blob: 6fb1227f638537d1292d2a820509abad0d64dbfa [file] [log] [blame]
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001/*
2 * Copyright (C) 2005 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
Jason Parksdcd39582009-11-03 12:14:38 -080017#define LOG_TAG "IPCThreadState"
18
Mathias Agopianc5b2c0b2009-05-19 19:08:10 -070019#include <binder/IPCThreadState.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080020
Mathias Agopianc5b2c0b2009-05-19 19:08:10 -070021#include <binder/Binder.h>
22#include <binder/BpBinder.h>
Mathias Agopian002e1e52013-05-06 20:20:50 -070023#include <binder/TextOutput.h>
24
Steven Moreland7732a092019-01-02 17:54:16 -080025#include <android-base/macros.h>
Glenn Kastena26e1cf2012-03-16 07:15:23 -070026#include <cutils/sched_policy.h>
Steven Moreland7732a092019-01-02 17:54:16 -080027#include <utils/CallStack.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080028#include <utils/Log.h>
Colin Cross96e83222016-04-15 14:29:55 -070029#include <utils/SystemClock.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080030#include <utils/threads.h>
31
Mathias Agopian208059f2009-05-18 15:08:03 -070032#include <private/binder/binder_module.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080033
Hans Boehma997b232019-04-12 16:59:00 -070034#include <atomic>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080035#include <errno.h>
Colin Cross96e83222016-04-15 14:29:55 -070036#include <inttypes.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080037#include <pthread.h>
38#include <sched.h>
Yabin Cui8fb2d252015-01-26 19:45:47 -080039#include <signal.h>
40#include <stdio.h>
41#include <sys/ioctl.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080042#include <sys/resource.h>
Yabin Cui8fb2d252015-01-26 19:45:47 -080043#include <unistd.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080044
Steven Morelanda4853cd2019-07-12 15:44:37 -070045#include "Static.h"
46
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080047#if LOG_NDEBUG
48
49#define IF_LOG_TRANSACTIONS() if (false)
50#define IF_LOG_COMMANDS() if (false)
51#define LOG_REMOTEREFS(...)
52#define IF_LOG_REMOTEREFS() if (false)
Tim Murrayd429f4a2017-03-07 09:31:09 -080053
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080054#define LOG_THREADPOOL(...)
55#define LOG_ONEWAY(...)
56
57#else
58
Steve Block9f760152011-10-12 17:27:03 +010059#define IF_LOG_TRANSACTIONS() IF_ALOG(LOG_VERBOSE, "transact")
60#define IF_LOG_COMMANDS() IF_ALOG(LOG_VERBOSE, "ipc")
61#define LOG_REMOTEREFS(...) ALOG(LOG_DEBUG, "remoterefs", __VA_ARGS__)
62#define IF_LOG_REMOTEREFS() IF_ALOG(LOG_DEBUG, "remoterefs")
63#define LOG_THREADPOOL(...) ALOG(LOG_DEBUG, "threadpool", __VA_ARGS__)
64#define LOG_ONEWAY(...) ALOG(LOG_DEBUG, "ipc", __VA_ARGS__)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080065
66#endif
67
68// ---------------------------------------------------------------------------
69
70namespace android {
71
Chih-Hung Hsieh8e5337d2014-10-24 14:10:09 -070072// Static const and functions will be optimized out if not used,
73// when LOG_NDEBUG and references in IF_LOG_COMMANDS() are optimized out.
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080074static const char *kReturnStrings[] = {
Andy McFaddenaefc9cd2011-08-31 07:43:40 -070075 "BR_ERROR",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080076 "BR_OK",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080077 "BR_TRANSACTION",
78 "BR_REPLY",
79 "BR_ACQUIRE_RESULT",
80 "BR_DEAD_REPLY",
81 "BR_TRANSACTION_COMPLETE",
82 "BR_INCREFS",
83 "BR_ACQUIRE",
84 "BR_RELEASE",
85 "BR_DECREFS",
86 "BR_ATTEMPT_ACQUIRE",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080087 "BR_NOOP",
88 "BR_SPAWN_LOOPER",
89 "BR_FINISHED",
90 "BR_DEAD_BINDER",
Andy McFaddenaefc9cd2011-08-31 07:43:40 -070091 "BR_CLEAR_DEATH_NOTIFICATION_DONE",
Steven Morelandf0212002018-12-26 13:59:23 -080092 "BR_FAILED_REPLY",
Hang Lub185ac02021-03-24 13:17:22 +080093 "BR_FROZEN_REPLY",
94 "BR_ONEWAY_SPAM_SUSPECT",
Steven Morelandf0212002018-12-26 13:59:23 -080095 "BR_TRANSACTION_SEC_CTX",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080096};
97
98static const char *kCommandStrings[] = {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080099 "BC_TRANSACTION",
100 "BC_REPLY",
101 "BC_ACQUIRE_RESULT",
102 "BC_FREE_BUFFER",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800103 "BC_INCREFS",
104 "BC_ACQUIRE",
105 "BC_RELEASE",
106 "BC_DECREFS",
107 "BC_INCREFS_DONE",
108 "BC_ACQUIRE_DONE",
109 "BC_ATTEMPT_ACQUIRE",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800110 "BC_REGISTER_LOOPER",
111 "BC_ENTER_LOOPER",
112 "BC_EXIT_LOOPER",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800113 "BC_REQUEST_DEATH_NOTIFICATION",
114 "BC_CLEAR_DEATH_NOTIFICATION",
115 "BC_DEAD_BINDER_DONE"
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800116};
117
Olivier Gaillard91a04802018-11-14 17:32:41 +0000118static const int64_t kWorkSourcePropagatedBitIndex = 32;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100119
songjinshi73a7dde2016-10-18 21:05:56 +0800120static const char* getReturnString(uint32_t cmd)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800121{
songjinshi8e486c62019-04-04 11:22:52 +0800122 size_t idx = cmd & _IOC_NRMASK;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800123 if (idx < sizeof(kReturnStrings) / sizeof(kReturnStrings[0]))
124 return kReturnStrings[idx];
125 else
126 return "unknown";
127}
128
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800129static const void* printBinderTransactionData(TextOutput& out, const void* data)
130{
131 const binder_transaction_data* btd =
132 (const binder_transaction_data*)data;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700133 if (btd->target.handle < 1024) {
134 /* want to print descriptors in decimal; guess based on value */
135 out << "target.desc=" << btd->target.handle;
136 } else {
137 out << "target.ptr=" << btd->target.ptr;
138 }
139 out << " (cookie " << btd->cookie << ")" << endl
Jiyong Park16c6e702020-11-13 20:53:12 +0900140 << "code=" << TypeCode(btd->code) << ", flags=" << (void*)(uint64_t)btd->flags << endl
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800141 << "data=" << btd->data.ptr.buffer << " (" << (void*)btd->data_size
142 << " bytes)" << endl
143 << "offsets=" << btd->data.ptr.offsets << " (" << (void*)btd->offsets_size
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700144 << " bytes)";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800145 return btd+1;
146}
147
148static const void* printReturnCommand(TextOutput& out, const void* _cmd)
149{
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700150 static const size_t N = sizeof(kReturnStrings)/sizeof(kReturnStrings[0]);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800151 const int32_t* cmd = (const int32_t*)_cmd;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100152 uint32_t code = (uint32_t)*cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700153 size_t cmdIndex = code & 0xff;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100154 if (code == BR_ERROR) {
Jiyong Park16c6e702020-11-13 20:53:12 +0900155 out << "BR_ERROR: " << (void*)(uint64_t)(*cmd++) << endl;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800156 return cmd;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700157 } else if (cmdIndex >= N) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800158 out << "Unknown reply: " << code << endl;
159 return cmd;
160 }
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700161 out << kReturnStrings[cmdIndex];
Tim Murrayd429f4a2017-03-07 09:31:09 -0800162
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800163 switch (code) {
164 case BR_TRANSACTION:
165 case BR_REPLY: {
166 out << ": " << indent;
167 cmd = (const int32_t *)printBinderTransactionData(out, cmd);
168 out << dedent;
169 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800170
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800171 case BR_ACQUIRE_RESULT: {
172 const int32_t res = *cmd++;
173 out << ": " << res << (res ? " (SUCCESS)" : " (FAILURE)");
174 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800175
