blob: c6ef8388972fc3ce6cb1b81e583a008d1698952a [file] [log] [blame]
Tom Cherrybac32992015-07-31 12:45:25 -07001/*
2 * Copyright (C) 2015 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17#include "service.h"
18
19#include <fcntl.h>
Elliott Hughes9605a942016-11-10 17:43:47 -080020#include <inttypes.h>
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -040021#include <linux/securebits.h>
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -070022#include <sched.h>
23#include <sys/mount.h>
24#include <sys/prctl.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070025#include <sys/resource.h>
Tom Cherrybac32992015-07-31 12:45:25 -070026#include <sys/stat.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070027#include <sys/time.h>
Tom Cherrybac32992015-07-31 12:45:25 -070028#include <sys/types.h>
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -080029#include <sys/wait.h>
Tom Cherrybac32992015-07-31 12:45:25 -070030#include <termios.h>
Dan Albertaf9ba4d2015-08-11 16:37:04 -070031#include <unistd.h>
Tom Cherrybac32992015-07-31 12:45:25 -070032
33#include <selinux/selinux.h>
34
Elliott Hughes4f713192015-12-04 22:00:26 -080035#include <android-base/file.h>
Elliott Hughesda46b392016-10-11 17:09:00 -070036#include <android-base/parseint.h>
Elliott Hughes4f713192015-12-04 22:00:26 -080037#include <android-base/stringprintf.h>
Elliott Hughesf86b5a62016-06-24 15:12:21 -070038#include <android-base/strings.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070039#include <system/thread_defs.h>
Tom Cherrybac32992015-07-31 12:45:25 -070040
Collin Mullinerf7e79b92016-06-01 21:03:55 +000041#include <processgroup/processgroup.h>
42
Tom Cherrybac32992015-07-31 12:45:25 -070043#include "action.h"
44#include "init.h"
45#include "init_parser.h"
Tom Cherrybac32992015-07-31 12:45:25 -070046#include "log.h"
47#include "property_service.h"
48#include "util.h"
49
Elliott Hughesda46b392016-10-11 17:09:00 -070050using android::base::ParseInt;
Tom Cherryb7349902015-08-26 11:43:36 -070051using android::base::StringPrintf;
52using android::base::WriteStringToFile;
53
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -040054static std::string ComputeContextFromExecutable(std::string& service_name,
55 const std::string& service_path) {
56 std::string computed_context;
57
58 char* raw_con = nullptr;
59 char* raw_filecon = nullptr;
60
61 if (getcon(&raw_con) == -1) {
62 LOG(ERROR) << "could not get context while starting '" << service_name << "'";
63 return "";
64 }
65 std::unique_ptr<char> mycon(raw_con);
66
67 if (getfilecon(service_path.c_str(), &raw_filecon) == -1) {
68 LOG(ERROR) << "could not get file context while starting '" << service_name << "'";
69 return "";
70 }
71 std::unique_ptr<char> filecon(raw_filecon);
72
73 char* new_con = nullptr;
74 int rc = security_compute_create(mycon.get(), filecon.get(),
75 string_to_security_class("process"), &new_con);
76 if (rc == 0) {
77 computed_context = new_con;
78 free(new_con);
79 }
80 if (rc == 0 && computed_context == mycon.get()) {
81 LOG(ERROR) << "service " << service_name << " does not have a SELinux domain defined";
82 return "";
83 }
84 if (rc < 0) {
85 LOG(ERROR) << "could not get context while starting '" << service_name << "'";
86 return "";
87 }
88 return computed_context;
89}
90
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -070091static void SetUpPidNamespace(const std::string& service_name) {
92 constexpr unsigned int kSafeFlags = MS_NODEV | MS_NOEXEC | MS_NOSUID;
93
94 // It's OK to LOG(FATAL) in this function since it's running in the first
95 // child process.
