blob: cdc53ff3e7acfcc222b4208924178ef5c70a1bf4 [file] [log] [blame]
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001/*
2 * Copyright (C) 2005 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
Jason Parksdcd39582009-11-03 12:14:38 -080017#define LOG_TAG "IPCThreadState"
18
Mathias Agopianc5b2c0b2009-05-19 19:08:10 -070019#include <binder/IPCThreadState.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080020
Mathias Agopianc5b2c0b2009-05-19 19:08:10 -070021#include <binder/Binder.h>
22#include <binder/BpBinder.h>
Mathias Agopian002e1e52013-05-06 20:20:50 -070023#include <binder/TextOutput.h>
24
Steven Moreland7732a092019-01-02 17:54:16 -080025#include <utils/CallStack.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080026
Hans Boehma997b232019-04-12 16:59:00 -070027#include <atomic>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080028#include <errno.h>
Colin Cross96e83222016-04-15 14:29:55 -070029#include <inttypes.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080030#include <pthread.h>
31#include <sched.h>
Yabin Cui8fb2d252015-01-26 19:45:47 -080032#include <signal.h>
33#include <stdio.h>
34#include <sys/ioctl.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080035#include <sys/resource.h>
Yabin Cui8fb2d252015-01-26 19:45:47 -080036#include <unistd.h>
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080037
Tomasz Wasilczyk1d46f582024-05-21 15:06:29 -070038#include "Utils.h"
Steven Moreland6ba5a252021-05-04 22:49:00 +000039#include "binder_module.h"
Steven Morelanda4853cd2019-07-12 15:44:37 -070040
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080041#if LOG_NDEBUG
42
43#define IF_LOG_TRANSACTIONS() if (false)
44#define IF_LOG_COMMANDS() if (false)
mattgilbride85897672022-10-22 17:42:44 +000045#define LOG_REMOTEREFS(...)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080046#define IF_LOG_REMOTEREFS() if (false)
Tim Murrayd429f4a2017-03-07 09:31:09 -080047
mattgilbride85897672022-10-22 17:42:44 +000048#define LOG_THREADPOOL(...)
49#define LOG_ONEWAY(...)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080050
51#else
52
Steve Block9f760152011-10-12 17:27:03 +010053#define IF_LOG_TRANSACTIONS() IF_ALOG(LOG_VERBOSE, "transact")
54#define IF_LOG_COMMANDS() IF_ALOG(LOG_VERBOSE, "ipc")
55#define LOG_REMOTEREFS(...) ALOG(LOG_DEBUG, "remoterefs", __VA_ARGS__)
56#define IF_LOG_REMOTEREFS() IF_ALOG(LOG_DEBUG, "remoterefs")
57#define LOG_THREADPOOL(...) ALOG(LOG_DEBUG, "threadpool", __VA_ARGS__)
58#define LOG_ONEWAY(...) ALOG(LOG_DEBUG, "ipc", __VA_ARGS__)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080059
60#endif
61
62// ---------------------------------------------------------------------------
63
64namespace android {
65
Tomasz Wasilczyk1d46f582024-05-21 15:06:29 -070066using namespace std::chrono_literals;
67
Chih-Hung Hsieh8e5337d2014-10-24 14:10:09 -070068// Static const and functions will be optimized out if not used,
69// when LOG_NDEBUG and references in IF_LOG_COMMANDS() are optimized out.
Devin Moorea7499132023-12-15 18:48:39 +000070static const char* kReturnStrings[] = {
71 "BR_ERROR",
72 "BR_OK",
Devin Moore58029202023-12-15 18:58:48 +000073 "BR_TRANSACTION/BR_TRANSACTION_SEC_CTX",
Devin Moorea7499132023-12-15 18:48:39 +000074 "BR_REPLY",
75 "BR_ACQUIRE_RESULT",
76 "BR_DEAD_REPLY",
77 "BR_TRANSACTION_COMPLETE",
78 "BR_INCREFS",
79 "BR_ACQUIRE",
80 "BR_RELEASE",
81 "BR_DECREFS",
82 "BR_ATTEMPT_ACQUIRE",
83 "BR_NOOP",
84 "BR_SPAWN_LOOPER",
85 "BR_FINISHED",
86 "BR_DEAD_BINDER",
87 "BR_CLEAR_DEATH_NOTIFICATION_DONE",
88 "BR_FAILED_REPLY",
89 "BR_FROZEN_REPLY",
90 "BR_ONEWAY_SPAM_SUSPECT",
91 "BR_TRANSACTION_PENDING_FROZEN",
Yu-Ting Tsengd5fc4462024-04-30 15:07:13 -070092 "BR_FROZEN_BINDER",
93 "BR_CLEAR_FREEZE_NOTIFICATION_DONE",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -080094};
95
Yu-Ting Tsengd5fc4462024-04-30 15:07:13 -070096static const char* kCommandStrings[] = {
97 "BC_TRANSACTION",
98 "BC_REPLY",
99 "BC_ACQUIRE_RESULT",
100 "BC_FREE_BUFFER",
101 "BC_INCREFS",
102 "BC_ACQUIRE",
103 "BC_RELEASE",
104 "BC_DECREFS",
105 "BC_INCREFS_DONE",
106 "BC_ACQUIRE_DONE",
107 "BC_ATTEMPT_ACQUIRE",
108 "BC_REGISTER_LOOPER",
109 "BC_ENTER_LOOPER",
110 "BC_EXIT_LOOPER",
111 "BC_REQUEST_DEATH_NOTIFICATION",
112 "BC_CLEAR_DEATH_NOTIFICATION",
113 "BC_DEAD_BINDER_DONE",
114 "BC_TRANSACTION_SG",
115 "BC_REPLY_SG",
116 "BC_REQUEST_FREEZE_NOTIFICATION",
117 "BC_CLEAR_FREEZE_NOTIFICATION",
118 "BC_FREEZE_NOTIFICATION_DONE",
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800119};
120
Olivier Gaillard91a04802018-11-14 17:32:41 +0000121static const int64_t kWorkSourcePropagatedBitIndex = 32;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100122
songjinshi73a7dde2016-10-18 21:05:56 +0800123static const char* getReturnString(uint32_t cmd)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800124{
songjinshi8e486c62019-04-04 11:22:52 +0800125 size_t idx = cmd & _IOC_NRMASK;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800126 if (idx < sizeof(kReturnStrings) / sizeof(kReturnStrings[0]))
127 return kReturnStrings[idx];
128 else
129 return "unknown";
130}
131
Pawan Wagh7063b522022-09-28 18:52:26 +0000132static const void* printBinderTransactionData(std::ostream& out, const void* data) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800133 const binder_transaction_data* btd =
134 (const binder_transaction_data*)data;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700135 if (btd->target.handle < 1024) {
136 /* want to print descriptors in decimal; guess based on value */
Pawan Wagh7063b522022-09-28 18:52:26 +0000137 out << "\ttarget.desc=" << btd->target.handle;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700138 } else {
Pawan Wagh7063b522022-09-28 18:52:26 +0000139 out << "\ttarget.ptr=" << btd->target.ptr;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700140 }
Alice Ryhlc268ccb2022-11-17 10:18:38 +0000141 out << "\t (cookie " << btd->cookie << ")\n"
Pawan Wagh7063b522022-09-28 18:52:26 +0000142 << "\tcode=" << TypeCode(btd->code) << ", flags=" << (void*)(uint64_t)btd->flags << "\n"
Alice Ryhlc268ccb2022-11-17 10:18:38 +0000143 << "\tdata=" << btd->data.ptr.buffer << " (" << (void*)btd->data_size << " bytes)\n"
144 << "\toffsets=" << btd->data.ptr.offsets << " (" << (void*)btd->offsets_size << " bytes)\n";
145 return btd + 1;
146}
147
148static const void* printBinderTransactionDataSecCtx(std::ostream& out, const void* data) {
149 const binder_transaction_data_secctx* btd = (const binder_transaction_data_secctx*)data;
150
151 printBinderTransactionData(out, &btd->transaction_data);
152
153 char* secctx = (char*)btd->secctx;
154 out << "\tsecctx=" << secctx << "\n";
155
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800156 return btd+1;
157}
158
Pawan Wagh7063b522022-09-28 18:52:26 +0000159static const void* printReturnCommand(std::ostream& out, const void* _cmd) {
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700160 static const size_t N = sizeof(kReturnStrings)/sizeof(kReturnStrings[0]);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800161 const int32_t* cmd = (const int32_t*)_cmd;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100162 uint32_t code = (uint32_t)*cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700163 size_t cmdIndex = code & 0xff;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100164 if (code == BR_ERROR) {
Pawan Wagh7063b522022-09-28 18:52:26 +0000165 out << "\tBR_ERROR: " << (void*)(uint64_t)(*cmd++) << "\n";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800166 return cmd;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700167 } else if (cmdIndex >= N) {
Pawan Wagh7063b522022-09-28 18:52:26 +0000168 out << "\tUnknown reply: " << code << "\n";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800169 return cmd;
170 }
Pawan Wagh7063b522022-09-28 18:52:26 +0000171 out << "\t" << kReturnStrings[cmdIndex];
Tim Murrayd429f4a2017-03-07 09:31:09 -0800172
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800173 switch (code) {
Alice Ryhlc268ccb2022-11-17 10:18:38 +0000174 case BR_TRANSACTION_SEC_CTX: {
175 out << ": ";
176 cmd = (const int32_t*)printBinderTransactionDataSecCtx(out, cmd);
177 } break;
178
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800179 case BR_TRANSACTION:
180 case BR_REPLY: {
Pawan Wagh7063b522022-09-28 18:52:26 +0000181 out << ": ";
182 cmd = (const int32_t*)printBinderTransactionData(out, cmd);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800183 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800184
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800185 case BR_ACQUIRE_RESULT: {
186 const int32_t res = *cmd++;
187 out << ": " << res << (res ? " (SUCCESS)" : " (FAILURE)");
188 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800189
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800190 case BR_INCREFS:
191 case BR_ACQUIRE:
192 case BR_RELEASE:
193 case BR_DECREFS: {
194 const int32_t b = *cmd++;
195 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900196 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800197 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800198
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800199 case BR_ATTEMPT_ACQUIRE: {
200 const int32_t p = *cmd++;
201 const int32_t b = *cmd++;
202 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900203 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800204 << "), pri=" << p;
205 } break;
206
207 case BR_DEAD_BINDER:
208 case BR_CLEAR_DEATH_NOTIFICATION_DONE: {
209 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900210 out << ": death cookie " << (void*)(uint64_t)c;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800211 } break;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700212
Yu-Ting Tsengd5fc4462024-04-30 15:07:13 -0700213 case BR_FROZEN_BINDER: {
214 const int32_t c = *cmd++;
215 const int32_t h = *cmd++;
216 const int32_t isFrozen = *cmd++;
217 out << ": freeze cookie " << (void*)(uint64_t)c << " isFrozen: " << isFrozen;
218 } break;
219
220 case BR_CLEAR_FREEZE_NOTIFICATION_DONE: {
221 const int32_t c = *cmd++;
222 out << ": freeze cookie " << (void*)(uint64_t)c;
223 } break;
224
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700225 default:
226 // no details to show for: BR_OK, BR_DEAD_REPLY,
227 // BR_TRANSACTION_COMPLETE, BR_FINISHED
228 break;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800229 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800230
Pawan Wagh7063b522022-09-28 18:52:26 +0000231 out << "\n";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800232 return cmd;
233}
234
Devin Moore0272a5d2024-09-17 22:23:50 +0000235static void printReturnCommandParcel(std::ostream& out, const Parcel& parcel) {
236 const void* cmds = parcel.data();
237 out << "\t" << HexDump(cmds, parcel.dataSize()) << "\n";
238 IF_LOG_COMMANDS() {
239 const void* end = parcel.data() + parcel.dataSize();
240 while (cmds < end) cmds = printReturnCommand(out, cmds);
241 }
242}
243
Pawan Wagh7063b522022-09-28 18:52:26 +0000244static const void* printCommand(std::ostream& out, const void* _cmd) {
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700245 static const size_t N = sizeof(kCommandStrings)/sizeof(kCommandStrings[0]);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800246 const int32_t* cmd = (const int32_t*)_cmd;
