten Kongstad | d10d06d | 2019-01-07 17:26:25 -0800 | [diff] [blame] | 72 | PolicyBitmask ConvertAidlArgToPolicyBitmask(int32_t arg) { | 
|  | 73 | return static_cast<PolicyBitmask>(arg); | 
|  | 74 | } | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 75 |  | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 76 | }  // namespace | 
|  | 77 |  | 
| Mårten Kongstad | 0eba72a | 2018-11-29 08:23:14 +0100 | [diff] [blame] | 78 | namespace android::os { | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 79 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 80 | Status Idmap2Service::getIdmapPath(const std::string& overlay_path, | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 81 | int32_t user_id ATTRIBUTE_UNUSED, std::string* _aidl_return) { | 
|  | 82 | assert(_aidl_return); | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 83 | SYSTRACE << "Idmap2Service::getIdmapPath " << overlay_path; | 
|  | 84 | *_aidl_return = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 85 | return ok(); | 
|  | 86 | } | 
|  | 87 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 88 | Status Idmap2Service::removeIdmap(const std::string& overlay_path, int32_t user_id ATTRIBUTE_UNUSED, | 
|  | 89 | bool* _aidl_return) { | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 90 | assert(_aidl_return); | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 91 | SYSTRACE << "Idmap2Service::removeIdmap " << overlay_path; | 
| Mårten Kongstad | 1da49dc | 2019-01-14 10:03:53 +0100 | [diff] [blame] | 92 | const uid_t uid = IPCThreadState::self()->getCallingUid(); | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 93 | const std::string idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path); | 
| Mårten Kongstad | 1da49dc | 2019-01-14 10:03:53 +0100 | [diff] [blame] | 94 | if (!UidHasWriteAccessToPath(uid, idmap_path)) { | 
|  | 95 | *_aidl_return = false; | 
|  | 96 | return error(base::StringPrintf("failed to unlink %s: calling uid %d lacks write access", | 
|  | 97 | idmap_path.c_str(), uid)); | 
|  | 98 | } | 
| Mårten Kongstad | b877902 | 2018-11-29 09:53:17 +0100 | [diff] [blame] | 99 | if (unlink(idmap_path.c_str()) != 0) { | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 100 | *_aidl_return = false; | 
|  | 101 | return error("failed to unlink " + idmap_path + ": " + strerror(errno)); | 
|  | 102 | } | 
| Mårten Kongstad | b877902 | 2018-11-29 09:53:17 +0100 | [diff] [blame] | 103 | *_aidl_return = true; | 
|  | 104 | return ok(); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 105 | } | 
|  | 106 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 107 | Status Idmap2Service::verifyIdmap(const std::string& target_path, const std::string& overlay_path, | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 108 | const std::string& overlay_name, int32_t fulfilled_policies, | 
|  | 109 | bool enforce_overlayable, int32_t user_id ATTRIBUTE_UNUSED, | 
|  | 110 | bool* _aidl_return) { | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 111 | SYSTRACE << "Idmap2Service::verifyIdmap " << overlay_path; | 
| Mårten Kongstad | ef0695d | 2018-12-04 14:36:48 +0100 | [diff] [blame] | 112 | assert(_aidl_return); | 
| Ryan Mitchell | 038a284 | 2020-06-08 14:41:07 -0700 | [diff] [blame] | 113 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 114 | const std::string idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path); | 
| Mårten Kongstad | ef0695d | 2018-12-04 14:36:48 +0100 | [diff] [blame] | 115 | std::ifstream fin(idmap_path); | 
|  | 116 | const std::unique_ptr<const IdmapHeader> header = IdmapHeader::FromBinaryStream(fin); | 
