blob: dc6c8c07f2c1a338894aecbd1e969ba176ab26f2 [file] [log] [blame]
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -08001/*
2 * Copyright (C) 2019 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17//#define LOG_NDEBUG 0
18#define LOG_TAG "libprocessgroup"
19
T.J. Mercier39846112024-10-09 22:40:26 +000020#include <task_profiles.h>
21
22#include <map>
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -070023#include <optional>
T.J. Mercier39846112024-10-09 22:40:26 +000024#include <string>
25
T.J. Mercier54bfde02024-06-04 23:25:29 +000026#include <dirent.h>
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -080027#include <fcntl.h>
T.J. Mercier39846112024-10-09 22:40:26 +000028#include <sched.h>
29#include <sys/resource.h>
T.J. Mercier54bfde02024-06-04 23:25:29 +000030#include <unistd.h>
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -080031
32#include <android-base/file.h>
33#include <android-base/logging.h>
Suren Baghdasaryan35221b52020-11-20 17:08:51 -080034#include <android-base/properties.h>
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -080035#include <android-base/stringprintf.h>
Rick Yiubc1ad962020-10-26 20:32:52 +080036#include <android-base/strings.h>
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -080037#include <android-base/threads.h>
38
T.J. Mercier39846112024-10-09 22:40:26 +000039#include <build_flags.h>
40
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -080041#include <cutils/android_filesystem_config.h>
42
43#include <json/reader.h>
44#include <json/value.h>
45
46using android::base::GetThreadId;
Suren Baghdasaryan35221b52020-11-20 17:08:51 -080047using android::base::GetUintProperty;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -080048using android::base::StringPrintf;
Rick Yiubc1ad962020-10-26 20:32:52 +080049using android::base::StringReplace;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -080050using android::base::unique_fd;
51using android::base::WriteStringToFile;
52
Suren Baghdasaryan35221b52020-11-20 17:08:51 -080053static constexpr const char* TASK_PROFILE_DB_FILE = "/etc/task_profiles.json";
54static constexpr const char* TASK_PROFILE_DB_VENDOR_FILE = "/vendor/etc/task_profiles.json";
55
56static constexpr const char* TEMPLATE_TASK_PROFILE_API_FILE =
57 "/etc/task_profiles/task_profiles_%u.json";
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -070058namespace {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -080059
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -080060class FdCacheHelper {
61 public:
62 enum FdState {
63 FDS_INACCESSIBLE = -1,
64 FDS_APP_DEPENDENT = -2,
65 FDS_NOT_CACHED = -3,
66 };
67
68 static void Cache(const std::string& path, android::base::unique_fd& fd);
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -070069
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -080070 static void Drop(android::base::unique_fd& fd);
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -070071
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -080072 static void Init(const std::string& path, android::base::unique_fd& fd);
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -070073
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -080074 static bool IsCached(const android::base::unique_fd& fd) { return fd > FDS_INACCESSIBLE; }
75
76 private:
77 static bool IsAppDependentPath(const std::string& path);
78};
79
80void FdCacheHelper::Init(const std::string& path, android::base::unique_fd& fd) {
81 // file descriptors for app-dependent paths can't be cached
82 if (IsAppDependentPath(path)) {
83 // file descriptor is not cached
84 fd.reset(FDS_APP_DEPENDENT);
85 return;
86 }
87 // file descriptor can be cached later on request
88 fd.reset(FDS_NOT_CACHED);
89}
90
91void FdCacheHelper::Cache(const std::string& path, android::base::unique_fd& fd) {
92 if (fd != FDS_NOT_CACHED) {
93 return;
94 }
95
96 if (access(path.c_str(), W_OK) != 0) {
97 // file is not accessible
98 fd.reset(FDS_INACCESSIBLE);
99 return;
100 }
101
102 unique_fd tmp_fd(TEMP_FAILURE_RETRY(open(path.c_str(), O_WRONLY | O_CLOEXEC)));
103 if (tmp_fd < 0) {
104 PLOG(ERROR) << "Failed to cache fd '" << path << "'";
105 fd.reset(FDS_INACCESSIBLE);
106 return;
107 }
108
109 fd = std::move(tmp_fd);
110}
111
112void FdCacheHelper::Drop(android::base::unique_fd& fd) {
113 if (fd == FDS_NOT_CACHED) {
114 return;
115 }
116
117 fd.reset(FDS_NOT_CACHED);
118}
119
120bool FdCacheHelper::IsAppDependentPath(const std::string& path) {
121 return path.find("<uid>", 0) != std::string::npos || path.find("<pid>", 0) != std::string::npos;
122}
123
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -0700124std::optional<long> readLong(const std::string& str) {
125 char* end;
126 const long result = strtol(str.c_str(), &end, 10);
127 if (end > str.c_str()) {
128 return result;
129 }
130 return std::nullopt;
131}
132
133} // namespace
134
Bart Van Assche4c99e962022-02-03 19:50:16 +0000135IProfileAttribute::~IProfileAttribute() = default;
136
Suren Baghdasaryan35078462023-07-25 14:50:18 -0700137const std::string& ProfileAttribute::file_name() const {
138 if (controller()->version() == 2 && !file_v2_name_.empty()) return file_v2_name_;
139 return file_name_;
140}
141
T.J. Mercierfcb86662024-08-01 20:52:30 +0000142void ProfileAttribute::Reset(const CgroupControllerWrapper& controller,
143 const std::string& file_name, const std::string& file_v2_name) {
Suren Baghdasaryan81b9f0b2020-07-01 12:34:17 -0700144 controller_ = controller;
145 file_name_ = file_name;
Suren Baghdasaryan35078462023-07-25 14:50:18 -0700146 file_v2_name_ = file_v2_name;
Suren Baghdasaryan81b9f0b2020-07-01 12:34:17 -0700147}
148
T.J. Mercier1cfa2c42024-04-08 21:14:32 +0000149static bool isSystemApp(uid_t uid) {
150 return uid < AID_APP_START;
151}
152
T.J. Mercierd1e048f2024-03-28 00:33:44 +0000153std::string ConvertUidToPath(const char* root_cgroup_path, uid_t uid) {
T.J. Mercier1cfa2c42024-04-08 21:14:32 +0000154 if (android::libprocessgroup_flags::cgroup_v2_sys_app_isolation()) {
155 if (isSystemApp(uid))
156 return StringPrintf("%s/system/uid_%u", root_cgroup_path, uid);
157 else
158 return StringPrintf("%s/apps/uid_%u", root_cgroup_path, uid);
159 }
T.J. Mercierd1e048f2024-03-28 00:33:44 +0000160 return StringPrintf("%s/uid_%u", root_cgroup_path, uid);
161}
162
163std::string ConvertUidPidToPath(const char* root_cgroup_path, uid_t uid, pid_t pid) {
164 const std::string uid_path = ConvertUidToPath(root_cgroup_path, uid);
165 return StringPrintf("%s/pid_%d", uid_path.c_str(), pid);
166}
167
Suren Baghdasaryan34837982023-07-25 15:45:45 -0700168bool ProfileAttribute::GetPathForProcess(uid_t uid, pid_t pid, std::string* path) const {
169 if (controller()->version() == 2) {
T.J. Mercierd1e048f2024-03-28 00:33:44 +0000170 const std::string cgroup_path = ConvertUidPidToPath(controller()->path(), uid, pid);
171 *path = cgroup_path + "/" + file_name();
Suren Baghdasaryan34837982023-07-25 15:45:45 -0700172 return true;
173 }
174 return GetPathForTask(pid, path);
175}
176