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +0100247 uint32_t code = (uint32_t)*cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700248 size_t cmdIndex = code & 0xff;
249
250 if (cmdIndex >= N) {
Pawan Wagh7063b522022-09-28 18:52:26 +0000251 out << "Unknown command: " << code << "\n";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800252 return cmd;
253 }
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700254 out << kCommandStrings[cmdIndex];
255
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800256 switch (code) {
257 case BC_TRANSACTION:
258 case BC_REPLY: {
Pawan Wagh7063b522022-09-28 18:52:26 +0000259 out << ": ";
260 cmd = (const int32_t*)printBinderTransactionData(out, cmd);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800261 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800262
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800263 case BC_ACQUIRE_RESULT: {
264 const int32_t res = *cmd++;
265 out << ": " << res << (res ? " (SUCCESS)" : " (FAILURE)");
266 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800267
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800268 case BC_FREE_BUFFER: {
269 const int32_t buf = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900270 out << ": buffer=" << (void*)(uint64_t)buf;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800271 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800272
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800273 case BC_INCREFS:
274 case BC_ACQUIRE:
275 case BC_RELEASE:
276 case BC_DECREFS: {
277 const int32_t d = *cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700278 out << ": desc=" << d;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800279 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800280
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800281 case BC_INCREFS_DONE:
282 case BC_ACQUIRE_DONE: {
283 const int32_t b = *cmd++;
284 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900285 out << ": target=" << (void*)(uint64_t)b << " (cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800286 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800287
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800288 case BC_ATTEMPT_ACQUIRE: {
289 const int32_t p = *cmd++;
290 const int32_t d = *cmd++;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700291 out << ": desc=" << d << ", pri=" << p;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800292 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -0800293
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800294 case BC_REQUEST_DEATH_NOTIFICATION:
295 case BC_CLEAR_DEATH_NOTIFICATION: {
296 const int32_t h = *cmd++;
297 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900298 out << ": handle=" << h << " (death cookie " << (void*)(uint64_t)c << ")";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800299 } break;
300
Yu-Ting Tsengd5fc4462024-04-30 15:07:13 -0700301 case BC_REQUEST_FREEZE_NOTIFICATION:
302 case BC_CLEAR_FREEZE_NOTIFICATION: {
303 const int32_t h = *cmd++;
304 const int32_t c = *cmd++;
305 out << ": handle=" << h << " (freeze cookie " << (void*)(uint64_t)c << ")";
306 } break;
307
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800308 case BC_DEAD_BINDER_DONE: {
309 const int32_t c = *cmd++;
Jiyong Park16c6e702020-11-13 20:53:12 +0900310 out << ": death cookie " << (void*)(uint64_t)c;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800311 } break;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700312
Yu-Ting Tsengd5fc4462024-04-30 15:07:13 -0700313 case BC_FREEZE_NOTIFICATION_DONE: {
314 const int32_t c = *cmd++;
315 out << ": freeze cookie " << (void*)(uint64_t)c;
316 } break;
317
Andy McFaddenaefc9cd2011-08-31 07:43:40 -0700318 default:
319 // no details to show for: BC_REGISTER_LOOPER, BC_ENTER_LOOPER,
320 // BC_EXIT_LOOPER
321 break;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800322 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800323
Pawan Wagh7063b522022-09-28 18:52:26 +0000324 out << "\n";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800325 return cmd;
326}
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800327
Tomasz Wasilczyk370408e2024-06-21 15:45:26 -0700328LIBBINDER_IGNORE("-Wzero-as-null-pointer-constant")
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800329static pthread_mutex_t gTLSMutex = PTHREAD_MUTEX_INITIALIZER;
Tomasz Wasilczyk370408e2024-06-21 15:45:26 -0700330LIBBINDER_IGNORE_END()
Hans Boehma997b232019-04-12 16:59:00 -0700331static std::atomic<bool> gHaveTLS(false);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800332static pthread_key_t gTLS = 0;
Hans Boehma997b232019-04-12 16:59:00 -0700333static std::atomic<bool> gShutdown = false;
334static std::atomic<bool> gDisableBackgroundScheduling = false;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800335
336IPCThreadState* IPCThreadState::self()
337{
Hans Boehma997b232019-04-12 16:59:00 -0700338 if (gHaveTLS.load(std::memory_order_acquire)) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800339restart:
340 const pthread_key_t k = gTLS;
341 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(k);
342 if (st) return st;
343 return new IPCThreadState;
344 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800345
Hans Boehma997b232019-04-12 16:59:00 -0700346 // Racey, heuristic test for simultaneous shutdown.
347 if (gShutdown.load(std::memory_order_relaxed)) {
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800348 ALOGW("Calling IPCThreadState::self() during shutdown is dangerous, expect a crash.\n");
Yi Kongfdd8da92018-06-07 17:52:27 -0700349 return nullptr;
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800350 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800351
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800352 pthread_mutex_lock(&gTLSMutex);
Hans Boehma997b232019-04-12 16:59:00 -0700353 if (!gHaveTLS.load(std::memory_order_relaxed)) {
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800354 int key_create_value = pthread_key_create(&gTLS, threadDestructor);
355 if (key_create_value != 0) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800356 pthread_mutex_unlock(&gTLSMutex);
Andreas Gampef31a3eb2016-02-01 13:21:56 -0800357 ALOGW("IPCThreadState::self() unable to create TLS key, expect a crash: %s\n",
358 strerror(key_create_value));
Yi Kongfdd8da92018-06-07 17:52:27 -0700359 return nullptr;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800360 }
Hans Boehma997b232019-04-12 16:59:00 -0700361 gHaveTLS.store(true, std::memory_order_release);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800362 }
363 pthread_mutex_unlock(&gTLSMutex);
364 goto restart;
365}
366
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800367IPCThreadState* IPCThreadState::selfOrNull()
368{
Hans Boehma997b232019-04-12 16:59:00 -0700369 if (gHaveTLS.load(std::memory_order_acquire)) {
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800370 const pthread_key_t k = gTLS;
371 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(k);
372 return st;
373 }
Yi Kongfdd8da92018-06-07 17:52:27 -0700374 return nullptr;
Brad Fitzpatrick1b608432010-12-13 16:52:35 -0800375}
376
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800377void IPCThreadState::shutdown()
378{
Hans Boehma997b232019-04-12 16:59:00 -0700379 gShutdown.store(true, std::memory_order_relaxed);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800380
Hans Boehma997b232019-04-12 16:59:00 -0700381 if (gHaveTLS.load(std::memory_order_acquire)) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800382 // XXX Need to wait for all thread pool threads to exit!
383 IPCThreadState* st = (IPCThreadState*)pthread_getspecific(gTLS);
384 if (st) {
385 delete st;
Yi Kongfdd8da92018-06-07 17:52:27 -0700386 pthread_setspecific(gTLS, nullptr);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800387 }
zhongjieff405782016-03-09 15:05:04 +0800388 pthread_key_delete(gTLS);
Hans Boehma997b232019-04-12 16:59:00 -0700389 gHaveTLS.store(false, std::memory_order_release);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800390 }
391}
392
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -0800393void IPCThreadState::disableBackgroundScheduling(bool disable)
394{
Hans Boehma997b232019-04-12 16:59:00 -0700395 gDisableBackgroundScheduling.store(disable, std::memory_order_relaxed);
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -0800396}
397
Martijn Coenen2b631742017-05-05 11:16:59 -0700398bool IPCThreadState::backgroundSchedulingDisabled()
399{
Hans Boehma997b232019-04-12 16:59:00 -0700400 return gDisableBackgroundScheduling.load(std::memory_order_relaxed);
Martijn Coenen2b631742017-05-05 11:16:59 -0700401}
402
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800403status_t IPCThreadState::clearLastError()
404{
405 const status_t err = mLastError;
406 mLastError = NO_ERROR;
407 return err;
408}
409
Dan Stoza9c634fd2014-11-26 12:23:23 -0800410pid_t IPCThreadState::getCallingPid() const
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800411{
Steven Moreland35626652021-05-15 01:32:04 +0000412 checkContextIsBinderForUse(__func__);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800413 return mCallingPid;
414}
415
Steven Morelandf0212002018-12-26 13:59:23 -0800416const char* IPCThreadState::getCallingSid() const
417{
Steven Moreland35626652021-05-15 01:32:04 +0000418 checkContextIsBinderForUse(__func__);
Steven Morelandf0212002018-12-26 13:59:23 -0800419 return mCallingSid;
420}
421
Dan Stoza9c634fd2014-11-26 12:23:23 -0800422uid_t IPCThreadState::getCallingUid() const
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800423{
Steven Moreland35626652021-05-15 01:32:04 +0000424 checkContextIsBinderForUse(__func__);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800425 return mCallingUid;
426}
427
Steven Moreland35626652021-05-15 01:32:04 +0000428const IPCThreadState::SpGuard* IPCThreadState::pushGetCallingSpGuard(const SpGuard* guard) {
429 const SpGuard* orig = mServingStackPointerGuard;
430 mServingStackPointerGuard = guard;
431 return orig;
432}
433
434void IPCThreadState::restoreGetCallingSpGuard(const SpGuard* guard) {
435 mServingStackPointerGuard = guard;
436}
437
438void IPCThreadState::checkContextIsBinderForUse(const char* use) const {
Tomasz Wasilczykdf07f942023-11-02 15:07:45 -0700439 if (mServingStackPointerGuard == nullptr) [[likely]] {
440 return;
441 }
Steven Moreland35626652021-05-15 01:32:04 +0000442
443 if (!mServingStackPointer || mServingStackPointerGuard->address < mServingStackPointer) {
444 LOG_ALWAYS_FATAL("In context %s, %s does not make sense (binder sp: %p, guard: %p).",
445 mServingStackPointerGuard->context, use, mServingStackPointer,
446 mServingStackPointerGuard->address);
447 }
448
449 // in the case mServingStackPointer is deeper in the stack than the guard,
450 // we must be serving a binder transaction (maybe nested). This is a binder
451 // context, so we don't abort
452}
453
mattgilbride85897672022-10-22 17:42:44 +0000454constexpr uint32_t encodeExplicitIdentity(bool hasExplicitIdentity, pid_t callingPid) {
455 uint32_t as_unsigned = static_cast<uint32_t>(callingPid);
456 if (hasExplicitIdentity) {
457 return as_unsigned | (1 << 30);
458 } else {
459 return as_unsigned & ~(1 << 30);
460 }
461}
462
463constexpr int64_t packCallingIdentity(bool hasExplicitIdentity, uid_t callingUid,
464 pid_t callingPid) {
465 // Calling PID is a 32-bit signed integer, but doesn't consume the entire 32 bit space.