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800176 case BR_INCREFS:
177 case BR_ACQUIRE:
178 case BR_RELEASE:
179 case BR_DECREFS: {
180 const int32_t b = *cmd++;
181 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900182 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800183 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800184
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800185 case BR_ATTEMPT_ACQUIRE: {
186 const int32_t p = *cmd++;
187 const int32_t b = *cmd++;
188 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900189 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800190 << "), pri=" << p;
191 } break;
192
193 case BR_DEAD_BINDER:
194 case BR_CLEAR_DEATH_NOTIFICATION_DONE: {
195 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900196 out << ": death cookie " << (void*)(uint64_t)c;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800197 } break;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700198
199 default:
200 // no details to show for: BR_OK, BR_DEAD_REPLY,
201 // BR_TRANSACTION_COMPLETE, BR_FINISHED
202 break;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800203 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800204
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800205 out << endl;
206 return cmd;
207}
208
209static const void* printCommand(TextOutput& out, const void* _cmd)
210{
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700211 static const size_t N = sizeof(kCommandStrings)/sizeof(kCommandStrings[0]);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800212 const int32_t* cmd = (const int32_t*)_cmd;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100213 uint32_t code = (uint32_t)*cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700214 size_t cmdIndex = code & 0xff;
215
216 if (cmdIndex >= N) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800217 out << "Unknown command: " << code << endl;
218 return cmd;
219 }
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700220 out << kCommandStrings[cmdIndex];
221
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800222 switch (code) {
223 case BC_TRANSACTION:
224 case BC_REPLY: {
225 out << ": " << indent;
226 cmd = (const int32_t *)printBinderTransactionData(out, cmd);
227 out << dedent;
228 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800229
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800230 case BC_ACQUIRE_RESULT: {
231 const int32_t res = *cmd++;
232 out << ": " << res << (res ? " (SUCCESS)" : " (FAILURE)");
233 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800234
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800235 case BC_FREE_BUFFER: {
236 const int32_t buf = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900237 out << ": buffer=" << (void*)(uint64_t)buf;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800238 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800239
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800240 case BC_INCREFS:
241 case BC_ACQUIRE:
242 case BC_RELEASE:
243 case BC_DECREFS: {
244 const int32_t d = *cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700245 out << ": desc=" << d;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800246 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800247
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800248 case BC_INCREFS_DONE:
249 case BC_ACQUIRE_DONE: {
250 const int32_t b = *cmd++;
251 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900252 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800253 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800254
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800255 case BC_ATTEMPT_ACQUIRE: {
256 const int32_t p = *cmd++;
257 const int32_t d = *cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700258 out << ": desc=" << d << ", pri=" << p;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800259 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800260
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800261 case BC_REQUEST_DEATH_NOTIFICATION:
262 case BC_CLEAR_DEATH_NOTIFICATION: {
263 const int32_t h = *cmd++;
264 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900265 out << ": handle=" << h << " (death cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800266 } break;
267
268 case BC_DEAD_BINDER_DONE: {
269 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900270 out << ": death cookie " << (void*)(uint64_t)c;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800271 } break;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700272
273 default:
274 // no details to show for: BC_REGISTER_LOOPER, BC_ENTER_LOOPER,
275 // BC_EXIT_LOOPER
276 break;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800277 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800278
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800279 out << endl;
280 return cmd;
281}
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800282
283static pthread_mutex_t gTLSMutex = PTHREAD_MUTEX_INITIALIZER;
Hans Boehma997b232019-04-12 16:59:00 -0700284static std::atomic<bool> gHaveTLS(false);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800285static pthread_key_t gTLS = 0;
Hans Boehma997b232019-04-12 16:59:00 -0700286static std::atomic<bool> gShutdown = false;
287static std::atomic<bool> gDisableBackgroundScheduling = false;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800288
289IPCThreadState* IPCThreadState::self()
290{
Hans Boehma997b232019-04-12 16:59:00 -0700291 if (gHaveTLS.load(std::memory_order_acquire)) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800292restart:
293 const pthread_key_t k = gTLS;
294 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(k);
295 if (st) return st;
296 return new IPCThreadState;
297 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800298
Hans Boehma997b232019-04-12 16:59:00 -0700299 // Racey, heuristic test for simultaneous shutdown.
300 if (gShutdown.load(std::memory_order_relaxed)) {
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800301 ALOGW("Calling IPCThreadState::self() during shutdown is dangerous, expect a crash.\n");
Yi Kongfdd8da92018-06-07 17:52:27 -0700302 return nullptr;
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800303 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800304
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800305 pthread_mutex_lock(&gTLSMutex);
Hans Boehma997b232019-04-12 16:59:00 -0700306 if (!gHaveTLS.load(std::memory_order_relaxed)) {
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800307 int key_create_value = pthread_key_create(&gTLS, threadDestructor);
308 if (key_create_value != 0) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800309 pthread_mutex_unlock(&gTLSMutex);
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800310 ALOGW("IPCThreadState::self() unable to create TLS key, expect a crash: %s\n",
311 strerror(key_create_value));
Yi Kongfdd8da92018-06-07 17:52:27 -0700312 return nullptr;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800313 }
Hans Boehma997b232019-04-12 16:59:00 -0700314 gHaveTLS.store(true, std::memory_order_release);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800315 }
316 pthread_mutex_unlock(&gTLSMutex);
317 goto restart;
318}
319
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800320IPCThreadState* IPCThreadState::selfOrNull()
321{
Hans Boehma997b232019-04-12 16:59:00 -0700322 if (gHaveTLS.load(std::memory_order_acquire)) {
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800323 const pthread_key_t k = gTLS;
324 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(k);
325 return st;
326 }
Yi Kongfdd8da92018-06-07 17:52:27 -0700327 return nullptr;
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800328}
329
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800330void IPCThreadState::shutdown()
331{
Hans Boehma997b232019-04-12 16:59:00 -0700332 gShutdown.store(true, std::memory_order_relaxed);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800333
Hans Boehma997b232019-04-12 16:59:00 -0700334 if (gHaveTLS.load(std::memory_order_acquire)) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800335 // XXX Need to wait for all thread pool threads to exit!
