blob: fa8459106633bab6222c54c4e4c9b49af36c3ad0 [file] [log] [blame]
Andrew Walbranf395b822021-05-05 10:38:59 +00001// Copyright 2021, The Android Open Source Project
2//
3// Licensed under the Apache License, Version 2.0 (the "License");
4// you may not use this file except in compliance with the License.
5// You may obtain a copy of the License at
6//
7// http://www.apache.org/licenses/LICENSE-2.0
8//
9// Unless required by applicable law or agreed to in writing, software
10// distributed under the License is distributed on an "AS IS" BASIS,
11// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12// See the License for the specific language governing permissions and
13// limitations under the License.
14
15//! Command to run a VM.
16
Jiyong Park48b354d2021-07-15 15:04:38 +090017use crate::create_partition::command_create_partition;
Jooyung Han21e9b922021-06-26 04:14:16 +090018use android_system_virtualizationservice::aidl::android::system::virtualizationservice::{
David Brazdil7d1e5ec2023-02-06 17:56:29 +000019 CpuTopology::CpuTopology,
Alan Stokes0d1ef782022-09-27 13:46:35 +010020 IVirtualizationService::IVirtualizationService,
21 PartitionType::PartitionType,
22 VirtualMachineAppConfig::{DebugLevel::DebugLevel, Payload::Payload, VirtualMachineAppConfig},
23 VirtualMachineConfig::VirtualMachineConfig,
Inseob Kim7b5f65c2022-11-15 14:27:04 +090024 VirtualMachinePayloadConfig::VirtualMachinePayloadConfig,
Andrew Walbranf8d94112021-09-07 11:45:36 +000025 VirtualMachineState::VirtualMachineState,
Jooyung Han21e9b922021-06-26 04:14:16 +090026};
Nikita Ioffeb0b67562022-11-22 15:48:06 +000027use anyhow::{anyhow, bail, Context, Error};
Alan Stokes0e82b502022-08-08 14:44:48 +010028use binder::ParcelFileDescriptor;
Nikita Ioffefc041962023-01-18 00:10:40 +000029use glob::glob;
Inseob Kima5a262f2021-11-17 19:41:03 +090030use microdroid_payload_config::VmPayloadConfig;
Nikita Ioffeb0b67562022-11-22 15:48:06 +000031use rand::{distributions::Alphanumeric, Rng};
32use std::fs;
Andrew Walbranf395b822021-05-05 10:38:59 +000033use std::fs::File;
Alan Stokesf30982b2022-11-18 11:50:32 +000034use std::io;
Andrew Walbranf395b822021-05-05 10:38:59 +000035use std::os::unix::io::{AsRawFd, FromRawFd};
Inseob Kima5a262f2021-11-17 19:41:03 +090036use std::path::{Path, PathBuf};
Alan Stokes2bead0d2022-09-05 16:58:34 +010037use vmclient::{ErrorCode, VmInstance};
Jiyong Park48b354d2021-07-15 15:04:38 +090038use vmconfig::{open_parcel_file, VmConfig};
Inseob Kima5a262f2021-11-17 19:41:03 +090039use zip::ZipArchive;
Andrew Walbranf395b822021-05-05 10:38:59 +000040
Jooyung Han21e9b922021-06-26 04:14:16 +090041/// Run a VM from the given APK, idsig, and config.