466 // To future-proof this and because we have extra capacity, we decided to also support -1,
467 // since this constant is used to represent invalid UID in other places of the system.
468 // Thus, we pack hasExplicitIdentity into the 2nd bit from the left. This allows us to
469 // preserve the (left-most) bit for the sign while also encoding the value of
470 // hasExplicitIdentity.
471 // 32b | 1b | 1b | 30b
472 // token = [ calling uid | calling pid(sign) | has explicit identity | calling pid(rest) ]
473 uint64_t token = (static_cast<uint64_t>(callingUid) << 32) |
474 encodeExplicitIdentity(hasExplicitIdentity, callingPid);
475 return static_cast<int64_t>(token);
476}
477
478constexpr bool unpackHasExplicitIdentity(int64_t token) {
479 return static_cast<int32_t>(token) & (1 << 30);
480}
481
482constexpr uid_t unpackCallingUid(int64_t token) {
483 return static_cast<uid_t>(token >> 32);
484}
485
486constexpr pid_t unpackCallingPid(int64_t token) {
487 int32_t encodedPid = static_cast<int32_t>(token);
488 if (encodedPid & (1 << 31)) {
489 return encodedPid | (1 << 30);
490 } else {
491 return encodedPid & ~(1 << 30);
492 }
493}
494
495static_assert(unpackHasExplicitIdentity(packCallingIdentity(true, 1000, 9999)) == true,
496 "pack true hasExplicit");
497
498static_assert(unpackCallingUid(packCallingIdentity(true, 1000, 9999)) == 1000, "pack true uid");
499
500static_assert(unpackCallingPid(packCallingIdentity(true, 1000, 9999)) == 9999, "pack true pid");
501
502static_assert(unpackHasExplicitIdentity(packCallingIdentity(false, 1000, 9999)) == false,
503 "pack false hasExplicit");
504
505static_assert(unpackCallingUid(packCallingIdentity(false, 1000, 9999)) == 1000, "pack false uid");
506
507static_assert(unpackCallingPid(packCallingIdentity(false, 1000, 9999)) == 9999, "pack false pid");
508
509static_assert(unpackHasExplicitIdentity(packCallingIdentity(true, 1000, -1)) == true,
510 "pack true (negative) hasExplicit");
511
512static_assert(unpackCallingUid(packCallingIdentity(true, 1000, -1)) == 1000,
513 "pack true (negative) uid");
514
515static_assert(unpackCallingPid(packCallingIdentity(true, 1000, -1)) == -1,
516 "pack true (negative) pid");
517
518static_assert(unpackHasExplicitIdentity(packCallingIdentity(false, 1000, -1)) == false,
519 "pack false (negative) hasExplicit");
520
521static_assert(unpackCallingUid(packCallingIdentity(false, 1000, -1)) == 1000,
522 "pack false (negative) uid");
523
524static_assert(unpackCallingPid(packCallingIdentity(false, 1000, -1)) == -1,
525 "pack false (negative) pid");
526
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800527int64_t IPCThreadState::clearCallingIdentity()
528{
Steven Morelandf0212002018-12-26 13:59:23 -0800529 // ignore mCallingSid for legacy reasons
mattgilbride85897672022-10-22 17:42:44 +0000530 int64_t token = packCallingIdentity(mHasExplicitIdentity, mCallingUid, mCallingPid);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800531 clearCaller();
mattgilbride85897672022-10-22 17:42:44 +0000532 mHasExplicitIdentity = true;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800533 return token;
534}
535
mattgilbride85897672022-10-22 17:42:44 +0000536bool IPCThreadState::hasExplicitIdentity() {
537 return mHasExplicitIdentity;
538}
539
Brad Fitzpatrick702ea9d2010-06-18 13:07:53 -0700540void IPCThreadState::setStrictModePolicy(int32_t policy)
541{
542 mStrictModePolicy = policy;
543}
544
Brad Fitzpatricka877cd82010-07-07 16:06:39 -0700545int32_t IPCThreadState::getStrictModePolicy() const
546{
Brad Fitzpatrick702ea9d2010-06-18 13:07:53 -0700547 return mStrictModePolicy;
548}
549
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000550int64_t IPCThreadState::setCallingWorkSourceUid(uid_t uid)
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100551{
Olivier Gaillard91a04802018-11-14 17:32:41 +0000552 int64_t token = setCallingWorkSourceUidWithoutPropagation(uid);
553 mPropagateWorkSource = true;
554 return token;
555}
556
557int64_t IPCThreadState::setCallingWorkSourceUidWithoutPropagation(uid_t uid)
558{
559 const int64_t propagatedBit = ((int64_t)mPropagateWorkSource) << kWorkSourcePropagatedBitIndex;
560 int64_t token = propagatedBit | mWorkSource;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100561 mWorkSource = uid;
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000562 return token;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100563}
564
Olivier Gaillard91a04802018-11-14 17:32:41 +0000565void IPCThreadState::clearPropagateWorkSource()
566{
567 mPropagateWorkSource = false;
568}
569
570bool IPCThreadState::shouldPropagateWorkSource() const
571{
572 return mPropagateWorkSource;
573}
574
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000575uid_t IPCThreadState::getCallingWorkSourceUid() const
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100576{
577 return mWorkSource;
578}
579
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000580int64_t IPCThreadState::clearCallingWorkSource()
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100581{
Olivier Gaillarda8e7bf22018-11-14 15:35:50 +0000582 return setCallingWorkSourceUid(kUnsetWorkSource);
583}
584
585void IPCThreadState::restoreCallingWorkSource(int64_t token)
586{
587 uid_t uid = (int)token;
Olivier Gaillard91a04802018-11-14 17:32:41 +0000588 setCallingWorkSourceUidWithoutPropagation(uid);
589 mPropagateWorkSource = ((token >> kWorkSourcePropagatedBitIndex) & 1) == 1;
Olivier Gaillard0e0f1de2018-08-16 14:04:09 +0100590}
591
Brad Fitzpatrick52736032010-08-30 16:01:16 -0700592void IPCThreadState::setLastTransactionBinderFlags(int32_t flags)
593{
594 mLastTransactionBinderFlags = flags;
595}
596
597int32_t IPCThreadState::getLastTransactionBinderFlags() const
598{
599 return mLastTransactionBinderFlags;
600}
601
Steven Moreland9514b202020-09-21 18:03:27 +0000602void IPCThreadState::setCallRestriction(ProcessState::CallRestriction restriction) {
603 mCallRestriction = restriction;
604}
605
606ProcessState::CallRestriction IPCThreadState::getCallRestriction() const {
607 return mCallRestriction;
608}
609
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800610void IPCThreadState::restoreCallingIdentity(int64_t token)
611{
mattgilbride85897672022-10-22 17:42:44 +0000612 mCallingUid = unpackCallingUid(token);
Steven Morelandf0212002018-12-26 13:59:23 -0800613 mCallingSid = nullptr; // not enough data to restore
mattgilbride85897672022-10-22 17:42:44 +0000614 mCallingPid = unpackCallingPid(token);
615 mHasExplicitIdentity = unpackHasExplicitIdentity(token);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800616}
617
618void IPCThreadState::clearCaller()
619{
Marco Nelissend43b1942009-07-17 07:59:17 -0700620 mCallingPid = getpid();
Steven Morelandf0212002018-12-26 13:59:23 -0800621 mCallingSid = nullptr; // expensive to lookup
Marco Nelissend43b1942009-07-17 07:59:17 -0700622 mCallingUid = getuid();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800623}
624
625void IPCThreadState::flushCommands()
626{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -0200627 if (mProcess->mDriverFD < 0)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800628 return;
Steven Moreland17305282025-01-09 21:28:44 +0000629
630 if (status_t res = talkWithDriver(false); res != OK) {
631 // TODO: we may want to abort for some of these cases
632 ALOGW("1st call to talkWithDriver returned error in flushCommands: %s",
633 statusToString(res).c_str());
634 }
635
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700636 // The flush could have caused post-write refcount decrements to have
637 // been executed, which in turn could result in BC_RELEASE/BC_DECREFS
638 // being queued in mOut. So flush again, if we need to.
639 if (mOut.dataSize() > 0) {
Steven Moreland17305282025-01-09 21:28:44 +0000640 if (status_t res = talkWithDriver(false); res != OK) {
641 // TODO: we may want to abort for some of these cases
642 ALOGW("2nd call to talkWithDriver returned error in flushCommands: %s",
643 statusToString(res).c_str());
644 }
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700645 }
646 if (mOut.dataSize() > 0) {
647 ALOGW("mOut.dataSize() > 0 after flushCommands()");
648 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800649}
650
Martijn Coenen0442a862017-11-17 10:46:32 +0100651bool IPCThreadState::flushIfNeeded()
652{
Frankie Changf4c81372021-05-18 13:08:05 +0800653 if (mIsLooper || mServingStackPointer != nullptr || mIsFlushing) {
Martijn Coenen0442a862017-11-17 10:46:32 +0100654 return false;
655 }
Frankie Changf4c81372021-05-18 13:08:05 +0800656 mIsFlushing = true;
Martijn Coenen0442a862017-11-17 10:46:32 +0100657 // In case this thread is not a looper and is not currently serving a binder transaction,
658 // there's no guarantee that this thread will call back into the kernel driver any time
659 // soon. Therefore, flush pending commands such as BC_FREE_BUFFER, to prevent them from getting
660 // stuck in this thread's out buffer.