|  | 117 | fin.close(); | 
| hg.choi | a3a6813 | 2020-01-15 17:12:48 +0900 | [diff] [blame] | 118 | if (!header) { | 
|  | 119 | *_aidl_return = false; | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 120 | LOG(WARNING) << "failed to parse idmap header of '" << idmap_path << "'"; | 
|  | 121 | return ok(); | 
| hg.choi | a3a6813 | 2020-01-15 17:12:48 +0900 | [diff] [blame] | 122 | } | 
|  | 123 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 124 | const auto target = GetTargetContainer(target_path); | 
|  | 125 | if (!target) { | 
| Ryan Mitchell | a707013 | 2020-05-13 14:17:52 -0700 | [diff] [blame] | 126 | *_aidl_return = false; | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 127 | LOG(WARNING) << "failed to load target '" << target_path << "'"; | 
|  | 128 | return ok(); | 
|  | 129 | } | 
|  | 130 |  | 
|  | 131 | const auto overlay = OverlayResourceContainer::FromPath(overlay_path); | 
|  | 132 | if (!overlay) { | 
|  | 133 | *_aidl_return = false; | 
|  | 134 | LOG(WARNING) << "failed to load overlay '" << overlay_path << "'"; | 
|  | 135 | return ok(); | 
| Ryan Mitchell | a707013 | 2020-05-13 14:17:52 -0700 | [diff] [blame] | 136 | } | 
|  | 137 |  | 
|  | 138 | auto up_to_date = | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 139 | header->IsUpToDate(*GetPointer(*target), **overlay, overlay_name, | 
| Ryan Mitchell | 038a284 | 2020-06-08 14:41:07 -0700 | [diff] [blame] | 140 | ConvertAidlArgToPolicyBitmask(fulfilled_policies), enforce_overlayable); | 
| Ryan Mitchell | a707013 | 2020-05-13 14:17:52 -0700 | [diff] [blame] | 141 |  | 
| Ryan Mitchell | 038a284 | 2020-06-08 14:41:07 -0700 | [diff] [blame] | 142 | *_aidl_return = static_cast<bool>(up_to_date); | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 143 | if (!up_to_date) { | 
|  | 144 | LOG(WARNING) << "idmap '" << idmap_path | 
|  | 145 | << "' not up to date : " << up_to_date.GetErrorMessage(); | 
|  | 146 | } | 
|  | 147 | return ok(); | 
| Mårten Kongstad | ef0695d | 2018-12-04 14:36:48 +0100 | [diff] [blame] | 148 | } | 
|  | 149 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 150 | Status Idmap2Service::createIdmap(const std::string& target_path, const std::string& overlay_path, | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 151 | const std::string& overlay_name, int32_t fulfilled_policies, | 
|  | 152 | bool enforce_overlayable, int32_t user_id ATTRIBUTE_UNUSED, | 
| Jooyung Han | 16bac85 | 2020-08-10 12:53:14 +0900 | [diff] [blame] | 153 | std::optional<std::string>* _aidl_return) { | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 154 | assert(_aidl_return); | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 155 | SYSTRACE << "Idmap2Service::createIdmap " << target_path << " " << overlay_path; | 
| Jooyung Han | 605e39f | 2020-01-23 13:29:22 +0900 | [diff] [blame] | 156 | _aidl_return->reset(); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 157 |  | 
| Mårten Kongstad | d10d06d | 2019-01-07 17:26:25 -0800 | [diff] [blame] | 158 | const PolicyBitmask policy_bitmask = ConvertAidlArgToPolicyBitmask(fulfilled_policies); | 
|  | 159 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 160 | const std::string idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path); | 
| Mårten Kongstad | 1da49dc | 2019-01-14 10:03:53 +0100 | [diff] [blame] | 161 | const uid_t uid = IPCThreadState::self()->getCallingUid(); | 
|  | 162 | if (!UidHasWriteAccessToPath(uid, idmap_path)) { | 
|  | 163 | return error(base::StringPrintf("will not write to %s: calling uid %d lacks write accesss", | 
|  | 164 | idmap_path.c_str(), uid)); | 