T.J. Mercier1c007992024-01-25 16:29:54 +0000177bool ProfileAttribute::GetPathForTask(pid_t tid, std::string* path) const {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800178 std::string subgroup;
Yifan Hong53e0deb2019-03-22 17:01:08 -0700179 if (!controller()->GetTaskGroup(tid, &subgroup)) {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800180 return false;
181 }
182
183 if (path == nullptr) {
184 return true;
185 }
186
187 if (subgroup.empty()) {
Suren Baghdasaryan35078462023-07-25 14:50:18 -0700188 *path = StringPrintf("%s/%s", controller()->path(), file_name().c_str());
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800189 } else {
Suren Baghdasaryan35078462023-07-25 14:50:18 -0700190 *path = StringPrintf("%s/%s/%s", controller()->path(), subgroup.c_str(),
191 file_name().c_str());
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800192 }
193 return true;
194}
195
T.J. Mercierd1e048f2024-03-28 00:33:44 +0000196// NOTE: This function is for cgroup v2 only
T.J. Mercier5ed5e1b2022-08-22 21:25:09 +0000197bool ProfileAttribute::GetPathForUID(uid_t uid, std::string* path) const {
198 if (path == nullptr) {
199 return true;
200 }
201
T.J. Mercierd1e048f2024-03-28 00:33:44 +0000202 const std::string cgroup_path = ConvertUidToPath(controller()->path(), uid);
203 *path = cgroup_path + "/" + file_name();
T.J. Mercier5ed5e1b2022-08-22 21:25:09 +0000204 return true;
205}
206
T.J. Mercier1c007992024-01-25 16:29:54 +0000207bool SetTimerSlackAction::ExecuteForTask(pid_t tid) const {
T.J. Mercier07500812024-10-09 17:41:32 +0000208 const auto file = StringPrintf("/proc/%d/timerslack_ns", tid);
209 if (!WriteStringToFile(std::to_string(slack_), file)) {
210 if (errno == ENOENT) {
211 // This happens when process is already dead
212 return true;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800213 }
T.J. Mercier07500812024-10-09 17:41:32 +0000214 PLOG(ERROR) << "set_timerslack_ns write failed";
215 return false;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800216 }
217
218 return true;
219}
220
Suren Baghdasaryan34837982023-07-25 15:45:45 -0700221bool SetAttributeAction::WriteValueToFile(const std::string& path) const {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800222 if (!WriteStringToFile(value_, path)) {
Bart Van Assche9b5a2322022-03-22 16:15:00 -0700223 if (access(path.c_str(), F_OK) < 0) {
Bart Van Assche59af6802022-01-24 21:08:57 +0000224 if (optional_) {
225 return true;
226 } else {
227 LOG(ERROR) << "No such cgroup attribute: " << path;
228 return false;
229 }
230 }
Bart Van Assche54136f82022-03-31 11:26:42 -0700231 // The PLOG() statement below uses the error code stored in `errno` by
232 // WriteStringToFile() because access() only overwrites `errno` if it fails
233 // and because this code is only reached if the access() function returns 0.
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800234 PLOG(ERROR) << "Failed to write '" << value_ << "' to " << path;
235 return false;
236 }
237
238 return true;
239}
240
Suren Baghdasaryan34837982023-07-25 15:45:45 -0700241bool SetAttributeAction::ExecuteForProcess(uid_t uid, pid_t pid) const {
242 std::string path;
243
244 if (!attribute_->GetPathForProcess(uid, pid, &path)) {
245 LOG(ERROR) << "Failed to find cgroup for uid " << uid << " pid " << pid;
246 return false;
247 }
248
249 return WriteValueToFile(path);
250}
251
T.J. Mercier1c007992024-01-25 16:29:54 +0000252bool SetAttributeAction::ExecuteForTask(pid_t tid) const {
Suren Baghdasaryan34837982023-07-25 15:45:45 -0700253 std::string path;
254
255 if (!attribute_->GetPathForTask(tid, &path)) {
256 LOG(ERROR) << "Failed to find cgroup for tid " << tid;
257 return false;
258 }
259
260 return WriteValueToFile(path);
261}
262
T.J. Mercier5ed5e1b2022-08-22 21:25:09 +0000263bool SetAttributeAction::ExecuteForUID(uid_t uid) const {
264 std::string path;
265
266 if (!attribute_->GetPathForUID(uid, &path)) {
267 LOG(ERROR) << "Failed to find cgroup for uid " << uid;
268 return false;
269 }
270
271 if (!WriteStringToFile(value_, path)) {
272 if (access(path.c_str(), F_OK) < 0) {
273 if (optional_) {
274 return true;
275 } else {
276 LOG(ERROR) << "No such cgroup attribute: " << path;
277 return false;
278 }
279 }
280 PLOG(ERROR) << "Failed to write '" << value_ << "' to " << path;
281 return false;
282 }
283 return true;
284}
285
Suren Baghdasaryan8cacb612023-04-12 01:24:23 +0000286bool SetAttributeAction::IsValidForProcess(uid_t, pid_t pid) const {
287 return IsValidForTask(pid);
288}
289
T.J. Mercier1c007992024-01-25 16:29:54 +0000290bool SetAttributeAction::IsValidForTask(pid_t tid) const {
Suren Baghdasaryan8cacb612023-04-12 01:24:23 +0000291 std::string path;
292
293 if (!attribute_->GetPathForTask(tid, &path)) {
294 return false;
295 }
296
297 if (!access(path.c_str(), W_OK)) {
298 // operation will succeed
299 return true;
300 }
301
302 if (!access(path.c_str(), F_OK)) {
303 // file exists but not writable
304 return false;
305 }
306
307 // file does not exist, ignore if optional
308 return optional_;
309}
310
T.J. Mercierfcb86662024-08-01 20:52:30 +0000311SetCgroupAction::SetCgroupAction(const CgroupControllerWrapper& c, const std::string& p)
Rick Yiud4c53512021-11-21 15:57:36 +0800312 : controller_(c), path_(p) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800313 FdCacheHelper::Init(controller_.GetTasksFilePath(path_), fd_[ProfileAction::RCT_TASK]);
314 // uid and pid don't matter because IsAppDependentPath ensures the path doesn't use them
315 FdCacheHelper::Init(controller_.GetProcsFilePath(path_, 0, 0), fd_[ProfileAction::RCT_PROCESS]);
Rick Yiud4c53512021-11-21 15:57:36 +0800316}
317
T.J. Mercier1c007992024-01-25 16:29:54 +0000318bool SetCgroupAction::AddTidToCgroup(pid_t tid, int fd, ResourceCacheType cache_type) const {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800319 if (tid <= 0) {
320 return true;
321 }
322
323 std::string value = std::to_string(tid);
324
Suren Baghdasaryanec885562021-09-02 19:47:12 -0700325 if (TEMP_FAILURE_RETRY(write(fd, value.c_str(), value.length())) == value.length()) {
326 return true;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800327 }
328
Suren Baghdasaryanec885562021-09-02 19:47:12 -0700329 // If the thread is in the process of exiting, don't flag an error
330 if (errno == ESRCH) {
331 return true;
332 }
333
Bart Van Asschedf985342023-11-13 15:19:43 -0800334 const char* controller_name = controller()->name();
Suren Baghdasaryanec885562021-09-02 19:47:12 -0700335 // ENOSPC is returned when cpuset cgroup that we are joining has no online cpus
336 if (errno == ENOSPC && !strcmp(controller_name, "cpuset")) {
337 // This is an abnormal case happening only in testing, so report it only once
338 static bool empty_cpuset_reported = false;
339
340 if (empty_cpuset_reported) {
341 return true;
342 }
343
344 LOG(ERROR) << "Failed to add task '" << value
345 << "' into cpuset because all cpus in that cpuset are offline";
346 empty_cpuset_reported = true;
347 } else {
Bart Van Asschedf985342023-11-13 15:19:43 -0800348 PLOG(ERROR) << "AddTidToCgroup failed to write '" << value << "'; path=" << path_ << "; "
349 << (cache_type == RCT_TASK ? "task" : "process");