661 flushCommands();
Frankie Changf4c81372021-05-18 13:08:05 +0800662 mIsFlushing = false;
Martijn Coenen0442a862017-11-17 10:46:32 +0100663 return true;
664}
665
Wale Ogunwale376b8222015-04-13 16:16:10 -0700666void IPCThreadState::blockUntilThreadAvailable()
667{
Frederick Mayle263507f2024-05-30 14:54:27 -0700668 std::unique_lock lock_guard_(mProcess->mOnThreadAvailableLock);
669 mProcess->mOnThreadAvailableWaiting++;
670 mProcess->mOnThreadAvailableCondVar.wait(lock_guard_, [&] {
671 size_t max = mProcess->mMaxThreads;
672 size_t cur = mProcess->mExecutingThreadsCount;
673 if (cur < max) {
674 return true;
675 }
Frederick Mayle99490ac2024-06-18 12:21:18 -0700676 ALOGW("Waiting for thread to be free. mExecutingThreadsCount=%zu mMaxThreads=%zu\n", cur,
677 max);
Frederick Mayle263507f2024-05-30 14:54:27 -0700678 return false;
679 });
680 mProcess->mOnThreadAvailableWaiting--;
Wale Ogunwale376b8222015-04-13 16:16:10 -0700681}
682
Todd Poynor8d96cab2013-06-25 19:12:18 -0700683status_t IPCThreadState::getAndExecuteCommand()
684{
685 status_t result;
686 int32_t cmd;
687
688 result = talkWithDriver();
689 if (result >= NO_ERROR) {
690 size_t IN = mIn.dataAvail();
691 if (IN < sizeof(int32_t)) return result;
692 cmd = mIn.readInt32();
693 IF_LOG_COMMANDS() {
Pawan Wagh7063b522022-09-28 18:52:26 +0000694 std::ostringstream logStream;
695 logStream << "Processing top-level Command: " << getReturnString(cmd) << "\n";
696 std::string message = logStream.str();
697 ALOGI("%s", message.c_str());
Todd Poynor8d96cab2013-06-25 19:12:18 -0700698 }
699
Frederick Mayle263507f2024-05-30 14:54:27 -0700700 size_t newThreadsCount = mProcess->mExecutingThreadsCount.fetch_add(1) + 1;
701 if (newThreadsCount >= mProcess->mMaxThreads) {
Tomasz Wasilczyk1d46f582024-05-21 15:06:29 -0700702 auto expected = ProcessState::never();
703 mProcess->mStarvationStartTime
704 .compare_exchange_strong(expected, std::chrono::steady_clock::now());
Colin Cross96e83222016-04-15 14:29:55 -0700705 }
Wale Ogunwale376b8222015-04-13 16:16:10 -0700706
Todd Poynor8d96cab2013-06-25 19:12:18 -0700707 result = executeCommand(cmd);
708
Frederick Mayle263507f2024-05-30 14:54:27 -0700709 size_t maxThreads = mProcess->mMaxThreads;
710 newThreadsCount = mProcess->mExecutingThreadsCount.fetch_sub(1) - 1;
711 if (newThreadsCount < maxThreads) {
Tomasz Wasilczyk1d46f582024-05-21 15:06:29 -0700712 auto starvationStartTime =
713 mProcess->mStarvationStartTime.exchange(ProcessState::never());
714 if (starvationStartTime != ProcessState::never()) {
715 auto starvationTime = std::chrono::steady_clock::now() - starvationStartTime;
716 if (starvationTime > 100ms) {
Frederick Mayle263507f2024-05-30 14:54:27 -0700717 ALOGE("binder thread pool (%zu threads) starved for %" PRId64 " ms", maxThreads,
Tomasz Wasilczyk1d46f582024-05-21 15:06:29 -0700718 to_ms(starvationTime));
Frederick Mayle263507f2024-05-30 14:54:27 -0700719 }
Colin Cross96e83222016-04-15 14:29:55 -0700720 }
Colin Cross96e83222016-04-15 14:29:55 -0700721 }
Steven Morelandc648a762021-01-16 02:39:45 +0000722
723 // Cond broadcast can be expensive, so don't send it every time a binder
724 // call is processed. b/168806193
Frederick Mayle263507f2024-05-30 14:54:27 -0700725 if (mProcess->mOnThreadAvailableWaiting > 0) {
726 std::lock_guard lock_guard_(mProcess->mOnThreadAvailableLock);
727 mProcess->mOnThreadAvailableCondVar.notify_all();
Steven Morelandc648a762021-01-16 02:39:45 +0000728 }
Todd Poynor8d96cab2013-06-25 19:12:18 -0700729 }
730
731 return result;
732}
733
734// When we've cleared the incoming command queue, process any pending derefs
735void IPCThreadState::processPendingDerefs()
736{
737 if (mIn.dataPosition() >= mIn.dataSize()) {
Martijn Coenen0791fbf2017-08-08 15:36:16 +0200738 /*
739 * The decWeak()/decStrong() calls may cause a destructor to run,
740 * which in turn could have initiated an outgoing transaction,
741 * which in turn could cause us to add to the pending refs
742 * vectors; so instead of simply iterating, loop until they're empty.
743 *
744 * We do this in an outer loop, because calling decStrong()
745 * may result in something being added to mPendingWeakDerefs,
746 * which could be delayed until the next incoming command
747 * from the driver if we don't process it now.
748 */
749 while (mPendingWeakDerefs.size() > 0 || mPendingStrongDerefs.size() > 0) {
750 while (mPendingWeakDerefs.size() > 0) {
751 RefBase::weakref_type* refs = mPendingWeakDerefs[0];
752 mPendingWeakDerefs.removeAt(0);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700753 refs->decWeak(mProcess.get());
754 }
Todd Poynor8d96cab2013-06-25 19:12:18 -0700755
Martijn Coenen0791fbf2017-08-08 15:36:16 +0200756 if (mPendingStrongDerefs.size() > 0) {
757 // We don't use while() here because we don't want to re-order
758 // strong and weak decs at all; if this decStrong() causes both a
759 // decWeak() and a decStrong() to be queued, we want to process
760 // the decWeak() first.
761 BBinder* obj = mPendingStrongDerefs[0];
762 mPendingStrongDerefs.removeAt(0);
Todd Poynor8d96cab2013-06-25 19:12:18 -0700763 obj->decStrong(mProcess.get());
764 }
Todd Poynor8d96cab2013-06-25 19:12:18 -0700765 }
766 }
767}
768
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700769void IPCThreadState::processPostWriteDerefs()
770{
771 for (size_t i = 0; i < mPostWriteWeakDerefs.size(); i++) {
772 RefBase::weakref_type* refs = mPostWriteWeakDerefs[i];
773 refs->decWeak(mProcess.get());
774 }
775 mPostWriteWeakDerefs.clear();
776
777 for (size_t i = 0; i < mPostWriteStrongDerefs.size(); i++) {
778 RefBase* obj = mPostWriteStrongDerefs[i];
779 obj->decStrong(mProcess.get());
780 }
781 mPostWriteStrongDerefs.clear();
782}
783
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800784void IPCThreadState::joinThreadPool(bool isMain)
785{
Frederick Mayle263507f2024-05-30 14:54:27 -0700786 LOG_THREADPOOL("**** THREAD %p (PID %d) IS JOINING THE THREAD POOL\n", (void*)pthread_self(),
787 getpid());
Steven Morelandc86333d2024-12-13 20:03:37 +0000788 mProcess->checkExpectingThreadPoolStart();
Elie Kheirallah47431c12022-04-21 23:46:17 +0000789 mProcess->mCurrentThreads++;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800790 mOut.writeInt32(isMain ? BC_ENTER_LOOPER : BC_REGISTER_LOOPER);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800791
Martijn Coenen0442a862017-11-17 10:46:32 +0100792 mIsLooper = true;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800793 status_t result;
794 do {
Todd Poynor8d96cab2013-06-25 19:12:18 -0700795 processPendingDerefs();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800796 // now get the next command to be processed, waiting if necessary
Todd Poynor8d96cab2013-06-25 19:12:18 -0700797 result = getAndExecuteCommand();
Jason Parksdcd39582009-11-03 12:14:38 -0800798
Todd Poynor8d96cab2013-06-25 19:12:18 -0700799 if (result < NO_ERROR && result != TIMED_OUT && result != -ECONNREFUSED && result != -EBADF) {
Steven Moreland6adf33c2019-09-25 13:18:09 -0700800 LOG_ALWAYS_FATAL("getAndExecuteCommand(fd=%d) returned unexpected error %d, aborting",
Jeff Tinkeref073862013-06-11 11:30:21 -0700801 mProcess->mDriverFD, result);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800802 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800803
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800804 // Let this thread exit the thread pool if it is no longer
805 // needed and it is not the main process thread.