|  | 165 | } | 
|  | 166 |  | 
| Ryan Mitchell | b49cb5e | 2021-02-10 11:27:29 -0800 | [diff] [blame] | 167 | // idmap files are mapped with mmap in libandroidfw. Deleting and recreating the idmap guarantees | 
|  | 168 | // that existing memory maps will continue to be valid and unaffected. The file must be deleted | 
|  | 169 | // before attempting to create the idmap, so that if idmap  creation fails, the overlay will no | 
|  | 170 | // longer be usable. | 
|  | 171 | unlink(idmap_path.c_str()); | 
|  | 172 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 173 | const auto target = GetTargetContainer(target_path); | 
|  | 174 | if (!target) { | 
|  | 175 | return error("failed to load target '%s'" + target_path); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 176 | } | 
|  | 177 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 178 | const auto overlay = OverlayResourceContainer::FromPath(overlay_path); | 
|  | 179 | if (!overlay) { | 
|  | 180 | return error("failed to load apk overlay '%s'" + overlay_path); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 181 | } | 
|  | 182 |  | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 183 | const auto idmap = Idmap::FromContainers(*GetPointer(*target), **overlay, overlay_name, | 
|  | 184 | policy_bitmask, enforce_overlayable); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 185 | if (!idmap) { | 
| Mårten Kongstad | ce42490 | 2019-03-01 08:35:37 +0100 | [diff] [blame] | 186 | return error(idmap.GetErrorMessage()); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 187 | } | 
|  | 188 |  | 
| Mårten Kongstad | b877902 | 2018-11-29 09:53:17 +0100 | [diff] [blame] | 189 | umask(kIdmapFilePermissionMask); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 190 | std::ofstream fout(idmap_path); | 
|  | 191 | if (fout.fail()) { | 
|  | 192 | return error("failed to open idmap path " + idmap_path); | 
|  | 193 | } | 
| Ryan Mitchell | a909305 | 2020-03-26 17:15:01 -0700 | [diff] [blame] | 194 |  | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 195 | BinaryStreamVisitor visitor(fout); | 
| Mårten Kongstad | ce42490 | 2019-03-01 08:35:37 +0100 | [diff] [blame] | 196 | (*idmap)->accept(&visitor); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 197 | fout.close(); | 
|  | 198 | if (fout.fail()) { | 
| Ryan Mitchell | a909305 | 2020-03-26 17:15:01 -0700 | [diff] [blame] | 199 | unlink(idmap_path.c_str()); | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 200 | return error("failed to write to idmap path " + idmap_path); | 
|  | 201 | } | 
|  | 202 |  | 
| Jooyung Han | 16bac85 | 2020-08-10 12:53:14 +0900 | [diff] [blame] | 203 | *_aidl_return = idmap_path; | 
| Mårten Kongstad | 0275123 | 2018-04-27 13:16:32 +0200 | [diff] [blame] | 204 | return ok(); | 
|  | 205 | } | 
|  | 206 |  | 
| Ryan Mitchell | 2ed8bfa | 2021-01-08 13:34:28 -0800 | [diff] [blame] | 207 | idmap2::Result<Idmap2Service::TargetResourceContainerPtr> Idmap2Service::GetTargetContainer( | 
|  | 208 | const std::string& target_path) { | 
|  | 209 | if (target_path == kFrameworkPath) { | 
|  | 210 | if (framework_apk_cache_ == nullptr) { | 
|  | 211 | // Initialize the framework APK cache. | 
|  | 212 | auto target = TargetResourceContainer::FromPath(target_path); | 
|  | 213 | if (!target) { | 
|  | 214 | return target.GetError(); | 
|  | 215 | } | 
|  | 216 | framework_apk_cache_ = std::move(*target); | 
|  | 217 | } | 
|  | 218 | return {framework_apk_cache_.get()}; | 
|  | 219 | } | 
|  | 220 |  | 
|  | 221 | auto target = TargetResourceContainer::FromPath(target_path); | 
