blob: b50cfb3d19f3cddde599678261d3074ff988fc7e [file] [log] [blame]
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001/*
2 * Copyright (C) 2005 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
Jason Parksdcd39582009-11-03 12:14:38 -080017#define LOG_TAG "IPCThreadState"
18
Mathias Agopianc5b2c0b2009-05-19 19:08:10 -070019#include <binder/IPCThreadState.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080020
Mathias Agopianc5b2c0b2009-05-19 19:08:10 -070021#include <binder/Binder.h>
22#include <binder/BpBinder.h>
Mathias Agopian002e1e52013-05-06 20:20:50 -070023#include <binder/TextOutput.h>
24
Steven Moreland7732a092019-01-02 17:54:16 -080025#include <android-base/macros.h>
Glenn Kastena26e1cf2012-03-16 07:15:23 -070026#include <cutils/sched_policy.h>
Steven Moreland7732a092019-01-02 17:54:16 -080027#include <utils/CallStack.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080028#include <utils/Log.h>
Colin Cross96e83222016-04-15 14:29:55 -070029#include <utils/SystemClock.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080030
Hans Boehma997b232019-04-12 16:59:00 -070031#include <atomic>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080032#include <errno.h>
Colin Cross96e83222016-04-15 14:29:55 -070033#include <inttypes.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080034#include <pthread.h>
35#include <sched.h>
Yabin Cui8fb2d252015-01-26 19:45:47 -080036#include <signal.h>
37#include <stdio.h>
38#include <sys/ioctl.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080039#include <sys/resource.h>
Yabin Cui8fb2d252015-01-26 19:45:47 -080040#include <unistd.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080041
Steven Morelanda4853cd2019-07-12 15:44:37 -070042#include "Static.h"
Steven Moreland6ba5a252021-05-04 22:49:00 +000043#include "binder_module.h"
Steven Morelanda4853cd2019-07-12 15:44:37 -070044
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080045#if LOG_NDEBUG
46
47#define IF_LOG_TRANSACTIONS() if (false)
48#define IF_LOG_COMMANDS() if (false)
49#define LOG_REMOTEREFS(...)
50#define IF_LOG_REMOTEREFS() if (false)
Tim Murrayd429f4a2017-03-07 09:31:09 -080051
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080052#define LOG_THREADPOOL(...)
53#define LOG_ONEWAY(...)
54
55#else
56
Steve Block9f760152011-10-12 17:27:03 +010057#define IF_LOG_TRANSACTIONS() IF_ALOG(LOG_VERBOSE, "transact")
58#define IF_LOG_COMMANDS() IF_ALOG(LOG_VERBOSE, "ipc")
59#define LOG_REMOTEREFS(...) ALOG(LOG_DEBUG, "remoterefs", __VA_ARGS__)
60#define IF_LOG_REMOTEREFS() IF_ALOG(LOG_DEBUG, "remoterefs")
61#define LOG_THREADPOOL(...) ALOG(LOG_DEBUG, "threadpool", __VA_ARGS__)
62#define LOG_ONEWAY(...) ALOG(LOG_DEBUG, "ipc", __VA_ARGS__)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080063
64#endif
65
66// ---------------------------------------------------------------------------
67
68namespace android {
69
Chih-Hung Hsieh8e5337d2014-10-24 14:10:09 -070070// Static const and functions will be optimized out if not used,
71// when LOG_NDEBUG and references in IF_LOG_COMMANDS() are optimized out.
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080072static const char *kReturnStrings[] = {
Andy McFaddenaefc9cd2011-08-31 07:43:40 -070073 "BR_ERROR",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080074 "BR_OK",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080075 "BR_TRANSACTION",
76 "BR_REPLY",
77 "BR_ACQUIRE_RESULT",
78 "BR_DEAD_REPLY",
79 "BR_TRANSACTION_COMPLETE",
80 "BR_INCREFS",
81 "BR_ACQUIRE",
82 "BR_RELEASE",
83 "BR_DECREFS",
84 "BR_ATTEMPT_ACQUIRE",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080085 "BR_NOOP",
86 "BR_SPAWN_LOOPER",
87 "BR_FINISHED",
88 "BR_DEAD_BINDER",
Andy McFaddenaefc9cd2011-08-31 07:43:40 -070089 "BR_CLEAR_DEATH_NOTIFICATION_DONE",
Steven Morelandf0212002018-12-26 13:59:23 -080090 "BR_FAILED_REPLY",
Hang Lub185ac02021-03-24 13:17:22 +080091 "BR_FROZEN_REPLY",
92 "BR_ONEWAY_SPAM_SUSPECT",
Steven Morelandf0212002018-12-26 13:59:23 -080093 "BR_TRANSACTION_SEC_CTX",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080094};
95
96static const char *kCommandStrings[] = {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080097 "BC_TRANSACTION",
98 "BC_REPLY",
99 "BC_ACQUIRE_RESULT",
100 "BC_FREE_BUFFER",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800101 "BC_INCREFS",
102 "BC_ACQUIRE",
103 "BC_RELEASE",
104 "BC_DECREFS",
105 "BC_INCREFS_DONE",
106 "BC_ACQUIRE_DONE",
107 "BC_ATTEMPT_ACQUIRE",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800108 "BC_REGISTER_LOOPER",
109 "BC_ENTER_LOOPER",
110 "BC_EXIT_LOOPER",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800111 "BC_REQUEST_DEATH_NOTIFICATION",
112 "BC_CLEAR_DEATH_NOTIFICATION",
113 "BC_DEAD_BINDER_DONE"
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800114};
115
Olivier Gaillard91a04802018-11-14 17:32:41 +0000116static const int64_t kWorkSourcePropagatedBitIndex = 32;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100117
songjinshi73a7dde2016-10-18 21:05:56 +0800118static const char* getReturnString(uint32_t cmd)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800119{
songjinshi8e486c62019-04-04 11:22:52 +0800120 size_t idx = cmd & _IOC_NRMASK;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800121 if (idx < sizeof(kReturnStrings) / sizeof(kReturnStrings[0]))
122 return kReturnStrings[idx];
123 else
124 return "unknown";
125}
126
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800127static const void* printBinderTransactionData(TextOutput& out, const void* data)
128{
129 const binder_transaction_data* btd =
130 (const binder_transaction_data*)data;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700131 if (btd->target.handle < 1024) {
132 /* want to print descriptors in decimal; guess based on value */
133 out << "target.desc=" << btd->target.handle;
134 } else {
135 out << "target.ptr=" << btd->target.ptr;
136 }
137 out << " (cookie " << btd->cookie << ")" << endl
Jiyong Park16c6e702020-11-13 20:53:12 +0900138 << "code=" << TypeCode(btd->code) << ", flags=" << (void*)(uint64_t)btd->flags << endl
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800139 << "data=" << btd->data.ptr.buffer << " (" << (void*)btd->data_size
140 << " bytes)" << endl
141 << "offsets=" << btd->data.ptr.offsets << " (" << (void*)btd->offsets_size
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700142 << " bytes)";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800143 return btd+1;
144}
145
146static const void* printReturnCommand(TextOutput& out, const void* _cmd)
147{
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700148 static const size_t N = sizeof(kReturnStrings)/sizeof(kReturnStrings[0]);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800149 const int32_t* cmd = (const int32_t*)_cmd;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100150 uint32_t code = (uint32_t)*cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700151 size_t cmdIndex = code & 0xff;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100152 if (code == BR_ERROR) {
Jiyong Park16c6e702020-11-13 20:53:12 +0900153 out << "BR_ERROR: " << (void*)(uint64_t)(*cmd++) << endl;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800154 return cmd;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700155 } else if (cmdIndex >= N) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800156 out << "Unknown reply: " << code << endl;
157 return cmd;
158 }
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700159 out << kReturnStrings[cmdIndex];
Tim Murrayd429f4a2017-03-07 09:31:09 -0800160
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800161 switch (code) {
162 case BR_TRANSACTION:
163 case BR_REPLY: {
164 out << ": " << indent;
165 cmd = (const int32_t *)printBinderTransactionData(out, cmd);
166 out << dedent;
167 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800168
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800169 case BR_ACQUIRE_RESULT: {
170 const int32_t res = *cmd++;
171 out << ": " << res << (res ? " (SUCCESS)" : " (FAILURE)");
172 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800173
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800174 case BR_INCREFS:
175 case BR_ACQUIRE:
176 case BR_RELEASE:
177 case BR_DECREFS: {
178 const int32_t b = *cmd++;
179 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900180 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800181 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800182
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800183 case BR_ATTEMPT_ACQUIRE: {
184 const int32_t p = *cmd++;
185 const int32_t b = *cmd++;
186 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900187 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800188 << "), pri=" << p;
189 } break;
190
191 case BR_DEAD_BINDER:
192 case BR_CLEAR_DEATH_NOTIFICATION_DONE: {
193 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900194 out << ": death cookie " << (void*)(uint64_t)c;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800195 } break;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700196
197 default:
198 // no details to show for: BR_OK, BR_DEAD_REPLY,
199 // BR_TRANSACTION_COMPLETE, BR_FINISHED
200 break;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800201 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800202
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800203 out << endl;
204 return cmd;
205}
206
207static const void* printCommand(TextOutput& out, const void* _cmd)
208{