806 if(result == TIMED_OUT && !isMain) {
807 break;
808 }
809 } while (result != -ECONNREFUSED && result != -EBADF);
810
Wei Wangc7341432016-10-19 10:23:59 -0700811 LOG_THREADPOOL("**** THREAD %p (PID %d) IS LEAVING THE THREAD POOL err=%d\n",
812 (void*)pthread_self(), getpid(), result);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800813
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800814 mOut.writeInt32(BC_EXIT_LOOPER);
Martijn Coenen0442a862017-11-17 10:46:32 +0100815 mIsLooper = false;
Steven Moreland17305282025-01-09 21:28:44 +0000816 if (status_t res = talkWithDriver(false); res != OK) {
817 // TODO: we may want to abort for some of these cases
818 ALOGW("call to talkWithDriver in joinThreadPool returned error: %s, FD: %d",
819 statusToString(res).c_str(), mProcess->mDriverFD);
820 }
Frederick Mayle263507f2024-05-30 14:54:27 -0700821 size_t oldCount = mProcess->mCurrentThreads.fetch_sub(1);
822 LOG_ALWAYS_FATAL_IF(oldCount == 0,
823 "Threadpool thread count underflowed. Thread cannot exist and exit in "
824 "empty threadpool\n"
Elie Kheirallah47431c12022-04-21 23:46:17 +0000825 "Misconfiguration. Increase threadpool max threads configuration\n");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800826}
827
Steven Morelandd8c85672020-07-24 21:30:41 +0000828status_t IPCThreadState::setupPolling(int* fd)
Todd Poynor8d96cab2013-06-25 19:12:18 -0700829{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -0200830 if (mProcess->mDriverFD < 0) {
Todd Poynor8d96cab2013-06-25 19:12:18 -0700831 return -EBADF;
832 }
833
834 mOut.writeInt32(BC_ENTER_LOOPER);
Steven Morelandf210b502021-01-15 23:40:32 +0000835 flushCommands();
Todd Poynor8d96cab2013-06-25 19:12:18 -0700836 *fd = mProcess->mDriverFD;
Elie Kheirallah47431c12022-04-21 23:46:17 +0000837 mProcess->mCurrentThreads++;
Todd Poynor8d96cab2013-06-25 19:12:18 -0700838 return 0;
839}
840
841status_t IPCThreadState::handlePolledCommands()
842{
843 status_t result;
844
845 do {
846 result = getAndExecuteCommand();
847 } while (mIn.dataPosition() < mIn.dataSize());
848
849 processPendingDerefs();
850 flushCommands();
851 return result;
852}
853
Colin Cross6f4f3ab2014-02-05 17:42:44 -0800854void IPCThreadState::stopProcess(bool /*immediate*/)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800855{
Steven Morelanddab29652025-01-27 17:44:30 -0800856 //ALOGI("**** STOPPING PROCESS");
857 (void)flushCommands();
858 int fd = mProcess->mDriverFD;
859 mProcess->mDriverFD = -1;
860 close(fd);
861 //kill(getpid(), SIGKILL);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800862}
863
864status_t IPCThreadState::transact(int32_t handle,
865 uint32_t code, const Parcel& data,
866 Parcel* reply, uint32_t flags)
867{
Steven Moreland5553ac42020-11-11 02:14:45 +0000868 LOG_ALWAYS_FATAL_IF(data.isForRpc(), "Parcel constructed for RPC, but being used with binder.");
869
Ganesh Mahendran58e5daa2017-10-11 18:05:13 +0800870 status_t err;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800871
872 flags |= TF_ACCEPT_FDS;
873
874 IF_LOG_TRANSACTIONS() {
Pawan Wagh7063b522022-09-28 18:52:26 +0000875 std::ostringstream logStream;
876 logStream << "BC_TRANSACTION thr " << (void*)pthread_self() << " / hand " << handle
877 << " / code " << TypeCode(code) << ": \t" << data << "\n";
878 std::string message = logStream.str();
879 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800880 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800881
Ganesh Mahendran58e5daa2017-10-11 18:05:13 +0800882 LOG_ONEWAY(">>>> SEND from pid %d uid %d %s", getpid(), getuid(),
883 (flags & TF_ONE_WAY) == 0 ? "READ REPLY" : "ONE WAY");
Yi Kongfdd8da92018-06-07 17:52:27 -0700884 err = writeTransactionData(BC_TRANSACTION, flags, handle, code, data, nullptr);
Tim Murrayd429f4a2017-03-07 09:31:09 -0800885
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800886 if (err != NO_ERROR) {
887 if (reply) reply->setError(err);
888 return (mLastError = err);
889 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800890
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800891 if ((flags & TF_ONE_WAY) == 0) {
Tomasz Wasilczykdf07f942023-11-02 15:07:45 -0700892 if (mCallRestriction != ProcessState::CallRestriction::NONE) [[unlikely]] {
Steven Moreland7732a092019-01-02 17:54:16 -0800893 if (mCallRestriction == ProcessState::CallRestriction::ERROR_IF_NOT_ONEWAY) {
Steven Moreland8cb34fc2019-05-13 11:44:55 -0700894 ALOGE("Process making non-oneway call (code: %u) but is restricted.", code);
Steven Moreland7732a092019-01-02 17:54:16 -0800895 CallStack::logStack("non-oneway call", CallStack::getCurrent(10).get(),
896 ANDROID_LOG_ERROR);
897 } else /* FATAL_IF_NOT_ONEWAY */ {
Steven Morelandfcc77f12020-09-01 01:16:11 +0000898 LOG_ALWAYS_FATAL("Process may not make non-oneway calls (code: %u).", code);
Steven Moreland7732a092019-01-02 17:54:16 -0800899 }
900 }
901
Tomasz Wasilczykdf07f942023-11-02 15:07:45 -0700902#if 0
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700903 if (code == 4) { // relayout
Steve Blocka19954a2012-01-04 20:05:49 +0000904 ALOGI(">>>>>> CALLING transaction 4");
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700905 } else {
Steve Blocka19954a2012-01-04 20:05:49 +0000906 ALOGI(">>>>>> CALLING transaction %d", code);
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700907 }
Tomasz Wasilczykdf07f942023-11-02 15:07:45 -0700908#endif
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800909 if (reply) {
910 err = waitForResponse(reply);
911 } else {
912 Parcel fakeReply;
913 err = waitForResponse(&fakeReply);
914 }
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700915 #if 0
916 if (code == 4) { // relayout
Steve Blocka19954a2012-01-04 20:05:49 +0000917 ALOGI("<<<<<< RETURNING transaction 4");
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700918 } else {
Steve Blocka19954a2012-01-04 20:05:49 +0000919 ALOGI("<<<<<< RETURNING transaction %d", code);
Dianne Hackborn67f78c42010-09-24 11:16:23 -0700920 }
921 #endif
Tim Murrayd429f4a2017-03-07 09:31:09 -0800922
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800923 IF_LOG_TRANSACTIONS() {
Pawan Wagh7063b522022-09-28 18:52:26 +0000924 std::ostringstream logStream;
925 logStream << "BR_REPLY thr " << (void*)pthread_self() << " / hand " << handle << ": ";
926 if (reply)
927 logStream << "\t" << *reply << "\n";
928 else
929 logStream << "(none requested)"
930 << "\n";
931 std::string message = logStream.str();
932 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800933 }
934 } else {
Yi Kongfdd8da92018-06-07 17:52:27 -0700935 err = waitForResponse(nullptr, nullptr);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800936 }
Tim Murrayd429f4a2017-03-07 09:31:09 -0800937
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800938 return err;
939}
940
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700941void IPCThreadState::incStrongHandle(int32_t handle, BpBinder *proxy)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800942{
943 LOG_REMOTEREFS("IPCThreadState::incStrongHandle(%d)\n", handle);
944 mOut.writeInt32(BC_ACQUIRE);
945 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100946 if (!flushIfNeeded()) {
947 // Create a temp reference until the driver has handled this command.
948 proxy->incStrong(mProcess.get());
949 mPostWriteStrongDerefs.push(proxy);
950 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800951}
952
953void IPCThreadState::decStrongHandle(int32_t handle)
954{
955 LOG_REMOTEREFS("IPCThreadState::decStrongHandle(%d)\n", handle);
956 mOut.writeInt32(BC_RELEASE);
957 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100958 flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800959}
960
Martijn Coenen7c170bb2018-05-04 17:28:55 -0700961void IPCThreadState::incWeakHandle(int32_t handle, BpBinder *proxy)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800962{
963 LOG_REMOTEREFS("IPCThreadState::incWeakHandle(%d)\n", handle);
964 mOut.writeInt32(BC_INCREFS);
965 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100966 if (!flushIfNeeded()) {
967 // Create a temp reference until the driver has handled this command.
968 proxy->getWeakRefs()->incWeak(mProcess.get());
969 mPostWriteWeakDerefs.push(proxy->getWeakRefs());
970 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800971}
972
973void IPCThreadState::decWeakHandle(int32_t handle)
974{
975 LOG_REMOTEREFS("IPCThreadState::decWeakHandle(%d)\n", handle);
976 mOut.writeInt32(BC_DECREFS);
977 mOut.writeInt32(handle);
Martijn Coenen0442a862017-11-17 10:46:32 +0100978 flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800979}
980
Steven Moreland1bf42912024-02-16 22:29:42 +0000981status_t IPCThreadState::attemptIncStrongHandle(int32_t handle) {
Arve HjønnevÄg11cfdcc2014-02-14 20:14:02 -0800982 (void)handle;
983 ALOGE("%s(%d): Not supported\n", __func__, handle);
984 return INVALID_OPERATION;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800985}
986
987void IPCThreadState::expungeHandle(int32_t handle, IBinder* binder)
988{
989#if LOG_REFCOUNTS
liangweikanga43ee152016-10-25 16:37:54 +0800990 ALOGV("IPCThreadState::expungeHandle(%ld)\n", handle);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800991#endif
Manoj Gupta9cec85b2017-09-19 16:34:29 -0700992 self()->mProcess->expungeHandle(handle, binder); // NOLINT
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -0800993}
994
995status_t IPCThreadState::requestDeathNotification(int32_t handle, BpBinder* proxy)
996{
997 mOut.writeInt32(BC_REQUEST_DEATH_NOTIFICATION);
998 mOut.writeInt32((int32_t)handle);
Serban Constantinescuf683e012013-11-05 16:53:55 +0000999 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001000 return NO_ERROR;
1001}
1002
1003status_t IPCThreadState::clearDeathNotification(int32_t handle, BpBinder* proxy)
1004{
1005 mOut.writeInt32(BC_CLEAR_DEATH_NOTIFICATION);
1006 mOut.writeInt32((int32_t)handle);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001007 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001008 return NO_ERROR;
1009}
1010
Yu-Ting Tsengd5fc4462024-04-30 15:07:13 -07001011status_t IPCThreadState::addFrozenStateChangeCallback(int32_t handle, BpBinder* proxy) {
1012 static bool isSupported =
1013 ProcessState::isDriverFeatureEnabled(ProcessState::DriverFeature::FREEZE_NOTIFICATION);
1014 if (!isSupported) {
1015 return INVALID_OPERATION;
1016 }
1017 proxy->getWeakRefs()->incWeak(proxy);
1018 mOut.writeInt32(BC_REQUEST_FREEZE_NOTIFICATION);
1019 mOut.writeInt32((int32_t)handle);
1020 mOut.writePointer((uintptr_t)proxy);
1021 flushCommands();
1022 return NO_ERROR;
1023}
1024
1025status_t IPCThreadState::removeFrozenStateChangeCallback(int32_t handle, BpBinder* proxy) {
1026 static bool isSupported =
1027 ProcessState::isDriverFeatureEnabled(ProcessState::DriverFeature::FREEZE_NOTIFICATION);
1028 if (!isSupported) {
1029 return INVALID_OPERATION;
1030 }
1031 mOut.writeInt32(BC_CLEAR_FREEZE_NOTIFICATION);
1032 mOut.writeInt32((int32_t)handle);
1033 mOut.writePointer((uintptr_t)proxy);
1034 flushCommands();
1035 return NO_ERROR;
1036}
1037
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001038IPCThreadState::IPCThreadState()
Steven Moreland35626652021-05-15 01:32:04 +00001039 : mProcess(ProcessState::self()),
1040 mServingStackPointer(nullptr),
1041 mServingStackPointerGuard(nullptr),
1042 mWorkSource(kUnsetWorkSource),
1043 mPropagateWorkSource(false),
1044 mIsLooper(false),
Frankie Changf4c81372021-05-18 13:08:05 +08001045 mIsFlushing(false),
Steven Moreland35626652021-05-15 01:32:04 +00001046 mStrictModePolicy(0),
1047 mLastTransactionBinderFlags(0),
1048 mCallRestriction(mProcess->mCallRestriction) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001049 pthread_setspecific(gTLS, this);
Dianne Hackborn8c6cedc2009-12-07 17:59:37 -08001050 clearCaller();
mattgilbride85897672022-10-22 17:42:44 +00001051 mHasExplicitIdentity = false;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001052 mIn.setDataCapacity(256);
1053 mOut.setDataCapacity(256);
1054}
1055
1056IPCThreadState::~IPCThreadState()