Jiyong Park48b354d2021-07-15 15:04:38 +090042#[allow(clippy::too_many_arguments)]
Jooyung Han21e9b922021-06-26 04:14:16 +090043pub fn command_run_app(
Seungjae Yoo62085c02022-08-12 04:44:52 +000044 name: Option<String>,
Andrew Walbran616d13f2022-05-12 18:35:55 +000045 service: &dyn IVirtualizationService,
Jooyung Han21e9b922021-06-26 04:14:16 +090046 apk: &Path,
47 idsig: &Path,
Jiyong Park48b354d2021-07-15 15:04:38 +090048 instance: &Path,
Shikha Panwar22e70452022-10-10 18:32:55 +000049 storage: Option<&Path>,
50 storage_size: Option<u64>,
Inseob Kim7b5f65c2022-11-15 14:27:04 +090051 config_path: Option<String>,
Alan Stokes8f12f2b2023-01-09 09:19:20 +000052 payload_binary_name: Option<String>,
Jiyong Parkb8182bb2021-10-26 22:53:08 +090053 console_path: Option<&Path>,
Jooyung Han21e9b922021-06-26 04:14:16 +090054 log_path: Option<&Path>,
Jiyong Parkc2a49cc2021-10-15 00:02:12 +090055 debug_level: DebugLevel,
Andrew Walbran3994f002022-01-27 17:33:45 +000056 protected: bool,
Jiyong Parkd63cfff2021-09-27 20:10:17 +090057 mem: Option<u32>,
David Brazdil7d1e5ec2023-02-06 17:56:29 +000058 cpu_topology: CpuTopology,
Jiyong Parkdfe16d62022-04-20 17:32:12 +090059 task_profiles: Vec<String>,
Inseob Kima5a262f2021-11-17 19:41:03 +090060 extra_idsigs: &[PathBuf],
Jooyung Han21e9b922021-06-26 04:14:16 +090061) -> Result<(), Error> {
Steven Moreland6a55e2e2022-10-22 00:30:42 +000062 let apk_file = File::open(apk).context("Failed to open APK file")?;
63
Inseob Kim7b5f65c2022-11-15 14:27:04 +090064 let extra_apks = match config_path.as_deref() {
65 Some(path) => parse_extra_apk_list(apk, path)?,
66 None => vec![],
67 };
68
Inseob Kima5a262f2021-11-17 19:41:03 +090069 if extra_apks.len() != extra_idsigs.len() {
70 bail!(
71 "Found {} extra apks, but there are {} extra idsigs",
72 extra_apks.len(),
73 extra_idsigs.len()
74 )
75 }
76
77 for i in 0..extra_apks.len() {
78 let extra_apk_fd = ParcelFileDescriptor::new(File::open(&extra_apks[i])?);
79 let extra_idsig_fd = ParcelFileDescriptor::new(File::create(&extra_idsigs[i])?);
80 service.createOrUpdateIdsigFile(&extra_apk_fd, &extra_idsig_fd)?;
81 }
82
Jiyong Park0a248432021-08-20 23:32:39 +090083 let idsig_file = File::create(idsig).context("Failed to create idsig file")?;
84
85 let apk_fd = ParcelFileDescriptor::new(apk_file);
86 let idsig_fd = ParcelFileDescriptor::new(idsig_file);
87 service.createOrUpdateIdsigFile(&apk_fd, &idsig_fd)?;
88
Jooyung Han21e9b922021-06-26 04:14:16 +090089 let idsig_file = File::open(idsig).context("Failed to open idsig file")?;
Jiyong Park0a248432021-08-20 23:32:39 +090090 let idsig_fd = ParcelFileDescriptor::new(idsig_file);
Jiyong Park48b354d2021-07-15 15:04:38 +090091
92 if !instance.exists() {
93 const INSTANCE_FILE_SIZE: u64 = 10 * 1024 * 1024;
Jiyong Park9dd389e2021-08-23 20:42:59 +090094 command_create_partition(
Andrew Walbran616d13f2022-05-12 18:35:55 +000095 service,
Jiyong Park9dd389e2021-08-23 20:42:59 +090096 instance,
97 INSTANCE_FILE_SIZE,
98 PartitionType::ANDROID_VM_INSTANCE,
99 )?;
Jiyong Park48b354d2021-07-15 15:04:38 +0900100 }
101
Shikha Panwar22e70452022-10-10 18:32:55 +0000102 let storage = if let Some(path) = storage {
103 if !path.exists() {
104 command_create_partition(
105 service,
106 path,
107 storage_size.unwrap_or(10 * 1024 * 1024),
Shikha Panwar9fd198f2022-11-18 17:43:43 +0000108 PartitionType::ENCRYPTEDSTORE,
Shikha Panwar22e70452022-10-10 18:32:55 +0000109 )?;