|  | 222 | if (!target) { | 
|  | 223 | return target.GetError(); | 
|  | 224 | } | 
|  | 225 | return {std::move(*target)}; | 
|  | 226 | } | 
|  | 227 |  | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 228 | Status Idmap2Service::createFabricatedOverlay( | 
|  | 229 | const os::FabricatedOverlayInternal& overlay, | 
|  | 230 | std::optional<os::FabricatedOverlayInfo>* _aidl_return) { | 
|  | 231 | idmap2::FabricatedOverlay::Builder builder(overlay.packageName, overlay.overlayName, | 
|  | 232 | overlay.targetPackageName); | 
|  | 233 | if (!overlay.targetOverlayable.empty()) { | 
|  | 234 | builder.SetOverlayable(overlay.targetOverlayable); | 
|  | 235 | } | 
|  | 236 |  | 
|  | 237 | for (const auto& res : overlay.entries) { | 
|  | 238 | builder.SetResourceValue(res.resourceName, res.dataType, res.data); | 
|  | 239 | } | 
|  | 240 |  | 
|  | 241 | // Generate the file path of the fabricated overlay and ensure it does not collide with an | 
|  | 242 | // existing path. Re-registering a fabricated overlay will always result in an updated path. | 
|  | 243 | std::string path; | 
|  | 244 | std::string file_name; | 
|  | 245 | do { | 
|  | 246 | constexpr size_t kSuffixLength = 4; | 
|  | 247 | const std::string random_suffix = RandomStringForPath(kSuffixLength); | 
|  | 248 | file_name = StringPrintf("%s-%s-%s.frro", overlay.packageName.c_str(), | 
|  | 249 | overlay.overlayName.c_str(), random_suffix.c_str()); | 
|  | 250 | path = StringPrintf("%s/%s", kIdmapCacheDir, file_name.c_str()); | 
|  | 251 |  | 
|  | 252 | // Invoking std::filesystem::exists with a file name greater than 255 characters will cause this | 
|  | 253 | // process to abort since the name exceeds the maximum file name size. | 
|  | 254 | const size_t kMaxFileNameLength = 255; | 
|  | 255 | if (file_name.size() > kMaxFileNameLength) { | 
|  | 256 | return error( | 
|  | 257 | base::StringPrintf("fabricated overlay file name '%s' longer than %zu characters", | 
|  | 258 | file_name.c_str(), kMaxFileNameLength)); | 
|  | 259 | } | 
|  | 260 | } while (std::filesystem::exists(path)); | 
|  | 261 |  | 
|  | 262 | const uid_t uid = IPCThreadState::self()->getCallingUid(); | 
|  | 263 | if (!UidHasWriteAccessToPath(uid, path)) { | 
|  | 264 | return error(base::StringPrintf("will not write to %s: calling uid %d lacks write access", | 
|  | 265 | path.c_str(), uid)); | 
|  | 266 | } | 
|  | 267 |  | 
| Mårten Kongstad | a384fb7 | 2021-05-10 08:34:54 +0000 | [diff] [blame] | 268 | const auto frro = builder.Build(); | 
|  | 269 | if (!frro) { | 
|  | 270 | return error(StringPrintf("failed to serialize '%s:%s': %s", overlay.packageName.c_str(), | 
|  | 271 | overlay.overlayName.c_str(), frro.GetErrorMessage().c_str())); | 
|  | 272 | } | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 273 | // Persist the fabricated overlay. | 
|  | 274 | umask(kIdmapFilePermissionMask); | 
|  | 275 | std::ofstream fout(path); | 
|  | 276 | if (fout.fail()) { | 
|  | 277 | return error("failed to open frro path " + path); | 
|  | 278 | } | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 279 | auto result = frro->ToBinaryStream(fout); | 
|  | 280 | if (!result) { | 
|  | 281 | unlink(path.c_str()); | 
|  | 282 | return error("failed to write to frro path " + path + ": " + result.GetErrorMessage()); | 
|  | 283 | } | 
|  | 284 | if (fout.fail()) { | 
|  | 285 | unlink(path.c_str()); | 
|  | 286 | return error("failed to write to frro path " + path); | 
|  | 287 | } | 
|  | 288 |  | 
|  | 289 | os::FabricatedOverlayInfo out_info; | 
|  | 290 | out_info.packageName = overlay.packageName; | 