Suren Baghdasaryanec885562021-09-02 19:47:12 -0700350 }
351
352 return false;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800353}
354
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800355ProfileAction::CacheUseResult SetCgroupAction::UseCachedFd(ResourceCacheType cache_type,
356 int id) const {
357 std::lock_guard<std::mutex> lock(fd_mutex_);
358 if (FdCacheHelper::IsCached(fd_[cache_type])) {
359 // fd is cached, reuse it
Bart Van Asschedf985342023-11-13 15:19:43 -0800360 if (!AddTidToCgroup(id, fd_[cache_type], cache_type)) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800361 LOG(ERROR) << "Failed to add task into cgroup";
362 return ProfileAction::FAIL;
363 }
364 return ProfileAction::SUCCESS;
365 }
366
367 if (fd_[cache_type] == FdCacheHelper::FDS_INACCESSIBLE) {
368 // no permissions to access the file, ignore
369 return ProfileAction::SUCCESS;
370 }
371
372 if (cache_type == ResourceCacheType::RCT_TASK &&
373 fd_[cache_type] == FdCacheHelper::FDS_APP_DEPENDENT) {
374 // application-dependent path can't be used with tid
Bart Van Assche7a952612022-10-12 13:27:28 -0700375 LOG(ERROR) << Name() << ": application profile can't be applied to a thread";
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800376 return ProfileAction::FAIL;
377 }
378
379 return ProfileAction::UNUSED;
380}
381
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800382bool SetCgroupAction::ExecuteForProcess(uid_t uid, pid_t pid) const {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800383 CacheUseResult result = UseCachedFd(ProfileAction::RCT_PROCESS, pid);
384 if (result != ProfileAction::UNUSED) {
385 return result == ProfileAction::SUCCESS;
386 }
387
388 // fd was not cached or cached fd can't be used
Yifan Hong53e0deb2019-03-22 17:01:08 -0700389 std::string procs_path = controller()->GetProcsFilePath(path_, uid, pid);
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800390 unique_fd tmp_fd(TEMP_FAILURE_RETRY(open(procs_path.c_str(), O_WRONLY | O_CLOEXEC)));
391 if (tmp_fd < 0) {
Bart Van Assche7a952612022-10-12 13:27:28 -0700392 PLOG(WARNING) << Name() << "::" << __func__ << ": failed to open " << procs_path;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800393 return false;
394 }
Bart Van Asschedf985342023-11-13 15:19:43 -0800395 if (!AddTidToCgroup(pid, tmp_fd, RCT_PROCESS)) {
Wei Wangd71d3012019-03-07 11:59:12 -0800396 LOG(ERROR) << "Failed to add task into cgroup";
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800397 return false;
398 }
399
400 return true;
401}
402
T.J. Mercier1c007992024-01-25 16:29:54 +0000403bool SetCgroupAction::ExecuteForTask(pid_t tid) const {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800404 CacheUseResult result = UseCachedFd(ProfileAction::RCT_TASK, tid);
405 if (result != ProfileAction::UNUSED) {
406 return result == ProfileAction::SUCCESS;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800407 }
408
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800409 // fd was not cached or cached fd can't be used
Yifan Hong53e0deb2019-03-22 17:01:08 -0700410 std::string tasks_path = controller()->GetTasksFilePath(path_);
Suren Baghdasaryanbee9f572019-02-05 16:44:22 -0800411 unique_fd tmp_fd(TEMP_FAILURE_RETRY(open(tasks_path.c_str(), O_WRONLY | O_CLOEXEC)));
412 if (tmp_fd < 0) {
Bart Van Assche7a952612022-10-12 13:27:28 -0700413 PLOG(WARNING) << Name() << "::" << __func__ << ": failed to open " << tasks_path;
Suren Baghdasaryan8a315d22019-02-14 14:40:41 -0800414 return false;
Suren Baghdasaryanbee9f572019-02-05 16:44:22 -0800415 }
Bart Van Asschedf985342023-11-13 15:19:43 -0800416 if (!AddTidToCgroup(tid, tmp_fd, RCT_TASK)) {
Wei Wangd71d3012019-03-07 11:59:12 -0800417 LOG(ERROR) << "Failed to add task into cgroup";
Suren Baghdasaryanbee9f572019-02-05 16:44:22 -0800418 return false;
419 }
420
421 return true;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800422}
423
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800424void SetCgroupAction::EnableResourceCaching(ResourceCacheType cache_type) {
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -0800425 std::lock_guard<std::mutex> lock(fd_mutex_);
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800426 // Return early to prevent unnecessary calls to controller_.Get{Tasks|Procs}FilePath() which
427 // include regex evaluations
428 if (fd_[cache_type] != FdCacheHelper::FDS_NOT_CACHED) {
429 return;
430 }
431 switch (cache_type) {
432 case (ProfileAction::RCT_TASK):
433 FdCacheHelper::Cache(controller_.GetTasksFilePath(path_), fd_[cache_type]);
434 break;
435 case (ProfileAction::RCT_PROCESS):
436 // uid and pid don't matter because IsAppDependentPath ensures the path doesn't use them
437 FdCacheHelper::Cache(controller_.GetProcsFilePath(path_, 0, 0), fd_[cache_type]);
438 break;
439 default:
440 LOG(ERROR) << "Invalid cache type is specified!";
441 break;
442 }
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -0800443}
444
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800445void SetCgroupAction::DropResourceCaching(ResourceCacheType cache_type) {
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -0800446 std::lock_guard<std::mutex> lock(fd_mutex_);
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800447 FdCacheHelper::Drop(fd_[cache_type]);
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -0800448}
449
Suren Baghdasaryan8cacb612023-04-12 01:24:23 +0000450bool SetCgroupAction::IsValidForProcess(uid_t uid, pid_t pid) const {
451 std::lock_guard<std::mutex> lock(fd_mutex_);
452 if (FdCacheHelper::IsCached(fd_[ProfileAction::RCT_PROCESS])) {
453 return true;
454 }
455
456 if (fd_[ProfileAction::RCT_PROCESS] == FdCacheHelper::FDS_INACCESSIBLE) {
457 return false;
458 }
459
460 std::string procs_path = controller()->GetProcsFilePath(path_, uid, pid);
461 return access(procs_path.c_str(), W_OK) == 0;
462}
463
464bool SetCgroupAction::IsValidForTask(int) const {
465 std::lock_guard<std::mutex> lock(fd_mutex_);
466 if (FdCacheHelper::IsCached(fd_[ProfileAction::RCT_TASK])) {
467 return true;
468 }
469
470 if (fd_[ProfileAction::RCT_TASK] == FdCacheHelper::FDS_INACCESSIBLE) {
471 return false;
472 }
473
474 if (fd_[ProfileAction::RCT_TASK] == FdCacheHelper::FDS_APP_DEPENDENT) {
475 // application-dependent path can't be used with tid
476 return false;
477 }
478
479 std::string tasks_path = controller()->GetTasksFilePath(path_);
480 return access(tasks_path.c_str(), W_OK) == 0;
481}
482
Rick Yiu9221b1e2022-02-10 16:44:43 +0800483WriteFileAction::WriteFileAction(const std::string& task_path, const std::string& proc_path,
484 const std::string& value, bool logfailures)
485 : task_path_(task_path), proc_path_(proc_path), value_(value), logfailures_(logfailures) {
486 FdCacheHelper::Init(task_path_, fd_[ProfileAction::RCT_TASK]);
487 if (!proc_path_.empty()) FdCacheHelper::Init(proc_path_, fd_[ProfileAction::RCT_PROCESS]);
Rick Yiud4c53512021-11-21 15:57:36 +0800488}
Rick Yiubc1ad962020-10-26 20:32:52 +0800489
Rick Yiu9221b1e2022-02-10 16:44:43 +0800490bool WriteFileAction::WriteValueToFile(const std::string& value_, ResourceCacheType cache_type,