110 }
111 Some(open_parcel_file(path, true)?)
112 } else {
113 None
114 };
115
Inseob Kima5a262f2021-11-17 19:41:03 +0900116 let extra_idsig_files: Result<Vec<File>, _> = extra_idsigs.iter().map(File::open).collect();
117 let extra_idsig_fds = extra_idsig_files?.into_iter().map(ParcelFileDescriptor::new).collect();
118
Inseob Kim7b5f65c2022-11-15 14:27:04 +0900119 let payload = if let Some(config_path) = config_path {
Alan Stokes8f12f2b2023-01-09 09:19:20 +0000120 if payload_binary_name.is_some() {
121 bail!("Only one of --config-path or --payload-binary-name can be defined")
Inseob Kim7b5f65c2022-11-15 14:27:04 +0900122 }
123 Payload::ConfigPath(config_path)
Alan Stokes8f12f2b2023-01-09 09:19:20 +0000124 } else if let Some(payload_binary_name) = payload_binary_name {
125 Payload::PayloadConfig(VirtualMachinePayloadConfig {
126 payloadBinaryName: payload_binary_name,
127 })
Inseob Kim7b5f65c2022-11-15 14:27:04 +0900128 } else {
Alan Stokes8f12f2b2023-01-09 09:19:20 +0000129 bail!("Either --config-path or --payload-binary-name must be defined")
Inseob Kim7b5f65c2022-11-15 14:27:04 +0900130 };
131
132 let payload_config_str = format!("{:?}!{:?}", apk, payload);
133
Jooyung Han21e9b922021-06-26 04:14:16 +0900134 let config = VirtualMachineConfig::AppConfig(VirtualMachineAppConfig {
Seungjae Yoo62085c02022-08-12 04:44:52 +0000135 name: name.unwrap_or_else(|| String::from("VmRunApp")),
Jiyong Park0a248432021-08-20 23:32:39 +0900136 apk: apk_fd.into(),
137 idsig: idsig_fd.into(),
Inseob Kima5a262f2021-11-17 19:41:03 +0900138 extraIdsigs: extra_idsig_fds,
Jiyong Park48b354d2021-07-15 15:04:38 +0900139 instanceImage: open_parcel_file(instance, true /* writable */)?.into(),
Shikha Panwar22e70452022-10-10 18:32:55 +0000140 encryptedStorageImage: storage,
Inseob Kim7b5f65c2022-11-15 14:27:04 +0900141 payload,
Jiyong Parkc2a49cc2021-10-15 00:02:12 +0900142 debugLevel: debug_level,
Andrew Walbran3994f002022-01-27 17:33:45 +0000143 protectedVm: protected,
Jiyong Parkd63cfff2021-09-27 20:10:17 +0900144 memoryMib: mem.unwrap_or(0) as i32, // 0 means use the VM default
David Brazdil7d1e5ec2023-02-06 17:56:29 +0000145 cpuTopology: cpu_topology,
Jiyong Parkdfe16d62022-04-20 17:32:12 +0900146 taskProfiles: task_profiles,
Jooyung Han21e9b922021-06-26 04:14:16 +0900147 });
David Brazdil2b6352f2023-01-12 11:01:17 +0000148 run(service, &config, &payload_config_str, console_path, log_path)
Jooyung Han21e9b922021-06-26 04:14:16 +0900149}
150
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000151fn find_empty_payload_apk_path() -> Result<PathBuf, Error> {
Nikita Ioffefc041962023-01-18 00:10:40 +0000152 const GLOB_PATTERN: &str = "/apex/com.android.virt/app/**/EmptyPayloadApp.apk";
153 let mut entries: Vec<PathBuf> =
154 glob(GLOB_PATTERN).context("failed to glob")?.filter_map(|e| e.ok()).collect();
155 if entries.len() > 1 {
156 return Err(anyhow!("Found more than one apk matching {}", GLOB_PATTERN));
157 }
158 match entries.pop() {
159 Some(path) => Ok(path),
160 None => Err(anyhow!("No apks match {}", GLOB_PATTERN)),
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000161 }
162}