|  | 291 | out_info.overlayName = overlay.overlayName; | 
|  | 292 | out_info.targetPackageName = overlay.targetPackageName; | 
|  | 293 | out_info.targetOverlayable = overlay.targetOverlayable; | 
|  | 294 | out_info.path = path; | 
|  | 295 | *_aidl_return = out_info; | 
|  | 296 | return ok(); | 
|  | 297 | } | 
|  | 298 |  | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 299 | Status Idmap2Service::acquireFabricatedOverlayIterator(int32_t* _aidl_return) { | 
|  | 300 | std::lock_guard l(frro_iter_mutex_); | 
| Ryan Mitchell | b887f68 | 2021-07-15 10:43:42 -0700 | [diff] [blame] | 301 | if (frro_iter_.has_value()) { | 
|  | 302 | LOG(WARNING) << "active ffro iterator was not previously released"; | 
|  | 303 | } | 
|  | 304 | frro_iter_ = std::filesystem::directory_iterator(kIdmapCacheDir); | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 305 | if (frro_iter_id_ == std::numeric_limits<int32_t>::max()) { | 
|  | 306 | frro_iter_id_ = 0; | 
|  | 307 | } else { | 
|  | 308 | ++frro_iter_id_; | 
|  | 309 | } | 
|  | 310 | *_aidl_return = frro_iter_id_; | 
| Ryan Mitchell | b887f68 | 2021-07-15 10:43:42 -0700 | [diff] [blame] | 311 | return ok(); | 
|  | 312 | } | 
|  | 313 |  | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 314 | Status Idmap2Service::releaseFabricatedOverlayIterator(int32_t iteratorId) { | 
|  | 315 | std::lock_guard l(frro_iter_mutex_); | 
| Ryan Mitchell | b887f68 | 2021-07-15 10:43:42 -0700 | [diff] [blame] | 316 | if (!frro_iter_.has_value()) { | 
|  | 317 | LOG(WARNING) << "no active ffro iterator to release"; | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 318 | } else if (frro_iter_id_ != iteratorId) { | 
|  | 319 | LOG(WARNING) << "incorrect iterator id in a call to release"; | 
|  | 320 | } else { | 
|  | 321 | frro_iter_.reset(); | 
| Ryan Mitchell | b887f68 | 2021-07-15 10:43:42 -0700 | [diff] [blame] | 322 | } | 
|  | 323 | return ok(); | 
|  | 324 | } | 
|  | 325 |  | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 326 | Status Idmap2Service::nextFabricatedOverlayInfos(int32_t iteratorId, | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 327 | std::vector<os::FabricatedOverlayInfo>* _aidl_return) { | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 328 | std::lock_guard l(frro_iter_mutex_); | 
|  | 329 |  | 
| Ryan Mitchell | b887f68 | 2021-07-15 10:43:42 -0700 | [diff] [blame] | 330 | constexpr size_t kMaxEntryCount = 100; | 
|  | 331 | if (!frro_iter_.has_value()) { | 
|  | 332 | return error("no active frro iterator"); | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 333 | } else if (frro_iter_id_ != iteratorId) { | 
|  | 334 | return error("incorrect iterator id in a call to next"); | 
| Ryan Mitchell | b887f68 | 2021-07-15 10:43:42 -0700 | [diff] [blame] | 335 | } | 
|  | 336 |  | 
|  | 337 | size_t count = 0; | 
|  | 338 | auto& entry_iter = *frro_iter_; | 
|  | 339 | auto entry_iter_end = end(*frro_iter_); | 
|  | 340 | for (; entry_iter != entry_iter_end && count < kMaxEntryCount; ++entry_iter) { | 
|  | 341 | auto& entry = *entry_iter; | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 342 | if (!entry.is_regular_file() || !android::IsFabricatedOverlay(entry.path().native())) { | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 343 | continue; | 
|  | 344 | } | 
|  | 345 |  | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 346 | const auto overlay = FabricatedOverlayContainer::FromPath(entry.path().native()); | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 347 | if (!overlay) { | 