T.J. Mercierd6fb2252024-01-24 23:42:39 +0000491 uid_t uid, pid_t pid, bool logfailures) const {
Rick Yiu9221b1e2022-02-10 16:44:43 +0800492 std::string value(value_);
493
494 value = StringReplace(value, "<uid>", std::to_string(uid), true);
495 value = StringReplace(value, "<pid>", std::to_string(pid), true);
496
497 CacheUseResult result = UseCachedFd(cache_type, value);
498
499 if (result != ProfileAction::UNUSED) {
500 return result == ProfileAction::SUCCESS;
501 }
502
503 std::string path;
504 if (cache_type == ProfileAction::RCT_TASK || proc_path_.empty()) {
505 path = task_path_;
506 } else {
507 path = proc_path_;
508 }
509
Rick Yiud4c53512021-11-21 15:57:36 +0800510 // Use WriteStringToFd instead of WriteStringToFile because the latter will open file with
511 // O_TRUNC which causes kernfs_mutex contention
512 unique_fd tmp_fd(TEMP_FAILURE_RETRY(open(path.c_str(), O_WRONLY | O_CLOEXEC)));
Rick Yiubc1ad962020-10-26 20:32:52 +0800513
Rick Yiud4c53512021-11-21 15:57:36 +0800514 if (tmp_fd < 0) {
Bart Van Assche7a952612022-10-12 13:27:28 -0700515 if (logfailures) PLOG(WARNING) << Name() << "::" << __func__ << ": failed to open " << path;
Rick Yiud4c53512021-11-21 15:57:36 +0800516 return false;
517 }
518
519 if (!WriteStringToFd(value, tmp_fd)) {
520 if (logfailures) PLOG(ERROR) << "Failed to write '" << value << "' to " << path;
Rick Yiubc1ad962020-10-26 20:32:52 +0800521 return false;
522 }
523
524 return true;
525}
526
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800527ProfileAction::CacheUseResult WriteFileAction::UseCachedFd(ResourceCacheType cache_type,
528 const std::string& value) const {
Rick Yiud4c53512021-11-21 15:57:36 +0800529 std::lock_guard<std::mutex> lock(fd_mutex_);
Rick Yiu9221b1e2022-02-10 16:44:43 +0800530 if (FdCacheHelper::IsCached(fd_[cache_type])) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800531 // fd is cached, reuse it
Rick Yiu9221b1e2022-02-10 16:44:43 +0800532 bool ret = WriteStringToFd(value, fd_[cache_type]);
533
534 if (!ret && logfailures_) {
535 if (cache_type == ProfileAction::RCT_TASK || proc_path_.empty()) {
536 PLOG(ERROR) << "Failed to write '" << value << "' to " << task_path_;
537 } else {
538 PLOG(ERROR) << "Failed to write '" << value << "' to " << proc_path_;
539 }
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800540 }
Rick Yiu9221b1e2022-02-10 16:44:43 +0800541 return ret ? ProfileAction::SUCCESS : ProfileAction::FAIL;
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800542 }
543
Rick Yiu9221b1e2022-02-10 16:44:43 +0800544 if (fd_[cache_type] == FdCacheHelper::FDS_INACCESSIBLE) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800545 // no permissions to access the file, ignore
546 return ProfileAction::SUCCESS;
547 }
548
Rick Yiu9221b1e2022-02-10 16:44:43 +0800549 if (cache_type == ResourceCacheType::RCT_TASK &&
550 fd_[cache_type] == FdCacheHelper::FDS_APP_DEPENDENT) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800551 // application-dependent path can't be used with tid
Bart Van Assche7a952612022-10-12 13:27:28 -0700552 LOG(ERROR) << Name() << ": application profile can't be applied to a thread";
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800553 return ProfileAction::FAIL;
554 }
555 return ProfileAction::UNUSED;
556}
557
558bool WriteFileAction::ExecuteForProcess(uid_t uid, pid_t pid) const {
Rick Yiu9221b1e2022-02-10 16:44:43 +0800559 if (!proc_path_.empty()) {
560 return WriteValueToFile(value_, ProfileAction::RCT_PROCESS, uid, pid, logfailures_);
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800561 }
562
Rick Yiu9221b1e2022-02-10 16:44:43 +0800563 DIR* d;
564 struct dirent* de;
565 char proc_path[255];
T.J. Mercierd6fb2252024-01-24 23:42:39 +0000566 pid_t t_pid;
Rick Yiud4c53512021-11-21 15:57:36 +0800567
Rick Yiu9221b1e2022-02-10 16:44:43 +0800568 sprintf(proc_path, "/proc/%d/task", pid);
569 if (!(d = opendir(proc_path))) {
570 return false;
571 }
572
573 while ((de = readdir(d))) {
574 if (de->d_name[0] == '.') {
575 continue;
576 }
577
578 t_pid = atoi(de->d_name);
579
580 if (!t_pid) {
581 continue;
582 }
583
584 WriteValueToFile(value_, ProfileAction::RCT_TASK, uid, t_pid, logfailures_);
585 }
586
587 closedir(d);
588
589 return true;
Rick Yiud4c53512021-11-21 15:57:36 +0800590}
591
T.J. Mercier1c007992024-01-25 16:29:54 +0000592bool WriteFileAction::ExecuteForTask(pid_t tid) const {
Rick Yiu9221b1e2022-02-10 16:44:43 +0800593 return WriteValueToFile(value_, ProfileAction::RCT_TASK, getuid(), tid, logfailures_);
594}
Rick Yiubc1ad962020-10-26 20:32:52 +0800595
Rick Yiu9221b1e2022-02-10 16:44:43 +0800596void WriteFileAction::EnableResourceCaching(ResourceCacheType cache_type) {
597 std::lock_guard<std::mutex> lock(fd_mutex_);
598 if (fd_[cache_type] != FdCacheHelper::FDS_NOT_CACHED) {
599 return;
Rick Yiubc1ad962020-10-26 20:32:52 +0800600 }
Rick Yiu9221b1e2022-02-10 16:44:43 +0800601 switch (cache_type) {
602 case (ProfileAction::RCT_TASK):
603 FdCacheHelper::Cache(task_path_, fd_[cache_type]);
604 break;
605 case (ProfileAction::RCT_PROCESS):
606 if (!proc_path_.empty()) FdCacheHelper::Cache(proc_path_, fd_[cache_type]);
607 break;
608 default:
609 LOG(ERROR) << "Invalid cache type is specified!";
610 break;
611 }
Rick Yiubc1ad962020-10-26 20:32:52 +0800612}
613
Rick Yiu9221b1e2022-02-10 16:44:43 +0800614void WriteFileAction::DropResourceCaching(ResourceCacheType cache_type) {
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -0800615 std::lock_guard<std::mutex> lock(fd_mutex_);
Rick Yiu9221b1e2022-02-10 16:44:43 +0800616 FdCacheHelper::Drop(fd_[cache_type]);
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -0800617}
618
Suren Baghdasaryan8cacb612023-04-12 01:24:23 +0000619bool WriteFileAction::IsValidForProcess(uid_t, pid_t) const {
620 std::lock_guard<std::mutex> lock(fd_mutex_);
621 if (FdCacheHelper::IsCached(fd_[ProfileAction::RCT_PROCESS])) {
622 return true;
623 }
624
625 if (fd_[ProfileAction::RCT_PROCESS] == FdCacheHelper::FDS_INACCESSIBLE) {
626 return false;
627 }
628
629 return access(proc_path_.empty() ? task_path_.c_str() : proc_path_.c_str(), W_OK) == 0;
630}
631
632bool WriteFileAction::IsValidForTask(int) const {
633 std::lock_guard<std::mutex> lock(fd_mutex_);
634 if (FdCacheHelper::IsCached(fd_[ProfileAction::RCT_TASK])) {
635 return true;
636 }
637
638 if (fd_[ProfileAction::RCT_TASK] == FdCacheHelper::FDS_INACCESSIBLE) {
639 return false;
640 }
641
642 if (fd_[ProfileAction::RCT_TASK] == FdCacheHelper::FDS_APP_DEPENDENT) {
643 // application-dependent path can't be used with tid
644 return false;
645 }
646
647 return access(task_path_.c_str(), W_OK) == 0;
648}
649
T.J. Mercier39846112024-10-09 22:40:26 +0000650bool SetSchedulerPolicyAction::isNormalPolicy(int policy) {
651 return policy == SCHED_OTHER || policy == SCHED_BATCH || policy == SCHED_IDLE;
652}
653
654bool SetSchedulerPolicyAction::toPriority(int policy, int virtual_priority, int& priority_out) {
655 constexpr int VIRTUAL_PRIORITY_MIN = 1;
656 constexpr int VIRTUAL_PRIORITY_MAX = 99;
657
658 if (virtual_priority < VIRTUAL_PRIORITY_MIN || virtual_priority > VIRTUAL_PRIORITY_MAX) {