336 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(gTLS);
337 if (st) {
338 delete st;
Yi Kongfdd8da92018-06-07 17:52:27 -0700339 pthread_setspecific(gTLS, nullptr);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800340 }
zhongjieff405782016-03-09 15:05:04 +0800341 pthread_key_delete(gTLS);
Hans Boehma997b232019-04-12 16:59:00 -0700342 gHaveTLS.store(false, std::memory_order_release);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800343 }
344}
345
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -0800346void IPCThreadState::disableBackgroundScheduling(bool disable)
347{
Hans Boehma997b232019-04-12 16:59:00 -0700348 gDisableBackgroundScheduling.store(disable, std::memory_order_relaxed);
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -0800349}
350
Martijn Coenen2b631742017-05-05 11:16:59 -0700351bool IPCThreadState::backgroundSchedulingDisabled()
352{
Hans Boehma997b232019-04-12 16:59:00 -0700353 return gDisableBackgroundScheduling.load(std::memory_order_relaxed);
Martijn Coenen2b631742017-05-05 11:16:59 -0700354}
355
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800356sp<ProcessState> IPCThreadState::process()
357{
358 return mProcess;
359}
360
361status_t IPCThreadState::clearLastError()
362{
363 const status_t err = mLastError;
364 mLastError = NO_ERROR;
365 return err;
366}
367
Dan Stoza9c634fd2014-11-26 12:23:23 -0800368pid_t IPCThreadState::getCallingPid() const
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800369{
370 return mCallingPid;
371}
372
Steven Morelandf0212002018-12-26 13:59:23 -0800373const char* IPCThreadState::getCallingSid() const
374{
375 return mCallingSid;
376}
377
Dan Stoza9c634fd2014-11-26 12:23:23 -0800378uid_t IPCThreadState::getCallingUid() const
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800379{
380 return mCallingUid;
381}
382
383int64_t IPCThreadState::clearCallingIdentity()
384{
Steven Morelandf0212002018-12-26 13:59:23 -0800385 // ignore mCallingSid for legacy reasons
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800386 int64_t token = ((int64_t)mCallingUid<<32) | mCallingPid;
387 clearCaller();
388 return token;
389}
390
Brad Fitzpatrick702ea9d2010-06-18 13:07:53 -0700391void IPCThreadState::setStrictModePolicy(int32_t policy)
392{
393 mStrictModePolicy = policy;
394}
395
Brad Fitzpatricka877cd82010-07-07 16:06:39 -0700396int32_t IPCThreadState::getStrictModePolicy() const
397{
Brad Fitzpatrick702ea9d2010-06-18 13:07:53 -0700398 return mStrictModePolicy;
399}
400
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000401int64_t IPCThreadState::setCallingWorkSourceUid(uid_t uid)
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100402{
Olivier Gaillard91a04802018-11-14 17:32:41 +0000403 int64_t token = setCallingWorkSourceUidWithoutPropagation(uid);
404 mPropagateWorkSource = true;
405 return token;
406}
407
408int64_t IPCThreadState::setCallingWorkSourceUidWithoutPropagation(uid_t uid)
409{
410 const int64_t propagatedBit = ((int64_t)mPropagateWorkSource) << kWorkSourcePropagatedBitIndex;
411 int64_t token = propagatedBit | mWorkSource;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100412 mWorkSource = uid;
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000413 return token;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100414}
415
Olivier Gaillard91a04802018-11-14 17:32:41 +0000416void IPCThreadState::clearPropagateWorkSource()
417{
418 mPropagateWorkSource = false;
419}
420
421bool IPCThreadState::shouldPropagateWorkSource() const
422{
423 return mPropagateWorkSource;
424}
425
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000426uid_t IPCThreadState::getCallingWorkSourceUid() const
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100427{
428 return mWorkSource;
429}
430
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000431int64_t IPCThreadState::clearCallingWorkSource()
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100432{
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000433 return setCallingWorkSourceUid(kUnsetWorkSource);
434}
435
436void IPCThreadState::restoreCallingWorkSource(int64_t token)
437{
438 uid_t uid = (int)token;
Olivier Gaillard91a04802018-11-14 17:32:41 +0000439 setCallingWorkSourceUidWithoutPropagation(uid);
440 mPropagateWorkSource = ((token >> kWorkSourcePropagatedBitIndex) & 1) == 1;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100441}
442
Brad Fitzpatrick52736032010-08-30 16:01:16 -0700443void IPCThreadState::setLastTransactionBinderFlags(int32_t flags)
444{
445 mLastTransactionBinderFlags = flags;
446}
447
448int32_t IPCThreadState::getLastTransactionBinderFlags() const
449{
450 return mLastTransactionBinderFlags;
451}
452
Steven Moreland9514b202020-09-21 18:03:27 +0000453void IPCThreadState::setCallRestriction(ProcessState::CallRestriction restriction) {
454 mCallRestriction = restriction;
455}
456
457ProcessState::CallRestriction IPCThreadState::getCallRestriction() const {
458 return mCallRestriction;
459}
460
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800461void IPCThreadState::restoreCallingIdentity(int64_t token)
462{
463 mCallingUid = (int)(token>>32);
Steven Morelandf0212002018-12-26 13:59:23 -0800464 mCallingSid = nullptr; // not enough data to restore
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800465 mCallingPid = (int)token;
466}
467
468void IPCThreadState::clearCaller()
469{
Marco Nelissend43b1942009-07-17 07:59:17 -0700470 mCallingPid = getpid();
Steven Morelandf0212002018-12-26 13:59:23 -0800471 mCallingSid = nullptr; // expensive to lookup
Marco Nelissend43b1942009-07-17 07:59:17 -0700472 mCallingUid = getuid();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800473}
474
475void IPCThreadState::flushCommands()
476{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -0200477 if (mProcess->mDriverFD < 0)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800478 return;
479 talkWithDriver(false);
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700480 // The flush could have caused post-write refcount decrements to have
481 // been executed, which in turn could result in BC_RELEASE/BC_DECREFS
482 // being queued in mOut. So flush again, if we need to.
483 if (mOut.dataSize() > 0) {
484 talkWithDriver(false);
485 }
486 if (mOut.dataSize() > 0) {
487 ALOGW("mOut.dataSize() > 0 after flushCommands()");
488 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800489}
490
Martijn Coenen0442a862017-11-17 10:46:32 +0100491bool IPCThreadState::flushIfNeeded()
492{
493 if (mIsLooper || mServingStackPointer != nullptr) {
494 return false;
495 }
496 // In case this thread is not a looper and is not currently serving a binder transaction,
497 // there's no guarantee that this thread will call back into the kernel driver any time
498 // soon. Therefore, flush pending commands such as BC_FREE_BUFFER, to prevent them from getting
499 // stuck in this thread's out buffer.
500 flushCommands();
501 return true;
502}
503
Wale Ogunwale376b8222015-04-13 16:16:10 -0700504void IPCThreadState::blockUntilThreadAvailable()
505{
506 pthread_mutex_lock(&mProcess->mThreadCountLock);
Steven Morelandc648a762021-01-16 02:39:45 +0000507 mProcess->mWaitingForThreads++;
Wale Ogunwale376b8222015-04-13 16:16:10 -0700508 while (mProcess->mExecutingThreadsCount >= mProcess->mMaxThreads) {
Wale Ogunwalea3206e62015-04-21 12:29:50 -0700509 ALOGW("Waiting for thread to be free. mExecutingThreadsCount=%lu mMaxThreads=%lu\n",
510 static_cast<unsigned long>(mProcess->mExecutingThreadsCount),
511 static_cast<unsigned long>(mProcess->mMaxThreads));
Wale Ogunwale376b8222015-04-13 16:16:10 -0700512 pthread_cond_wait(&mProcess->mThreadCountDecrement, &mProcess->mThreadCountLock);
513 }
Steven Morelandc648a762021-01-16 02:39:45 +0000514 mProcess->mWaitingForThreads--;
Wale Ogunwale376b8222015-04-13 16:16:10 -0700515 pthread_mutex_unlock(&mProcess->mThreadCountLock);
516}
517
Todd Poynor8d96cab2013-06-25 19:12:18 -0700518status_t IPCThreadState::getAndExecuteCommand()
519{
520 status_t result;
521 int32_t cmd;
522
523 result = talkWithDriver();
524 if (result >= NO_ERROR) {
525 size_t IN = mIn.dataAvail();
526 if (IN < sizeof(int32_t)) return result;
527 cmd = mIn.readInt32();
528 IF_LOG_COMMANDS() {
529 alog << "Processing top-level Command: "
530 << getReturnString(cmd) << endl;
531 }
532
Wale Ogunwale376b8222015-04-13 16:16:10 -0700533 pthread_mutex_lock(&mProcess->mThreadCountLock);
534 mProcess->mExecutingThreadsCount++;
Colin Cross96e83222016-04-15 14:29:55 -0700535 if (mProcess->mExecutingThreadsCount >= mProcess->mMaxThreads &&
536 mProcess->mStarvationStartTimeMs == 0) {
537 mProcess->mStarvationStartTimeMs = uptimeMillis();
538 }
Wale Ogunwale376b8222015-04-13 16:16:10 -0700539 pthread_mutex_unlock(&mProcess->mThreadCountLock);
540
Todd Poynor8d96cab2013-06-25 19:12:18 -0700541 result = executeCommand(cmd);
542
Wale Ogunwale376b8222015-04-13 16:16:10 -0700543 pthread_mutex_lock(&mProcess->mThreadCountLock);
544 mProcess->mExecutingThreadsCount--;
Colin Cross96e83222016-04-15 14:29:55 -0700545 if (mProcess->mExecutingThreadsCount < mProcess->mMaxThreads &&
546 mProcess->mStarvationStartTimeMs != 0) {
547 int64_t starvationTimeMs = uptimeMillis() - mProcess->mStarvationStartTimeMs;
548 if (starvationTimeMs > 100) {
549 ALOGE("binder thread pool (%zu threads) starved for %" PRId64 " ms",
550 mProcess->mMaxThreads, starvationTimeMs);
551 }
552 mProcess->mStarvationStartTimeMs = 0;
553 }
Steven Morelandc648a762021-01-16 02:39:45 +0000554
555 // Cond broadcast can be expensive, so don't send it every time a binder
556 // call is processed. b/168806193
557 if (mProcess->mWaitingForThreads > 0) {
558 pthread_cond_broadcast(&mProcess->mThreadCountDecrement);
559 }
Wale Ogunwale376b8222015-04-13 16:16:10 -0700560 pthread_mutex_unlock(&mProcess->mThreadCountLock);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700561 }
562
563 return result;
564}
565
566// When we've cleared the incoming command queue, process any pending derefs
567void IPCThreadState::processPendingDerefs()
568{
569 if (mIn.dataPosition() >= mIn.dataSize()) {
Martijn Coenen0791fbf2017-08-08 15:36:16 +0200570 /*
571 * The decWeak()/decStrong() calls may cause a destructor to run,
572 * which in turn could have initiated an outgoing transaction,
573 * which in turn could cause us to add to the pending refs
574 * vectors; so instead of simply iterating, loop until they're empty.