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700209 static const size_t N = sizeof(kCommandStrings)/sizeof(kCommandStrings[0]);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800210 const int32_t* cmd = (const int32_t*)_cmd;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100211 uint32_t code = (uint32_t)*cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700212 size_t cmdIndex = code & 0xff;
213
214 if (cmdIndex >= N) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800215 out << "Unknown command: " << code << endl;
216 return cmd;
217 }
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700218 out << kCommandStrings[cmdIndex];
219
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800220 switch (code) {
221 case BC_TRANSACTION:
222 case BC_REPLY: {
223 out << ": " << indent;
224 cmd = (const int32_t *)printBinderTransactionData(out, cmd);
225 out << dedent;
226 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800227
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800228 case BC_ACQUIRE_RESULT: {
229 const int32_t res = *cmd++;
230 out << ": " << res << (res ? " (SUCCESS)" : " (FAILURE)");
231 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800232
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800233 case BC_FREE_BUFFER: {
234 const int32_t buf = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900235 out << ": buffer=" << (void*)(uint64_t)buf;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800236 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800237
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800238 case BC_INCREFS:
239 case BC_ACQUIRE:
240 case BC_RELEASE:
241 case BC_DECREFS: {
242 const int32_t d = *cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700243 out << ": desc=" << d;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800244 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800245
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800246 case BC_INCREFS_DONE:
247 case BC_ACQUIRE_DONE: {
248 const int32_t b = *cmd++;
249 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900250 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800251 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800252
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800253 case BC_ATTEMPT_ACQUIRE: {
254 const int32_t p = *cmd++;
255 const int32_t d = *cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700256 out << ": desc=" << d << ", pri=" << p;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800257 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800258
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800259 case BC_REQUEST_DEATH_NOTIFICATION:
260 case BC_CLEAR_DEATH_NOTIFICATION: {
261 const int32_t h = *cmd++;
262 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900263 out << ": handle=" << h << " (death cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800264 } break;
265
266 case BC_DEAD_BINDER_DONE: {
267 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900268 out << ": death cookie " << (void*)(uint64_t)c;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800269 } break;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700270
271 default:
272 // no details to show for: BC_REGISTER_LOOPER, BC_ENTER_LOOPER,
273 // BC_EXIT_LOOPER
274 break;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800275 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800276
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800277 out << endl;
278 return cmd;
279}
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800280
281static pthread_mutex_t gTLSMutex = PTHREAD_MUTEX_INITIALIZER;
Hans Boehma997b232019-04-12 16:59:00 -0700282static std::atomic<bool> gHaveTLS(false);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800283static pthread_key_t gTLS = 0;
Hans Boehma997b232019-04-12 16:59:00 -0700284static std::atomic<bool> gShutdown = false;
285static std::atomic<bool> gDisableBackgroundScheduling = false;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800286
287IPCThreadState* IPCThreadState::self()
288{
Hans Boehma997b232019-04-12 16:59:00 -0700289 if (gHaveTLS.load(std::memory_order_acquire)) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800290restart:
291 const pthread_key_t k = gTLS;
292 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(k);
293 if (st) return st;
294 return new IPCThreadState;
295 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800296
Hans Boehma997b232019-04-12 16:59:00 -0700297 // Racey, heuristic test for simultaneous shutdown.
298 if (gShutdown.load(std::memory_order_relaxed)) {
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800299 ALOGW("Calling IPCThreadState::self() during shutdown is dangerous, expect a crash.\n");
Yi Kongfdd8da92018-06-07 17:52:27 -0700300 return nullptr;
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800301 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800302
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800303 pthread_mutex_lock(&gTLSMutex);
Hans Boehma997b232019-04-12 16:59:00 -0700304 if (!gHaveTLS.load(std::memory_order_relaxed)) {
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800305 int key_create_value = pthread_key_create(&gTLS, threadDestructor);
306 if (key_create_value != 0) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800307 pthread_mutex_unlock(&gTLSMutex);
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800308 ALOGW("IPCThreadState::self() unable to create TLS key, expect a crash: %s\n",
309 strerror(key_create_value));
Yi Kongfdd8da92018-06-07 17:52:27 -0700310 return nullptr;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800311 }
Hans Boehma997b232019-04-12 16:59:00 -0700312 gHaveTLS.store(true, std::memory_order_release);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800313 }
314 pthread_mutex_unlock(&gTLSMutex);
315 goto restart;
316}
317
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800318IPCThreadState* IPCThreadState::selfOrNull()
319{
Hans Boehma997b232019-04-12 16:59:00 -0700320 if (gHaveTLS.load(std::memory_order_acquire)) {
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800321 const pthread_key_t k = gTLS;
322 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(k);
323 return st;
324 }
Yi Kongfdd8da92018-06-07 17:52:27 -0700325 return nullptr;
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800326}
327
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800328void IPCThreadState::shutdown()
329{
Hans Boehma997b232019-04-12 16:59:00 -0700330 gShutdown.store(true, std::memory_order_relaxed);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800331
Hans Boehma997b232019-04-12 16:59:00 -0700332 if (gHaveTLS.load(std::memory_order_acquire)) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800333 // XXX Need to wait for all thread pool threads to exit!
334 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(gTLS);
335 if (st) {
336 delete st;
Yi Kongfdd8da92018-06-07 17:52:27 -0700337 pthread_setspecific(gTLS, nullptr);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800338 }
zhongjieff405782016-03-09 15:05:04 +0800339 pthread_key_delete(gTLS);
Hans Boehma997b232019-04-12 16:59:00 -0700340 gHaveTLS.store(false, std::memory_order_release);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800341 }
342}
343
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -0800344void IPCThreadState::disableBackgroundScheduling(bool disable)
345{
Hans Boehma997b232019-04-12 16:59:00 -0700346 gDisableBackgroundScheduling.store(disable, std::memory_order_relaxed);
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -0800347}
348
Martijn Coenen2b631742017-05-05 11:16:59 -0700349bool IPCThreadState::backgroundSchedulingDisabled()
350{
Hans Boehma997b232019-04-12 16:59:00 -0700351 return gDisableBackgroundScheduling.load(std::memory_order_relaxed);
Martijn Coenen2b631742017-05-05 11:16:59 -0700352}
353
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800354status_t IPCThreadState::clearLastError()
355{
356 const status_t err = mLastError;
357 mLastError = NO_ERROR;
358 return err;
359}
360
Dan Stoza9c634fd2014-11-26 12:23:23 -0800361pid_t IPCThreadState::getCallingPid() const
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800362{
Steven Moreland35626652021-05-15 01:32:04 +0000363 checkContextIsBinderForUse(__func__);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800364 return mCallingPid;
365}
366
Steven Morelandf0212002018-12-26 13:59:23 -0800367const char* IPCThreadState::getCallingSid() const
368{
Steven Moreland35626652021-05-15 01:32:04 +0000369 checkContextIsBinderForUse(__func__);
Steven Morelandf0212002018-12-26 13:59:23 -0800370 return mCallingSid;
371}
372
Dan Stoza9c634fd2014-11-26 12:23:23 -0800373uid_t IPCThreadState::getCallingUid() const
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800374{
Steven Moreland35626652021-05-15 01:32:04 +0000375 checkContextIsBinderForUse(__func__);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800376 return mCallingUid;
377}
378
Steven Moreland35626652021-05-15 01:32:04 +0000379const IPCThreadState::SpGuard* IPCThreadState::pushGetCallingSpGuard(const SpGuard* guard) {
380 const SpGuard* orig = mServingStackPointerGuard;
381 mServingStackPointerGuard = guard;
382 return orig;
383}
384
385void IPCThreadState::restoreGetCallingSpGuard(const SpGuard* guard) {
386 mServingStackPointerGuard = guard;
387}
388
389void IPCThreadState::checkContextIsBinderForUse(const char* use) const {