163
164fn create_work_dir() -> Result<PathBuf, Error> {
165 let s: String =
166 rand::thread_rng().sample_iter(&Alphanumeric).take(17).map(char::from).collect();
167 let work_dir = PathBuf::from("/data/local/tmp/microdroid").join(s);
168 println!("creating work dir {}", work_dir.display());
169 fs::create_dir_all(&work_dir).context("failed to mkdir")?;
170 Ok(work_dir)
171}
172
173/// Run a VM with Microdroid
174#[allow(clippy::too_many_arguments)]
175pub fn command_run_microdroid(
176 name: Option<String>,
177 service: &dyn IVirtualizationService,
178 work_dir: Option<PathBuf>,
179 storage: Option<&Path>,
180 storage_size: Option<u64>,
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000181 console_path: Option<&Path>,
182 log_path: Option<&Path>,
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000183 debug_level: DebugLevel,
184 protected: bool,
185 mem: Option<u32>,
David Brazdil7d1e5ec2023-02-06 17:56:29 +0000186 cpu_topology: CpuTopology,
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000187 task_profiles: Vec<String>,
188) -> Result<(), Error> {
Nikita Ioffefc041962023-01-18 00:10:40 +0000189 let apk = find_empty_payload_apk_path()?;
190 println!("found path {}", apk.display());
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000191
192 let work_dir = work_dir.unwrap_or(create_work_dir()?);
193 let idsig = work_dir.join("apk.idsig");
194 println!("apk.idsig path: {}", idsig.display());
195 let instance_img = work_dir.join("instance.img");
196 println!("instance.img path: {}", instance_img.display());
197
Alan Stokes8f12f2b2023-01-09 09:19:20 +0000198 let payload_binary_name = "MicrodroidEmptyPayloadJniLib.so";
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000199 let extra_sig = [];
200 command_run_app(
201 name,
202 service,
203 &apk,
204 &idsig,
205 &instance_img,
206 storage,
207 storage_size,
208 /* config_path= */ None,
Alan Stokes8f12f2b2023-01-09 09:19:20 +0000209 Some(payload_binary_name.to_owned()),
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000210 console_path,
211 log_path,
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000212 debug_level,
213 protected,
214 mem,
David Brazdil7d1e5ec2023-02-06 17:56:29 +0000215 cpu_topology,
Nikita Ioffeb0b67562022-11-22 15:48:06 +0000216 task_profiles,
217 &extra_sig,
218 )
219}
220
Andrew Walbranf395b822021-05-05 10:38:59 +0000221/// Run a VM from the given configuration file.
Jooyung Hanb7983a22022-02-22 05:21:27 +0900222#[allow(clippy::too_many_arguments)]
Andrew Walbranf395b822021-05-05 10:38:59 +0000223pub fn command_run(
Seungjae Yoo62085c02022-08-12 04:44:52 +0000224 name: Option<String>,
Andrew Walbran616d13f2022-05-12 18:35:55 +0000225 service: &dyn IVirtualizationService,
Andrew Walbranf395b822021-05-05 10:38:59 +0000226 config_path: &Path,
Jiyong Parkb8182bb2021-10-26 22:53:08 +0900227 console_path: Option<&Path>,
Jooyung Hanb7983a22022-02-22 05:21:27 +0900228 log_path: Option<&Path>,
Jiyong Parkd63cfff2021-09-27 20:10:17 +0900229 mem: Option<u32>,
David Brazdil7d1e5ec2023-02-06 17:56:29 +0000230 cpu_topology: CpuTopology,
Jiyong Parkdfe16d62022-04-20 17:32:12 +0900231 task_profiles: Vec<String>,