575 *
576 * We do this in an outer loop, because calling decStrong()
577 * may result in something being added to mPendingWeakDerefs,
578 * which could be delayed until the next incoming command
579 * from the driver if we don't process it now.
580 */
581 while (mPendingWeakDerefs.size() > 0 || mPendingStrongDerefs.size() > 0) {
582 while (mPendingWeakDerefs.size() > 0) {
583 RefBase::weakref_type* refs = mPendingWeakDerefs[0];
584 mPendingWeakDerefs.removeAt(0);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700585 refs->decWeak(mProcess.get());
586 }
Todd Poynor8d96cab2013-06-25 19:12:18 -0700587
Martijn Coenen0791fbf2017-08-08 15:36:16 +0200588 if (mPendingStrongDerefs.size() > 0) {
589 // We don't use while() here because we don't want to re-order
590 // strong and weak decs at all; if this decStrong() causes both a
591 // decWeak() and a decStrong() to be queued, we want to process
592 // the decWeak() first.
593 BBinder* obj = mPendingStrongDerefs[0];
594 mPendingStrongDerefs.removeAt(0);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700595 obj->decStrong(mProcess.get());
596 }
Todd Poynor8d96cab2013-06-25 19:12:18 -0700597 }
598 }
599}
600
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700601void IPCThreadState::processPostWriteDerefs()
602{
603 for (size_t i = 0; i < mPostWriteWeakDerefs.size(); i++) {
604 RefBase::weakref_type* refs = mPostWriteWeakDerefs[i];
605 refs->decWeak(mProcess.get());
606 }
607 mPostWriteWeakDerefs.clear();
608
609 for (size_t i = 0; i < mPostWriteStrongDerefs.size(); i++) {
610 RefBase* obj = mPostWriteStrongDerefs[i];
611 obj->decStrong(mProcess.get());
612 }
613 mPostWriteStrongDerefs.clear();
614}
615
Jintao Zhu413a00e2021-01-16 17:42:00 +0800616void IPCThreadState::createTransactionReference(RefBase* ref)
617{
618 ref->incStrong(mProcess.get());
619 mPostWriteStrongDerefs.push(ref);
620}
621
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800622void IPCThreadState::joinThreadPool(bool isMain)
623{
624 LOG_THREADPOOL("**** THREAD %p (PID %d) IS JOINING THE THREAD POOL\n", (void*)pthread_self(), getpid());
625
626 mOut.writeInt32(isMain ? BC_ENTER_LOOPER : BC_REGISTER_LOOPER);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800627
Martijn Coenen0442a862017-11-17 10:46:32 +0100628 mIsLooper = true;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800629 status_t result;
630 do {
Todd Poynor8d96cab2013-06-25 19:12:18 -0700631 processPendingDerefs();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800632 // now get the next command to be processed, waiting if necessary
Todd Poynor8d96cab2013-06-25 19:12:18 -0700633 result = getAndExecuteCommand();
Jason Parksdcd39582009-11-03 12:14:38 -0800634
Todd Poynor8d96cab2013-06-25 19:12:18 -0700635 if (result < NO_ERROR && result != TIMED_OUT && result != -ECONNREFUSED && result != -EBADF) {
Steven Moreland6adf33c2019-09-25 13:18:09 -0700636 LOG_ALWAYS_FATAL("getAndExecuteCommand(fd=%d) returned unexpected error %d, aborting",
Jeff Tinkeref073862013-06-11 11:30:21 -0700637 mProcess->mDriverFD, result);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800638 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800639
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800640 // Let this thread exit the thread pool if it is no longer
641 // needed and it is not the main process thread.
642 if(result == TIMED_OUT && !isMain) {
643 break;
644 }
645 } while (result != -ECONNREFUSED && result != -EBADF);
646
Wei Wangc7341432016-10-19 10:23:59 -0700647 LOG_THREADPOOL("**** THREAD %p (PID %d) IS LEAVING THE THREAD POOL err=%d\n",
648 (void*)pthread_self(), getpid(), result);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800649
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800650 mOut.writeInt32(BC_EXIT_LOOPER);
Martijn Coenen0442a862017-11-17 10:46:32 +0100651 mIsLooper = false;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800652 talkWithDriver(false);
653}
654
Steven Morelandd8c85672020-07-24 21:30:41 +0000655status_t IPCThreadState::setupPolling(int* fd)
Todd Poynor8d96cab2013-06-25 19:12:18 -0700656{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -0200657 if (mProcess->mDriverFD < 0) {
Todd Poynor8d96cab2013-06-25 19:12:18 -0700658 return -EBADF;
659 }
660
661 mOut.writeInt32(BC_ENTER_LOOPER);
Steven Morelandf210b502021-01-15 23:40:32 +0000662 flushCommands();
Todd Poynor8d96cab2013-06-25 19:12:18 -0700663 *fd = mProcess->mDriverFD;
664 return 0;
665}
666
667status_t IPCThreadState::handlePolledCommands()
668{
669 status_t result;
670
671 do {
672 result = getAndExecuteCommand();
673 } while (mIn.dataPosition() < mIn.dataSize());
674
675 processPendingDerefs();
676 flushCommands();
677 return result;
678}
679
Colin Cross6f4f3ab2014-02-05 17:42:44 -0800680void IPCThreadState::stopProcess(bool /*immediate*/)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800681{
Steve Blocka19954a2012-01-04 20:05:49 +0000682 //ALOGI("**** STOPPING PROCESS");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800683 flushCommands();
684 int fd = mProcess->mDriverFD;
685 mProcess->mDriverFD = -1;
686 close(fd);
687 //kill(getpid(), SIGKILL);
688}
689
690status_t IPCThreadState::transact(int32_t handle,
691 uint32_t code, const Parcel& data,
692 Parcel* reply, uint32_t flags)
693{
Steven Moreland5553ac42020-11-11 02:14:45 +0000694 LOG_ALWAYS_FATAL_IF(data.isForRpc(), "Parcel constructed for RPC, but being used with binder.");
695
Ganesh Mahendran58e5daa2017-10-11 18:05:13 +0800696 status_t err;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800697
698 flags |= TF_ACCEPT_FDS;
699
700 IF_LOG_TRANSACTIONS() {
701 TextOutput::Bundle _b(alog);
702 alog << "BC_TRANSACTION thr " << (void*)pthread_self() << " / hand "
703 << handle << " / code " << TypeCode(code) << ": "
704 << indent << data << dedent << endl;
705 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800706
Ganesh Mahendran58e5daa2017-10-11 18:05:13 +0800707 LOG_ONEWAY(">>>> SEND from pid %d uid %d %s", getpid(), getuid(),
708 (flags & TF_ONE_WAY) == 0 ? "READ REPLY" : "ONE WAY");
Yi Kongfdd8da92018-06-07 17:52:27 -0700709 err = writeTransactionData(BC_TRANSACTION, flags, handle, code, data, nullptr);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800710
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800711 if (err != NO_ERROR) {
712 if (reply) reply->setError(err);
713 return (mLastError = err);
714 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800715
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800716 if ((flags & TF_ONE_WAY) == 0) {
Steven Moreland7732a092019-01-02 17:54:16 -0800717 if (UNLIKELY(mCallRestriction != ProcessState::CallRestriction::NONE)) {
718 if (mCallRestriction == ProcessState::CallRestriction::ERROR_IF_NOT_ONEWAY) {
Steven Moreland8cb34fc2019-05-13 11:44:55 -0700719 ALOGE("Process making non-oneway call (code: %u) but is restricted.", code);
Steven Moreland7732a092019-01-02 17:54:16 -0800720 CallStack::logStack("non-oneway call", CallStack::getCurrent(10).get(),
721 ANDROID_LOG_ERROR);
722 } else /* FATAL_IF_NOT_ONEWAY */ {
Steven Morelandfcc77f12020-09-01 01:16:11 +0000723 LOG_ALWAYS_FATAL("Process may not make non-oneway calls (code: %u).", code);
Steven Moreland7732a092019-01-02 17:54:16 -0800724 }
725 }
726
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700727 #if 0
728 if (code == 4) { // relayout
Steve Blocka19954a2012-01-04 20:05:49 +0000729 ALOGI(">>>>>> CALLING transaction 4");
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700730 } else {
Steve Blocka19954a2012-01-04 20:05:49 +0000731 ALOGI(">>>>>> CALLING transaction %d", code);
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700732 }
733 #endif
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800734 if (reply) {
735 err = waitForResponse(reply);
736 } else {
737 Parcel fakeReply;
738 err = waitForResponse(&fakeReply);
739 }
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700740 #if 0
741 if (code == 4) { // relayout
Steve Blocka19954a2012-01-04 20:05:49 +0000742 ALOGI("<<<<<< RETURNING transaction 4");
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700743 } else {
Steve Blocka19954a2012-01-04 20:05:49 +0000744 ALOGI("<<<<<< RETURNING transaction %d", code);
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700745 }
746 #endif
Tim Murrayd429f4a2017-03-07 09:31:09 -0800747
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800748 IF_LOG_TRANSACTIONS() {
749 TextOutput::Bundle _b(alog);
750 alog << "BR_REPLY thr " << (void*)pthread_self() << " / hand "
751 << handle << ": ";
752 if (reply) alog << indent << *reply << dedent << endl;
753 else alog << "(none requested)" << endl;
754 }
755 } else {
Yi Kongfdd8da92018-06-07 17:52:27 -0700756 err = waitForResponse(nullptr, nullptr);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800757 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800758
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800759 return err;
760}
761
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700762void IPCThreadState::incStrongHandle(int32_t handle, BpBinder *proxy)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800763{
764 LOG_REMOTEREFS("IPCThreadState::incStrongHandle(%d)\n", handle);
765 mOut.writeInt32(BC_ACQUIRE);
766 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100767 if (!flushIfNeeded()) {
768 // Create a temp reference until the driver has handled this command.