659 LOG(WARNING) << "SetSchedulerPolicy: invalid priority (" << virtual_priority
660 << ") for policy (" << policy << ")";
661 return false;
662 }
663
664 const int min = sched_get_priority_min(policy);
665 if (min == -1) {
666 PLOG(ERROR) << "SetSchedulerPolicy: Cannot get min sched priority for policy " << policy;
667 return false;
668 }
669
670 const int max = sched_get_priority_max(policy);
671 if (max == -1) {
672 PLOG(ERROR) << "SetSchedulerPolicy: Cannot get max sched priority for policy " << policy;
673 return false;
674 }
675
676 priority_out = min + (virtual_priority - VIRTUAL_PRIORITY_MIN) * (max - min) /
677 (VIRTUAL_PRIORITY_MAX - VIRTUAL_PRIORITY_MIN);
678
679 return true;
680}
681
682bool SetSchedulerPolicyAction::ExecuteForTask(pid_t tid) const {
683 struct sched_param param = {};
684 param.sched_priority = isNormalPolicy(policy_) ? 0 : *priority_or_nice_;
685 if (sched_setscheduler(tid, policy_, &param) == -1) {
686 PLOG(WARNING) << "SetSchedulerPolicy: Failed to apply scheduler policy (" << policy_
687 << ") with priority (" << *priority_or_nice_ << ") to tid " << tid;
688 return false;
689 }
690
691 if (isNormalPolicy(policy_) && priority_or_nice_ &&
692 setpriority(PRIO_PROCESS, tid, *priority_or_nice_) == -1) {
693 PLOG(WARNING) << "SetSchedulerPolicy: Failed to apply nice (" << *priority_or_nice_
694 << ") to tid " << tid;
695 return false;
696 }
697
698 return true;
699}
700
Rick Yiu0b211fa2019-09-16 19:07:17 +0800701bool ApplyProfileAction::ExecuteForProcess(uid_t uid, pid_t pid) const {
702 for (const auto& profile : profiles_) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800703 profile->ExecuteForProcess(uid, pid);
Rick Yiu0b211fa2019-09-16 19:07:17 +0800704 }
705 return true;
706}
707
T.J. Mercier1c007992024-01-25 16:29:54 +0000708bool ApplyProfileAction::ExecuteForTask(pid_t tid) const {
Rick Yiu0b211fa2019-09-16 19:07:17 +0800709 for (const auto& profile : profiles_) {
Wei Wang8722e4d2021-05-14 12:34:54 -0700710 profile->ExecuteForTask(tid);
Rick Yiu0b211fa2019-09-16 19:07:17 +0800711 }
712 return true;
713}
714
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800715void ApplyProfileAction::EnableResourceCaching(ResourceCacheType cache_type) {
Suren Baghdasaryan911109c2020-02-13 17:28:00 -0800716 for (const auto& profile : profiles_) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800717 profile->EnableResourceCaching(cache_type);
Suren Baghdasaryan911109c2020-02-13 17:28:00 -0800718 }
719}
720
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800721void ApplyProfileAction::DropResourceCaching(ResourceCacheType cache_type) {
Suren Baghdasaryan911109c2020-02-13 17:28:00 -0800722 for (const auto& profile : profiles_) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800723 profile->DropResourceCaching(cache_type);
Suren Baghdasaryan911109c2020-02-13 17:28:00 -0800724 }
725}
726
Suren Baghdasaryan8cacb612023-04-12 01:24:23 +0000727bool ApplyProfileAction::IsValidForProcess(uid_t uid, pid_t pid) const {
728 for (const auto& profile : profiles_) {
729 if (!profile->IsValidForProcess(uid, pid)) {
730 return false;
731 }
732 }
733 return true;
734}
735
T.J. Mercier1c007992024-01-25 16:29:54 +0000736bool ApplyProfileAction::IsValidForTask(pid_t tid) const {
Suren Baghdasaryan8cacb612023-04-12 01:24:23 +0000737 for (const auto& profile : profiles_) {
738 if (!profile->IsValidForTask(tid)) {
739 return false;
740 }
741 }
742 return true;
743}
744
Suren Baghdasaryan84385952020-01-24 16:36:10 -0800745void TaskProfile::MoveTo(TaskProfile* profile) {
746 profile->elements_ = std::move(elements_);
747 profile->res_cached_ = res_cached_;
748}
749
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800750bool TaskProfile::ExecuteForProcess(uid_t uid, pid_t pid) const {
751 for (const auto& element : elements_) {
752 if (!element->ExecuteForProcess(uid, pid)) {
Bart Van Asschef096bd22022-01-24 19:59:13 +0000753 LOG(VERBOSE) << "Applying profile action " << element->Name() << " failed";
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800754 return false;
755 }
756 }
757 return true;
758}
759
T.J. Mercier1c007992024-01-25 16:29:54 +0000760bool TaskProfile::ExecuteForTask(pid_t tid) const {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800761 if (tid == 0) {
762 tid = GetThreadId();
763 }
764 for (const auto& element : elements_) {
765 if (!element->ExecuteForTask(tid)) {
Bart Van Asschef096bd22022-01-24 19:59:13 +0000766 LOG(VERBOSE) << "Applying profile action " << element->Name() << " failed";
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800767 return false;
768 }
769 }
770 return true;
771}
772
T.J. Mercier5ed5e1b2022-08-22 21:25:09 +0000773bool TaskProfile::ExecuteForUID(uid_t uid) const {
774 for (const auto& element : elements_) {
775 if (!element->ExecuteForUID(uid)) {
776 LOG(VERBOSE) << "Applying profile action " << element->Name() << " failed";
777 return false;
778 }
779 }
780 return true;
781}
782
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800783void TaskProfile::EnableResourceCaching(ProfileAction::ResourceCacheType cache_type) {
Suren Baghdasaryan8a315d22019-02-14 14:40:41 -0800784 if (res_cached_) {
785 return;
786 }
787
788 for (auto& element : elements_) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800789 element->EnableResourceCaching(cache_type);
Suren Baghdasaryan8a315d22019-02-14 14:40:41 -0800790 }
791
792 res_cached_ = true;
793}
794
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800795void TaskProfile::DropResourceCaching(ProfileAction::ResourceCacheType cache_type) {
Riddle Hsua6abd822019-06-18 15:53:53 -0600796 if (!res_cached_) {
797 return;
798 }
799
800 for (auto& element : elements_) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800801 element->DropResourceCaching(cache_type);
Riddle Hsua6abd822019-06-18 15:53:53 -0600802 }
803
804 res_cached_ = false;
805}
806
Suren Baghdasaryan8cacb612023-04-12 01:24:23 +0000807bool TaskProfile::IsValidForProcess(uid_t uid, pid_t pid) const {
808 for (const auto& element : elements_) {
809 if (!element->IsValidForProcess(uid, pid)) return false;
810 }
811 return true;
812}
813
T.J. Mercier1c007992024-01-25 16:29:54 +0000814bool TaskProfile::IsValidForTask(pid_t tid) const {
Suren Baghdasaryan8cacb612023-04-12 01:24:23 +0000815 for (const auto& element : elements_) {
816 if (!element->IsValidForTask(tid)) return false;
817 }
818 return true;
819}
820
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800821void TaskProfiles::DropResourceCaching(ProfileAction::ResourceCacheType cache_type) const {
Riddle Hsua6abd822019-06-18 15:53:53 -0600822 for (auto& iter : profiles_) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -0800823 iter.second->DropResourceCaching(cache_type);
Riddle Hsua6abd822019-06-18 15:53:53 -0600824 }
825}
826
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800827TaskProfiles& TaskProfiles::GetInstance() {
Peter Collingbournedba6d442019-03-20 21:09:46 -0700828 // Deliberately leak this object to avoid a race between destruction on
829 // process exit and concurrent access from another thread.