Andrew Walbranf395b822021-05-05 10:38:59 +0000232) -> Result<(), Error> {
Andrew Walbran3a5a9212021-05-04 17:09:08 +0000233 let config_file = File::open(config_path).context("Failed to open config file")?;
Jiyong Parkd63cfff2021-09-27 20:10:17 +0900234 let mut config =
Andrew Walbran3a5a9212021-05-04 17:09:08 +0000235 VmConfig::load(&config_file).context("Failed to parse config file")?.to_parcelable()?;
Jiyong Parkd63cfff2021-09-27 20:10:17 +0900236 if let Some(mem) = mem {
237 config.memoryMib = mem as i32;
238 }
Seungjae Yoo62085c02022-08-12 04:44:52 +0000239 if let Some(name) = name {
240 config.name = name;
241 } else {
242 config.name = String::from("VmRun");
243 }
David Brazdil7d1e5ec2023-02-06 17:56:29 +0000244 config.cpuTopology = cpu_topology;
Jiyong Parkdfe16d62022-04-20 17:32:12 +0900245 config.taskProfiles = task_profiles;
Jooyung Han21e9b922021-06-26 04:14:16 +0900246 run(
247 service,
248 &VirtualMachineConfig::RawConfig(config),
249 &format!("{:?}", config_path),
Jiyong Parkb8182bb2021-10-26 22:53:08 +0900250 console_path,
Jooyung Hanb7983a22022-02-22 05:21:27 +0900251 log_path,
Jooyung Han21e9b922021-06-26 04:14:16 +0900252 )
253}
254
Andrew Walbranf8d94112021-09-07 11:45:36 +0000255fn state_to_str(vm_state: VirtualMachineState) -> &'static str {
256 match vm_state {
257 VirtualMachineState::NOT_STARTED => "NOT_STARTED",
258 VirtualMachineState::STARTING => "STARTING",
259 VirtualMachineState::STARTED => "STARTED",
260 VirtualMachineState::READY => "READY",
261 VirtualMachineState::FINISHED => "FINISHED",
262 VirtualMachineState::DEAD => "DEAD",
263 _ => "(invalid state)",
264 }
265}
266
Jooyung Han21e9b922021-06-26 04:14:16 +0900267fn run(
Andrew Walbran616d13f2022-05-12 18:35:55 +0000268 service: &dyn IVirtualizationService,
Jooyung Han21e9b922021-06-26 04:14:16 +0900269 config: &VirtualMachineConfig,
Inseob Kim7b5f65c2022-11-15 14:27:04 +0900270 payload_config: &str,
Jiyong Parkb8182bb2021-10-26 22:53:08 +0900271 console_path: Option<&Path>,
Jooyung Han21e9b922021-06-26 04:14:16 +0900272 log_path: Option<&Path>,
273) -> Result<(), Error> {
Jiyong Parkb8182bb2021-10-26 22:53:08 +0900274 let console = if let Some(console_path) = console_path {
Andrew Walbrand0ef4002022-05-16 16:14:10 +0000275 Some(
Jiyong Parkb8182bb2021-10-26 22:53:08 +0900276 File::create(console_path)
277 .with_context(|| format!("Failed to open console file {:?}", console_path))?,
Andrew Walbrand0ef4002022-05-16 16:14:10 +0000278 )
Jiyong Parkb8182bb2021-10-26 22:53:08 +0900279 } else {
Andrew Walbrand0ef4002022-05-16 16:14:10 +0000280 Some(duplicate_stdout()?)
Jiyong Parkb8182bb2021-10-26 22:53:08 +0900281 };
282 let log = if let Some(log_path) = log_path {
Andrew Walbrand0ef4002022-05-16 16:14:10 +0000283 Some(
Andrew Walbranbe429242021-06-28 12:22:54 +0000284 File::create(log_path)
285 .with_context(|| format!("Failed to open log file {:?}", log_path))?,
Andrew Walbrand0ef4002022-05-16 16:14:10 +0000286 )
Andrew Walbranbe429242021-06-28 12:22:54 +0000287 } else {
Andrew Walbrand0ef4002022-05-16 16:14:10 +0000288 Some(duplicate_stdout()?)