390 if (LIKELY(mServingStackPointerGuard == nullptr)) return;
391
392 if (!mServingStackPointer || mServingStackPointerGuard->address < mServingStackPointer) {
393 LOG_ALWAYS_FATAL("In context %s, %s does not make sense (binder sp: %p, guard: %p).",
394 mServingStackPointerGuard->context, use, mServingStackPointer,
395 mServingStackPointerGuard->address);
396 }
397
398 // in the case mServingStackPointer is deeper in the stack than the guard,
399 // we must be serving a binder transaction (maybe nested). This is a binder
400 // context, so we don't abort
401}
402
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800403int64_t IPCThreadState::clearCallingIdentity()
404{
Steven Morelandf0212002018-12-26 13:59:23 -0800405 // ignore mCallingSid for legacy reasons
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800406 int64_t token = ((int64_t)mCallingUid<<32) | mCallingPid;
407 clearCaller();
408 return token;
409}
410
Brad Fitzpatrick702ea9d2010-06-18 13:07:53 -0700411void IPCThreadState::setStrictModePolicy(int32_t policy)
412{
413 mStrictModePolicy = policy;
414}
415
Brad Fitzpatricka877cd82010-07-07 16:06:39 -0700416int32_t IPCThreadState::getStrictModePolicy() const
417{
Brad Fitzpatrick702ea9d2010-06-18 13:07:53 -0700418 return mStrictModePolicy;
419}
420
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000421int64_t IPCThreadState::setCallingWorkSourceUid(uid_t uid)
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100422{
Olivier Gaillard91a04802018-11-14 17:32:41 +0000423 int64_t token = setCallingWorkSourceUidWithoutPropagation(uid);
424 mPropagateWorkSource = true;
425 return token;
426}
427
428int64_t IPCThreadState::setCallingWorkSourceUidWithoutPropagation(uid_t uid)
429{
430 const int64_t propagatedBit = ((int64_t)mPropagateWorkSource) << kWorkSourcePropagatedBitIndex;
431 int64_t token = propagatedBit | mWorkSource;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100432 mWorkSource = uid;
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000433 return token;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100434}
435
Olivier Gaillard91a04802018-11-14 17:32:41 +0000436void IPCThreadState::clearPropagateWorkSource()
437{
438 mPropagateWorkSource = false;
439}
440
441bool IPCThreadState::shouldPropagateWorkSource() const
442{
443 return mPropagateWorkSource;
444}
445
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000446uid_t IPCThreadState::getCallingWorkSourceUid() const
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100447{
448 return mWorkSource;
449}
450
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000451int64_t IPCThreadState::clearCallingWorkSource()
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100452{
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000453 return setCallingWorkSourceUid(kUnsetWorkSource);
454}
455
456void IPCThreadState::restoreCallingWorkSource(int64_t token)
457{
458 uid_t uid = (int)token;
Olivier Gaillard91a04802018-11-14 17:32:41 +0000459 setCallingWorkSourceUidWithoutPropagation(uid);
460 mPropagateWorkSource = ((token >> kWorkSourcePropagatedBitIndex) & 1) == 1;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100461}
462
Brad Fitzpatrick52736032010-08-30 16:01:16 -0700463void IPCThreadState::setLastTransactionBinderFlags(int32_t flags)
464{
465 mLastTransactionBinderFlags = flags;
466}
467
468int32_t IPCThreadState::getLastTransactionBinderFlags() const
469{
470 return mLastTransactionBinderFlags;
471}
472
Steven Moreland9514b202020-09-21 18:03:27 +0000473void IPCThreadState::setCallRestriction(ProcessState::CallRestriction restriction) {
474 mCallRestriction = restriction;
475}
476
477ProcessState::CallRestriction IPCThreadState::getCallRestriction() const {
478 return mCallRestriction;
479}
480
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800481void IPCThreadState::restoreCallingIdentity(int64_t token)
482{
483 mCallingUid = (int)(token>>32);
Steven Morelandf0212002018-12-26 13:59:23 -0800484 mCallingSid = nullptr; // not enough data to restore
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800485 mCallingPid = (int)token;
486}
487
488void IPCThreadState::clearCaller()
489{
Marco Nelissend43b1942009-07-17 07:59:17 -0700490 mCallingPid = getpid();
Steven Morelandf0212002018-12-26 13:59:23 -0800491 mCallingSid = nullptr; // expensive to lookup
Marco Nelissend43b1942009-07-17 07:59:17 -0700492 mCallingUid = getuid();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800493}
494
495void IPCThreadState::flushCommands()
496{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -0200497 if (mProcess->mDriverFD < 0)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800498 return;
499 talkWithDriver(false);
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700500 // The flush could have caused post-write refcount decrements to have
501 // been executed, which in turn could result in BC_RELEASE/BC_DECREFS
502 // being queued in mOut. So flush again, if we need to.
503 if (mOut.dataSize() > 0) {
504 talkWithDriver(false);
505 }
506 if (mOut.dataSize() > 0) {
507 ALOGW("mOut.dataSize() > 0 after flushCommands()");
508 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800509}
510
Martijn Coenen0442a862017-11-17 10:46:32 +0100511bool IPCThreadState::flushIfNeeded()
512{
Frankie Changf4c81372021-05-18 13:08:05 +0800513 if (mIsLooper || mServingStackPointer != nullptr || mIsFlushing) {
Martijn Coenen0442a862017-11-17 10:46:32 +0100514 return false;
515 }
Frankie Changf4c81372021-05-18 13:08:05 +0800516 mIsFlushing = true;
Martijn Coenen0442a862017-11-17 10:46:32 +0100517 // In case this thread is not a looper and is not currently serving a binder transaction,
518 // there's no guarantee that this thread will call back into the kernel driver any time
519 // soon. Therefore, flush pending commands such as BC_FREE_BUFFER, to prevent them from getting
520 // stuck in this thread's out buffer.
521 flushCommands();
Frankie Changf4c81372021-05-18 13:08:05 +0800522 mIsFlushing = false;
Martijn Coenen0442a862017-11-17 10:46:32 +0100523 return true;
524}
525
Wale Ogunwale376b8222015-04-13 16:16:10 -0700526void IPCThreadState::blockUntilThreadAvailable()
527{
528 pthread_mutex_lock(&mProcess->mThreadCountLock);
Steven Morelandc648a762021-01-16 02:39:45 +0000529 mProcess->mWaitingForThreads++;
Wale Ogunwale376b8222015-04-13 16:16:10 -0700530 while (mProcess->mExecutingThreadsCount >= mProcess->mMaxThreads) {
Wale Ogunwalea3206e62015-04-21 12:29:50 -0700531 ALOGW("Waiting for thread to be free. mExecutingThreadsCount=%lu mMaxThreads=%lu\n",
532 static_cast<unsigned long>(mProcess->mExecutingThreadsCount),
533 static_cast<unsigned long>(mProcess->mMaxThreads));
Wale Ogunwale376b8222015-04-13 16:16:10 -0700534 pthread_cond_wait(&mProcess->mThreadCountDecrement, &mProcess->mThreadCountLock);
535 }
Steven Morelandc648a762021-01-16 02:39:45 +0000536 mProcess->mWaitingForThreads--;
Wale Ogunwale376b8222015-04-13 16:16:10 -0700537 pthread_mutex_unlock(&mProcess->mThreadCountLock);
538}
539
Todd Poynor8d96cab2013-06-25 19:12:18 -0700540status_t IPCThreadState::getAndExecuteCommand()
541{
542 status_t result;
543 int32_t cmd;
544
545 result = talkWithDriver();
546 if (result >= NO_ERROR) {
547 size_t IN = mIn.dataAvail();
548 if (IN < sizeof(int32_t)) return result;
549 cmd = mIn.readInt32();
550 IF_LOG_COMMANDS() {
551 alog << "Processing top-level Command: "
552 << getReturnString(cmd) << endl;
553 }
554
Wale Ogunwale376b8222015-04-13 16:16:10 -0700555 pthread_mutex_lock(&mProcess->mThreadCountLock);
556 mProcess->mExecutingThreadsCount++;
Colin Cross96e83222016-04-15 14:29:55 -0700557 if (mProcess->mExecutingThreadsCount >= mProcess->mMaxThreads &&
558 mProcess->mStarvationStartTimeMs == 0) {
559 mProcess->mStarvationStartTimeMs = uptimeMillis();
560 }
Wale Ogunwale376b8222015-04-13 16:16:10 -0700561 pthread_mutex_unlock(&mProcess->mThreadCountLock);
562
Todd Poynor8d96cab2013-06-25 19:12:18 -0700563 result = executeCommand(cmd);
564
Wale Ogunwale376b8222015-04-13 16:16:10 -0700565 pthread_mutex_lock(&mProcess->mThreadCountLock);
566 mProcess->mExecutingThreadsCount--;
Colin Cross96e83222016-04-15 14:29:55 -0700567 if (mProcess->mExecutingThreadsCount < mProcess->mMaxThreads &&
568 mProcess->mStarvationStartTimeMs != 0) {
569 int64_t starvationTimeMs = uptimeMillis() - mProcess->mStarvationStartTimeMs;
570 if (starvationTimeMs > 100) {
571 ALOGE("binder thread pool (%zu threads) starved for %" PRId64 " ms",
572 mProcess->mMaxThreads, starvationTimeMs);
573 }
574 mProcess->mStarvationStartTimeMs = 0;
575 }
Steven Morelandc648a762021-01-16 02:39:45 +0000576
577 // Cond broadcast can be expensive, so don't send it every time a binder
578 // call is processed. b/168806193
579 if (mProcess->mWaitingForThreads > 0) {
580 pthread_cond_broadcast(&mProcess->mThreadCountDecrement);
581 }
Wale Ogunwale376b8222015-04-13 16:16:10 -0700582 pthread_mutex_unlock(&mProcess->mThreadCountLock);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700583 }
584
585 return result;
586}
587
588// When we've cleared the incoming command queue, process any pending derefs
589void IPCThreadState::processPendingDerefs()
590{
591 if (mIn.dataPosition() >= mIn.dataSize()) {
Martijn Coenen0791fbf2017-08-08 15:36:16 +0200592 /*
593 * The decWeak()/decStrong() calls may cause a destructor to run,
594 * which in turn could have initiated an outgoing transaction,
595 * which in turn could cause us to add to the pending refs
596 * vectors; so instead of simply iterating, loop until they're empty.