769 proxy->incStrong(mProcess.get());
770 mPostWriteStrongDerefs.push(proxy);
771 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800772}
773
774void IPCThreadState::decStrongHandle(int32_t handle)
775{
776 LOG_REMOTEREFS("IPCThreadState::decStrongHandle(%d)\n", handle);
777 mOut.writeInt32(BC_RELEASE);
778 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100779 flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800780}
781
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700782void IPCThreadState::incWeakHandle(int32_t handle, BpBinder *proxy)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800783{
784 LOG_REMOTEREFS("IPCThreadState::incWeakHandle(%d)\n", handle);
785 mOut.writeInt32(BC_INCREFS);
786 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100787 if (!flushIfNeeded()) {
788 // Create a temp reference until the driver has handled this command.
789 proxy->getWeakRefs()->incWeak(mProcess.get());
790 mPostWriteWeakDerefs.push(proxy->getWeakRefs());
791 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800792}
793
794void IPCThreadState::decWeakHandle(int32_t handle)
795{
796 LOG_REMOTEREFS("IPCThreadState::decWeakHandle(%d)\n", handle);
797 mOut.writeInt32(BC_DECREFS);
798 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100799 flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800800}
801
802status_t IPCThreadState::attemptIncStrongHandle(int32_t handle)
803{
Arve HjønnevÄg11cfdcc2014-02-14 20:14:02 -0800804#if HAS_BC_ATTEMPT_ACQUIRE
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700805 LOG_REMOTEREFS("IPCThreadState::attemptIncStrongHandle(%d)\n", handle);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800806 mOut.writeInt32(BC_ATTEMPT_ACQUIRE);
807 mOut.writeInt32(0); // xxx was thread priority
808 mOut.writeInt32(handle);
809 status_t result = UNKNOWN_ERROR;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800810
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800811 waitForResponse(NULL, &result);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800812
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800813#if LOG_REFCOUNTS
liangweikanga43ee152016-10-25 16:37:54 +0800814 ALOGV("IPCThreadState::attemptIncStrongHandle(%ld) = %s\n",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800815 handle, result == NO_ERROR ? "SUCCESS" : "FAILURE");
816#endif
Tim Murrayd429f4a2017-03-07 09:31:09 -0800817
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800818 return result;
Arve HjønnevÄg11cfdcc2014-02-14 20:14:02 -0800819#else
820 (void)handle;
821 ALOGE("%s(%d): Not supported\n", __func__, handle);
822 return INVALID_OPERATION;
823#endif
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800824}
825
826void IPCThreadState::expungeHandle(int32_t handle, IBinder* binder)
827{
828#if LOG_REFCOUNTS
liangweikanga43ee152016-10-25 16:37:54 +0800829 ALOGV("IPCThreadState::expungeHandle(%ld)\n", handle);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800830#endif
Manoj Gupta9cec85b2017-09-19 16:34:29 -0700831 self()->mProcess->expungeHandle(handle, binder); // NOLINT
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800832}
833
834status_t IPCThreadState::requestDeathNotification(int32_t handle, BpBinder* proxy)
835{
836 mOut.writeInt32(BC_REQUEST_DEATH_NOTIFICATION);
837 mOut.writeInt32((int32_t)handle);
Serban Constantinescuf683e012013-11-05 16:53:55 +0000838 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800839 return NO_ERROR;
840}
841
842status_t IPCThreadState::clearDeathNotification(int32_t handle, BpBinder* proxy)
843{
844 mOut.writeInt32(BC_CLEAR_DEATH_NOTIFICATION);
845 mOut.writeInt32((int32_t)handle);
Serban Constantinescuf683e012013-11-05 16:53:55 +0000846 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800847 return NO_ERROR;
848}
849
850IPCThreadState::IPCThreadState()
Brad Fitzpatrick52736032010-08-30 16:01:16 -0700851 : mProcess(ProcessState::self()),
Steven Moreland39d887d2020-01-31 14:56:45 -0800852 mServingStackPointer(nullptr),
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100853 mWorkSource(kUnsetWorkSource),
Olivier Gaillard91a04802018-11-14 17:32:41 +0000854 mPropagateWorkSource(false),
Martijn Coenen0442a862017-11-17 10:46:32 +0100855 mIsLooper(false),
Brad Fitzpatrick52736032010-08-30 16:01:16 -0700856 mStrictModePolicy(0),
Steven Moreland7732a092019-01-02 17:54:16 -0800857 mLastTransactionBinderFlags(0),
858 mCallRestriction(mProcess->mCallRestriction)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800859{
860 pthread_setspecific(gTLS, this);
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -0800861 clearCaller();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800862 mIn.setDataCapacity(256);
863 mOut.setDataCapacity(256);
864}
865
866IPCThreadState::~IPCThreadState()
867{
868}
869
Martijn Coenenea0090a2017-11-02 18:54:40 +0000870status_t IPCThreadState::sendReply(const Parcel& reply, uint32_t flags)
871{
872 status_t err;
873 status_t statusBuffer;
874 err = writeTransactionData(BC_REPLY, flags, -1, 0, reply, &statusBuffer);
875 if (err < NO_ERROR) return err;
876
Yi Kongfdd8da92018-06-07 17:52:27 -0700877 return waitForResponse(nullptr, nullptr);
Martijn Coenenea0090a2017-11-02 18:54:40 +0000878}
879
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800880status_t IPCThreadState::waitForResponse(Parcel *reply, status_t *acquireResult)
881{
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100882 uint32_t cmd;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800883 int32_t err;
884
885 while (1) {
886 if ((err=talkWithDriver()) < NO_ERROR) break;
887 err = mIn.errorCheck();
888 if (err < NO_ERROR) break;
889 if (mIn.dataAvail() == 0) continue;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800890
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100891 cmd = (uint32_t)mIn.readInt32();
Tim Murrayd429f4a2017-03-07 09:31:09 -0800892
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800893 IF_LOG_COMMANDS() {
894 alog << "Processing waitForResponse Command: "
895 << getReturnString(cmd) << endl;
896 }
897
898 switch (cmd) {
Hang Lub185ac02021-03-24 13:17:22 +0800899 case BR_ONEWAY_SPAM_SUSPECT:
900 ALOGE("Process seems to be sending too many oneway calls.");
901 CallStack::logStack("oneway spamming", CallStack::getCurrent().get(),
902 ANDROID_LOG_ERROR);
903 [[fallthrough]];
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800904 case BR_TRANSACTION_COMPLETE:
905 if (!reply && !acquireResult) goto finish;
906 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800907
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800908 case BR_DEAD_REPLY:
909 err = DEAD_OBJECT;
910 goto finish;
911
912 case BR_FAILED_REPLY:
913 err = FAILED_TRANSACTION;
914 goto finish;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800915
Marco Ballesio7ee17572020-09-08 10:30:03 -0700916 case BR_FROZEN_REPLY:
917 err = FAILED_TRANSACTION;
918 goto finish;
919
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800920 case BR_ACQUIRE_RESULT:
921 {
Steve Block67263472012-01-09 18:35:44 +0000922 ALOG_ASSERT(acquireResult != NULL, "Unexpected brACQUIRE_RESULT");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800923 const int32_t result = mIn.readInt32();
924 if (!acquireResult) continue;
925 *acquireResult = result ? NO_ERROR : INVALID_OPERATION;
926 }
927 goto finish;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800928
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800929 case BR_REPLY:
930 {
931 binder_transaction_data tr;
932 err = mIn.read(&tr, sizeof(tr));
Steve Block67263472012-01-09 18:35:44 +0000933 ALOG_ASSERT(err == NO_ERROR, "Not enough command data for brREPLY");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800934 if (err != NO_ERROR) goto finish;
935
936 if (reply) {
937 if ((tr.flags & TF_STATUS_CODE) == 0) {
938 reply->ipcSetDataReference(
939 reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
940 tr.data_size,
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -0800941 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
942 tr.offsets_size/sizeof(binder_size_t),
Steven Moreland161fe122020-11-12 23:16:47 +0000943 freeBuffer);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800944 } else {
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -0800945 err = *reinterpret_cast<const status_t*>(tr.data.ptr.buffer);
