blob: 4a45eb558671b1385fdf9fb095ce14a9c169307e [file] [log] [blame]
chaviw8ffc7b82020-08-18 11:25:37 -07001/*
2 * Copyright (C) 2020 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17// TODO(b/129481165): remove the #pragma below and fix conversion issues
18#pragma clang diagnostic push
19#pragma clang diagnostic ignored "-Wconversion"
20
Huihong Luo05539a12022-02-23 10:29:40 -080021#include <android/gui/ISurfaceComposer.h>
Ana Krulec13be8ad2018-08-21 02:43:56 +000022#include <gtest/gtest.h>
Huihong Luo3bdef862022-03-03 11:57:19 -080023#include <gui/AidlStatusUtil.h>
Ana Krulec13be8ad2018-08-21 02:43:56 +000024#include <gui/LayerDebugInfo.h>
25#include <gui/Surface.h>
26#include <gui/SurfaceComposerClient.h>
Ana Krulec13be8ad2018-08-21 02:43:56 +000027#include <private/android_filesystem_config.h>
Huihong Luo05539a12022-02-23 10:29:40 -080028#include <private/gui/ComposerServiceAIDL.h>
Marin Shalamanova7fe3042021-01-29 21:02:08 +010029#include <ui/DisplayMode.h>
Marin Shalamanov228f46b2021-01-28 21:11:45 +010030#include <ui/DynamicDisplayInfo.h>
Ana Krulec13be8ad2018-08-21 02:43:56 +000031#include <utils/String8.h>
Dominik Laskowski3cb3d4e2019-11-21 11:14:45 -080032#include <functional>
chaviw8ffc7b82020-08-18 11:25:37 -070033#include "utils/ScreenshotUtils.h"
Dominik Laskowski3cb3d4e2019-11-21 11:14:45 -080034
Ana Krulec13be8ad2018-08-21 02:43:56 +000035namespace android {
36
37using Transaction = SurfaceComposerClient::Transaction;
Huihong Luo05539a12022-02-23 10:29:40 -080038using gui::LayerDebugInfo;
Huihong Luo3bdef862022-03-03 11:57:19 -080039using gui::aidl_utils::statusTFromBinderStatus;
Peiyong Lin4f3fddf2019-01-24 17:21:24 -080040using ui::ColorMode;
Ana Krulec13be8ad2018-08-21 02:43:56 +000041
42namespace {
43const String8 DISPLAY_NAME("Credentials Display Test");
44const String8 SURFACE_NAME("Test Surface Name");
Ana Krulec13be8ad2018-08-21 02:43:56 +000045} // namespace
46
47/**
48 * This class tests the CheckCredentials method in SurfaceFlinger.
49 * Methods like EnableVsyncInjections and InjectVsync are not tested since they do not
50 * return anything meaningful.
51 */
Ady Abrahamb0dbdaa2020-01-06 16:19:42 -080052
53// TODO(b/129481165): remove the #pragma below and fix conversion issues
54#pragma clang diagnostic push
55#pragma clang diagnostic ignored "-Wconversion"
Ana Krulec13be8ad2018-08-21 02:43:56 +000056class CredentialsTest : public ::testing::Test {
57protected:
Chavi Weingartenc73be482022-08-31 16:55:07 +000058 void SetUp() override { ASSERT_NO_FATAL_FAILURE(initClient()); }
Ana Krulec13be8ad2018-08-21 02:43:56 +000059
60 void TearDown() override {
61 mComposerClient->dispose();
62 mBGSurfaceControl.clear();
63 mComposerClient.clear();
Ana Krulec13be8ad2018-08-21 02:43:56 +000064 }
65
66 sp<IBinder> mDisplay;
67 sp<IBinder> mVirtualDisplay;
68 sp<SurfaceComposerClient> mComposerClient;
69 sp<SurfaceControl> mBGSurfaceControl;
70 sp<SurfaceControl> mVirtualSurfaceControl;
71
72 void initClient() {
Ady Abrahamd11bade2022-08-01 16:18:03 -070073 mComposerClient = sp<SurfaceComposerClient>::make();
Ana Krulec13be8ad2018-08-21 02:43:56 +000074 ASSERT_EQ(NO_ERROR, mComposerClient->initCheck());
75 }
76
Huihong Luo31b5ac22022-08-15 20:38:10 -070077 static sp<IBinder> getFirstDisplayToken() {
78 const auto ids = SurfaceComposerClient::getPhysicalDisplayIds();
79 if (ids.empty()) {
80 return nullptr;
81 }
82
83 return SurfaceComposerClient::getPhysicalDisplayToken(ids.front());
84 }
85
Sally Qi6bb12822022-10-05 11:42:30 -070086 static std::optional<uint64_t> getFirstDisplayId() {
87 const auto ids = SurfaceComposerClient::getPhysicalDisplayIds();
88 if (ids.empty()) {
89 return std::nullopt;
90 }
91
92 return ids.front().value;
93 }
94
Ana Krulec13be8ad2018-08-21 02:43:56 +000095 void setupBackgroundSurface() {
Huihong Luo31b5ac22022-08-15 20:38:10 -070096 mDisplay = getFirstDisplayToken();