| Ryan Mitchell | b887f68 | 2021-07-15 10:43:42 -0700 | [diff] [blame] | 348 | LOG(WARNING) << "Failed to open '" << entry.path() << "': " << overlay.GetErrorMessage(); | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 349 | continue; | 
|  | 350 | } | 
|  | 351 |  | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 352 | auto info = (*overlay)->GetManifestInfo(); | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 353 | os::FabricatedOverlayInfo out_info; | 
| Yurii Zubrytskyi | 7b4d4ca | 2022-09-29 16:43:04 -0700 | [diff] [blame] | 354 | out_info.packageName = std::move(info.package_name); | 
|  | 355 | out_info.overlayName = std::move(info.name); | 
|  | 356 | out_info.targetPackageName = std::move(info.target_package); | 
|  | 357 | out_info.targetOverlayable = std::move(info.target_name); | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 358 | out_info.path = entry.path(); | 
|  | 359 | _aidl_return->emplace_back(std::move(out_info)); | 
| Ryan Mitchell | b887f68 | 2021-07-15 10:43:42 -0700 | [diff] [blame] | 360 | count++; | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 361 | } | 
| Ryan Mitchell | 6a2ca78 | 2021-01-19 13:51:15 -0800 | [diff] [blame] | 362 | return ok(); | 
|  | 363 | } | 
|  | 364 |  | 
|  | 365 | binder::Status Idmap2Service::deleteFabricatedOverlay(const std::string& overlay_path, | 
|  | 366 | bool* _aidl_return) { | 
|  | 367 | SYSTRACE << "Idmap2Service::deleteFabricatedOverlay " << overlay_path; | 
|  | 368 | const uid_t uid = IPCThreadState::self()->getCallingUid(); | 
|  | 369 |  | 
|  | 370 | if (!UidHasWriteAccessToPath(uid, overlay_path)) { | 
|  | 371 | *_aidl_return = false; | 
|  | 372 | return error(base::StringPrintf("failed to unlink %s: calling uid %d lacks write access", | 
|  | 373 | overlay_path.c_str(), uid)); | 
|  | 374 | } | 
|  | 375 |  | 
|  | 376 | const std::string idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path); | 
|  | 377 | if (!UidHasWriteAccessToPath(uid, idmap_path)) { | 
|  | 378 | *_aidl_return = false; | 
|  | 379 | return error(base::StringPrintf("failed to unlink %s: calling uid %d lacks write access", | 
|  | 380 | idmap_path.c_str(), uid)); | 
|  | 381 | } | 
|  | 382 |  | 
|  | 383 | if (unlink(overlay_path.c_str()) != 0) { | 
|  | 384 | *_aidl_return = false; | 
|  | 385 | return error("failed to unlink " + overlay_path + ": " + strerror(errno)); | 
|  | 386 | } | 
|  | 387 |  | 
|  | 388 | if (unlink(idmap_path.c_str()) != 0) { | 
|  | 389 | *_aidl_return = false; | 
|  | 390 | return error("failed to unlink " + idmap_path + ": " + strerror(errno)); | 
|  | 391 | } | 
|  | 392 |  | 
|  | 393 | *_aidl_return = true; | 
|  | 394 | return ok(); | 
|  | 395 | } | 
|  | 396 |  | 
| Mårten Kongstad | 99ae898 | 2021-05-10 11:00:17 +0000 | [diff] [blame] | 397 | binder::Status Idmap2Service::dumpIdmap(const std::string& overlay_path, | 
|  | 398 | std::string* _aidl_return) { | 
|  | 399 | assert(_aidl_return); | 
|  | 400 |  | 
|  | 401 | const auto idmap_path = Idmap::CanonicalIdmapPathFor(kIdmapCacheDir, overlay_path); | 
|  | 402 | std::ifstream fin(idmap_path); | 
|  | 403 | const auto idmap = Idmap::FromBinaryStream(fin); | 
|  | 404 | fin.close(); | 
|  | 405 | if (!idmap) { | 
|  | 406 | return error(idmap.GetErrorMessage()); | 
|  | 407 | } | 
|  | 408 |  | 
|  | 409 | std::stringstream stream; | 
|  | 410 | PrettyPrintVisitor visitor(stream); | 
|  | 411 | (*idmap)->accept(&visitor); | 
|  | 412 | *_aidl_return = stream.str(); | 
|  | 413 |  | 
|  | 414 | return ok(); | 
|  | 415 | } | 
|  | 416 |  | 
| Mårten Kongstad | 0eba72a | 2018-11-29 08:23:14 +0100 | [diff] [blame] | 417 | }  // namespace android::os |