96 if (mount("", "/proc", "proc", kSafeFlags | MS_REMOUNT, "") == -1) {
Elliott Hughese18e7e52016-07-25 18:18:16 -070097 PLOG(FATAL) << "couldn't remount(/proc) for " << service_name;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -070098 }
99
100 if (prctl(PR_SET_NAME, service_name.c_str()) == -1) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700101 PLOG(FATAL) << "couldn't set name for " << service_name;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700102 }
103
104 pid_t child_pid = fork();
105 if (child_pid == -1) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700106 PLOG(FATAL) << "couldn't fork init inside the PID namespace for " << service_name;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700107 }
108
109 if (child_pid > 0) {
110 // So that we exit with the right status.
111 static int init_exitstatus = 0;
112 signal(SIGTERM, [](int) { _exit(init_exitstatus); });
113
114 pid_t waited_pid;
115 int status;
116 while ((waited_pid = wait(&status)) > 0) {
117 // This loop will end when there are no processes left inside the
118 // PID namespace or when the init process inside the PID namespace
119 // gets a signal.
120 if (waited_pid == child_pid) {
121 init_exitstatus = status;
122 }
123 }
124 if (!WIFEXITED(init_exitstatus)) {
125 _exit(EXIT_FAILURE);
126 }
127 _exit(WEXITSTATUS(init_exitstatus));
128 }
129}
130
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400131static void ExpandArgs(const std::vector<std::string>& args, std::vector<char*>* strs) {
132 std::vector<std::string> expanded_args;
133 expanded_args.resize(args.size());
134 strs->push_back(const_cast<char*>(args[0].c_str()));
135 for (std::size_t i = 1; i < args.size(); ++i) {
136 if (!expand_props(args[i], &expanded_args[i])) {
137 LOG(FATAL) << args[0] << ": cannot expand '" << args[i] << "'";
138 }
139 strs->push_back(const_cast<char*>(expanded_args[i].c_str()));
140 }
141 strs->push_back(nullptr);
142}
143
Tom Cherrybac32992015-07-31 12:45:25 -0700144ServiceEnvironmentInfo::ServiceEnvironmentInfo() {
145}
146
147ServiceEnvironmentInfo::ServiceEnvironmentInfo(const std::string& name,
148 const std::string& value)
149 : name(name), value(value) {
150}
151
Wei Wang641ff0a2017-03-27 10:59:11 -0700152Service::Service(const std::string& name, const std::vector<std::string>& args)
153 : name_(name),
154 classnames_({"default"}),
155 flags_(0),
156 pid_(0),
157 crash_count_(0),
158 uid_(0),
159 gid_(0),
160 namespace_flags_(0),
161 seclabel_(""),
162 ioprio_class_(IoSchedClass_NONE),
163 ioprio_pri_(0),
164 priority_(0),
165 oom_score_adjust_(-1000),
166 args_(args) {
Tom Cherrybac32992015-07-31 12:45:25 -0700167 onrestart_.InitSingleTrigger("onrestart");
168}
169
Wei Wang641ff0a2017-03-27 10:59:11 -0700170Service::Service(const std::string& name, unsigned flags, uid_t uid, gid_t gid,
171 const std::vector<gid_t>& supp_gids, const CapSet& capabilities,
172 unsigned namespace_flags, const std::string& seclabel,
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700173 const std::vector<std::string>& args)
Wei Wang641ff0a2017-03-27 10:59:11 -0700174 : name_(name),
175 classnames_({"default"}),
176 flags_(flags),
177 pid_(0),
178 crash_count_(0),
179 uid_(uid),
180 gid_(gid),
181 supp_gids_(supp_gids),
182 capabilities_(capabilities),
183 namespace_flags_(namespace_flags),
184 seclabel_(seclabel),
185 ioprio_class_(IoSchedClass_NONE),
186 ioprio_pri_(0),
187 priority_(0),
188 oom_score_adjust_(-1000),
189 args_(args) {
Tom Cherrybac32992015-07-31 12:45:25 -0700190 onrestart_.InitSingleTrigger("onrestart");
191}
192
193void Service::NotifyStateChange(const std::string& new_state) const {
Tom Cherrybac32992015-07-31 12:45:25 -0700194 if ((flags_ & SVC_EXEC) != 0) {
195 // 'exec' commands don't have properties tracking their state.
