Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2017 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | #include "service.h" |
| 18 | |
| 19 | #include <algorithm> |
Bart Van Assche | 86a2ae2 | 2023-11-14 16:13:50 -0800 | [diff] [blame] | 20 | #include <fstream> |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 21 | #include <memory> |
| 22 | #include <type_traits> |
| 23 | #include <vector> |
| 24 | |
| 25 | #include <gtest/gtest.h> |
| 26 | |
Bart Van Assche | 86a2ae2 | 2023-11-14 16:13:50 -0800 | [diff] [blame] | 27 | #include <android-base/file.h> |
| 28 | #include <android-base/stringprintf.h> |
| 29 | #include <android-base/strings.h> |
| 30 | #include <selinux/selinux.h> |
| 31 | #include <sys/signalfd.h> |
Suren Baghdasaryan | c29c2ba | 2019-10-22 17:18:42 -0700 | [diff] [blame] | 32 | #include "lmkd_service.h" |
Bart Van Assche | 86a2ae2 | 2023-11-14 16:13:50 -0800 | [diff] [blame] | 33 | #include "reboot.h" |
| 34 | #include "service.h" |
| 35 | #include "service_list.h" |
| 36 | #include "service_parser.h" |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 37 | #include "util.h" |
| 38 | |
Bart Van Assche | 86a2ae2 | 2023-11-14 16:13:50 -0800 | [diff] [blame] | 39 | using ::android::base::ReadFileToString; |
| 40 | using ::android::base::StringPrintf; |
| 41 | using ::android::base::StringReplace; |
| 42 | using ::android::base::unique_fd; |
| 43 | using ::android::base::WriteStringToFd; |
| 44 | using ::android::base::WriteStringToFile; |
| 45 | |
Tom Cherry | 81f5d3e | 2017-06-22 12:53:17 -0700 | [diff] [blame] | 46 | namespace android { |
| 47 | namespace init { |
| 48 | |
Bart Van Assche | 86a2ae2 | 2023-11-14 16:13:50 -0800 | [diff] [blame] | 49 | static std::string GetSecurityContext() { |
| 50 | char* ctx; |
| 51 | if (getcon(&ctx) == -1) { |
| 52 | ADD_FAILURE() << "Failed to call getcon : " << strerror(errno); |
| 53 | } |
| 54 | std::string result{ctx}; |
| 55 | freecon(ctx); |
| 56 | return result; |
| 57 | } |
| 58 | |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 59 | TEST(service, pod_initialized) { |
| 60 | constexpr auto memory_size = sizeof(Service); |
Tom Cherry | 247ffbf | 2019-07-08 15:09:36 -0700 | [diff] [blame] | 61 | alignas(alignof(Service)) unsigned char old_memory[memory_size]; |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 62 | |
| 63 | for (std::size_t i = 0; i < memory_size; ++i) { |
| 64 | old_memory[i] = 0xFF; |
| 65 | } |
| 66 | |
| 67 | std::vector<std::string> dummy_args{"/bin/test"}; |
Tom Cherry | cb0f9bb | 2017-09-12 15:58:47 -0700 | [diff] [blame] | 68 | Service* service_in_old_memory = |
Deyao Ren | df40ed1 | 2022-07-14 22:51:10 +0000 | [diff] [blame] | 69 | new (old_memory) Service("test_old_memory", nullptr, /*filename=*/"", dummy_args); |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 70 | |
| 71 | EXPECT_EQ(0U, service_in_old_memory->flags()); |
| 72 | EXPECT_EQ(0, service_in_old_memory->pid()); |
| 73 | EXPECT_EQ(0, service_in_old_memory->crash_count()); |
| 74 | EXPECT_EQ(0U, service_in_old_memory->uid()); |
| 75 | EXPECT_EQ(0U, service_in_old_memory->gid()); |
Tom Cherry | 247ffbf | 2019-07-08 15:09:36 -0700 | [diff] [blame] | 76 | EXPECT_EQ(0, service_in_old_memory->namespace_flags()); |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 77 | EXPECT_EQ(IoSchedClass_NONE, service_in_old_memory->ioprio_class()); |
| 78 | EXPECT_EQ(0, service_in_old_memory->ioprio_pri()); |
| 79 | EXPECT_EQ(0, service_in_old_memory->priority()); |
Suren Baghdasaryan | c29c2ba | 2019-10-22 17:18:42 -0700 | [diff] [blame] | 80 | EXPECT_EQ(DEFAULT_OOM_SCORE_ADJUST, service_in_old_memory->oom_score_adjust()); |
Tom Cherry | 33838b1 | 2017-05-04 11:32:36 -0700 | [diff] [blame] | 81 | EXPECT_FALSE(service_in_old_memory->process_cgroup_empty()); |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 82 | |
| 83 | for (std::size_t i = 0; i < memory_size; ++i) { |