597 *
598 * We do this in an outer loop, because calling decStrong()
599 * may result in something being added to mPendingWeakDerefs,
600 * which could be delayed until the next incoming command
601 * from the driver if we don't process it now.
602 */
603 while (mPendingWeakDerefs.size() > 0 || mPendingStrongDerefs.size() > 0) {
604 while (mPendingWeakDerefs.size() > 0) {
605 RefBase::weakref_type* refs = mPendingWeakDerefs[0];
606 mPendingWeakDerefs.removeAt(0);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700607 refs->decWeak(mProcess.get());
608 }
Todd Poynor8d96cab2013-06-25 19:12:18 -0700609
Martijn Coenen0791fbf2017-08-08 15:36:16 +0200610 if (mPendingStrongDerefs.size() > 0) {
611 // We don't use while() here because we don't want to re-order
612 // strong and weak decs at all; if this decStrong() causes both a
613 // decWeak() and a decStrong() to be queued, we want to process
614 // the decWeak() first.
615 BBinder* obj = mPendingStrongDerefs[0];
616 mPendingStrongDerefs.removeAt(0);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700617 obj->decStrong(mProcess.get());
618 }
Todd Poynor8d96cab2013-06-25 19:12:18 -0700619 }
620 }
621}
622
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700623void IPCThreadState::processPostWriteDerefs()
624{
625 for (size_t i = 0; i < mPostWriteWeakDerefs.size(); i++) {
626 RefBase::weakref_type* refs = mPostWriteWeakDerefs[i];
627 refs->decWeak(mProcess.get());
628 }
629 mPostWriteWeakDerefs.clear();
630
631 for (size_t i = 0; i < mPostWriteStrongDerefs.size(); i++) {
632 RefBase* obj = mPostWriteStrongDerefs[i];
633 obj->decStrong(mProcess.get());
634 }
635 mPostWriteStrongDerefs.clear();
636}
637
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800638void IPCThreadState::joinThreadPool(bool isMain)
639{
640 LOG_THREADPOOL("**** THREAD %p (PID %d) IS JOINING THE THREAD POOL\n", (void*)pthread_self(), getpid());
Elie Kheirallah47431c12022-04-21 23:46:17 +0000641 pthread_mutex_lock(&mProcess->mThreadCountLock);
642 mProcess->mCurrentThreads++;
643 pthread_mutex_unlock(&mProcess->mThreadCountLock);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800644 mOut.writeInt32(isMain ? BC_ENTER_LOOPER : BC_REGISTER_LOOPER);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800645
Martijn Coenen0442a862017-11-17 10:46:32 +0100646 mIsLooper = true;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800647 status_t result;
648 do {
Todd Poynor8d96cab2013-06-25 19:12:18 -0700649 processPendingDerefs();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800650 // now get the next command to be processed, waiting if necessary
Todd Poynor8d96cab2013-06-25 19:12:18 -0700651 result = getAndExecuteCommand();
Jason Parksdcd39582009-11-03 12:14:38 -0800652
Todd Poynor8d96cab2013-06-25 19:12:18 -0700653 if (result < NO_ERROR && result != TIMED_OUT && result != -ECONNREFUSED && result != -EBADF) {
Steven Moreland6adf33c2019-09-25 13:18:09 -0700654 LOG_ALWAYS_FATAL("getAndExecuteCommand(fd=%d) returned unexpected error %d, aborting",
Jeff Tinkeref073862013-06-11 11:30:21 -0700655 mProcess->mDriverFD, result);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800656 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800657
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800658 // Let this thread exit the thread pool if it is no longer
659 // needed and it is not the main process thread.
660 if(result == TIMED_OUT && !isMain) {
661 break;
662 }
663 } while (result != -ECONNREFUSED && result != -EBADF);
664
Wei Wangc7341432016-10-19 10:23:59 -0700665 LOG_THREADPOOL("**** THREAD %p (PID %d) IS LEAVING THE THREAD POOL err=%d\n",
666 (void*)pthread_self(), getpid(), result);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800667
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800668 mOut.writeInt32(BC_EXIT_LOOPER);
Martijn Coenen0442a862017-11-17 10:46:32 +0100669 mIsLooper = false;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800670 talkWithDriver(false);
Elie Kheirallah47431c12022-04-21 23:46:17 +0000671 pthread_mutex_lock(&mProcess->mThreadCountLock);
672 LOG_ALWAYS_FATAL_IF(mProcess->mCurrentThreads == 0,
673 "Threadpool thread count = 0. Thread cannot exist and exit in empty "
674 "threadpool\n"
675 "Misconfiguration. Increase threadpool max threads configuration\n");
676 mProcess->mCurrentThreads--;
677 pthread_mutex_unlock(&mProcess->mThreadCountLock);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800678}
679
Steven Morelandd8c85672020-07-24 21:30:41 +0000680status_t IPCThreadState::setupPolling(int* fd)
Todd Poynor8d96cab2013-06-25 19:12:18 -0700681{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -0200682 if (mProcess->mDriverFD < 0) {
Todd Poynor8d96cab2013-06-25 19:12:18 -0700683 return -EBADF;
684 }
685
686 mOut.writeInt32(BC_ENTER_LOOPER);
Steven Morelandf210b502021-01-15 23:40:32 +0000687 flushCommands();
Todd Poynor8d96cab2013-06-25 19:12:18 -0700688 *fd = mProcess->mDriverFD;
Elie Kheirallah47431c12022-04-21 23:46:17 +0000689 pthread_mutex_lock(&mProcess->mThreadCountLock);
690 mProcess->mCurrentThreads++;
691 pthread_mutex_unlock(&mProcess->mThreadCountLock);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700692 return 0;
693}
694
695status_t IPCThreadState::handlePolledCommands()
696{
697 status_t result;
698
699 do {
700 result = getAndExecuteCommand();
701 } while (mIn.dataPosition() < mIn.dataSize());
702
703 processPendingDerefs();
704 flushCommands();
705 return result;
706}
707
Colin Cross6f4f3ab2014-02-05 17:42:44 -0800708void IPCThreadState::stopProcess(bool /*immediate*/)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800709{
Steve Blocka19954a2012-01-04 20:05:49 +0000710 //ALOGI("**** STOPPING PROCESS");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800711 flushCommands();
712 int fd = mProcess->mDriverFD;
713 mProcess->mDriverFD = -1;
714 close(fd);
715 //kill(getpid(), SIGKILL);
716}
717
718status_t IPCThreadState::transact(int32_t handle,
719 uint32_t code, const Parcel& data,
720 Parcel* reply, uint32_t flags)
721{
Steven Moreland5553ac42020-11-11 02:14:45 +0000722 LOG_ALWAYS_FATAL_IF(data.isForRpc(), "Parcel constructed for RPC, but being used with binder.");
723
Ganesh Mahendran58e5daa2017-10-11 18:05:13 +0800724 status_t err;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800725
726 flags |= TF_ACCEPT_FDS;
727
728 IF_LOG_TRANSACTIONS() {
729 TextOutput::Bundle _b(alog);
730 alog << "BC_TRANSACTION thr " << (void*)pthread_self() << " / hand "
731 << handle << " / code " << TypeCode(code) << ": "
732 << indent << data << dedent << endl;
733 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800734
Ganesh Mahendran58e5daa2017-10-11 18:05:13 +0800735 LOG_ONEWAY(">>>> SEND from pid %d uid %d %s", getpid(), getuid(),
736 (flags & TF_ONE_WAY) == 0 ? "READ REPLY" : "ONE WAY");
Yi Kongfdd8da92018-06-07 17:52:27 -0700737 err = writeTransactionData(BC_TRANSACTION, flags, handle, code, data, nullptr);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800738
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800739 if (err != NO_ERROR) {
740 if (reply) reply->setError(err);
741 return (mLastError = err);
742 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800743
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800744 if ((flags & TF_ONE_WAY) == 0) {
Steven Moreland7732a092019-01-02 17:54:16 -0800745 if (UNLIKELY(mCallRestriction != ProcessState::CallRestriction::NONE)) {
746 if (mCallRestriction == ProcessState::CallRestriction::ERROR_IF_NOT_ONEWAY) {
Steven Moreland8cb34fc2019-05-13 11:44:55 -0700747 ALOGE("Process making non-oneway call (code: %u) but is restricted.", code);
Steven Moreland7732a092019-01-02 17:54:16 -0800748 CallStack::logStack("non-oneway call", CallStack::getCurrent(10).get(),
749 ANDROID_LOG_ERROR);
750 } else /* FATAL_IF_NOT_ONEWAY */ {
Steven Morelandfcc77f12020-09-01 01:16:11 +0000751 LOG_ALWAYS_FATAL("Process may not make non-oneway calls (code: %u).", code);
Steven Moreland7732a092019-01-02 17:54:16 -0800752 }
753 }
754
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700755 #if 0
756 if (code == 4) { // relayout
Steve Blocka19954a2012-01-04 20:05:49 +0000757 ALOGI(">>>>>> CALLING transaction 4");
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700758 } else {
Steve Blocka19954a2012-01-04 20:05:49 +0000759 ALOGI(">>>>>> CALLING transaction %d", code);
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700760 }
761 #endif
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800762 if (reply) {
763 err = waitForResponse(reply);
764 } else {
765 Parcel fakeReply;
766 err = waitForResponse(&fakeReply);
767 }
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700768 #if 0
769 if (code == 4) { // relayout
Steve Blocka19954a2012-01-04 20:05:49 +0000770 ALOGI("<<<<<< RETURNING transaction 4");