830 static auto* instance = new TaskProfiles;
831 return *instance;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800832}
833
834TaskProfiles::TaskProfiles() {
Suren Baghdasaryan756a6042020-12-03 11:38:42 -0800835 // load system task profiles
836 if (!Load(CgroupMap::GetInstance(), TASK_PROFILE_DB_FILE)) {
837 LOG(ERROR) << "Loading " << TASK_PROFILE_DB_FILE << " for [" << getpid() << "] failed";
838 }
Suren Baghdasaryan35221b52020-11-20 17:08:51 -0800839
840 // load API-level specific system task profiles if available
Suren Baghdasaryan756a6042020-12-03 11:38:42 -0800841 unsigned int api_level = GetUintProperty<unsigned int>("ro.product.first_api_level", 0);
Suren Baghdasaryan35221b52020-11-20 17:08:51 -0800842 if (api_level > 0) {
843 std::string api_profiles_path =
844 android::base::StringPrintf(TEMPLATE_TASK_PROFILE_API_FILE, api_level);
845 if (!access(api_profiles_path.c_str(), F_OK) || errno != ENOENT) {
Suren Baghdasaryan756a6042020-12-03 11:38:42 -0800846 if (!Load(CgroupMap::GetInstance(), api_profiles_path)) {
Suren Baghdasaryanc2ee2e52022-01-20 10:58:43 -0800847 LOG(ERROR) << "Loading " << api_profiles_path << " for [" << getpid() << "] failed";
Suren Baghdasaryan756a6042020-12-03 11:38:42 -0800848 }
Suren Baghdasaryan35221b52020-11-20 17:08:51 -0800849 }
850 }
851
Suren Baghdasaryan05da67c2019-02-19 15:01:28 -0800852 // load vendor task profiles if the file exists
853 if (!access(TASK_PROFILE_DB_VENDOR_FILE, F_OK) &&
854 !Load(CgroupMap::GetInstance(), TASK_PROFILE_DB_VENDOR_FILE)) {
855 LOG(ERROR) << "Loading " << TASK_PROFILE_DB_VENDOR_FILE << " for [" << getpid()
856 << "] failed";
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800857 }
858}
859
Suren Baghdasaryan05da67c2019-02-19 15:01:28 -0800860bool TaskProfiles::Load(const CgroupMap& cg_map, const std::string& file_name) {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800861 std::string json_doc;
862
Suren Baghdasaryan05da67c2019-02-19 15:01:28 -0800863 if (!android::base::ReadFileToString(file_name, &json_doc)) {
864 LOG(ERROR) << "Failed to read task profiles from " << file_name;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800865 return false;
866 }
867
Haibo Huangd9ac92a2021-02-24 17:34:50 -0800868 Json::CharReaderBuilder builder;
869 std::unique_ptr<Json::CharReader> reader(builder.newCharReader());
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800870 Json::Value root;
Haibo Huangd9ac92a2021-02-24 17:34:50 -0800871 std::string errorMessage;
872 if (!reader->parse(&*json_doc.begin(), &*json_doc.end(), &root, &errorMessage)) {
873 LOG(ERROR) << "Failed to parse task profiles: " << errorMessage;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800874 return false;
875 }
876
Suren Baghdasaryane681df42019-02-20 16:17:22 -0800877 const Json::Value& attr = root["Attributes"];
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800878 for (Json::Value::ArrayIndex i = 0; i < attr.size(); ++i) {
879 std::string name = attr[i]["Name"].asString();
Suren Baghdasaryan05da67c2019-02-19 15:01:28 -0800880 std::string controller_name = attr[i]["Controller"].asString();
881 std::string file_attr = attr[i]["File"].asString();
Bart Van Asschebc077ff2022-02-17 01:26:44 +0000882 std::string file_v2_attr = attr[i]["FileV2"].asString();
883
884 if (!file_v2_attr.empty() && file_attr.empty()) {
885 LOG(ERROR) << "Attribute " << name << " has FileV2 but no File property";
886 return false;
887 }
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800888
Suren Baghdasaryan81b9f0b2020-07-01 12:34:17 -0700889 auto controller = cg_map.FindController(controller_name);
890 if (controller.HasValue()) {
891 auto iter = attributes_.find(name);
892 if (iter == attributes_.end()) {
Bart Van Asschebc077ff2022-02-17 01:26:44 +0000893 attributes_[name] =
894 std::make_unique<ProfileAttribute>(controller, file_attr, file_v2_attr);
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800895 } else {
Suren Baghdasaryan35078462023-07-25 14:50:18 -0700896 iter->second->Reset(controller, file_attr, file_v2_attr);
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800897 }
898 } else {
Suren Baghdasaryan81b9f0b2020-07-01 12:34:17 -0700899 LOG(WARNING) << "Controller " << controller_name << " is not found";
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800900 }
901 }
902
Suren Baghdasaryane681df42019-02-20 16:17:22 -0800903 const Json::Value& profiles_val = root["Profiles"];
904 for (Json::Value::ArrayIndex i = 0; i < profiles_val.size(); ++i) {
905 const Json::Value& profile_val = profiles_val[i];
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800906
Suren Baghdasaryane681df42019-02-20 16:17:22 -0800907 std::string profile_name = profile_val["Name"].asString();
908 const Json::Value& actions = profile_val["Actions"];
Bart Van Asschef096bd22022-01-24 19:59:13 +0000909 auto profile = std::make_shared<TaskProfile>(profile_name);
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800910
Suren Baghdasaryane681df42019-02-20 16:17:22 -0800911 for (Json::Value::ArrayIndex act_idx = 0; act_idx < actions.size(); ++act_idx) {
912 const Json::Value& action_val = actions[act_idx];
913 std::string action_name = action_val["Name"].asString();
914 const Json::Value& params_val = action_val["Params"];
915 if (action_name == "JoinCgroup") {
916 std::string controller_name = params_val["Controller"].asString();
917 std::string path = params_val["Path"].asString();
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800918
Yifan Hong53e0deb2019-03-22 17:01:08 -0700919 auto controller = cg_map.FindController(controller_name);
920 if (controller.HasValue()) {
Bart Van Assche2953a922023-11-14 07:33:00 -0800921 if (controller.version() == 1) {
922 profile->Add(std::make_unique<SetCgroupAction>(controller, path));
923 } else {
924 LOG(WARNING) << "A JoinCgroup action in the " << profile_name
925 << " profile is used for controller " << controller_name
926 << " in the cgroup v2 hierarchy and will be ignored";
927 }
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800928 } else {
Suren Baghdasaryan05da67c2019-02-19 15:01:28 -0800929 LOG(WARNING) << "JoinCgroup: controller " << controller_name << " is not found";
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800930 }
Suren Baghdasaryane681df42019-02-20 16:17:22 -0800931 } else if (action_name == "SetTimerSlack") {
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -0700932 const std::string slack_string = params_val["Slack"].asString();