Dominik Laskowskidcb38bb2019-01-25 02:35:50 -080097 ASSERT_FALSE(mDisplay == nullptr);
98
Marin Shalamanova7fe3042021-01-29 21:02:08 +010099 ui::DisplayMode mode;
100 ASSERT_EQ(NO_ERROR, SurfaceComposerClient::getActiveDisplayMode(mDisplay, &mode));
Ana Krulec13be8ad2018-08-21 02:43:56 +0000101
102 // Background surface
Marin Shalamanova7fe3042021-01-29 21:02:08 +0100103 mBGSurfaceControl = mComposerClient->createSurface(SURFACE_NAME, mode.resolution.getWidth(),
104 mode.resolution.getHeight(),
105 PIXEL_FORMAT_RGBA_8888, 0);
Ana Krulec13be8ad2018-08-21 02:43:56 +0000106 ASSERT_TRUE(mBGSurfaceControl != nullptr);
107 ASSERT_TRUE(mBGSurfaceControl->isValid());
108
109 Transaction t;
Dominik Laskowski29fa1462021-04-27 15:51:50 -0700110 t.setDisplayLayerStack(mDisplay, ui::DEFAULT_LAYER_STACK);
Ana Krulec13be8ad2018-08-21 02:43:56 +0000111 ASSERT_EQ(NO_ERROR,
112 t.setLayer(mBGSurfaceControl, INT_MAX - 3).show(mBGSurfaceControl).apply());
113 }
114
Ana Krulec13be8ad2018-08-21 02:43:56 +0000115 /**
Ana Krulec13be8ad2018-08-21 02:43:56 +0000116 * Template function the check a condition for different types of users: root
117 * graphics, system, and non-supported user. Root, graphics, and system should
118 * always equal privilegedValue, and non-supported user should equal unprivilegedValue.
119 */
120 template <typename T>
121 void checkWithPrivileges(std::function<T()> condition, T privilegedValue, T unprivilegedValue) {
122 // Check with root.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000123 {
124 UIDFaker f(AID_SYSTEM);
125 ASSERT_EQ(privilegedValue, condition());
126 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000127
128 // Check as a Graphics user.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000129 {
130 UIDFaker f(AID_GRAPHICS);
131 ASSERT_EQ(privilegedValue, condition());
132 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000133
134 // Check as a system user.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000135 {
136 UIDFaker f(AID_SYSTEM);
137 ASSERT_EQ(privilegedValue, condition());
138 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000139
140 // Check as a non-supported user.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000141 {
142 UIDFaker f(AID_BIN);
143 ASSERT_EQ(unprivilegedValue, condition());
144 }
chaviwd4a61642020-09-01 14:53:46 -0700145
146 // Check as shell since shell has some additional permissions
Chavi Weingartenc73be482022-08-31 16:55:07 +0000147 {
148 UIDFaker f(AID_SHELL);
149 ASSERT_EQ(privilegedValue, condition());
150 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000151 }
152};
153
154TEST_F(CredentialsTest, ClientInitTest) {
155 // Root can init can init the client.
156 ASSERT_NO_FATAL_FAILURE(initClient());
157
158 // Graphics can init the client.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000159 {
160 UIDFaker f(AID_GRAPHICS);
161 ASSERT_NO_FATAL_FAILURE(initClient());
162 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000163
164 // System can init the client.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000165 {
166 UIDFaker f(AID_SYSTEM);
167 ASSERT_NO_FATAL_FAILURE(initClient());
168 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000169
Robert Carrb89ea9d2018-12-10 13:01:14 -0800170 // Anyone else can init the client.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000171 {
172 UIDFaker f(AID_BIN);
173 mComposerClient = sp<SurfaceComposerClient>::make();
174 ASSERT_NO_FATAL_FAILURE(initClient());
175 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000176}
177
178TEST_F(CredentialsTest, GetBuiltInDisplayAccessTest) {
Huihong Luo31b5ac22022-08-15 20:38:10 -0700179 std::function<bool()> condition = [] { return getFirstDisplayToken() != nullptr; };
Ana Krulec13be8ad2018-08-21 02:43:56 +0000180 // Anyone can access display information.