1057{
1058}
1059
Martijn Coenenea0090a2017-11-02 18:54:40 +00001060status_t IPCThreadState::sendReply(const Parcel& reply, uint32_t flags)
1061{
1062 status_t err;
1063 status_t statusBuffer;
1064 err = writeTransactionData(BC_REPLY, flags, -1, 0, reply, &statusBuffer);
1065 if (err < NO_ERROR) return err;
1066
Yi Kongfdd8da92018-06-07 17:52:27 -07001067 return waitForResponse(nullptr, nullptr);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001068}
1069
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001070status_t IPCThreadState::waitForResponse(Parcel *reply, status_t *acquireResult)
1071{
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +01001072 uint32_t cmd;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001073 int32_t err;
1074
1075 while (1) {
1076 if ((err=talkWithDriver()) < NO_ERROR) break;
1077 err = mIn.errorCheck();
1078 if (err < NO_ERROR) break;
1079 if (mIn.dataAvail() == 0) continue;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001080
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +01001081 cmd = (uint32_t)mIn.readInt32();
Tim Murrayd429f4a2017-03-07 09:31:09 -08001082
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001083 IF_LOG_COMMANDS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001084 std::ostringstream logStream;
1085 logStream << "Processing waitForResponse Command: " << getReturnString(cmd) << "\n";
1086 std::string message = logStream.str();
1087 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001088 }
1089
1090 switch (cmd) {
Hang Lub185ac02021-03-24 13:17:22 +08001091 case BR_ONEWAY_SPAM_SUSPECT:
1092 ALOGE("Process seems to be sending too many oneway calls.");
1093 CallStack::logStack("oneway spamming", CallStack::getCurrent().get(),
1094 ANDROID_LOG_ERROR);
1095 [[fallthrough]];
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001096 case BR_TRANSACTION_COMPLETE:
1097 if (!reply && !acquireResult) goto finish;
1098 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001099
Li Li0e3443d2022-12-07 21:51:19 -08001100 case BR_TRANSACTION_PENDING_FROZEN:
1101 ALOGW("Sending oneway calls to frozen process.");
1102 goto finish;
1103
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001104 case BR_DEAD_REPLY:
1105 err = DEAD_OBJECT;
1106 goto finish;
1107
1108 case BR_FAILED_REPLY:
1109 err = FAILED_TRANSACTION;
1110 goto finish;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001111
Marco Ballesio7ee17572020-09-08 10:30:03 -07001112 case BR_FROZEN_REPLY:
Steven Moreland389154e2024-05-28 22:22:38 +00001113 ALOGW("Transaction failed because process frozen.");
Marco Ballesio7ee17572020-09-08 10:30:03 -07001114 err = FAILED_TRANSACTION;
1115 goto finish;
1116
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001117 case BR_ACQUIRE_RESULT:
1118 {
Steve Block67263472012-01-09 18:35:44 +00001119 ALOG_ASSERT(acquireResult != NULL, "Unexpected brACQUIRE_RESULT");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001120 const int32_t result = mIn.readInt32();
1121 if (!acquireResult) continue;
1122 *acquireResult = result ? NO_ERROR : INVALID_OPERATION;
1123 }
1124 goto finish;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001125
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001126 case BR_REPLY:
1127 {
1128 binder_transaction_data tr;
1129 err = mIn.read(&tr, sizeof(tr));
Steve Block67263472012-01-09 18:35:44 +00001130 ALOG_ASSERT(err == NO_ERROR, "Not enough command data for brREPLY");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001131 if (err != NO_ERROR) goto finish;
1132
1133 if (reply) {
1134 if ((tr.flags & TF_STATUS_CODE) == 0) {
1135 reply->ipcSetDataReference(
1136 reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
1137 tr.data_size,
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001138 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
1139 tr.offsets_size/sizeof(binder_size_t),
Steven Moreland161fe122020-11-12 23:16:47 +00001140 freeBuffer);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001141 } else {
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001142 err = *reinterpret_cast<const status_t*>(tr.data.ptr.buffer);
Frederick Mayle53b6ffe2022-07-15 20:14:01 +00001143 freeBuffer(reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
1144 tr.data_size,
1145 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
1146 tr.offsets_size / sizeof(binder_size_t));
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001147 }
1148 } else {
Frederick Mayle53b6ffe2022-07-15 20:14:01 +00001149 freeBuffer(reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer), tr.data_size,
1150 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
1151 tr.offsets_size / sizeof(binder_size_t));
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001152 continue;
1153 }
1154 }
1155 goto finish;
1156
1157 default:
1158 err = executeCommand(cmd);
1159 if (err != NO_ERROR) goto finish;
1160 break;
1161 }
1162 }
1163
1164finish:
1165 if (err != NO_ERROR) {
1166 if (acquireResult) *acquireResult = err;
1167 if (reply) reply->setError(err);
1168 mLastError = err;
Carlos Llamasb235b122021-12-20 06:38:44 -08001169 logExtendedError();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001170 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001171
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001172 return err;
1173}
1174
1175status_t IPCThreadState::talkWithDriver(bool doReceive)
1176{
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -02001177 if (mProcess->mDriverFD < 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +01001178 return -EBADF;
1179 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001180
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001181 binder_write_read bwr;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001182
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001183 // Is the read buffer empty?
1184 const bool needRead = mIn.dataPosition() >= mIn.dataSize();
Tim Murrayd429f4a2017-03-07 09:31:09 -08001185
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001186 // We don't want to write anything if we are still reading
1187 // from data left in the input buffer and the caller
1188 // has requested to read the next data.
1189 const size_t outAvail = (!doReceive || needRead) ? mOut.dataSize() : 0;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001190
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001191 bwr.write_size = outAvail;
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001192 bwr.write_buffer = (uintptr_t)mOut.data();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001193
1194 // This is what we'll read.
1195 if (doReceive && needRead) {
1196 bwr.read_size = mIn.dataCapacity();
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001197 bwr.read_buffer = (uintptr_t)mIn.data();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001198 } else {
1199 bwr.read_size = 0;
Ben Chengd640f892011-12-01 17:11:32 -08001200 bwr.read_buffer = 0;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001201 }
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001202
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001203 IF_LOG_COMMANDS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001204 std::ostringstream logStream;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001205 if (outAvail != 0) {
Pawan Wagh7063b522022-09-28 18:52:26 +00001206 logStream << "Sending commands to driver: ";
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001207 const void* cmds = (const void*)bwr.write_buffer;
Pawan Wagh7063b522022-09-28 18:52:26 +00001208 const void* end = ((const uint8_t*)cmds) + bwr.write_size;
1209 logStream << "\t" << HexDump(cmds, bwr.write_size) << "\n";
1210 while (cmds < end) cmds = printCommand(logStream, cmds);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001211 }
Pawan Wagh7063b522022-09-28 18:52:26 +00001212 logStream << "Size of receive buffer: " << bwr.read_size << ", needRead: " << needRead
1213 << ", doReceive: " << doReceive << "\n";
1214
1215 std::string message = logStream.str();
1216 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001217 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001218
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001219 // Return immediately if there is nothing to do.
1220 if ((bwr.write_size == 0) && (bwr.read_size == 0)) return NO_ERROR;
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001221
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001222 bwr.write_consumed = 0;
1223 bwr.read_consumed = 0;
1224 status_t err;
1225 do {
1226 IF_LOG_COMMANDS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001227 std::ostringstream logStream;
1228 logStream << "About to read/write, write size = " << mOut.dataSize() << "\n";
1229 std::string message = logStream.str();
1230 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001231 }
Elliott Hughes6071da72015-08-12 15:27:47 -07001232#if defined(__ANDROID__)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001233 if (ioctl(mProcess->mDriverFD, BINDER_WRITE_READ, &bwr) >= 0)
1234 err = NO_ERROR;
1235 else
1236 err = -errno;
1237#else
1238 err = INVALID_OPERATION;
1239#endif
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -02001240 if (mProcess->mDriverFD < 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +01001241 err = -EBADF;
1242 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001243 IF_LOG_COMMANDS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001244 std::ostringstream logStream;
1245 logStream << "Finished read/write, write size = " << mOut.dataSize() << "\n";
1246 std::string message = logStream.str();
1247 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001248 }
1249 } while (err == -EINTR);
Andy McFaddenaefc9cd2011-08-31 07:43:40 -07001250
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001251 IF_LOG_COMMANDS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001252 std::ostringstream logStream;
1253 logStream << "Our err: " << (void*)(intptr_t)err
1254 << ", write consumed: " << bwr.write_consumed << " (of " << mOut.dataSize()
1255 << "), read consumed: " << bwr.read_consumed << "\n";
1256 std::string message = logStream.str();
1257 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001258 }
1259
1260 if (err >= NO_ERROR) {
1261 if (bwr.write_consumed > 0) {
Devin Moore0272a5d2024-09-17 22:23:50 +00001262 if (bwr.write_consumed < mOut.dataSize()) {
1263 std::ostringstream logStream;
1264 printReturnCommandParcel(logStream, mIn);
Steven Morelandb077deb2020-04-16 16:22:52 -07001265 LOG_ALWAYS_FATAL("Driver did not consume write buffer. "
Devin Moore0272a5d2024-09-17 22:23:50 +00001266 "err: %s consumed: %zu of %zu.\n"
1267 "Return command: %s",
1268 statusToString(err).c_str(), (size_t)bwr.write_consumed,
1269 mOut.dataSize(), logStream.str().c_str());
1270 } else {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001271 mOut.setDataSize(0);
Martijn Coenen7c170bb2018-05-04 17:28:55 -07001272 processPostWriteDerefs();
1273 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001274 }
1275 if (bwr.read_consumed > 0) {
1276 mIn.setDataSize(bwr.read_consumed);
1277 mIn.setDataPosition(0);
1278 }
1279 IF_LOG_COMMANDS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001280 std::ostringstream logStream;
Devin Moore0272a5d2024-09-17 22:23:50 +00001281 printReturnCommandParcel(logStream, mIn);
1282 ALOGI("%s", logStream.str().c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001283 }
1284 return NO_ERROR;
1285 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001286
Theodore Duboisbf144632023-01-09 15:36:49 -08001287 ALOGE_IF(mProcess->mDriverFD >= 0,
1288 "Driver returned error (%s). This is a bug in either libbinder or the driver. This "
1289 "thread's connection to %s will no longer work.",
1290 statusToString(err).c_str(), mProcess->mDriverName.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001291 return err;
1292}
1293
1294status_t IPCThreadState::writeTransactionData(int32_t cmd, uint32_t binderFlags,