Andrew Walbranbe429242021-06-28 12:22:54 +0000289 };
Jiyong Parkb8182bb2021-10-26 22:53:08 +0900290
Alan Stokes0e82b502022-08-08 14:44:48 +0100291 let callback = Box::new(Callback {});
292 let vm = VmInstance::create(service, config, console, log, Some(callback))
293 .context("Failed to create VM")?;
Andrew Walbrand0ef4002022-05-16 16:14:10 +0000294 vm.start().context("Failed to start VM")?;
Andrew Walbranf395b822021-05-05 10:38:59 +0000295
Andrew Walbranf8d94112021-09-07 11:45:36 +0000296 println!(
297 "Created VM from {} with CID {}, state is {}.",
Inseob Kim7b5f65c2022-11-15 14:27:04 +0900298 payload_config,
Andrew Walbrand0ef4002022-05-16 16:14:10 +0000299 vm.cid(),
300 state_to_str(vm.state()?)
Andrew Walbranf8d94112021-09-07 11:45:36 +0000301 );
Andrew Walbranf395b822021-05-05 10:38:59 +0000302
David Brazdil2b6352f2023-01-12 11:01:17 +0000303 // Wait until the VM or VirtualizationService dies. If we just returned immediately then the
304 // IVirtualMachine Binder object would be dropped and the VM would be killed.
305 let death_reason = vm.wait_for_death();
306 println!("VM ended: {:?}", death_reason);
Andrew Walbranf395b822021-05-05 10:38:59 +0000307 Ok(())
308}
309
Inseob Kima5a262f2021-11-17 19:41:03 +0900310fn parse_extra_apk_list(apk: &Path, config_path: &str) -> Result<Vec<String>, Error> {
311 let mut archive = ZipArchive::new(File::open(apk)?)?;
312 let config_file = archive.by_name(config_path)?;
313 let config: VmPayloadConfig = serde_json::from_reader(config_file)?;
314 Ok(config.extra_apks.into_iter().map(|x| x.path).collect())
315}
316
Alan Stokes0e82b502022-08-08 14:44:48 +0100317struct Callback {}
Andrew Walbranf395b822021-05-05 10:38:59 +0000318
Alan Stokes0e82b502022-08-08 14:44:48 +0100319impl vmclient::VmCallback for Callback {
David Brazdil451cc962022-10-14 14:08:12 +0100320 fn on_payload_started(&self, _cid: i32) {
321 eprintln!("payload started");
322 }
323
Alan Stokes0e82b502022-08-08 14:44:48 +0100324 fn on_payload_ready(&self, _cid: i32) {
Inseob Kim8dbc3222021-09-01 21:50:23 +0900325 eprintln!("payload is ready");
Inseob Kim14cb8692021-08-31 21:50:39 +0900326 }
327
Alan Stokes0e82b502022-08-08 14:44:48 +0100328 fn on_payload_finished(&self, _cid: i32, exit_code: i32) {
Inseob Kim8dbc3222021-09-01 21:50:23 +0900329 eprintln!("payload finished with exit code {}", exit_code);
Inseob Kim2444af92021-08-31 01:22:50 +0900330 }
331
Alan Stokes2bead0d2022-09-05 16:58:34 +0100332 fn on_error(&self, _cid: i32, error_code: ErrorCode, message: &str) {
333 eprintln!("VM encountered an error: code={:?}, message={}", error_code, message);
Andrew Walbranf395b822021-05-05 10:38:59 +0000334 }
335}
336
337/// Safely duplicate the standard output file descriptor.
338fn duplicate_stdout() -> io::Result<File> {
339 let stdout_fd = io::stdout().as_raw_fd();
340 // Safe because this just duplicates a file descriptor which we know to be valid, and we check
341 // for an error.
342 let dup_fd = unsafe { libc::dup(stdout_fd) };
343 if dup_fd < 0 {
344 Err(io::Error::last_os_error())
345 } else {
346 // Safe because we have just duplicated the file descriptor so we own it, and `from_raw_fd`
347 // takes ownership of it.
348 Ok(unsafe { File::from_raw_fd(dup_fd) })
349 }
350}