Sally Qi6bb12822022-10-05 11:42:30 -0700181 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges(condition, true, false));
Ana Krulec13be8ad2018-08-21 02:43:56 +0000182}
183
184TEST_F(CredentialsTest, AllowedGetterMethodsTest) {
185 // The following methods are tested with a UID that is not root, graphics,
186 // or system, to show that anyone can access them.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000187 UIDFaker f(AID_BIN);
Sally Qi6bb12822022-10-05 11:42:30 -0700188 const auto id = getFirstDisplayId();
189 ASSERT_TRUE(id);
Marin Shalamanov228f46b2021-01-28 21:11:45 +0100190 ui::DynamicDisplayInfo info;
Sally Qi6bb12822022-10-05 11:42:30 -0700191 ASSERT_EQ(NO_ERROR, SurfaceComposerClient::getDynamicDisplayInfoFromId(*id, &info));
Ana Krulec13be8ad2018-08-21 02:43:56 +0000192}
193
Marin Shalamanov228f46b2021-01-28 21:11:45 +0100194TEST_F(CredentialsTest, GetDynamicDisplayInfoTest) {
Sally Qi6bb12822022-10-05 11:42:30 -0700195 const auto id = getFirstDisplayId();
196 ASSERT_TRUE(id);
Ana Krulec13be8ad2018-08-21 02:43:56 +0000197 std::function<status_t()> condition = [=]() {
Marin Shalamanov228f46b2021-01-28 21:11:45 +0100198 ui::DynamicDisplayInfo info;
Sally Qi6bb12822022-10-05 11:42:30 -0700199 return SurfaceComposerClient::getDynamicDisplayInfoFromId(*id, &info);
Ana Krulec13be8ad2018-08-21 02:43:56 +0000200 };
201 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges<status_t>(condition, NO_ERROR, NO_ERROR));
202}
203
Daniel Solomon42d04562019-01-20 21:03:19 -0800204TEST_F(CredentialsTest, GetDisplayNativePrimariesTest) {
Huihong Luo31b5ac22022-08-15 20:38:10 -0700205 const auto display = getFirstDisplayToken();
Daniel Solomon42d04562019-01-20 21:03:19 -0800206 std::function<status_t()> condition = [=]() {
207 ui::DisplayPrimaries primaries;
208 return SurfaceComposerClient::getDisplayNativePrimaries(display, primaries);
209 };
210 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges<status_t>(condition, NO_ERROR, NO_ERROR));
211}
212
Steven Thomasa87ed452020-01-03 16:10:05 -0800213TEST_F(CredentialsTest, SetDesiredDisplayConfigsTest) {
Huihong Luo31b5ac22022-08-15 20:38:10 -0700214 const auto display = getFirstDisplayToken();
Ady Abraham285f8c12022-10-11 17:12:14 -0700215 gui::DisplayModeSpecs specs;
216 status_t res = SurfaceComposerClient::getDesiredDisplayModeSpecs(display, &specs);
Steven Thomasa87ed452020-01-03 16:10:05 -0800217 ASSERT_EQ(res, NO_ERROR);
Ady Abraham285f8c12022-10-11 17:12:14 -0700218 gui::DisplayModeSpecs setSpecs;
Ana Krulec13be8ad2018-08-21 02:43:56 +0000219 std::function<status_t()> condition = [=]() {
Ady Abraham285f8c12022-10-11 17:12:14 -0700220 return SurfaceComposerClient::setDesiredDisplayModeSpecs(display, specs);
Ana Krulec13be8ad2018-08-21 02:43:56 +0000221 };
222 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges<status_t>(condition, NO_ERROR, PERMISSION_DENIED));
223}
224
225TEST_F(CredentialsTest, SetActiveColorModeTest) {
Huihong Luo31b5ac22022-08-15 20:38:10 -0700226 const auto display = getFirstDisplayToken();
Ana Krulec13be8ad2018-08-21 02:43:56 +0000227 std::function<status_t()> condition = [=]() {
228 return SurfaceComposerClient::setActiveColorMode(display, ui::ColorMode::NATIVE);
229 };
230 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges<status_t>(condition, NO_ERROR, PERMISSION_DENIED));
231}
232
Ana Krulec13be8ad2018-08-21 02:43:56 +0000233TEST_F(CredentialsTest, CreateDisplayTest) {
chaviwd4a61642020-09-01 14:53:46 -0700234 // Only graphics and system processes can create a secure display.