196 return;
197 }
198
Tom Cherryb7349902015-08-26 11:43:36 -0700199 std::string prop_name = StringPrintf("init.svc.%s", name_.c_str());
Tom Cherrybac32992015-07-31 12:45:25 -0700200 property_set(prop_name.c_str(), new_state.c_str());
Elliott Hughes9605a942016-11-10 17:43:47 -0800201
202 if (new_state == "running") {
Elliott Hughes9605a942016-11-10 17:43:47 -0800203 uint64_t start_ns = time_started_.time_since_epoch().count();
Elliott Hughes331cf2f2016-11-29 19:20:58 +0000204 property_set(StringPrintf("ro.boottime.%s", name_.c_str()).c_str(),
205 StringPrintf("%" PRIu64, start_ns).c_str());
Elliott Hughes9605a942016-11-10 17:43:47 -0800206 }
Tom Cherrybac32992015-07-31 12:45:25 -0700207}
208
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700209void Service::KillProcessGroup(int signal) {
Elliott Hughes1e730242016-08-02 14:20:40 -0700210 LOG(INFO) << "Sending signal " << signal
211 << " to service '" << name_
212 << "' (pid " << pid_ << ") process group...";
213 if (killProcessGroup(uid_, pid_, signal) == -1) {
214 PLOG(ERROR) << "killProcessGroup(" << uid_ << ", " << pid_ << ", " << signal << ") failed";
215 }
216 if (kill(-pid_, signal) == -1) {
217 PLOG(ERROR) << "kill(" << pid_ << ", " << signal << ") failed";
218 }
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700219}
220
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400221void Service::SetProcessAttributes() {
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400222 // Keep capabilites on uid change.
223 if (capabilities_.any() && uid_) {
224 if (prctl(PR_SET_SECUREBITS, SECBIT_KEEP_CAPS | SECBIT_KEEP_CAPS_LOCKED) != 0) {
225 PLOG(FATAL) << "prtcl(PR_SET_KEEPCAPS) failed for " << name_;
226 }
227 }
228
Elliott Hughese18e7e52016-07-25 18:18:16 -0700229 // TODO: work out why this fails for `console` then upgrade to FATAL.
230 if (setpgid(0, getpid()) == -1) PLOG(ERROR) << "setpgid failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400231
232 if (gid_) {
233 if (setgid(gid_) != 0) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700234 PLOG(FATAL) << "setgid failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400235 }
236 }
Nick Kralevich80960d22016-10-29 12:20:00 -0700237 if (setgroups(supp_gids_.size(), &supp_gids_[0]) != 0) {
238 PLOG(FATAL) << "setgroups failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400239 }
240 if (uid_) {
241 if (setuid(uid_) != 0) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700242 PLOG(FATAL) << "setuid failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400243 }
244 }
245 if (!seclabel_.empty()) {
246 if (setexeccon(seclabel_.c_str()) < 0) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700247 PLOG(FATAL) << "cannot setexeccon('" << seclabel_ << "') for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400248 }
249 }
250 if (priority_ != 0) {
251 if (setpriority(PRIO_PROCESS, 0, priority_) != 0) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700252 PLOG(FATAL) << "setpriority failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400253 }
254 }
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400255 if (capabilities_.any()) {
256 if (!SetCapsForExec(capabilities_)) {
257 LOG(FATAL) << "cannot set capabilities for " << name_;
258 }
259 }
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400260}
261
Tom Cherrybac32992015-07-31 12:45:25 -0700262bool Service::Reap() {
263 if (!(flags_ & SVC_ONESHOT) || (flags_ & SVC_RESTART)) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700264 KillProcessGroup(SIGKILL);
Tom Cherrybac32992015-07-31 12:45:25 -0700265 }
266
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700267 // Remove any descriptor resources we may have created.
268 std::for_each(descriptors_.begin(), descriptors_.end(),
269 std::bind(&DescriptorInfo::Clean, std::placeholders::_1));
Tom Cherrybac32992015-07-31 12:45:25 -0700270
271 if (flags_ & SVC_EXEC) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700272 LOG(INFO) << "SVC_EXEC pid " << pid_ << " finished...";
Tom Cherrybac32992015-07-31 12:45:25 -0700273 return true;
274 }
275
276 pid_ = 0;
277 flags_ &= (~SVC_RUNNING);
278
279 // Oneshot processes go into the disabled state on exit,
280 // except when manually restarted.