933 std::optional<long> slack = readLong(slack_string);
934 if (slack && *slack >= 0) {
935 profile->Add(std::make_unique<SetTimerSlackAction>(*slack));
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800936 } else {
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -0700937 LOG(WARNING) << "SetTimerSlack: invalid parameter: " << slack_string;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800938 }
Suren Baghdasaryane681df42019-02-20 16:17:22 -0800939 } else if (action_name == "SetAttribute") {
940 std::string attr_name = params_val["Name"].asString();
941 std::string attr_value = params_val["Value"].asString();
Bart Van Assche59af6802022-01-24 21:08:57 +0000942 bool optional = strcmp(params_val["Optional"].asString().c_str(), "true") == 0;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800943
Suren Baghdasaryane681df42019-02-20 16:17:22 -0800944 auto iter = attributes_.find(attr_name);
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800945 if (iter != attributes_.end()) {
Bart Van Assche59af6802022-01-24 21:08:57 +0000946 profile->Add(std::make_unique<SetAttributeAction>(iter->second.get(),
947 attr_value, optional));
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800948 } else {
Suren Baghdasaryane681df42019-02-20 16:17:22 -0800949 LOG(WARNING) << "SetAttribute: unknown attribute: " << attr_name;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -0800950 }
Rick Yiubc1ad962020-10-26 20:32:52 +0800951 } else if (action_name == "WriteFile") {
952 std::string attr_filepath = params_val["FilePath"].asString();
Rick Yiu9221b1e2022-02-10 16:44:43 +0800953 std::string attr_procfilepath = params_val["ProcFilePath"].asString();
Rick Yiubc1ad962020-10-26 20:32:52 +0800954 std::string attr_value = params_val["Value"].asString();
Rick Yiu9221b1e2022-02-10 16:44:43 +0800955 // FilePath and Value are mandatory
Rick Yiubc1ad962020-10-26 20:32:52 +0800956 if (!attr_filepath.empty() && !attr_value.empty()) {
Rick Yiu49fce952021-04-08 22:10:06 +0800957 std::string attr_logfailures = params_val["LogFailures"].asString();
958 bool logfailures = attr_logfailures.empty() || attr_logfailures == "true";
Rick Yiu9221b1e2022-02-10 16:44:43 +0800959 profile->Add(std::make_unique<WriteFileAction>(attr_filepath, attr_procfilepath,
960 attr_value, logfailures));
Rick Yiubc1ad962020-10-26 20:32:52 +0800961 } else if (attr_filepath.empty()) {
962 LOG(WARNING) << "WriteFile: invalid parameter: "
963 << "empty filepath";
964 } else if (attr_value.empty()) {
965 LOG(WARNING) << "WriteFile: invalid parameter: "
966 << "empty value";
967 }
T.J. Mercier39846112024-10-09 22:40:26 +0000968 } else if (action_name == "SetSchedulerPolicy") {
969 const std::map<std::string, int> POLICY_MAP = {
970 {"SCHED_OTHER", SCHED_OTHER},
971 {"SCHED_BATCH", SCHED_BATCH},
972 {"SCHED_IDLE", SCHED_IDLE},
973 {"SCHED_FIFO", SCHED_FIFO},
974 {"SCHED_RR", SCHED_RR},
975 };
976 const std::string policy_str = params_val["Policy"].asString();
977
978 const auto it = POLICY_MAP.find(policy_str);
979 if (it == POLICY_MAP.end()) {
980 LOG(WARNING) << "SetSchedulerPolicy: invalid policy " << policy_str;
981 continue;
982 }
983
984 const int policy = it->second;
985
986 if (SetSchedulerPolicyAction::isNormalPolicy(policy)) {
987 if (params_val.isMember("Priority")) {
988 LOG(WARNING) << "SetSchedulerPolicy: Normal policies (" << policy_str
989 << ") use Nice values, not Priority values";
990 }
991
992 if (params_val.isMember("Nice")) {
993 // If present, this optional value will be passed in an additional syscall
994 // to setpriority(), since the sched_priority value must be 0 for calls to
995 // sched_setscheduler() with "normal" policies.
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -0700996 const std::string nice_string = params_val["Nice"].asString();
997 const std::optional<int> nice = readLong(nice_string);
T.J. Mercier39846112024-10-09 22:40:26 +0000998
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -0700999 if (!nice) {
1000 LOG(FATAL) << "Invalid nice value specified: " << nice_string;
1001 }
T.J. Mercier39846112024-10-09 22:40:26 +00001002 const int LINUX_MIN_NICE = -20;
1003 const int LINUX_MAX_NICE = 19;
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -07001004 if (*nice < LINUX_MIN_NICE || *nice > LINUX_MAX_NICE) {
1005 LOG(WARNING) << "SetSchedulerPolicy: Provided nice (" << *nice
T.J. Mercier39846112024-10-09 22:40:26 +00001006 << ") appears out of range.";
1007 }
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -07001008 profile->Add(std::make_unique<SetSchedulerPolicyAction>(policy, *nice));
T.J. Mercier39846112024-10-09 22:40:26 +00001009 } else {
1010 profile->Add(std::make_unique<SetSchedulerPolicyAction>(policy));
1011 }
1012 } else {
1013 if (params_val.isMember("Nice")) {
1014 LOG(WARNING) << "SetSchedulerPolicy: Real-time policies (" << policy_str
1015 << ") use Priority values, not Nice values";
1016 }
1017
1018 // This is a "virtual priority" as described by `man 2 sched_get_priority_min`
1019 // that will be mapped onto the following range for the provided policy:
1020 // [sched_get_priority_min(), sched_get_priority_max()]
T.J. Mercier39846112024-10-09 22:40:26 +00001021
Siarhei Vishniakou930f77b2024-10-15 13:21:19 -07001022 const std::string priority_string = params_val["Priority"].asString();
1023 std::optional<long> virtual_priority = readLong(priority_string);
1024 if (virtual_priority && *virtual_priority > 0) {
1025 int priority;
1026 if (SetSchedulerPolicyAction::toPriority(policy, *virtual_priority,
1027 priority)) {
1028 profile->Add(
1029 std::make_unique<SetSchedulerPolicyAction>(policy, priority));
1030 }
1031 } else {
1032 LOG(WARNING) << "Invalid priority value: " << priority_string;
T.J. Mercier39846112024-10-09 22:40:26 +00001033 }
1034 }
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -08001035 } else {
Suren Baghdasaryane681df42019-02-20 16:17:22 -08001036 LOG(WARNING) << "Unknown profile action: " << action_name;
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -08001037 }
1038 }
Suren Baghdasaryan84385952020-01-24 16:36:10 -08001039 auto iter = profiles_.find(profile_name);
1040 if (iter == profiles_.end()) {
1041 profiles_[profile_name] = profile;
1042 } else {
1043 // Move the content rather that replace the profile because old profile might be
1044 // referenced from an aggregate profile if vendor overrides task profiles