Ana Krulec13be8ad2018-08-21 02:43:56 +0000235 std::function<bool()> condition = [=]() {
236 sp<IBinder> testDisplay = SurfaceComposerClient::createDisplay(DISPLAY_NAME, true);
237 return testDisplay.get() != nullptr;
238 };
chaviwd4a61642020-09-01 14:53:46 -0700239
240 // Check with root.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000241 {
242 UIDFaker f(AID_ROOT);
243 ASSERT_FALSE(condition());
244 }
chaviwd4a61642020-09-01 14:53:46 -0700245
246 // Check as a Graphics user.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000247 {
248 UIDFaker f(AID_GRAPHICS);
249 ASSERT_TRUE(condition());
250 }
chaviwd4a61642020-09-01 14:53:46 -0700251
252 // Check as a system user.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000253 {
254 UIDFaker f(AID_SYSTEM);
255 ASSERT_TRUE(condition());
256 }
chaviwd4a61642020-09-01 14:53:46 -0700257
258 // Check as a non-supported user.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000259 {
260 UIDFaker f(AID_BIN);
261 ASSERT_FALSE(condition());
262 }
chaviwd4a61642020-09-01 14:53:46 -0700263
264 // Check as shell since shell has some additional permissions
Chavi Weingartenc73be482022-08-31 16:55:07 +0000265 {
266 UIDFaker f(AID_SHELL);
267 ASSERT_FALSE(condition());
268 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000269
270 condition = [=]() {
271 sp<IBinder> testDisplay = SurfaceComposerClient::createDisplay(DISPLAY_NAME, false);
272 return testDisplay.get() != nullptr;
273 };
274 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges(condition, true, false));
275}
276
Ana Krulec13be8ad2018-08-21 02:43:56 +0000277TEST_F(CredentialsTest, CaptureTest) {
Huihong Luo31b5ac22022-08-15 20:38:10 -0700278 const auto display = getFirstDisplayToken();
Ana Krulec13be8ad2018-08-21 02:43:56 +0000279 std::function<status_t()> condition = [=]() {
280 sp<GraphicBuffer> outBuffer;
chaviw690db382020-07-27 16:46:46 -0700281 DisplayCaptureArgs captureArgs;
282 captureArgs.displayToken = display;
283 ScreenCaptureResults captureResults;
chaviw8ffc7b82020-08-18 11:25:37 -0700284 return ScreenCapture::captureDisplay(captureArgs, captureResults);
Ana Krulec13be8ad2018-08-21 02:43:56 +0000285 };
286 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges<status_t>(condition, NO_ERROR, PERMISSION_DENIED));
287}
288
289TEST_F(CredentialsTest, CaptureLayersTest) {
290 setupBackgroundSurface();
291 sp<GraphicBuffer> outBuffer;
292 std::function<status_t()> condition = [=]() {
chaviw26c52482020-07-28 16:25:52 -0700293 LayerCaptureArgs captureArgs;
294 captureArgs.layerHandle = mBGSurfaceControl->getHandle();
295 captureArgs.sourceCrop = {0, 0, 1, 1};
296
297 ScreenCaptureResults captureResults;
chaviw8ffc7b82020-08-18 11:25:37 -0700298 return ScreenCapture::captureLayers(captureArgs, captureResults);
Ana Krulec13be8ad2018-08-21 02:43:56 +0000299 };
300 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges<status_t>(condition, NO_ERROR, PERMISSION_DENIED));
301}
302
303/**
304 * The following tests are for methods accessible directly through SurfaceFlinger.
305 */
Ana Krulec13be8ad2018-08-21 02:43:56 +0000306TEST_F(CredentialsTest, GetLayerDebugInfo) {
307 setupBackgroundSurface();
Huihong Luo05539a12022-02-23 10:29:40 -0800308 sp<gui::ISurfaceComposer> sf(ComposerServiceAIDL::getComposerService());
Ana Krulec13be8ad2018-08-21 02:43:56 +0000309
310 // Historically, only root and shell can access the getLayerDebugInfo which
311 // is called when we call dumpsys. I don't see a reason why we should change this.