281 if ((flags_ & SVC_ONESHOT) && !(flags_ & SVC_RESTART)) {
282 flags_ |= SVC_DISABLED;
283 }
284
285 // Disabled and reset processes do not get restarted automatically.
286 if (flags_ & (SVC_DISABLED | SVC_RESET)) {
287 NotifyStateChange("stopped");
288 return false;
289 }
290
Elliott Hughes9605a942016-11-10 17:43:47 -0800291 // If we crash > 4 times in 4 minutes, reboot into recovery.
292 boot_clock::time_point now = boot_clock::now();
Tom Cherrybac32992015-07-31 12:45:25 -0700293 if ((flags_ & SVC_CRITICAL) && !(flags_ & SVC_RESTART)) {
Elliott Hughes9605a942016-11-10 17:43:47 -0800294 if (now < time_crashed_ + 4min) {
295 if (++crash_count_ > 4) {
Elliott Hughes331cf2f2016-11-29 19:20:58 +0000296 LOG(ERROR) << "critical process '" << name_ << "' exited 4 times in 4 minutes";
297 panic();
Tom Cherrybac32992015-07-31 12:45:25 -0700298 }
299 } else {
300 time_crashed_ = now;
Elliott Hughes9605a942016-11-10 17:43:47 -0800301 crash_count_ = 1;
Tom Cherrybac32992015-07-31 12:45:25 -0700302 }
303 }
304
305 flags_ &= (~SVC_RESTART);
306 flags_ |= SVC_RESTARTING;
307
308 // Execute all onrestart commands for this service.
309 onrestart_.ExecuteAllCommands();
310
311 NotifyStateChange("restarting");
312 return false;
313}
314
315void Service::DumpState() const {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700316 LOG(INFO) << "service " << name_;
Wei Wang641ff0a2017-03-27 10:59:11 -0700317 LOG(INFO) << " class '" << android::base::Join(classnames_, " ") << "'";
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700318 LOG(INFO) << " exec "<< android::base::Join(args_, " ");
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700319 std::for_each(descriptors_.begin(), descriptors_.end(),
320 [] (const auto& info) { LOG(INFO) << *info; });
Tom Cherrybac32992015-07-31 12:45:25 -0700321}
322
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400323bool Service::ParseCapabilities(const std::vector<std::string>& args, std::string* err) {
324 capabilities_ = 0;
325
Jorge Lucangeli Obesf3f824e2016-12-15 12:13:38 -0500326 if (!CapAmbientSupported()) {
327 *err = "capabilities requested but the kernel does not support ambient capabilities";
328 return false;
329 }
330
331 unsigned int last_valid_cap = GetLastValidCap();
332 if (last_valid_cap >= capabilities_.size()) {
333 LOG(WARNING) << "last valid run-time capability is larger than CAP_LAST_CAP";
334 }
335
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400336 for (size_t i = 1; i < args.size(); i++) {
337 const std::string& arg = args[i];
Jorge Lucangeli Obesf3f824e2016-12-15 12:13:38 -0500338 int res = LookupCap(arg);
339 if (res < 0) {
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400340 *err = StringPrintf("invalid capability '%s'", arg.c_str());
341 return false;
342 }
Jorge Lucangeli Obesf3f824e2016-12-15 12:13:38 -0500343 unsigned int cap = static_cast<unsigned int>(res); // |res| is >= 0.