1295 int32_t handle, uint32_t code, const Parcel& data, status_t* statusBuffer)
1296{
1297 binder_transaction_data tr;
1298
Arve HjønnevÄg07fd0f12014-02-18 21:10:29 -08001299 tr.target.ptr = 0; /* Don't pass uninitialized stack data to a remote process */
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001300 tr.target.handle = handle;
1301 tr.code = code;
1302 tr.flags = binderFlags;
Evgeniy Stepanovd5474322011-04-21 14:15:00 +04001303 tr.cookie = 0;
1304 tr.sender_pid = 0;
1305 tr.sender_euid = 0;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001306
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001307 const status_t err = data.errorCheck();
1308 if (err == NO_ERROR) {
1309 tr.data_size = data.ipcDataSize();
1310 tr.data.ptr.buffer = data.ipcData();
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001311 tr.offsets_size = data.ipcObjectsCount()*sizeof(binder_size_t);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001312 tr.data.ptr.offsets = data.ipcObjects();
1313 } else if (statusBuffer) {
1314 tr.flags |= TF_STATUS_CODE;
1315 *statusBuffer = err;
1316 tr.data_size = sizeof(status_t);
Arve HjønnevÄg87b30d02014-02-18 21:04:31 -08001317 tr.data.ptr.buffer = reinterpret_cast<uintptr_t>(statusBuffer);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001318 tr.offsets_size = 0;
Arve HjønnevÄg84e625a2014-01-28 20:12:59 -08001319 tr.data.ptr.offsets = 0;
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001320 } else {
1321 return (mLastError = err);
1322 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001323
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001324 mOut.writeInt32(cmd);
1325 mOut.write(&tr, sizeof(tr));
Tim Murrayd429f4a2017-03-07 09:31:09 -08001326
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001327 return NO_ERROR;
1328}
1329
1330sp<BBinder> the_context_object;
1331
Jiyong Park384328e2020-11-13 17:16:48 +09001332void IPCThreadState::setTheContextObject(const sp<BBinder>& obj)
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001333{
1334 the_context_object = obj;
1335}
1336
1337status_t IPCThreadState::executeCommand(int32_t cmd)
1338{
1339 BBinder* obj;
1340 RefBase::weakref_type* refs;
1341 status_t result = NO_ERROR;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001342
Bernhard RosenkrƤnzer74debb02014-11-25 21:55:33 +01001343 switch ((uint32_t)cmd) {
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001344 case BR_ERROR:
1345 result = mIn.readInt32();
1346 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001347
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001348 case BR_OK:
1349 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001350
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001351 case BR_ACQUIRE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001352 refs = (RefBase::weakref_type*)mIn.readPointer();
1353 obj = (BBinder*)mIn.readPointer();
Steve Block67263472012-01-09 18:35:44 +00001354 ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001355 "BR_ACQUIRE: object %p does not match cookie %p (expected %p)",
1356 refs, obj, refs->refBase());
1357 obj->incStrong(mProcess.get());
1358 IF_LOG_REMOTEREFS() {
1359 LOG_REMOTEREFS("BR_ACQUIRE from driver on %p", obj);
1360 obj->printRefs();
1361 }
1362 mOut.writeInt32(BC_ACQUIRE_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001363 mOut.writePointer((uintptr_t)refs);
1364 mOut.writePointer((uintptr_t)obj);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001365 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001366
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001367 case BR_RELEASE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001368 refs = (RefBase::weakref_type*)mIn.readPointer();
1369 obj = (BBinder*)mIn.readPointer();
Steve Block67263472012-01-09 18:35:44 +00001370 ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001371 "BR_RELEASE: object %p does not match cookie %p (expected %p)",
1372 refs, obj, refs->refBase());
1373 IF_LOG_REMOTEREFS() {
1374 LOG_REMOTEREFS("BR_RELEASE from driver on %p", obj);
1375 obj->printRefs();
1376 }
1377 mPendingStrongDerefs.push(obj);
1378 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001379
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001380 case BR_INCREFS:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001381 refs = (RefBase::weakref_type*)mIn.readPointer();
1382 obj = (BBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001383 refs->incWeak(mProcess.get());
1384 mOut.writeInt32(BC_INCREFS_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001385 mOut.writePointer((uintptr_t)refs);
1386 mOut.writePointer((uintptr_t)obj);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001387 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001388
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001389 case BR_DECREFS:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001390 refs = (RefBase::weakref_type*)mIn.readPointer();
Jiyong Park5970d0a2022-03-08 16:56:13 +09001391 // NOLINTNEXTLINE(clang-analyzer-deadcode.DeadStores)
1392 obj = (BBinder*)mIn.readPointer(); // consume
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001393 // NOTE: This assertion is not valid, because the object may no
1394 // longer exist (thus the (BBinder*)cast above resulting in a different
1395 // memory address).
Steve Block67263472012-01-09 18:35:44 +00001396 //ALOG_ASSERT(refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001397 // "BR_DECREFS: object %p does not match cookie %p (expected %p)",
1398 // refs, obj, refs->refBase());
1399 mPendingWeakDerefs.push(refs);
1400 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001401
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001402 case BR_ATTEMPT_ACQUIRE:
Serban Constantinescuf683e012013-11-05 16:53:55 +00001403 refs = (RefBase::weakref_type*)mIn.readPointer();
1404 obj = (BBinder*)mIn.readPointer();
Tim Murrayd429f4a2017-03-07 09:31:09 -08001405
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001406 {
1407 const bool success = refs->attemptIncStrong(mProcess.get());
Steve Block67263472012-01-09 18:35:44 +00001408 ALOG_ASSERT(success && refs->refBase() == obj,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001409 "BR_ATTEMPT_ACQUIRE: object %p does not match cookie %p (expected %p)",
1410 refs, obj, refs->refBase());
Tim Murrayd429f4a2017-03-07 09:31:09 -08001411
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001412 mOut.writeInt32(BC_ACQUIRE_RESULT);
1413 mOut.writeInt32((int32_t)success);
1414 }
1415 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001416
Steven Morelandf0212002018-12-26 13:59:23 -08001417 case BR_TRANSACTION_SEC_CTX:
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001418 case BR_TRANSACTION:
1419 {
Steven Morelandf0212002018-12-26 13:59:23 -08001420 binder_transaction_data_secctx tr_secctx;
1421 binder_transaction_data& tr = tr_secctx.transaction_data;
1422
1423 if (cmd == (int) BR_TRANSACTION_SEC_CTX) {
1424 result = mIn.read(&tr_secctx, sizeof(tr_secctx));
1425 } else {
1426 result = mIn.read(&tr, sizeof(tr));
1427 tr_secctx.secctx = 0;
1428 }
1429
Steve Block67263472012-01-09 18:35:44 +00001430 ALOG_ASSERT(result == NO_ERROR,
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001431 "Not enough command data for brTRANSACTION");
1432 if (result != NO_ERROR) break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001433
Martijn Coenenea0090a2017-11-02 18:54:40 +00001434 Parcel buffer;
1435 buffer.ipcSetDataReference(
1436 reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer),
1437 tr.data_size,
1438 reinterpret_cast<const binder_size_t*>(tr.data.ptr.offsets),
Steven Moreland161fe122020-11-12 23:16:47 +00001439 tr.offsets_size/sizeof(binder_size_t), freeBuffer);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001440
Steven Moreland39d887d2020-01-31 14:56:45 -08001441 const void* origServingStackPointer = mServingStackPointer;
Steven Moreland35626652021-05-15 01:32:04 +00001442 mServingStackPointer = __builtin_frame_address(0);
Steven Moreland39d887d2020-01-31 14:56:45 -08001443
Martijn Coenenea0090a2017-11-02 18:54:40 +00001444 const pid_t origPid = mCallingPid;
Steven Morelandf0212002018-12-26 13:59:23 -08001445 const char* origSid = mCallingSid;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001446 const uid_t origUid = mCallingUid;
mattgilbride85897672022-10-22 17:42:44 +00001447 const bool origHasExplicitIdentity = mHasExplicitIdentity;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001448 const int32_t origStrictModePolicy = mStrictModePolicy;
1449 const int32_t origTransactionBinderFlags = mLastTransactionBinderFlags;
Olivier Gaillard91a04802018-11-14 17:32:41 +00001450 const int32_t origWorkSource = mWorkSource;
1451 const bool origPropagateWorkSet = mPropagateWorkSource;
1452 // Calling work source will be set by Parcel#enforceInterface. Parcel#enforceInterface
1453 // is only guaranteed to be called for AIDL-generated stubs so we reset the work source
1454 // here to never propagate it.
1455 clearCallingWorkSource();
1456 clearPropagateWorkSource();
Martijn Coenenea0090a2017-11-02 18:54:40 +00001457
1458 mCallingPid = tr.sender_pid;
Steven Morelandf0212002018-12-26 13:59:23 -08001459 mCallingSid = reinterpret_cast<const char*>(tr_secctx.secctx);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001460 mCallingUid = tr.sender_euid;
mattgilbride85897672022-10-22 17:42:44 +00001461 mHasExplicitIdentity = false;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001462 mLastTransactionBinderFlags = tr.flags;
1463
Steven Morelandf0212002018-12-26 13:59:23 -08001464 // ALOGI(">>>> TRANSACT from pid %d sid %s uid %d\n", mCallingPid,
1465 // (mCallingSid ? mCallingSid : "<N/A>"), mCallingUid);
Martijn Coenenea0090a2017-11-02 18:54:40 +00001466
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001467 Parcel reply;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001468 status_t error;
1469 IF_LOG_TRANSACTIONS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001470 std::ostringstream logStream;
1471 logStream << "BR_TRANSACTION thr " << (void*)pthread_self() << " / obj "
1472 << tr.target.ptr << " / code " << TypeCode(tr.code) << ": \t" << buffer
1473 << "\n"
1474 << "Data addr = " << reinterpret_cast<const uint8_t*>(tr.data.ptr.buffer)
1475 << ", offsets addr="
1476 << reinterpret_cast<const size_t*>(tr.data.ptr.offsets) << "\n";
1477 std::string message = logStream.str();
1478 ALOGI("%s", message.c_str());
Martijn Coenenea0090a2017-11-02 18:54:40 +00001479 }
1480 if (tr.target.ptr) {
1481 // We only have a weak reference on the target object, so we must first try to
1482 // safely acquire a strong reference before doing anything else with it.
1483 if (reinterpret_cast<RefBase::weakref_type*>(
1484 tr.target.ptr)->attemptIncStrong(this)) {
1485 error = reinterpret_cast<BBinder*>(tr.cookie)->transact(tr.code, buffer,
1486 &reply, tr.flags);
1487 reinterpret_cast<BBinder*>(tr.cookie)->decStrong(this);
Dianne Hackbornc1114612016-03-21 10:36:54 -07001488 } else {
Martijn Coenenea0090a2017-11-02 18:54:40 +00001489 error = UNKNOWN_TRANSACTION;
Dianne Hackbornc1114612016-03-21 10:36:54 -07001490 }
Brad Fitzpatrick52736032010-08-30 16:01:16 -07001491
Martijn Coenenea0090a2017-11-02 18:54:40 +00001492 } else {
1493 error = the_context_object->transact(tr.code, buffer, &reply, tr.flags);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001494 }
Dianne Hackborn5ee2c9d2014-09-30 11:30:03 -07001495
Steven Morelandf0212002018-12-26 13:59:23 -08001496 //ALOGI("<<<< TRANSACT from pid %d restore pid %d sid %s uid %d\n",
1497 // mCallingPid, origPid, (origSid ? origSid : "<N/A>"), origUid);
Tim Murrayd429f4a2017-03-07 09:31:09 -08001498
Martijn Coenenea0090a2017-11-02 18:54:40 +00001499 if ((tr.flags & TF_ONE_WAY) == 0) {
1500 LOG_ONEWAY("Sending reply to %d!", mCallingPid);
1501 if (error < NO_ERROR) reply.setError(error);
Steven Morelandf183fdd2020-10-27 00:12:12 +00001502
Steven Morelandce15b9f2022-09-08 17:42:45 +00001503 // b/238777741: clear buffer before we send the reply.