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700771 } else {
Steve Blocka19954a2012-01-04 20:05:49 +0000772 ALOGI("<<<<<< RETURNING transaction %d", code);
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700773 }
774 #endif
Tim Murrayd429f4a2017-03-07 09:31:09 -0800775
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800776 IF_LOG_TRANSACTIONS() {
777 TextOutput::Bundle _b(alog);
778 alog << "BR_REPLY thr " << (void*)pthread_self() << " / hand "
779 << handle << ": ";
780 if (reply) alog << indent << *reply << dedent << endl;
781 else alog << "(none requested)" << endl;
782 }
783 } else {
Yi Kongfdd8da92018-06-07 17:52:27 -0700784 err = waitForResponse(nullptr, nullptr);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800785 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800786
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800787 return err;
788}
789
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700790void IPCThreadState::incStrongHandle(int32_t handle, BpBinder *proxy)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800791{
792 LOG_REMOTEREFS("IPCThreadState::incStrongHandle(%d)\n", handle);
793 mOut.writeInt32(BC_ACQUIRE);
794 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100795 if (!flushIfNeeded()) {
796 // Create a temp reference until the driver has handled this command.
797 proxy->incStrong(mProcess.get());
798 mPostWriteStrongDerefs.push(proxy);
799 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800800}
801
802void IPCThreadState::decStrongHandle(int32_t handle)
803{
804 LOG_REMOTEREFS("IPCThreadState::decStrongHandle(%d)\n", handle);
805 mOut.writeInt32(BC_RELEASE);
806 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100807 flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800808}
809
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700810void IPCThreadState::incWeakHandle(int32_t handle, BpBinder *proxy)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800811{
812 LOG_REMOTEREFS("IPCThreadState::incWeakHandle(%d)\n", handle);
813 mOut.writeInt32(BC_INCREFS);
814 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100815 if (!flushIfNeeded()) {
816 // Create a temp reference until the driver has handled this command.
817 proxy->getWeakRefs()->incWeak(mProcess.get());
818 mPostWriteWeakDerefs.push(proxy->getWeakRefs());
819 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800820}
821
822void IPCThreadState::decWeakHandle(int32_t handle)
823{
824 LOG_REMOTEREFS("IPCThreadState::decWeakHandle(%d)\n", handle);
825 mOut.writeInt32(BC_DECREFS);
826 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100827 flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800828}
829
830status_t IPCThreadState::attemptIncStrongHandle(int32_t handle)
831{
Arve HjønnevÄg11cfdcc2014-02-14 20:14:02 -0800832#if HAS_BC_ATTEMPT_ACQUIRE
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700833 LOG_REMOTEREFS("IPCThreadState::attemptIncStrongHandle(%d)\n", handle);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800834 mOut.writeInt32(BC_ATTEMPT_ACQUIRE);
835 mOut.writeInt32(0); // xxx was thread priority
836 mOut.writeInt32(handle);
837 status_t result = UNKNOWN_ERROR;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800838
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800839 waitForResponse(NULL, &result);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800840
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800841#if LOG_REFCOUNTS
liangweikanga43ee152016-10-25 16:37:54 +0800842 ALOGV("IPCThreadState::attemptIncStrongHandle(%ld) = %s\n",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800843 handle, result == NO_ERROR ? "SUCCESS" : "FAILURE");
844#endif
Tim Murrayd429f4a2017-03-07 09:31:09 -0800845
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800846 return result;
Arve HjønnevÄg11cfdcc2014-02-14 20:14:02 -0800847#else
848 (void)handle;
849 ALOGE("%s(%d): Not supported\n", __func__, handle);
850 return INVALID_OPERATION;
851#endif
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800852}
853
854void IPCThreadState::expungeHandle(int32_t handle, IBinder* binder)
855{
856#if LOG_REFCOUNTS
liangweikanga43ee152016-10-25 16:37:54 +0800857 ALOGV("IPCThreadState::expungeHandle(%ld)\n", handle);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800858#endif
Manoj Gupta9cec85b2017-09-19 16:34:29 -0700859 self()->mProcess->expungeHandle(handle, binder); // NOLINT
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800860}
861
862status_t IPCThreadState::requestDeathNotification(int32_t handle, BpBinder* proxy)
863{
864 mOut.writeInt32(BC_REQUEST_DEATH_NOTIFICATION);
865 mOut.writeInt32((int32_t)handle);
Serban Constantinescuf683e012013-11-05 16:53:55 +0000866 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800867 return NO_ERROR;
868}
869
870status_t IPCThreadState::clearDeathNotification(int32_t handle, BpBinder* proxy)
871{
872 mOut.writeInt32(BC_CLEAR_DEATH_NOTIFICATION);
873 mOut.writeInt32((int32_t)handle);
Serban Constantinescuf683e012013-11-05 16:53:55 +0000874 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800875 return NO_ERROR;
876}
877
878IPCThreadState::IPCThreadState()
Steven Moreland35626652021-05-15 01:32:04 +0000879 : mProcess(ProcessState::self()),
880 mServingStackPointer(nullptr),
881 mServingStackPointerGuard(nullptr),
882 mWorkSource(kUnsetWorkSource),
883 mPropagateWorkSource(false),
884 mIsLooper(false),
Frankie Changf4c81372021-05-18 13:08:05 +0800885 mIsFlushing(false),
Steven Moreland35626652021-05-15 01:32:04 +0000886 mStrictModePolicy(0),
887 mLastTransactionBinderFlags(0),
888 mCallRestriction(mProcess->mCallRestriction) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800889 pthread_setspecific(gTLS, this);
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -0800890 clearCaller();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800891 mIn.setDataCapacity(256);
892 mOut.setDataCapacity(256);
893}
894
895IPCThreadState::~IPCThreadState()
896{
897}
898
Martijn Coenenea0090a2017-11-02 18:54:40 +0000899status_t IPCThreadState::sendReply(const Parcel& reply, uint32_t flags)
900{
901 status_t err;
902 status_t statusBuffer;
903 err = writeTransactionData(BC_REPLY, flags, -1, 0, reply, &statusBuffer);
904 if (err < NO_ERROR) return err;
905
Yi Kongfdd8da92018-06-07 17:52:27 -0700906 return waitForResponse(nullptr, nullptr);
Martijn Coenenea0090a2017-11-02 18:54:40 +0000907}
908
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800909status_t IPCThreadState::waitForResponse(Parcel *reply, status_t *acquireResult)
910{
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100911 uint32_t cmd;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800912 int32_t err;
913
914 while (1) {
915 if ((err=talkWithDriver()) < NO_ERROR) break;
916 err = mIn.errorCheck();
917 if (err < NO_ERROR) break;
918 if (mIn.dataAvail() == 0) continue;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800919
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100920 cmd = (uint32_t)mIn.readInt32();
Tim Murrayd429f4a2017-03-07 09:31:09 -0800921
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800922 IF_LOG_COMMANDS() {
923 alog << "Processing waitForResponse Command: "
924 << getReturnString(cmd) << endl;
925 }
926
927 switch (cmd) {
Hang Lub185ac02021-03-24 13:17:22 +0800928 case BR_ONEWAY_SPAM_SUSPECT:
929 ALOGE("Process seems to be sending too many oneway calls.");
930 CallStack::logStack("oneway spamming", CallStack::getCurrent().get(),
931 ANDROID_LOG_ERROR);
932 [[fallthrough]];
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800933 case BR_TRANSACTION_COMPLETE:
934 if (!reply && !acquireResult) goto finish;
935 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800936
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800937 case BR_DEAD_REPLY:
938 err = DEAD_OBJECT;
939 goto finish;
940
941 case BR_FAILED_REPLY:
942 err = FAILED_TRANSACTION;
943 goto finish;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800944
Marco Ballesio7ee17572020-09-08 10:30:03 -0700945 case BR_FROZEN_REPLY:
946 err = FAILED_TRANSACTION;
947 goto finish;
948
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800949 case BR_ACQUIRE_RESULT:
950 {
Steve Block67263472012-01-09 18:35:44 +0000951 ALOG_ASSERT(acquireResult != NULL, "Unexpected brACQUIRE_RESULT");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800952 const int32_t result = mIn.readInt32();
953 if (!acquireResult) continue;
954 *acquireResult = result ? NO_ERROR : INVALID_OPERATION;
955 }
956 goto finish;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800957
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800958 case BR_REPLY:
959 {
960 binder_transaction_data tr;
961 err = mIn.read(&tr, sizeof(tr));