Yi Kongfdd8da92018-06-07 17:52:27 -0700946 freeBuffer(nullptr,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800947 reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
948 tr.data_size,
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -0800949 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
Steven Moreland161fe122020-11-12 23:16:47 +0000950 tr.offsets_size/sizeof(binder_size_t));
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800951 }
952 } else {
Yi Kongfdd8da92018-06-07 17:52:27 -0700953 freeBuffer(nullptr,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800954 reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
955 tr.data_size,
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -0800956 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
Steven Moreland161fe122020-11-12 23:16:47 +0000957 tr.offsets_size/sizeof(binder_size_t));
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800958 continue;
959 }
960 }
961 goto finish;
962
963 default:
964 err = executeCommand(cmd);
965 if (err != NO_ERROR) goto finish;
966 break;
967 }
968 }
969
970finish:
971 if (err != NO_ERROR) {
972 if (acquireResult) *acquireResult = err;
973 if (reply) reply->setError(err);
974 mLastError = err;
975 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800976
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800977 return err;
978}
979
980status_t IPCThreadState::talkWithDriver(bool doReceive)
981{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -0200982 if (mProcess->mDriverFD < 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +0100983 return -EBADF;
984 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800985
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800986 binder_write_read bwr;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800987
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800988 // Is the read buffer empty?
989 const bool needRead = mIn.dataPosition() >= mIn.dataSize();
Tim Murrayd429f4a2017-03-07 09:31:09 -0800990
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800991 // We don't want to write anything if we are still reading
992 // from data left in the input buffer and the caller
993 // has requested to read the next data.
994 const size_t outAvail = (!doReceive || needRead) ? mOut.dataSize() : 0;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800995
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800996 bwr.write_size = outAvail;
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -0800997 bwr.write_buffer = (uintptr_t)mOut.data();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800998
999 // This is what we'll read.
1000 if (doReceive && needRead) {
1001 bwr.read_size = mIn.dataCapacity();
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001002 bwr.read_buffer = (uintptr_t)mIn.data();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001003 } else {
1004 bwr.read_size = 0;
Ben Chengd640f892011-12-01 17:11:32 -08001005 bwr.read_buffer = 0;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001006 }
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001007
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001008 IF_LOG_COMMANDS() {
1009 TextOutput::Bundle _b(alog);
1010 if (outAvail != 0) {
1011 alog << "Sending commands to driver: " << indent;
1012 const void* cmds = (const void*)bwr.write_buffer;
1013 const void* end = ((const uint8_t*)cmds)+bwr.write_size;
1014 alog << HexDump(cmds, bwr.write_size) << endl;
1015 while (cmds < end) cmds = printCommand(alog, cmds);
1016 alog << dedent;
1017 }
1018 alog << "Size of receive buffer: " << bwr.read_size
1019 << ", needRead: " << needRead << ", doReceive: " << doReceive << endl;
1020 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001021
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001022 // Return immediately if there is nothing to do.
1023 if ((bwr.write_size == 0) && (bwr.read_size == 0)) return NO_ERROR;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001024
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001025 bwr.write_consumed = 0;
1026 bwr.read_consumed = 0;
1027 status_t err;
1028 do {
1029 IF_LOG_COMMANDS() {
1030 alog << "About to read/write, write size = " << mOut.dataSize() << endl;
1031 }
Elliott Hughes6071da72015-08-12 15:27:47 -07001032#if defined(__ANDROID__)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001033 if (ioctl(mProcess->mDriverFD, BINDER_WRITE_READ, &bwr) >= 0)
1034 err = NO_ERROR;
1035 else
1036 err = -errno;
1037#else
1038 err = INVALID_OPERATION;
1039#endif
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -02001040 if (mProcess->mDriverFD < 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +01001041 err = -EBADF;
1042 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001043 IF_LOG_COMMANDS() {
1044 alog << "Finished read/write, write size = " << mOut.dataSize() << endl;
1045 }
1046 } while (err == -EINTR);
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001047
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001048 IF_LOG_COMMANDS() {
Colin Cross6f4f3ab2014-02-05 17:42:44 -08001049 alog << "Our err: " << (void*)(intptr_t)err << ", write consumed: "
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001050 << bwr.write_consumed << " (of " << mOut.dataSize()
Todd Poynor8d96cab2013-06-25 19:12:18 -07001051 << "), read consumed: " << bwr.read_consumed << endl;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001052 }
1053
1054 if (err >= NO_ERROR) {
1055 if (bwr.write_consumed > 0) {
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001056 if (bwr.write_consumed < mOut.dataSize())
Steven Morelandb077deb2020-04-16 16:22:52 -07001057 LOG_ALWAYS_FATAL("Driver did not consume write buffer. "
1058 "err: %s consumed: %zu of %zu",
1059 statusToString(err).c_str(),
1060 (size_t)bwr.write_consumed,
1061 mOut.dataSize());
Martijn Coenen7c170bb2018-05-04 17:28:55 -07001062 else {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001063 mOut.setDataSize(0);
Martijn Coenen7c170bb2018-05-04 17:28:55 -07001064 processPostWriteDerefs();
1065 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001066 }
1067 if (bwr.read_consumed > 0) {
1068 mIn.setDataSize(bwr.read_consumed);
1069 mIn.setDataPosition(0);
1070 }
1071 IF_LOG_COMMANDS() {
1072 TextOutput::Bundle _b(alog);
1073 alog << "Remaining data size: " << mOut.dataSize() << endl;
1074 alog << "Received commands from driver: " << indent;
1075 const void* cmds = mIn.data();
1076 const void* end = mIn.data() + mIn.dataSize();
1077 alog << HexDump(cmds, mIn.dataSize()) << endl;
1078 while (cmds < end) cmds = printReturnCommand(alog, cmds);
1079 alog << dedent;
1080 }
1081 return NO_ERROR;
1082 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001083
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001084 return err;
1085}
1086
1087status_t IPCThreadState::writeTransactionData(int32_t cmd, uint32_t binderFlags,
1088 int32_t handle, uint32_t code, const Parcel& data, status_t* statusBuffer)
1089{
1090 binder_transaction_data tr;
1091
Arve HjønnevÄg07fd0f12014-02-18 21:10:29 -08001092 tr.target.ptr = 0; /* Don't pass uninitialized stack data to a remote process */
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001093 tr.target.handle = handle;
1094 tr.code = code;
1095 tr.flags = binderFlags;
Evgeniy Stepanovd5474322011-04-21 14:15:00 +04001096 tr.cookie = 0;
1097 tr.sender_pid = 0;
1098 tr.sender_euid = 0;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001099
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001100 const status_t err = data.errorCheck();
1101 if (err == NO_ERROR) {
1102 tr.data_size = data.ipcDataSize();
1103 tr.data.ptr.buffer = data.ipcData();
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001104 tr.offsets_size = data.ipcObjectsCount()*sizeof(binder_size_t);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001105 tr.data.ptr.offsets = data.ipcObjects();
1106 } else if (statusBuffer) {
1107 tr.flags |= TF_STATUS_CODE;
1108 *statusBuffer = err;
1109 tr.data_size = sizeof(status_t);
Arve HjønnevÄg87b30d02014-02-18 21:04:31 -08001110 tr.data.ptr.buffer = reinterpret_cast<uintptr_t>(statusBuffer);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001111 tr.offsets_size = 0;
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001112 tr.data.ptr.offsets = 0;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001113 } else {
1114 return (mLastError = err);
1115 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001116