344 if (cap > last_valid_cap) {
345 *err = StringPrintf("capability '%s' not supported by the kernel", arg.c_str());
346 return false;
347 }
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400348 capabilities_[cap] = true;
349 }
350 return true;
351}
352
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400353bool Service::ParseClass(const std::vector<std::string>& args, std::string* err) {
Wei Wang641ff0a2017-03-27 10:59:11 -0700354 classnames_ = std::set<std::string>(args.begin() + 1, args.end());
Tom Cherryb7349902015-08-26 11:43:36 -0700355 return true;
356}
Tom Cherrybac32992015-07-31 12:45:25 -0700357
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400358bool Service::ParseConsole(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700359 flags_ |= SVC_CONSOLE;
Viorel Suman70daa672016-03-21 10:08:07 +0200360 console_ = args.size() > 1 ? "/dev/" + args[1] : "";
Tom Cherryb7349902015-08-26 11:43:36 -0700361 return true;
362}
Tom Cherrybac32992015-07-31 12:45:25 -0700363
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400364bool Service::ParseCritical(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700365 flags_ |= SVC_CRITICAL;
366 return true;
367}
Tom Cherrybac32992015-07-31 12:45:25 -0700368
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400369bool Service::ParseDisabled(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700370 flags_ |= SVC_DISABLED;
371 flags_ |= SVC_RC_DISABLED;
372 return true;
373}
Tom Cherrybac32992015-07-31 12:45:25 -0700374
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400375bool Service::ParseGroup(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700376 gid_ = decode_uid(args[1].c_str());
377 for (std::size_t n = 2; n < args.size(); n++) {
378 supp_gids_.emplace_back(decode_uid(args[n].c_str()));
Tom Cherrybac32992015-07-31 12:45:25 -0700379 }
380 return true;
381}
382
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400383bool Service::ParsePriority(const std::vector<std::string>& args, std::string* err) {
Elliott Hughesda46b392016-10-11 17:09:00 -0700384 priority_ = 0;
385 if (!ParseInt(args[1], &priority_,
Keun-young Parkdd34ca42016-11-11 18:06:31 -0800386 static_cast<int>(ANDROID_PRIORITY_HIGHEST), // highest is negative
387 static_cast<int>(ANDROID_PRIORITY_LOWEST))) {
Vitalii Tomkiv081705c2016-05-18 17:36:30 -0700388 *err = StringPrintf("process priority value must be range %d - %d",
389 ANDROID_PRIORITY_HIGHEST, ANDROID_PRIORITY_LOWEST);
390 return false;
391 }
Vitalii Tomkiv081705c2016-05-18 17:36:30 -0700392 return true;
393}
394
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400395bool Service::ParseIoprio(const std::vector<std::string>& args, std::string* err) {
Elliott Hughesda46b392016-10-11 17:09:00 -0700396 if (!ParseInt(args[2], &ioprio_pri_, 0, 7)) {
Tom Cherryb7349902015-08-26 11:43:36 -0700397 *err = "priority value must be range 0 - 7";
398 return false;
399 }
400
401 if (args[1] == "rt") {
402 ioprio_class_ = IoSchedClass_RT;
403 } else if (args[1] == "be") {
404 ioprio_class_ = IoSchedClass_BE;
405 } else if (args[1] == "idle") {
406 ioprio_class_ = IoSchedClass_IDLE;
407 } else {
408 *err = "ioprio option usage: ioprio <rt|be|idle> <0-7>";
409 return false;
410 }
411
412 return true;
413}
414
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400415bool Service::ParseKeycodes(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700416 for (std::size_t i = 1; i < args.size(); i++) {
Elliott Hughesda46b392016-10-11 17:09:00 -0700417 int code;
418 if (ParseInt(args[i], &code)) {
419 keycodes_.emplace_back(code);
420 } else {
421 LOG(WARNING) << "ignoring invalid keycode: " << args[i];
422 }
Tom Cherryb7349902015-08-26 11:43:36 -0700423 }
424 return true;
425}
426
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400427bool Service::ParseOneshot(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700428 flags_ |= SVC_ONESHOT;
429 return true;
430}
431
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400432bool Service::ParseOnrestart(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700433 std::vector<std::string> str_args(args.begin() + 1, args.end());
434 onrestart_.AddCommand(str_args, "", 0, err);
435 return true;
436}
437
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400438bool Service::ParseNamespace(const std::vector<std::string>& args, std::string* err) {
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700439 for (size_t i = 1; i < args.size(); i++) {
440 if (args[i] == "pid") {
441 namespace_flags_ |= CLONE_NEWPID;
442 // PID namespaces require mount namespaces.