Steve Block67263472012-01-09 18:35:44 +0000962 ALOG_ASSERT(err == NO_ERROR, "Not enough command data for brREPLY");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800963 if (err != NO_ERROR) goto finish;
964
965 if (reply) {
966 if ((tr.flags & TF_STATUS_CODE) == 0) {
967 reply->ipcSetDataReference(
968 reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
969 tr.data_size,
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -0800970 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
971 tr.offsets_size/sizeof(binder_size_t),
Steven Moreland161fe122020-11-12 23:16:47 +0000972 freeBuffer);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800973 } else {
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -0800974 err = *reinterpret_cast<const status_t*>(tr.data.ptr.buffer);
Frederick Mayle53b6ffe2022-07-15 20:14:01 +0000975 freeBuffer(reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
976 tr.data_size,
977 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
978 tr.offsets_size / sizeof(binder_size_t));
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800979 }
980 } else {
Frederick Mayle53b6ffe2022-07-15 20:14:01 +0000981 freeBuffer(reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer), tr.data_size,
982 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
983 tr.offsets_size / sizeof(binder_size_t));
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800984 continue;
985 }
986 }
987 goto finish;
988
989 default:
990 err = executeCommand(cmd);
991 if (err != NO_ERROR) goto finish;
992 break;
993 }
994 }
995
996finish:
997 if (err != NO_ERROR) {
998 if (acquireResult) *acquireResult = err;
999 if (reply) reply->setError(err);
1000 mLastError = err;
Carlos Llamasb235b122021-12-20 06:38:44 -08001001 logExtendedError();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001002 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001003
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001004 return err;
1005}
1006
1007status_t IPCThreadState::talkWithDriver(bool doReceive)
1008{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -02001009 if (mProcess->mDriverFD < 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +01001010 return -EBADF;
1011 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001012
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001013 binder_write_read bwr;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001014
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001015 // Is the read buffer empty?
1016 const bool needRead = mIn.dataPosition() >= mIn.dataSize();
Tim Murrayd429f4a2017-03-07 09:31:09 -08001017
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001018 // We don't want to write anything if we are still reading
1019 // from data left in the input buffer and the caller
1020 // has requested to read the next data.
1021 const size_t outAvail = (!doReceive || needRead) ? mOut.dataSize() : 0;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001022
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001023 bwr.write_size = outAvail;
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001024 bwr.write_buffer = (uintptr_t)mOut.data();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001025
1026 // This is what we'll read.
1027 if (doReceive && needRead) {
1028 bwr.read_size = mIn.dataCapacity();
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001029 bwr.read_buffer = (uintptr_t)mIn.data();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001030 } else {
1031 bwr.read_size = 0;
Ben Chengd640f892011-12-01 17:11:32 -08001032 bwr.read_buffer = 0;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001033 }
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001034
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001035 IF_LOG_COMMANDS() {
1036 TextOutput::Bundle _b(alog);
1037 if (outAvail != 0) {
1038 alog << "Sending commands to driver: " << indent;
1039 const void* cmds = (const void*)bwr.write_buffer;
1040 const void* end = ((const uint8_t*)cmds)+bwr.write_size;
1041 alog << HexDump(cmds, bwr.write_size) << endl;
1042 while (cmds < end) cmds = printCommand(alog, cmds);
1043 alog << dedent;
1044 }
1045 alog << "Size of receive buffer: " << bwr.read_size
1046 << ", needRead: " << needRead << ", doReceive: " << doReceive << endl;
1047 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001048
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001049 // Return immediately if there is nothing to do.
1050 if ((bwr.write_size == 0) && (bwr.read_size == 0)) return NO_ERROR;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001051
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001052 bwr.write_consumed = 0;
1053 bwr.read_consumed = 0;
1054 status_t err;
1055 do {
1056 IF_LOG_COMMANDS() {
1057 alog << "About to read/write, write size = " << mOut.dataSize() << endl;
1058 }
Elliott Hughes6071da72015-08-12 15:27:47 -07001059#if defined(__ANDROID__)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001060 if (ioctl(mProcess->mDriverFD, BINDER_WRITE_READ, &bwr) >= 0)
1061 err = NO_ERROR;
1062 else
1063 err = -errno;
1064#else
1065 err = INVALID_OPERATION;
1066#endif
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -02001067 if (mProcess->mDriverFD < 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +01001068 err = -EBADF;
1069 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001070 IF_LOG_COMMANDS() {
1071 alog << "Finished read/write, write size = " << mOut.dataSize() << endl;
1072 }
1073 } while (err == -EINTR);
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001074
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001075 IF_LOG_COMMANDS() {
Colin Cross6f4f3ab2014-02-05 17:42:44 -08001076 alog << "Our err: " << (void*)(intptr_t)err << ", write consumed: "
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001077 << bwr.write_consumed << " (of " << mOut.dataSize()
Todd Poynor8d96cab2013-06-25 19:12:18 -07001078 << "), read consumed: " << bwr.read_consumed << endl;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001079 }
1080
1081 if (err >= NO_ERROR) {
1082 if (bwr.write_consumed > 0) {
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001083 if (bwr.write_consumed < mOut.dataSize())
Steven Morelandb077deb2020-04-16 16:22:52 -07001084 LOG_ALWAYS_FATAL("Driver did not consume write buffer. "
1085 "err: %s consumed: %zu of %zu",
1086 statusToString(err).c_str(),
1087 (size_t)bwr.write_consumed,
1088 mOut.dataSize());
Martijn Coenen7c170bb2018-05-04 17:28:55 -07001089 else {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001090 mOut.setDataSize(0);
Martijn Coenen7c170bb2018-05-04 17:28:55 -07001091 processPostWriteDerefs();
1092 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001093 }
1094 if (bwr.read_consumed > 0) {
1095 mIn.setDataSize(bwr.read_consumed);
1096 mIn.setDataPosition(0);
1097 }
1098 IF_LOG_COMMANDS() {
1099 TextOutput::Bundle _b(alog);
1100 alog << "Remaining data size: " << mOut.dataSize() << endl;
1101 alog << "Received commands from driver: " << indent;
1102 const void* cmds = mIn.data();
1103 const void* end = mIn.data() + mIn.dataSize();
1104 alog << HexDump(cmds, mIn.dataSize()) << endl;
1105 while (cmds < end) cmds = printReturnCommand(alog, cmds);
1106 alog << dedent;
1107 }
1108 return NO_ERROR;
1109 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001110
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001111 return err;
1112}
1113
1114status_t IPCThreadState::writeTransactionData(int32_t cmd, uint32_t binderFlags,
1115 int32_t handle, uint32_t code, const Parcel& data, status_t* statusBuffer)
1116{
1117 binder_transaction_data tr;
1118
Arve HjønnevÄg07fd0f12014-02-18 21:10:29 -08001119 tr.target.ptr = 0; /* Don't pass uninitialized stack data to a remote process */
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001120 tr.target.handle = handle;
1121 tr.code = code;
1122 tr.flags = binderFlags;
Evgeniy Stepanovd5474322011-04-21 14:15:00 +04001123 tr.cookie = 0;
1124 tr.sender_pid = 0;
1125 tr.sender_euid = 0;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001126
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001127 const status_t err = data.errorCheck();
1128 if (err == NO_ERROR) {
1129 tr.data_size = data.ipcDataSize();
1130 tr.data.ptr.buffer = data.ipcData();
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001131 tr.offsets_size = data.ipcObjectsCount()*sizeof(binder_size_t);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001132 tr.data.ptr.offsets = data.ipcObjects();
1133 } else if (statusBuffer) {
1134 tr.flags |= TF_STATUS_CODE;
1135 *statusBuffer = err;
1136 tr.data_size = sizeof(status_t);
Arve HjønnevÄg87b30d02014-02-18 21:04:31 -08001137 tr.data.ptr.buffer = reinterpret_cast<uintptr_t>(statusBuffer);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001138 tr.offsets_size = 0;
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001139 tr.data.ptr.offsets = 0;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001140 } else {