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001117 mOut.writeInt32(cmd);
1118 mOut.write(&tr, sizeof(tr));
Tim Murrayd429f4a2017-03-07 09:31:09 -08001119
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001120 return NO_ERROR;
1121}
1122
1123sp<BBinder> the_context_object;
1124
Jiyong Park384328e2020-11-13 17:16:48 +09001125void IPCThreadState::setTheContextObject(const sp<BBinder>& obj)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001126{
1127 the_context_object = obj;
1128}
1129
1130status_t IPCThreadState::executeCommand(int32_t cmd)
1131{
1132 BBinder* obj;
1133 RefBase::weakref_type* refs;
1134 status_t result = NO_ERROR;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001135
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +01001136 switch ((uint32_t)cmd) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001137 case BR_ERROR:
1138 result = mIn.readInt32();
1139 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001140
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001141 case BR_OK:
1142 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001143
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001144 case BR_ACQUIRE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001145 refs = (RefBase::weakref_type*)mIn.readPointer();
1146 obj = (BBinder*)mIn.readPointer();
Steve Block67263472012-01-09 18:35:44 +00001147 ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001148 "BR_ACQUIRE: object %p does not match cookie %p (expected %p)",
1149 refs, obj, refs->refBase());
1150 obj->incStrong(mProcess.get());
1151 IF_LOG_REMOTEREFS() {
1152 LOG_REMOTEREFS("BR_ACQUIRE from driver on %p", obj);
1153 obj->printRefs();
1154 }
1155 mOut.writeInt32(BC_ACQUIRE_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001156 mOut.writePointer((uintptr_t)refs);
1157 mOut.writePointer((uintptr_t)obj);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001158 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001159
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001160 case BR_RELEASE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001161 refs = (RefBase::weakref_type*)mIn.readPointer();
1162 obj = (BBinder*)mIn.readPointer();
Steve Block67263472012-01-09 18:35:44 +00001163 ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001164 "BR_RELEASE: object %p does not match cookie %p (expected %p)",
1165 refs, obj, refs->refBase());
1166 IF_LOG_REMOTEREFS() {
1167 LOG_REMOTEREFS("BR_RELEASE from driver on %p", obj);
1168 obj->printRefs();
1169 }
1170 mPendingStrongDerefs.push(obj);
1171 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001172
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001173 case BR_INCREFS:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001174 refs = (RefBase::weakref_type*)mIn.readPointer();
1175 obj = (BBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001176 refs->incWeak(mProcess.get());
1177 mOut.writeInt32(BC_INCREFS_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001178 mOut.writePointer((uintptr_t)refs);
1179 mOut.writePointer((uintptr_t)obj);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001180 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001181
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001182 case BR_DECREFS:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001183 refs = (RefBase::weakref_type*)mIn.readPointer();
1184 obj = (BBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001185 // NOTE: This assertion is not valid, because the object may no
1186 // longer exist (thus the (BBinder*)cast above resulting in a different
1187 // memory address).
Steve Block67263472012-01-09 18:35:44 +00001188 //ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001189 // "BR_DECREFS: object %p does not match cookie %p (expected %p)",
1190 // refs, obj, refs->refBase());
1191 mPendingWeakDerefs.push(refs);
1192 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001193
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001194 case BR_ATTEMPT_ACQUIRE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001195 refs = (RefBase::weakref_type*)mIn.readPointer();
1196 obj = (BBinder*)mIn.readPointer();
Tim Murrayd429f4a2017-03-07 09:31:09 -08001197
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001198 {
1199 const bool success = refs->attemptIncStrong(mProcess.get());
Steve Block67263472012-01-09 18:35:44 +00001200 ALOG_ASSERT(success && refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001201 "BR_ATTEMPT_ACQUIRE: object %p does not match cookie %p (expected %p)",
1202 refs, obj, refs->refBase());
Tim Murrayd429f4a2017-03-07 09:31:09 -08001203
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001204 mOut.writeInt32(BC_ACQUIRE_RESULT);
1205 mOut.writeInt32((int32_t)success);
1206 }
1207 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001208
Steven Morelandf0212002018-12-26 13:59:23 -08001209 case BR_TRANSACTION_SEC_CTX:
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001210 case BR_TRANSACTION:
1211 {
Steven Morelandf0212002018-12-26 13:59:23 -08001212 binder_transaction_data_secctx tr_secctx;
1213 binder_transaction_data& tr = tr_secctx.transaction_data;
1214
1215 if (cmd == (int) BR_TRANSACTION_SEC_CTX) {
1216 result = mIn.read(&tr_secctx, sizeof(tr_secctx));
1217 } else {
1218 result = mIn.read(&tr, sizeof(tr));
1219 tr_secctx.secctx = 0;
1220 }
1221
Steve Block67263472012-01-09 18:35:44 +00001222 ALOG_ASSERT(result == NO_ERROR,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001223 "Not enough command data for brTRANSACTION");
1224 if (result != NO_ERROR) break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001225
Martijn Coenenea0090a2017-11-02 18:54:40 +00001226 Parcel buffer;
1227 buffer.ipcSetDataReference(
1228 reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
1229 tr.data_size,
1230 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
Steven Moreland161fe122020-11-12 23:16:47 +00001231 tr.offsets_size/sizeof(binder_size_t), freeBuffer);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001232
Steven Moreland39d887d2020-01-31 14:56:45 -08001233 const void* origServingStackPointer = mServingStackPointer;
1234 mServingStackPointer = &origServingStackPointer; // anything on the stack
1235
Martijn Coenenea0090a2017-11-02 18:54:40 +00001236 const pid_t origPid = mCallingPid;
Steven Morelandf0212002018-12-26 13:59:23 -08001237 const char* origSid = mCallingSid;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001238 const uid_t origUid = mCallingUid;
1239 const int32_t origStrictModePolicy = mStrictModePolicy;
1240 const int32_t origTransactionBinderFlags = mLastTransactionBinderFlags;
Olivier Gaillard91a04802018-11-14 17:32:41 +00001241 const int32_t origWorkSource = mWorkSource;
1242 const bool origPropagateWorkSet = mPropagateWorkSource;
1243 // Calling work source will be set by Parcel#enforceInterface. Parcel#enforceInterface
1244 // is only guaranteed to be called for AIDL-generated stubs so we reset the work source
1245 // here to never propagate it.
1246 clearCallingWorkSource();
1247 clearPropagateWorkSource();
Martijn Coenenea0090a2017-11-02 18:54:40 +00001248
1249 mCallingPid = tr.sender_pid;
Steven Morelandf0212002018-12-26 13:59:23 -08001250 mCallingSid = reinterpret_cast<const char*>(tr_secctx.secctx);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001251 mCallingUid = tr.sender_euid;
1252 mLastTransactionBinderFlags = tr.flags;
1253
Steven Morelandf0212002018-12-26 13:59:23 -08001254 // ALOGI(">>>> TRANSACT from pid %d sid %s uid %d\n", mCallingPid,
1255 // (mCallingSid ? mCallingSid : "<N/A>"), mCallingUid);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001256
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001257 Parcel reply;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001258 status_t error;
1259 IF_LOG_TRANSACTIONS() {
1260 TextOutput::Bundle _b(alog);
1261 alog << "BR_TRANSACTION thr " << (void*)pthread_self()
1262 << " / obj " << tr.target.ptr << " / code "
1263 << TypeCode(tr.code) << ": " << indent << buffer
1264 << dedent << endl
1265 << "Data addr = "
1266 << reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer)
1267 << ", offsets addr="
1268 << reinterpret_cast<const size_t*>(tr.data.ptr.offsets) << endl;
1269 }
1270 if (tr.target.ptr) {
1271 // We only have a weak reference on the target object, so we must first try to
1272 // safely acquire a strong reference before doing anything else with it.