| 84 | old_memory[i] = 0xFF; |
| 85 | } |
| 86 | |
Tom Cherry | cb0f9bb | 2017-09-12 15:58:47 -0700 | [diff] [blame] | 87 | Service* service_in_old_memory2 = new (old_memory) Service( |
Deyao Ren | df40ed1 | 2022-07-14 22:51:10 +0000 | [diff] [blame] | 88 | "test_old_memory", 0U, 0U, 0U, std::vector<gid_t>(), 0U, "", |
| 89 | nullptr, /*filename=*/"", dummy_args); |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 90 | |
| 91 | EXPECT_EQ(0U, service_in_old_memory2->flags()); |
| 92 | EXPECT_EQ(0, service_in_old_memory2->pid()); |
| 93 | EXPECT_EQ(0, service_in_old_memory2->crash_count()); |
| 94 | EXPECT_EQ(0U, service_in_old_memory2->uid()); |
| 95 | EXPECT_EQ(0U, service_in_old_memory2->gid()); |
Tom Cherry | 247ffbf | 2019-07-08 15:09:36 -0700 | [diff] [blame] | 96 | EXPECT_EQ(0, service_in_old_memory2->namespace_flags()); |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 97 | EXPECT_EQ(IoSchedClass_NONE, service_in_old_memory2->ioprio_class()); |
| 98 | EXPECT_EQ(0, service_in_old_memory2->ioprio_pri()); |
| 99 | EXPECT_EQ(0, service_in_old_memory2->priority()); |
Suren Baghdasaryan | c29c2ba | 2019-10-22 17:18:42 -0700 | [diff] [blame] | 100 | EXPECT_EQ(DEFAULT_OOM_SCORE_ADJUST, service_in_old_memory2->oom_score_adjust()); |
Tom Cherry | 33838b1 | 2017-05-04 11:32:36 -0700 | [diff] [blame] | 101 | EXPECT_FALSE(service_in_old_memory->process_cgroup_empty()); |
Tom Cherry | 7da5485 | 2017-05-01 14:16:41 -0700 | [diff] [blame] | 102 | } |
Tom Cherry | 81f5d3e | 2017-06-22 12:53:17 -0700 | [diff] [blame] | 103 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 104 | TEST(service, make_temporary_oneshot_service_invalid_syntax) { |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 105 | std::vector<std::string> args; |
| 106 | // Nothing. |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 107 | ASSERT_FALSE(Service::MakeTemporaryOneshotService(args).ok()); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 108 | |
| 109 | // No arguments to 'exec'. |
| 110 | args.push_back("exec"); |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 111 | ASSERT_FALSE(Service::MakeTemporaryOneshotService(args).ok()); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 112 | |
| 113 | // No command in "exec --". |
| 114 | args.push_back("--"); |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 115 | ASSERT_FALSE(Service::MakeTemporaryOneshotService(args).ok()); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 116 | } |
| 117 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 118 | TEST(service, make_temporary_oneshot_service_too_many_supplementary_gids) { |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 119 | std::vector<std::string> args; |
| 120 | args.push_back("exec"); |
| 121 | args.push_back("seclabel"); |
| 122 | args.push_back("root"); // uid. |
| 123 | args.push_back("root"); // gid. |
| 124 | for (int i = 0; i < NR_SVC_SUPP_GIDS; ++i) { |
| 125 | args.push_back("root"); // Supplementary gid. |
| 126 | } |
| 127 | args.push_back("--"); |
| 128 | args.push_back("/system/bin/id"); |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 129 | ASSERT_FALSE(Service::MakeTemporaryOneshotService(args).ok()); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 130 | } |
| 131 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 132 | static void Test_make_temporary_oneshot_service(bool dash_dash, bool seclabel, bool uid, bool gid, |
| 133 | bool supplementary_gids) { |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 134 | std::vector<std::string> args; |
| 135 | args.push_back("exec"); |
| 136 | if (seclabel) { |
| 137 | args.push_back("u:r:su:s0"); // seclabel |
| 138 | if (uid) { |
| 139 | args.push_back("log"); // uid |
| 140 | if (gid) { |
| 141 | args.push_back("shell"); // gid |
| 142 | if (supplementary_gids) { |
| 143 | args.push_back("system"); // supplementary gid 0 |