1141 return (mLastError = err);
1142 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001143
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001144 mOut.writeInt32(cmd);
1145 mOut.write(&tr, sizeof(tr));
Tim Murrayd429f4a2017-03-07 09:31:09 -08001146
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001147 return NO_ERROR;
1148}
1149
1150sp<BBinder> the_context_object;
1151
Jiyong Park384328e2020-11-13 17:16:48 +09001152void IPCThreadState::setTheContextObject(const sp<BBinder>& obj)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001153{
1154 the_context_object = obj;
1155}
1156
1157status_t IPCThreadState::executeCommand(int32_t cmd)
1158{
1159 BBinder* obj;
1160 RefBase::weakref_type* refs;
1161 status_t result = NO_ERROR;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001162
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +01001163 switch ((uint32_t)cmd) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001164 case BR_ERROR:
1165 result = mIn.readInt32();
1166 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001167
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001168 case BR_OK:
1169 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001170
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001171 case BR_ACQUIRE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001172 refs = (RefBase::weakref_type*)mIn.readPointer();
1173 obj = (BBinder*)mIn.readPointer();
Steve Block67263472012-01-09 18:35:44 +00001174 ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001175 "BR_ACQUIRE: object %p does not match cookie %p (expected %p)",
1176 refs, obj, refs->refBase());
1177 obj->incStrong(mProcess.get());
1178 IF_LOG_REMOTEREFS() {
1179 LOG_REMOTEREFS("BR_ACQUIRE from driver on %p", obj);
1180 obj->printRefs();
1181 }
1182 mOut.writeInt32(BC_ACQUIRE_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001183 mOut.writePointer((uintptr_t)refs);
1184 mOut.writePointer((uintptr_t)obj);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001185 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001186
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001187 case BR_RELEASE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001188 refs = (RefBase::weakref_type*)mIn.readPointer();
1189 obj = (BBinder*)mIn.readPointer();
Steve Block67263472012-01-09 18:35:44 +00001190 ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001191 "BR_RELEASE: object %p does not match cookie %p (expected %p)",
1192 refs, obj, refs->refBase());
1193 IF_LOG_REMOTEREFS() {
1194 LOG_REMOTEREFS("BR_RELEASE from driver on %p", obj);
1195 obj->printRefs();
1196 }
1197 mPendingStrongDerefs.push(obj);
1198 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001199
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001200 case BR_INCREFS:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001201 refs = (RefBase::weakref_type*)mIn.readPointer();
1202 obj = (BBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001203 refs->incWeak(mProcess.get());
1204 mOut.writeInt32(BC_INCREFS_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001205 mOut.writePointer((uintptr_t)refs);
1206 mOut.writePointer((uintptr_t)obj);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001207 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001208
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001209 case BR_DECREFS:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001210 refs = (RefBase::weakref_type*)mIn.readPointer();
Jiyong Park5970d0a2022-03-08 16:56:13 +09001211 // NOLINTNEXTLINE(clang-analyzer-deadcode.DeadStores)
1212 obj = (BBinder*)mIn.readPointer(); // consume
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001213 // NOTE: This assertion is not valid, because the object may no
1214 // longer exist (thus the (BBinder*)cast above resulting in a different
1215 // memory address).
Steve Block67263472012-01-09 18:35:44 +00001216 //ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001217 // "BR_DECREFS: object %p does not match cookie %p (expected %p)",
1218 // refs, obj, refs->refBase());
1219 mPendingWeakDerefs.push(refs);
1220 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001221
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001222 case BR_ATTEMPT_ACQUIRE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001223 refs = (RefBase::weakref_type*)mIn.readPointer();
1224 obj = (BBinder*)mIn.readPointer();
Tim Murrayd429f4a2017-03-07 09:31:09 -08001225
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001226 {
1227 const bool success = refs->attemptIncStrong(mProcess.get());
Steve Block67263472012-01-09 18:35:44 +00001228 ALOG_ASSERT(success && refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001229 "BR_ATTEMPT_ACQUIRE: object %p does not match cookie %p (expected %p)",
1230 refs, obj, refs->refBase());
Tim Murrayd429f4a2017-03-07 09:31:09 -08001231
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001232 mOut.writeInt32(BC_ACQUIRE_RESULT);
1233 mOut.writeInt32((int32_t)success);
1234 }
1235 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001236
Steven Morelandf0212002018-12-26 13:59:23 -08001237 case BR_TRANSACTION_SEC_CTX:
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001238 case BR_TRANSACTION:
1239 {
Steven Morelandf0212002018-12-26 13:59:23 -08001240 binder_transaction_data_secctx tr_secctx;
1241 binder_transaction_data& tr = tr_secctx.transaction_data;
1242
1243 if (cmd == (int) BR_TRANSACTION_SEC_CTX) {
1244 result = mIn.read(&tr_secctx, sizeof(tr_secctx));
1245 } else {
1246 result = mIn.read(&tr, sizeof(tr));
1247 tr_secctx.secctx = 0;
1248 }
1249
Steve Block67263472012-01-09 18:35:44 +00001250 ALOG_ASSERT(result == NO_ERROR,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001251 "Not enough command data for brTRANSACTION");
1252 if (result != NO_ERROR) break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001253
Martijn Coenenea0090a2017-11-02 18:54:40 +00001254 Parcel buffer;
1255 buffer.ipcSetDataReference(
1256 reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
1257 tr.data_size,
1258 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
Steven Moreland161fe122020-11-12 23:16:47 +00001259 tr.offsets_size/sizeof(binder_size_t), freeBuffer);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001260
Steven Moreland39d887d2020-01-31 14:56:45 -08001261 const void* origServingStackPointer = mServingStackPointer;
Steven Moreland35626652021-05-15 01:32:04 +00001262 mServingStackPointer = __builtin_frame_address(0);
Steven Moreland39d887d2020-01-31 14:56:45 -08001263
Martijn Coenenea0090a2017-11-02 18:54:40 +00001264 const pid_t origPid = mCallingPid;
Steven Morelandf0212002018-12-26 13:59:23 -08001265 const char* origSid = mCallingSid;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001266 const uid_t origUid = mCallingUid;
1267 const int32_t origStrictModePolicy = mStrictModePolicy;
1268 const int32_t origTransactionBinderFlags = mLastTransactionBinderFlags;
Olivier Gaillard91a04802018-11-14 17:32:41 +00001269 const int32_t origWorkSource = mWorkSource;
1270 const bool origPropagateWorkSet = mPropagateWorkSource;
1271 // Calling work source will be set by Parcel#enforceInterface. Parcel#enforceInterface
1272 // is only guaranteed to be called for AIDL-generated stubs so we reset the work source
1273 // here to never propagate it.
1274 clearCallingWorkSource();
1275 clearPropagateWorkSource();
Martijn Coenenea0090a2017-11-02 18:54:40 +00001276
1277 mCallingPid = tr.sender_pid;
Steven Morelandf0212002018-12-26 13:59:23 -08001278 mCallingSid = reinterpret_cast<const char*>(tr_secctx.secctx);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001279 mCallingUid = tr.sender_euid;
1280 mLastTransactionBinderFlags = tr.flags;
1281
Steven Morelandf0212002018-12-26 13:59:23 -08001282 // ALOGI(">>>> TRANSACT from pid %d sid %s uid %d\n", mCallingPid,
1283 // (mCallingSid ? mCallingSid : "<N/A>"), mCallingUid);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001284
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001285 Parcel reply;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001286 status_t error;
1287 IF_LOG_TRANSACTIONS() {
1288 TextOutput::Bundle _b(alog);
1289 alog << "BR_TRANSACTION thr " << (void*)pthread_self()
1290 << " / obj " << tr.target.ptr << " / code "
1291 << TypeCode(tr.code) << ": " << indent << buffer
1292 << dedent << endl
1293 << "Data addr = "
1294 << reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer)
1295 << ", offsets addr="
1296 << reinterpret_cast<const size_t*>(tr.data.ptr.offsets) << endl;
1297 }
1298 if (tr.target.ptr) {
1299 // We only have a weak reference on the target object, so we must first try to
1300 // safely acquire a strong reference before doing anything else with it.