1045 profile->MoveTo(iter->second.get());
1046 profile.reset();
1047 }
Rick Yiu0b211fa2019-09-16 19:07:17 +08001048 }
1049
1050 const Json::Value& aggregateprofiles_val = root["AggregateProfiles"];
1051 for (Json::Value::ArrayIndex i = 0; i < aggregateprofiles_val.size(); ++i) {
1052 const Json::Value& aggregateprofile_val = aggregateprofiles_val[i];
1053
1054 std::string aggregateprofile_name = aggregateprofile_val["Name"].asString();
1055 const Json::Value& aggregateprofiles = aggregateprofile_val["Profiles"];
1056 std::vector<std::shared_ptr<TaskProfile>> profiles;
1057 bool ret = true;
1058
1059 for (Json::Value::ArrayIndex pf_idx = 0; pf_idx < aggregateprofiles.size(); ++pf_idx) {
1060 std::string profile_name = aggregateprofiles[pf_idx].asString();
1061
1062 if (profile_name == aggregateprofile_name) {
1063 LOG(WARNING) << "AggregateProfiles: recursive profile name: " << profile_name;
1064 ret = false;
1065 break;
1066 } else if (profiles_.find(profile_name) == profiles_.end()) {
1067 LOG(WARNING) << "AggregateProfiles: undefined profile name: " << profile_name;
1068 ret = false;
1069 break;
1070 } else {
1071 profiles.push_back(profiles_[profile_name]);
1072 }
1073 }
1074 if (ret) {
Bart Van Asschef096bd22022-01-24 19:59:13 +00001075 auto profile = std::make_shared<TaskProfile>(aggregateprofile_name);
Rick Yiu0b211fa2019-09-16 19:07:17 +08001076 profile->Add(std::make_unique<ApplyProfileAction>(profiles));
1077 profiles_[aggregateprofile_name] = profile;
1078 }
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -08001079 }
1080
1081 return true;
1082}
1083
Bart Van Assched0b8ce22022-08-02 13:06:26 -07001084TaskProfile* TaskProfiles::GetProfile(std::string_view name) const {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -08001085 auto iter = profiles_.find(name);
1086
1087 if (iter != profiles_.end()) {
1088 return iter->second.get();
1089 }
1090 return nullptr;
1091}
1092
Bart Van Assched0b8ce22022-08-02 13:06:26 -07001093const IProfileAttribute* TaskProfiles::GetAttribute(std::string_view name) const {
Suren Baghdasaryan82b72a52018-12-21 11:41:50 -08001094 auto iter = attributes_.find(name);
1095
1096 if (iter != attributes_.end()) {
1097 return iter->second.get();
1098 }
1099 return nullptr;
1100}
Rick Yiu0b211fa2019-09-16 19:07:17 +08001101
Bart Van Asschef32c4ec2022-08-02 13:18:12 -07001102template <typename T>
T.J. Mercier5ed5e1b2022-08-22 21:25:09 +00001103bool TaskProfiles::SetUserProfiles(uid_t uid, std::span<const T> profiles, bool use_fd_cache) {
1104 for (const auto& name : profiles) {
1105 TaskProfile* profile = GetProfile(name);
1106 if (profile != nullptr) {
1107 if (use_fd_cache) {
1108 profile->EnableResourceCaching(ProfileAction::RCT_PROCESS);
1109 }
1110 if (!profile->ExecuteForUID(uid)) {
1111 PLOG(WARNING) << "Failed to apply " << name << " process profile";
1112 }
1113 } else {
1114 PLOG(WARNING) << "Failed to find " << name << "process profile";
1115 }
1116 }
1117 return true;
1118}
1119
1120template <typename T>
Bart Van Asschef32c4ec2022-08-02 13:18:12 -07001121bool TaskProfiles::SetProcessProfiles(uid_t uid, pid_t pid, std::span<const T> profiles,
1122 bool use_fd_cache) {
Inseob Kim538fc1f2022-04-13 18:50:12 +00001123 bool success = true;
Rick Yiu0b211fa2019-09-16 19:07:17 +08001124 for (const auto& name : profiles) {
1125 TaskProfile* profile = GetProfile(name);
1126 if (profile != nullptr) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -08001127 if (use_fd_cache) {
1128 profile->EnableResourceCaching(ProfileAction::RCT_PROCESS);
1129 }
Rick Yiu0b211fa2019-09-16 19:07:17 +08001130 if (!profile->ExecuteForProcess(uid, pid)) {
Krzysztof Kosiński0310ec42023-03-01 04:17:57 +00001131 LOG(WARNING) << "Failed to apply " << name << " process profile";
Inseob Kim538fc1f2022-04-13 18:50:12 +00001132 success = false;
Rick Yiu0b211fa2019-09-16 19:07:17 +08001133 }
1134 } else {
Krzysztof Kosiński0310ec42023-03-01 04:17:57 +00001135 LOG(WARNING) << "Failed to find " << name << " process profile";
Inseob Kim538fc1f2022-04-13 18:50:12 +00001136 success = false;
Rick Yiu0b211fa2019-09-16 19:07:17 +08001137 }
1138 }
Inseob Kim538fc1f2022-04-13 18:50:12 +00001139 return success;
Rick Yiu0b211fa2019-09-16 19:07:17 +08001140}
1141
Bart Van Asschef32c4ec2022-08-02 13:18:12 -07001142template <typename T>
T.J. Mercier1c007992024-01-25 16:29:54 +00001143bool TaskProfiles::SetTaskProfiles(pid_t tid, std::span<const T> profiles, bool use_fd_cache) {
Inseob Kim538fc1f2022-04-13 18:50:12 +00001144 bool success = true;
Rick Yiu0b211fa2019-09-16 19:07:17 +08001145 for (const auto& name : profiles) {
1146 TaskProfile* profile = GetProfile(name);
1147 if (profile != nullptr) {
1148 if (use_fd_cache) {
Suren Baghdasaryanf3bdac72022-01-20 15:41:28 -08001149 profile->EnableResourceCaching(ProfileAction::RCT_TASK);
Rick Yiu0b211fa2019-09-16 19:07:17 +08001150 }
1151 if (!profile->ExecuteForTask(tid)) {
Krzysztof Kosiński0310ec42023-03-01 04:17:57 +00001152 LOG(WARNING) << "Failed to apply " << name << " task profile";
Inseob Kim538fc1f2022-04-13 18:50:12 +00001153 success = false;
Rick Yiu0b211fa2019-09-16 19:07:17 +08001154 }
1155 } else {
Krzysztof Kosiński0310ec42023-03-01 04:17:57 +00001156 LOG(WARNING) << "Failed to find " << name << " task profile";
Inseob Kim538fc1f2022-04-13 18:50:12 +00001157 success = false;
Rick Yiu0b211fa2019-09-16 19:07:17 +08001158 }
1159 }
Inseob Kim538fc1f2022-04-13 18:50:12 +00001160 return success;
Rick Yiu0b211fa2019-09-16 19:07:17 +08001161}
Bart Van Asschef32c4ec2022-08-02 13:18:12 -07001162
1163template bool TaskProfiles::SetProcessProfiles(uid_t uid, pid_t pid,
1164 std::span<const std::string> profiles,
1165 bool use_fd_cache);
1166template bool TaskProfiles::SetProcessProfiles(uid_t uid, pid_t pid,
1167 std::span<const std::string_view> profiles,
1168 bool use_fd_cache);
T.J. Mercier1c007992024-01-25 16:29:54 +00001169template bool TaskProfiles::SetTaskProfiles(pid_t tid, std::span<const std::string> profiles,
Bart Van Asschef32c4ec2022-08-02 13:18:12 -07001170 bool use_fd_cache);
T.J. Mercier1c007992024-01-25 16:29:54 +00001171template bool TaskProfiles::SetTaskProfiles(pid_t tid, std::span<const std::string_view> profiles,
Bart Van Asschef32c4ec2022-08-02 13:18:12 -07001172 bool use_fd_cache);
T.J. Mercier5ed5e1b2022-08-22 21:25:09 +00001173template bool TaskProfiles::SetUserProfiles(uid_t uid, std::span<const std::string> profiles,
1174 bool use_fd_cache);