| 144 | args.push_back("adb"); // supplementary gid 1 |
| 145 | } |
| 146 | } |
| 147 | } |
| 148 | } |
| 149 | if (dash_dash) { |
| 150 | args.push_back("--"); |
| 151 | } |
| 152 | args.push_back("/system/bin/toybox"); |
| 153 | args.push_back("id"); |
Tom Cherry | 4772f1d | 2019-07-30 09:34:41 -0700 | [diff] [blame] | 154 | auto service_ret = Service::MakeTemporaryOneshotService(args); |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 155 | ASSERT_RESULT_OK(service_ret); |
Tom Cherry | 4772f1d | 2019-07-30 09:34:41 -0700 | [diff] [blame] | 156 | auto svc = std::move(*service_ret); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 157 | |
| 158 | if (seclabel) { |
| 159 | ASSERT_EQ("u:r:su:s0", svc->seclabel()); |
| 160 | } else { |
| 161 | ASSERT_EQ("", svc->seclabel()); |
| 162 | } |
| 163 | if (uid) { |
Tom Cherry | 11a3aee | 2017-08-03 12:54:07 -0700 | [diff] [blame] | 164 | auto decoded_uid = DecodeUid("log"); |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 165 | ASSERT_RESULT_OK(decoded_uid); |
Tom Cherry | 11a3aee | 2017-08-03 12:54:07 -0700 | [diff] [blame] | 166 | ASSERT_EQ(*decoded_uid, svc->uid()); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 167 | } else { |
| 168 | ASSERT_EQ(0U, svc->uid()); |
| 169 | } |
| 170 | if (gid) { |
Tom Cherry | 11a3aee | 2017-08-03 12:54:07 -0700 | [diff] [blame] | 171 | auto decoded_uid = DecodeUid("shell"); |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 172 | ASSERT_RESULT_OK(decoded_uid); |
Tom Cherry | 11a3aee | 2017-08-03 12:54:07 -0700 | [diff] [blame] | 173 | ASSERT_EQ(*decoded_uid, svc->gid()); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 174 | } else { |
| 175 | ASSERT_EQ(0U, svc->gid()); |
| 176 | } |
| 177 | if (supplementary_gids) { |
| 178 | ASSERT_EQ(2U, svc->supp_gids().size()); |
Tom Cherry | 11a3aee | 2017-08-03 12:54:07 -0700 | [diff] [blame] | 179 | |
| 180 | auto decoded_uid = DecodeUid("system"); |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 181 | ASSERT_RESULT_OK(decoded_uid); |
Tom Cherry | 11a3aee | 2017-08-03 12:54:07 -0700 | [diff] [blame] | 182 | ASSERT_EQ(*decoded_uid, svc->supp_gids()[0]); |
| 183 | |
| 184 | decoded_uid = DecodeUid("adb"); |
Bernie Innocenti | cecebbb | 2020-02-06 03:49:33 +0900 | [diff] [blame] | 185 | ASSERT_RESULT_OK(decoded_uid); |
Tom Cherry | 11a3aee | 2017-08-03 12:54:07 -0700 | [diff] [blame] | 186 | ASSERT_EQ(*decoded_uid, svc->supp_gids()[1]); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 187 | } else { |
| 188 | ASSERT_EQ(0U, svc->supp_gids().size()); |
| 189 | } |
| 190 | |
| 191 | ASSERT_EQ(static_cast<std::size_t>(2), svc->args().size()); |
| 192 | ASSERT_EQ("/system/bin/toybox", svc->args()[0]); |
| 193 | ASSERT_EQ("id", svc->args()[1]); |
| 194 | } |
| 195 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 196 | TEST(service, make_temporary_oneshot_service_with_everything) { |
| 197 | Test_make_temporary_oneshot_service(true, true, true, true, true); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 198 | } |
| 199 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 200 | TEST(service, make_temporary_oneshot_service_with_seclabel_uid_gid) { |
| 201 | Test_make_temporary_oneshot_service(true, true, true, true, false); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 202 | } |
| 203 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 204 | TEST(service, make_temporary_oneshot_service_with_seclabel_uid) { |
| 205 | Test_make_temporary_oneshot_service(true, true, true, false, false); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 206 | } |
| 207 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 208 | TEST(service, make_temporary_oneshot_service_with_seclabel) { |
| 209 | Test_make_temporary_oneshot_service(true, true, false, false, false); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 210 | } |