312 std::vector<LayerDebugInfo> outLayers;
Chavi Weingartenc73be482022-08-31 16:55:07 +0000313 binder::Status status = binder::Status::ok();
Ana Krulec13be8ad2018-08-21 02:43:56 +0000314 // Check with root.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000315 {
316 UIDFaker f(AID_ROOT);
317 status = sf->getLayerDebugInfo(&outLayers);
318 ASSERT_EQ(NO_ERROR, statusTFromBinderStatus(status));
319 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000320
321 // Check as a shell.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000322 {
323 UIDFaker f(AID_SHELL);
324 status = sf->getLayerDebugInfo(&outLayers);
325 ASSERT_EQ(NO_ERROR, statusTFromBinderStatus(status));
326 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000327
328 // Check as anyone else.
Chavi Weingartenc73be482022-08-31 16:55:07 +0000329 {
330 UIDFaker f(AID_BIN);
331 status = sf->getLayerDebugInfo(&outLayers);
332 ASSERT_EQ(PERMISSION_DENIED, statusTFromBinderStatus(status));
333 }
Ana Krulec13be8ad2018-08-21 02:43:56 +0000334}
Peiyong Lin4f3fddf2019-01-24 17:21:24 -0800335
336TEST_F(CredentialsTest, IsWideColorDisplayBasicCorrectness) {
Huihong Luo31b5ac22022-08-15 20:38:10 -0700337 const auto display = getFirstDisplayToken();
Dominik Laskowskidcb38bb2019-01-25 02:35:50 -0800338 ASSERT_FALSE(display == nullptr);
Peiyong Lin4f3fddf2019-01-24 17:21:24 -0800339 bool result = false;
340 status_t error = SurfaceComposerClient::isWideColorDisplay(display, &result);
341 ASSERT_EQ(NO_ERROR, error);
342 bool hasWideColorMode = false;
Sally Qi6bb12822022-10-05 11:42:30 -0700343 const auto id = getFirstDisplayId();
344 ASSERT_TRUE(id);
Marin Shalamanov228f46b2021-01-28 21:11:45 +0100345 ui::DynamicDisplayInfo info;
Sally Qi6bb12822022-10-05 11:42:30 -0700346 SurfaceComposerClient::getDynamicDisplayInfoFromId(*id, &info);
Marin Shalamanov228f46b2021-01-28 21:11:45 +0100347 const auto& colorModes = info.supportedColorModes;
Peiyong Lin4f3fddf2019-01-24 17:21:24 -0800348 for (ColorMode colorMode : colorModes) {
349 switch (colorMode) {
350 case ColorMode::DISPLAY_P3:
351 case ColorMode::ADOBE_RGB:
352 case ColorMode::DCI_P3:
353 hasWideColorMode = true;
354 break;
355 default:
356 break;
357 }
358 }
359 ASSERT_EQ(hasWideColorMode, result);
360}
361
362TEST_F(CredentialsTest, IsWideColorDisplayWithPrivileges) {
Huihong Luo31b5ac22022-08-15 20:38:10 -0700363 const auto display = getFirstDisplayToken();
Dominik Laskowskidcb38bb2019-01-25 02:35:50 -0800364 ASSERT_FALSE(display == nullptr);
Peiyong Lin4f3fddf2019-01-24 17:21:24 -0800365 std::function<status_t()> condition = [=]() {
366 bool result = false;
367 return SurfaceComposerClient::isWideColorDisplay(display, &result);
368 };
369 ASSERT_NO_FATAL_FAILURE(checkWithPrivileges<status_t>(condition, NO_ERROR, NO_ERROR));
370}
371
Peiyong Lind1fedb42019-03-11 17:48:41 -0700372TEST_F(CredentialsTest, GetActiveColorModeBasicCorrectness) {
Sally Qi6bb12822022-10-05 11:42:30 -0700373 const auto id = getFirstDisplayId();
374 ASSERT_TRUE(id);
Marin Shalamanov228f46b2021-01-28 21:11:45 +0100375 ui::DynamicDisplayInfo info;
Sally Qi6bb12822022-10-05 11:42:30 -0700376 SurfaceComposerClient::getDynamicDisplayInfoFromId(*id, &info);
Marin Shalamanov228f46b2021-01-28 21:11:45 +0100377 ColorMode colorMode = info.activeColorMode;
Peiyong Lind1fedb42019-03-11 17:48:41 -0700378 ASSERT_NE(static_cast<ColorMode>(BAD_VALUE), colorMode);
379}
380
Ana Krulec13be8ad2018-08-21 02:43:56 +0000381} // namespace android
Ady Abrahamb0dbdaa2020-01-06 16:19:42 -0800382
383// TODO(b/129481165): remove the #pragma below and fix conversion issues
384#pragma clang diagnostic pop // ignored "-Wconversion"