1504 // Otherwise, there is a race where the client may
1505 // receive the reply and send another transaction
1506 // here and the space used by this transaction won't
1507 // be freed for the client.
1508 buffer.setDataSize(0);
1509
Steven Morelandf183fdd2020-10-27 00:12:12 +00001510 constexpr uint32_t kForwardReplyFlags = TF_CLEAR_BUF;
Steven Moreland17305282025-01-09 21:28:44 +00001511
1512 // TODO: we may want to abort if there is an error here, or return as 'error'
1513 // from this function, but the impact needs to be measured
1514 status_t error2 = sendReply(reply, (tr.flags & kForwardReplyFlags));
1515 if (error2 != OK) {
1516 ALOGE("error in sendReply for synchronous call: %s",
1517 statusToString(error2).c_str());
1518 }
Martijn Coenenea0090a2017-11-02 18:54:40 +00001519 } else {
Steven Moreland80844f72020-12-12 02:06:08 +00001520 if (error != OK) {
Pawan Wagh7063b522022-09-28 18:52:26 +00001521 std::ostringstream logStream;
1522 logStream << "oneway function results for code " << tr.code << " on binder at "
1523 << reinterpret_cast<void*>(tr.target.ptr)
1524 << " will be dropped but finished with status "
1525 << statusToString(error);
Steven Moreland80844f72020-12-12 02:06:08 +00001526
1527 // ideally we could log this even when error == OK, but it
1528 // causes too much logspam because some manually-written
1529 // interfaces have clients that call methods which always
1530 // write results, sometimes as oneway methods.
1531 if (reply.dataSize() != 0) {
Pawan Wagh7063b522022-09-28 18:52:26 +00001532 logStream << " and reply parcel size " << reply.dataSize();
Steven Moreland80844f72020-12-12 02:06:08 +00001533 }
Pawan Wagh7063b522022-09-28 18:52:26 +00001534 std::string message = logStream.str();
1535 ALOGI("%s", message.c_str());
Steven Morelandce66b8a2020-02-10 14:43:14 -08001536 }
Martijn Coenenea0090a2017-11-02 18:54:40 +00001537 LOG_ONEWAY("NOT sending reply to %d!", mCallingPid);
1538 }
1539
Steven Moreland39d887d2020-01-31 14:56:45 -08001540 mServingStackPointer = origServingStackPointer;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001541 mCallingPid = origPid;
Steven Morelandf0212002018-12-26 13:59:23 -08001542 mCallingSid = origSid;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001543 mCallingUid = origUid;
mattgilbride85897672022-10-22 17:42:44 +00001544 mHasExplicitIdentity = origHasExplicitIdentity;
Martijn Coenenea0090a2017-11-02 18:54:40 +00001545 mStrictModePolicy = origStrictModePolicy;
1546 mLastTransactionBinderFlags = origTransactionBinderFlags;
Olivier Gaillard91a04802018-11-14 17:32:41 +00001547 mWorkSource = origWorkSource;
1548 mPropagateWorkSource = origPropagateWorkSet;
Christopher Tate440fd872010-03-18 17:55:03 -07001549
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001550 IF_LOG_TRANSACTIONS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001551 std::ostringstream logStream;
1552 logStream << "BC_REPLY thr " << (void*)pthread_self() << " / obj " << tr.target.ptr
1553 << ": \t" << reply << "\n";
1554 std::string message = logStream.str();
1555 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001556 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001557
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001558 }
1559 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001560
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001561 case BR_DEAD_BINDER:
1562 {
Serban Constantinescuf683e012013-11-05 16:53:55 +00001563 BpBinder *proxy = (BpBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001564 proxy->sendObituary();
1565 mOut.writeInt32(BC_DEAD_BINDER_DONE);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001566 mOut.writePointer((uintptr_t)proxy);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001567 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001568
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001569 case BR_CLEAR_DEATH_NOTIFICATION_DONE:
1570 {
Serban Constantinescuf683e012013-11-05 16:53:55 +00001571 BpBinder *proxy = (BpBinder*)mIn.readPointer();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001572 proxy->getWeakRefs()->decWeak(proxy);
1573 } break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001574
Yu-Ting Tsengd5fc4462024-04-30 15:07:13 -07001575 case BR_FROZEN_BINDER: {
1576 const struct binder_frozen_state_info* data =
1577 reinterpret_cast<const struct binder_frozen_state_info*>(
1578 mIn.readInplace(sizeof(struct binder_frozen_state_info)));
1579 if (data == nullptr) {
1580 result = UNKNOWN_ERROR;
1581 break;
1582 }
1583 BpBinder* proxy = (BpBinder*)data->cookie;
1584 bool isFrozen = mIn.readInt32() > 0;
1585 proxy->getPrivateAccessor().onFrozenStateChanged(data->is_frozen);
1586 mOut.writeInt32(BC_FREEZE_NOTIFICATION_DONE);
1587 mOut.writePointer(data->cookie);
1588 } break;
1589
1590 case BR_CLEAR_FREEZE_NOTIFICATION_DONE: {
1591 BpBinder* proxy = (BpBinder*)mIn.readPointer();
1592 proxy->getWeakRefs()->decWeak(proxy);
1593 } break;
1594
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001595 case BR_FINISHED:
1596 result = TIMED_OUT;
1597 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001598
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001599 case BR_NOOP:
1600 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001601
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001602 case BR_SPAWN_LOOPER:
1603 mProcess->spawnPooledThread(false);
1604 break;
Tim Murrayd429f4a2017-03-07 09:31:09 -08001605
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001606 default:
liangweikanga43ee152016-10-25 16:37:54 +08001607 ALOGE("*** BAD COMMAND %d received from Binder driver\n", cmd);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001608 result = UNKNOWN_ERROR;
1609 break;
1610 }
1611
1612 if (result != NO_ERROR) {
1613 mLastError = result;
1614 }
Tim Murrayd429f4a2017-03-07 09:31:09 -08001615
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001616 return result;
1617}
1618
Steven Moreland39d887d2020-01-31 14:56:45 -08001619const void* IPCThreadState::getServingStackPointer() const {
1620 return mServingStackPointer;
Jayant Chowdharydac6dc82018-10-01 22:52:44 +00001621}
1622
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001623void IPCThreadState::threadDestructor(void *st)
1624{
Todd Poynor8d96cab2013-06-25 19:12:18 -07001625 IPCThreadState* const self = static_cast<IPCThreadState*>(st);
1626 if (self) {
1627 self->flushCommands();
Elliott Hughes6071da72015-08-12 15:27:47 -07001628#if defined(__ANDROID__)
Alexandre Baiãoc60c4fc2019-07-31 12:29:31 -02001629 if (self->mProcess->mDriverFD >= 0) {
Johannes Carlssondb1597a2011-02-17 14:06:53 +01001630 ioctl(self->mProcess->mDriverFD, BINDER_THREAD_EXIT, 0);
1631 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001632#endif
Todd Poynor8d96cab2013-06-25 19:12:18 -07001633 delete self;
1634 }
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001635}
1636
Li Li6f059292021-09-10 09:59:30 -07001637status_t IPCThreadState::getProcessFreezeInfo(pid_t pid, uint32_t *sync_received,
1638 uint32_t *async_received)
1639{
1640 int ret = 0;
Jiyong Park5970d0a2022-03-08 16:56:13 +09001641 binder_frozen_status_info info = {};
Li Li6f059292021-09-10 09:59:30 -07001642 info.pid = pid;
1643
1644#if defined(__ANDROID__)
1645 if (ioctl(self()->mProcess->mDriverFD, BINDER_GET_FROZEN_INFO, &info) < 0)
1646 ret = -errno;
1647#endif
1648 *sync_received = info.sync_recv;
1649 *async_received = info.async_recv;
1650
1651 return ret;
1652}
Li Li6f059292021-09-10 09:59:30 -07001653
Marco Ballesio7ee17572020-09-08 10:30:03 -07001654status_t IPCThreadState::freeze(pid_t pid, bool enable, uint32_t timeout_ms) {
1655 struct binder_freeze_info info;
1656 int ret = 0;
1657
1658 info.pid = pid;
1659 info.enable = enable;
1660 info.timeout_ms = timeout_ms;
1661
1662
1663#if defined(__ANDROID__)
1664 if (ioctl(self()->mProcess->mDriverFD, BINDER_FREEZE, &info) < 0)
1665 ret = -errno;
1666#endif
1667
1668 //
1669 // ret==-EAGAIN indicates that transactions have not drained.
1670 // Call again to poll for completion.
1671 //
1672 return ret;
1673}
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001674
Carlos Llamasb235b122021-12-20 06:38:44 -08001675void IPCThreadState::logExtendedError() {
1676 struct binder_extended_error ee = {.command = BR_OK};
1677
1678 if (!ProcessState::isDriverFeatureEnabled(ProcessState::DriverFeature::EXTENDED_ERROR))
1679 return;
1680
1681#if defined(__ANDROID__)
1682 if (ioctl(self()->mProcess->mDriverFD, BINDER_GET_EXTENDED_ERROR, &ee) < 0) {
1683 ALOGE("Failed to get extended error: %s", strerror(errno));
1684 return;
1685 }
1686#endif
1687
Steven Morelandb6fe2422024-05-25 00:25:02 +00001688 ALOGE_IF(ee.command != BR_OK, "Binder transaction failure. id: %d, BR_*: %d, error: %d (%s)",
1689 ee.id, ee.command, ee.param, strerror(-ee.param));
Carlos Llamasb235b122021-12-20 06:38:44 -08001690}
1691
Frederick Mayle53b6ffe2022-07-15 20:14:01 +00001692void IPCThreadState::freeBuffer(const uint8_t* data, size_t /*dataSize*/,
1693 const binder_size_t* /*objects*/, size_t /*objectsSize*/) {
Steve Blocka19954a2012-01-04 20:05:49 +00001694 //ALOGI("Freeing parcel %p", &parcel);
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001695 IF_LOG_COMMANDS() {
Pawan Wagh7063b522022-09-28 18:52:26 +00001696 std::ostringstream logStream;
1697 logStream << "Writing BC_FREE_BUFFER for " << data << "\n";
1698 std::string message = logStream.str();
1699 ALOGI("%s", message.c_str());
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001700 }
Steve Block67263472012-01-09 18:35:44 +00001701 ALOG_ASSERT(data != NULL, "Called with NULL data");
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001702 IPCThreadState* state = self();
1703 state->mOut.writeInt32(BC_FREE_BUFFER);
Serban Constantinescuf683e012013-11-05 16:53:55 +00001704 state->mOut.writePointer((uintptr_t)data);
Martijn Coenen0442a862017-11-17 10:46:32 +01001705 state->flushIfNeeded();
The Android Open Source Projectedbf3b62009-03-03 19:31:44 -08001706}
1707
Steven Moreland61ff8492019-09-26 16:05:45 -07001708} // namespace android