| 211 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 212 | TEST(service, make_temporary_oneshot_service_with_just_command) { |
| 213 | Test_make_temporary_oneshot_service(true, false, false, false, false); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 214 | } |
| 215 | |
Tom Cherry | 3b81f2d | 2017-07-28 14:48:41 -0700 | [diff] [blame] | 216 | TEST(service, make_temporary_oneshot_service_with_just_command_no_dash) { |
| 217 | Test_make_temporary_oneshot_service(false, false, false, false, false); |
Tom Cherry | 67dee62 | 2017-07-27 12:54:48 -0700 | [diff] [blame] | 218 | } |
| 219 | |
Bart Van Assche | 86a2ae2 | 2023-11-14 16:13:50 -0800 | [diff] [blame] | 220 | // Returns the path in the v2 cgroup hierarchy for a given process in the format /uid_%d/pid_%d. |
| 221 | static std::string CgroupPath(pid_t pid) { |
| 222 | std::string cgroup_path = StringPrintf("/proc/%d/cgroup", pid); |
| 223 | std::ifstream is(cgroup_path, std::ios::in); |
| 224 | std::string line; |
| 225 | while (std::getline(is, line)) { |
| 226 | if (line.substr(0, 3) == "0::") { |
| 227 | return line.substr(3); |
| 228 | } |
| 229 | } |
| 230 | return {}; |
| 231 | } |
| 232 | |
| 233 | class ServiceStopTest : public testing::TestWithParam<bool> {}; |
| 234 | |
| 235 | // Before November 2023, processes that were migrated to another v2 cgroup were ignored by |
| 236 | // Service::Stop() if their uid_%d/pid_%d cgroup directory got removed. This test, if run with the |
| 237 | // parameter set to 'true', verifies that such services are stopped. |
| 238 | TEST_P(ServiceStopTest, stop) { |
Bart Van Assche | fb3e64a | 2023-11-30 09:58:31 -0800 | [diff] [blame] | 239 | if (getuid() != 0) { |
| 240 | GTEST_SKIP() << "Must be run as root."; |
| 241 | return; |
| 242 | } |
| 243 | |
Bart Van Assche | 86a2ae2 | 2023-11-14 16:13:50 -0800 | [diff] [blame] | 244 | static constexpr std::string_view kServiceName = "ServiceA"; |
| 245 | static constexpr std::string_view kScriptTemplate = R"init( |
| 246 | service $name /system/bin/yes |
| 247 | user shell |
| 248 | group shell |
| 249 | seclabel $selabel |
| 250 | )init"; |
| 251 | |
| 252 | std::string script = StringReplace(StringReplace(kScriptTemplate, "$name", kServiceName, false), |
| 253 | "$selabel", GetSecurityContext(), false); |
| 254 | ServiceList& service_list = ServiceList::GetInstance(); |
| 255 | Parser parser; |
Jooyung Han | d51fb54 | 2024-08-21 16:25:10 +0900 | [diff] [blame] | 256 | parser.AddSectionParser("service", std::make_unique<ServiceParser>(&service_list, nullptr)); |
Bart Van Assche | 86a2ae2 | 2023-11-14 16:13:50 -0800 | [diff] [blame] | 257 | |
| 258 | TemporaryFile tf; |
| 259 | ASSERT_GE(tf.fd, 0); |
| 260 | ASSERT_TRUE(WriteStringToFd(script, tf.fd)); |
| 261 | ASSERT_TRUE(parser.ParseConfig(tf.path)); |
| 262 | |
| 263 | Service* const service = ServiceList::GetInstance().FindService(kServiceName); |
| 264 | ASSERT_NE(service, nullptr); |
| 265 | ASSERT_RESULT_OK(service->Start()); |
| 266 | ASSERT_TRUE(service->IsRunning()); |
| 267 | if (GetParam()) { |
| 268 | const pid_t pid = service->pid(); |
| 269 | const std::string cgroup_path = CgroupPath(pid); |
| 270 | EXPECT_NE(cgroup_path, ""); |
| 271 | EXPECT_NE(cgroup_path, "/"); |
| 272 | const std::string pid_str = std::to_string(pid); |
| 273 | EXPECT_TRUE(WriteStringToFile(pid_str, "/sys/fs/cgroup/cgroup.procs")); |
| 274 | EXPECT_EQ(CgroupPath(pid), "/"); |
| 275 | EXPECT_EQ(rmdir(("/sys/fs/cgroup" + cgroup_path).c_str()), 0); |
| 276 | } |
| 277 | EXPECT_EQ(0, StopServicesAndLogViolations({service->name()}, 10s, /*terminate=*/true)); |
| 278 | ServiceList::GetInstance().RemoveService(*service); |
| 279 | } |
| 280 | |
| 281 | INSTANTIATE_TEST_SUITE_P(service, ServiceStopTest, testing::Values(false, true)); |
| 282 | |
Tom Cherry | 81f5d3e | 2017-06-22 12:53:17 -0700 | [diff] [blame] | 283 | } // namespace init |
| 284 | } // namespace android |