1273 if (reinterpret_cast<RefBase::weakref_type*>(
1274 tr.target.ptr)->attemptIncStrong(this)) {
1275 error = reinterpret_cast<BBinder*>(tr.cookie)->transact(tr.code, buffer,
1276 &reply, tr.flags);
1277 reinterpret_cast<BBinder*>(tr.cookie)->decStrong(this);
Dianne Hackbornc1114612016-03-21 10:36:54 -07001278 } else {
Martijn Coenenea0090a2017-11-02 18:54:40 +00001279 error = UNKNOWN_TRANSACTION;
Dianne Hackbornc1114612016-03-21 10:36:54 -07001280 }
Brad Fitzpatrick52736032010-08-30 16:01:16 -07001281
Martijn Coenenea0090a2017-11-02 18:54:40 +00001282 } else {
1283 error = the_context_object->transact(tr.code, buffer, &reply, tr.flags);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001284 }
Dianne Hackborn5ee2c9d2014-09-30 11:30:03 -07001285
Steven Morelandf0212002018-12-26 13:59:23 -08001286 //ALOGI("<<<< TRANSACT from pid %d restore pid %d sid %s uid %d\n",
1287 // mCallingPid, origPid, (origSid ? origSid : "<N/A>"), origUid);
Tim Murrayd429f4a2017-03-07 09:31:09 -08001288
Martijn Coenenea0090a2017-11-02 18:54:40 +00001289 if ((tr.flags & TF_ONE_WAY) == 0) {
1290 LOG_ONEWAY("Sending reply to %d!", mCallingPid);
1291 if (error < NO_ERROR) reply.setError(error);
Steven Morelandf183fdd2020-10-27 00:12:12 +00001292
1293 constexpr uint32_t kForwardReplyFlags = TF_CLEAR_BUF;
1294 sendReply(reply, (tr.flags & kForwardReplyFlags));
Martijn Coenenea0090a2017-11-02 18:54:40 +00001295 } else {
Steven Moreland80844f72020-12-12 02:06:08 +00001296 if (error != OK) {
1297 alog << "oneway function results for code " << tr.code
1298 << " on binder at "
1299 << reinterpret_cast<void*>(tr.target.ptr)
1300 << " will be dropped but finished with status "
1301 << statusToString(error);
1302
1303 // ideally we could log this even when error == OK, but it
1304 // causes too much logspam because some manually-written
1305 // interfaces have clients that call methods which always
1306 // write results, sometimes as oneway methods.
1307 if (reply.dataSize() != 0) {
1308 alog << " and reply parcel size " << reply.dataSize();
1309 }
1310
1311 alog << endl;
Steven Morelandce66b8a2020-02-10 14:43:14 -08001312 }
Martijn Coenenea0090a2017-11-02 18:54:40 +00001313 LOG_ONEWAY("NOT sending reply to %d!", mCallingPid);
1314 }
1315
Steven Moreland39d887d2020-01-31 14:56:45 -08001316 mServingStackPointer = origServingStackPointer;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001317 mCallingPid = origPid;
Steven Morelandf0212002018-12-26 13:59:23 -08001318 mCallingSid = origSid;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001319 mCallingUid = origUid;
1320 mStrictModePolicy = origStrictModePolicy;
1321 mLastTransactionBinderFlags = origTransactionBinderFlags;
Olivier Gaillard91a04802018-11-14 17:32:41 +00001322 mWorkSource = origWorkSource;
1323 mPropagateWorkSource = origPropagateWorkSet;
Christopher Tate440fd872010-03-18 17:55:03 -07001324
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001325 IF_LOG_TRANSACTIONS() {
1326 TextOutput::Bundle _b(alog);
1327 alog << "BC_REPLY thr " << (void*)pthread_self() << " / obj "
1328 << tr.target.ptr << ": " << indent << reply << dedent << endl;
1329 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001330
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001331 }
1332 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001333
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001334 case BR_DEAD_BINDER:
1335 {
Serban Constantinescuf683e012013-11-05 16:53:55 +00001336 BpBinder *proxy = (BpBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001337 proxy->sendObituary();
1338 mOut.writeInt32(BC_DEAD_BINDER_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001339 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001340 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001341
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001342 case BR_CLEAR_DEATH_NOTIFICATION_DONE:
1343 {
Serban Constantinescuf683e012013-11-05 16:53:55 +00001344 BpBinder *proxy = (BpBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001345 proxy->getWeakRefs()->decWeak(proxy);
1346 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001347
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001348 case BR_FINISHED:
1349 result = TIMED_OUT;
1350 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001351
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001352 case BR_NOOP:
1353 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001354
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001355 case BR_SPAWN_LOOPER:
1356 mProcess->spawnPooledThread(false);
1357 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001358
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001359 default:
liangweikanga43ee152016-10-25 16:37:54 +08001360 ALOGE("*** BAD COMMAND %d received from Binder driver\n", cmd);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001361 result = UNKNOWN_ERROR;
1362 break;
1363 }
1364
1365 if (result != NO_ERROR) {
1366 mLastError = result;
1367 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001368
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001369 return result;
1370}
1371
Steven Moreland39d887d2020-01-31 14:56:45 -08001372const void* IPCThreadState::getServingStackPointer() const {
1373 return mServingStackPointer;
Jayant Chowdharydac6dc82018-10-01 22:52:44 +00001374}
1375
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001376void IPCThreadState::threadDestructor(void *st)
1377{
Todd Poynor8d96cab2013-06-25 19:12:18 -07001378 IPCThreadState* const self = static_cast<IPCThreadState*>(st);
1379 if (self) {
1380 self->flushCommands();
Elliott Hughes6071da72015-08-12 15:27:47 -07001381#if defined(__ANDROID__)
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -02001382 if (self->mProcess->mDriverFD >= 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +01001383 ioctl(self->mProcess->mDriverFD, BINDER_THREAD_EXIT, 0);
1384 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001385#endif
Todd Poynor8d96cab2013-06-25 19:12:18 -07001386 delete self;
1387 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001388}
1389
Marco Ballesiob09fc4a2020-09-11 16:17:21 -07001390status_t IPCThreadState::getProcessFreezeInfo(pid_t pid, bool *sync_received, bool *async_received)
1391{
1392 int ret = 0;
1393 binder_frozen_status_info info;
1394 info.pid = pid;
1395
1396#if defined(__ANDROID__)
1397 if (ioctl(self()->mProcess->mDriverFD, BINDER_GET_FROZEN_INFO, &info) < 0)
1398 ret = -errno;
1399#endif
1400 *sync_received = info.sync_recv;
1401 *async_received = info.async_recv;
1402
1403 return ret;
1404}
1405
Marco Ballesio7ee17572020-09-08 10:30:03 -07001406status_t IPCThreadState::freeze(pid_t pid, bool enable, uint32_t timeout_ms) {
1407 struct binder_freeze_info info;
1408 int ret = 0;
1409
1410 info.pid = pid;
1411 info.enable = enable;
1412 info.timeout_ms = timeout_ms;
1413
1414
1415#if defined(__ANDROID__)
1416 if (ioctl(self()->mProcess->mDriverFD, BINDER_FREEZE, &info) < 0)
1417 ret = -errno;
1418#endif
1419
1420 //
1421 // ret==-EAGAIN indicates that transactions have not drained.
1422 // Call again to poll for completion.
1423 //
1424 return ret;
1425}
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001426
Colin Cross6f4f3ab2014-02-05 17:42:44 -08001427void IPCThreadState::freeBuffer(Parcel* parcel, const uint8_t* data,
1428 size_t /*dataSize*/,
1429 const binder_size_t* /*objects*/,
Steven Moreland161fe122020-11-12 23:16:47 +00001430 size_t /*objectsSize*/)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001431{
Steve Blocka19954a2012-01-04 20:05:49 +00001432 //ALOGI("Freeing parcel %p", &parcel);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001433 IF_LOG_COMMANDS() {
1434 alog << "Writing BC_FREE_BUFFER for " << data << endl;
1435 }
Steve Block67263472012-01-09 18:35:44 +00001436 ALOG_ASSERT(data != NULL, "Called with NULL data");
Yi Kongfdd8da92018-06-07 17:52:27 -07001437 if (parcel != nullptr) parcel->closeFileDescriptors();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001438 IPCThreadState* state = self();
1439 state->mOut.writeInt32(BC_FREE_BUFFER);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001440 state->mOut.writePointer((uintptr_t)data);
Martijn Coenen0442a862017-11-17 10:46:32 +01001441 state->flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001442}
1443
Steven Moreland61ff8492019-09-26 16:05:45 -07001444} // namespace android