1301 if (reinterpret_cast<RefBase::weakref_type*>(
1302 tr.target.ptr)->attemptIncStrong(this)) {
1303 error = reinterpret_cast<BBinder*>(tr.cookie)->transact(tr.code, buffer,
1304 &reply, tr.flags);
1305 reinterpret_cast<BBinder*>(tr.cookie)->decStrong(this);
Dianne Hackbornc1114612016-03-21 10:36:54 -07001306 } else {
Martijn Coenenea0090a2017-11-02 18:54:40 +00001307 error = UNKNOWN_TRANSACTION;
Dianne Hackbornc1114612016-03-21 10:36:54 -07001308 }
Brad Fitzpatrick52736032010-08-30 16:01:16 -07001309
Martijn Coenenea0090a2017-11-02 18:54:40 +00001310 } else {
1311 error = the_context_object->transact(tr.code, buffer, &reply, tr.flags);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001312 }
Dianne Hackborn5ee2c9d2014-09-30 11:30:03 -07001313
Steven Morelandf0212002018-12-26 13:59:23 -08001314 //ALOGI("<<<< TRANSACT from pid %d restore pid %d sid %s uid %d\n",
1315 // mCallingPid, origPid, (origSid ? origSid : "<N/A>"), origUid);
Tim Murrayd429f4a2017-03-07 09:31:09 -08001316
Martijn Coenenea0090a2017-11-02 18:54:40 +00001317 if ((tr.flags & TF_ONE_WAY) == 0) {
1318 LOG_ONEWAY("Sending reply to %d!", mCallingPid);
1319 if (error < NO_ERROR) reply.setError(error);
Steven Morelandf183fdd2020-10-27 00:12:12 +00001320
1321 constexpr uint32_t kForwardReplyFlags = TF_CLEAR_BUF;
1322 sendReply(reply, (tr.flags & kForwardReplyFlags));
Martijn Coenenea0090a2017-11-02 18:54:40 +00001323 } else {
Steven Moreland80844f72020-12-12 02:06:08 +00001324 if (error != OK) {
1325 alog << "oneway function results for code " << tr.code
1326 << " on binder at "
1327 << reinterpret_cast<void*>(tr.target.ptr)
1328 << " will be dropped but finished with status "
1329 << statusToString(error);
1330
1331 // ideally we could log this even when error == OK, but it
1332 // causes too much logspam because some manually-written
1333 // interfaces have clients that call methods which always
1334 // write results, sometimes as oneway methods.
1335 if (reply.dataSize() != 0) {
1336 alog << " and reply parcel size " << reply.dataSize();
1337 }
1338
1339 alog << endl;
Steven Morelandce66b8a2020-02-10 14:43:14 -08001340 }
Martijn Coenenea0090a2017-11-02 18:54:40 +00001341 LOG_ONEWAY("NOT sending reply to %d!", mCallingPid);
1342 }
1343
Steven Moreland39d887d2020-01-31 14:56:45 -08001344 mServingStackPointer = origServingStackPointer;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001345 mCallingPid = origPid;
Steven Morelandf0212002018-12-26 13:59:23 -08001346 mCallingSid = origSid;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001347 mCallingUid = origUid;
1348 mStrictModePolicy = origStrictModePolicy;
1349 mLastTransactionBinderFlags = origTransactionBinderFlags;
Olivier Gaillard91a04802018-11-14 17:32:41 +00001350 mWorkSource = origWorkSource;
1351 mPropagateWorkSource = origPropagateWorkSet;
Christopher Tate440fd872010-03-18 17:55:03 -07001352
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001353 IF_LOG_TRANSACTIONS() {
1354 TextOutput::Bundle _b(alog);
1355 alog << "BC_REPLY thr " << (void*)pthread_self() << " / obj "
1356 << tr.target.ptr << ": " << indent << reply << dedent << endl;
1357 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001358
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001359 }
1360 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001361
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001362 case BR_DEAD_BINDER:
1363 {
Serban Constantinescuf683e012013-11-05 16:53:55 +00001364 BpBinder *proxy = (BpBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001365 proxy->sendObituary();
1366 mOut.writeInt32(BC_DEAD_BINDER_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001367 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001368 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001369
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001370 case BR_CLEAR_DEATH_NOTIFICATION_DONE:
1371 {
Serban Constantinescuf683e012013-11-05 16:53:55 +00001372 BpBinder *proxy = (BpBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001373 proxy->getWeakRefs()->decWeak(proxy);
1374 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001375
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001376 case BR_FINISHED:
1377 result = TIMED_OUT;
1378 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001379
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001380 case BR_NOOP:
1381 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001382
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001383 case BR_SPAWN_LOOPER:
1384 mProcess->spawnPooledThread(false);
1385 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001386
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001387 default:
liangweikanga43ee152016-10-25 16:37:54 +08001388 ALOGE("*** BAD COMMAND %d received from Binder driver\n", cmd);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001389 result = UNKNOWN_ERROR;
1390 break;
1391 }
1392
1393 if (result != NO_ERROR) {
1394 mLastError = result;
1395 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001396
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001397 return result;
1398}
1399
Steven Moreland39d887d2020-01-31 14:56:45 -08001400const void* IPCThreadState::getServingStackPointer() const {
1401 return mServingStackPointer;
Jayant Chowdharydac6dc82018-10-01 22:52:44 +00001402}
1403
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001404void IPCThreadState::threadDestructor(void *st)
1405{
Todd Poynor8d96cab2013-06-25 19:12:18 -07001406 IPCThreadState* const self = static_cast<IPCThreadState*>(st);
1407 if (self) {
1408 self->flushCommands();
Elliott Hughes6071da72015-08-12 15:27:47 -07001409#if defined(__ANDROID__)
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -02001410 if (self->mProcess->mDriverFD >= 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +01001411 ioctl(self->mProcess->mDriverFD, BINDER_THREAD_EXIT, 0);
1412 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001413#endif
Todd Poynor8d96cab2013-06-25 19:12:18 -07001414 delete self;
1415 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001416}
1417
Li Li6f059292021-09-10 09:59:30 -07001418status_t IPCThreadState::getProcessFreezeInfo(pid_t pid, uint32_t *sync_received,
1419 uint32_t *async_received)
1420{
1421 int ret = 0;
Jiyong Park5970d0a2022-03-08 16:56:13 +09001422 binder_frozen_status_info info = {};
Li Li6f059292021-09-10 09:59:30 -07001423 info.pid = pid;
1424
1425#if defined(__ANDROID__)
1426 if (ioctl(self()->mProcess->mDriverFD, BINDER_GET_FROZEN_INFO, &info) < 0)
1427 ret = -errno;
1428#endif
1429 *sync_received = info.sync_recv;
1430 *async_received = info.async_recv;
1431
1432 return ret;
1433}
Li Li6f059292021-09-10 09:59:30 -07001434
Marco Ballesio7ee17572020-09-08 10:30:03 -07001435status_t IPCThreadState::freeze(pid_t pid, bool enable, uint32_t timeout_ms) {
1436 struct binder_freeze_info info;
1437 int ret = 0;
1438
1439 info.pid = pid;
1440 info.enable = enable;
1441 info.timeout_ms = timeout_ms;
1442
1443
1444#if defined(__ANDROID__)
1445 if (ioctl(self()->mProcess->mDriverFD, BINDER_FREEZE, &info) < 0)
1446 ret = -errno;
1447#endif
1448
1449 //
1450 // ret==-EAGAIN indicates that transactions have not drained.
1451 // Call again to poll for completion.
1452 //
1453 return ret;
1454}
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001455
Carlos Llamasb235b122021-12-20 06:38:44 -08001456void IPCThreadState::logExtendedError() {
1457 struct binder_extended_error ee = {.command = BR_OK};
1458
1459 if (!ProcessState::isDriverFeatureEnabled(ProcessState::DriverFeature::EXTENDED_ERROR))
1460 return;
1461
1462#if defined(__ANDROID__)
1463 if (ioctl(self()->mProcess->mDriverFD, BINDER_GET_EXTENDED_ERROR, &ee) < 0) {
1464 ALOGE("Failed to get extended error: %s", strerror(errno));
1465 return;
1466 }
1467#endif
1468
1469 ALOGE_IF(ee.command != BR_OK, "Binder transaction failure: %d/%d/%d",
1470 ee.id, ee.command, ee.param);
1471}
1472
Frederick Mayle53b6ffe2022-07-15 20:14:01 +00001473void IPCThreadState::freeBuffer(const uint8_t* data, size_t /*dataSize*/,
1474 const binder_size_t* /*objects*/, size_t /*objectsSize*/) {
Steve Blocka19954a2012-01-04 20:05:49 +00001475 //ALOGI("Freeing parcel %p", &parcel);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001476 IF_LOG_COMMANDS() {
1477 alog << "Writing BC_FREE_BUFFER for " << data << endl;
1478 }
Steve Block67263472012-01-09 18:35:44 +00001479 ALOG_ASSERT(data != NULL, "Called with NULL data");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001480 IPCThreadState* state = self();
1481 state->mOut.writeInt32(BC_FREE_BUFFER);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001482 state->mOut.writePointer((uintptr_t)data);
Martijn Coenen0442a862017-11-17 10:46:32 +01001483 state->flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001484}
1485
Steven Moreland61ff8492019-09-26 16:05:45 -07001486} // namespace android