443 namespace_flags_ |= CLONE_NEWNS;
444 } else if (args[i] == "mnt") {
445 namespace_flags_ |= CLONE_NEWNS;
446 } else {
447 *err = "namespace must be 'pid' or 'mnt'";
448 return false;
449 }
450 }
451 return true;
452}
453
Marco Nelissen310f6702016-07-22 12:07:06 -0700454bool Service::ParseOomScoreAdjust(const std::vector<std::string>& args, std::string* err) {
Elliott Hughesda46b392016-10-11 17:09:00 -0700455 if (!ParseInt(args[1], &oom_score_adjust_, -1000, 1000)) {
Marco Nelissen310f6702016-07-22 12:07:06 -0700456 *err = "oom_score_adjust value must be in range -1000 - +1000";
457 return false;
458 }
Marco Nelissen310f6702016-07-22 12:07:06 -0700459 return true;
460}
461
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400462bool Service::ParseSeclabel(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700463 seclabel_ = args[1];
464 return true;
465}
466
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400467bool Service::ParseSetenv(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700468 envvars_.emplace_back(args[1], args[2]);
469 return true;
470}
471
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700472template <typename T>
473bool Service::AddDescriptor(const std::vector<std::string>& args, std::string* err) {
474 int perm = args.size() > 3 ? std::strtoul(args[3].c_str(), 0, 8) : -1;
475 uid_t uid = args.size() > 4 ? decode_uid(args[4].c_str()) : 0;
476 gid_t gid = args.size() > 5 ? decode_uid(args[5].c_str()) : 0;
477 std::string context = args.size() > 6 ? args[6] : "";
478
479 auto descriptor = std::make_unique<T>(args[1], args[2], uid, gid, perm, context);
480
481 auto old =
482 std::find_if(descriptors_.begin(), descriptors_.end(),
483 [&descriptor] (const auto& other) { return descriptor.get() == other.get(); });
484
485 if (old != descriptors_.end()) {
486 *err = "duplicate descriptor " + args[1] + " " + args[2];
487 return false;
488 }
489
490 descriptors_.emplace_back(std::move(descriptor));
491 return true;
492}
493
494// name type perm [ uid gid context ]
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400495bool Service::ParseSocket(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700496 if (args[2] != "dgram" && args[2] != "stream" && args[2] != "seqpacket") {
497 *err = "socket type must be 'dgram', 'stream' or 'seqpacket'";
498 return false;
499 }
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700500 return AddDescriptor<SocketInfo>(args, err);
501}
Tom Cherryb7349902015-08-26 11:43:36 -0700502
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700503// name type perm [ uid gid context ]
504bool Service::ParseFile(const std::vector<std::string>& args, std::string* err) {
505 if (args[2] != "r" && args[2] != "w" && args[2] != "rw") {
506 *err = "file type must be 'r', 'w' or 'rw'";
507 return false;
508 }
509 if ((args[1][0] != '/') || (args[1].find("../") != std::string::npos)) {
510 *err = "file name must not be relative";
511 return false;
512 }
513 return AddDescriptor<FileInfo>(args, err);
Tom Cherryb7349902015-08-26 11:43:36 -0700514}
515
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400516bool Service::ParseUser(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700517 uid_ = decode_uid(args[1].c_str());
518 return true;
519}
520
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400521bool Service::ParseWritepid(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700522 writepid_files_.assign(args.begin() + 1, args.end());
523 return true;
524}
525
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400526class Service::OptionParserMap : public KeywordMap<OptionParser> {
Tom Cherryb7349902015-08-26 11:43:36 -0700527public:
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400528 OptionParserMap() {
Tom Cherryb7349902015-08-26 11:43:36 -0700529 }
530private:
531 Map& map() const override;
532};
533
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400534Service::OptionParserMap::Map& Service::OptionParserMap::map() const {
Tom Cherryb7349902015-08-26 11:43:36 -0700535 constexpr std::size_t kMax = std::numeric_limits<std::size_t>::max();
Wei Wang641ff0a2017-03-27 10:59:11 -0700536 // clang-format off
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400537 static const Map option_parsers = {
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400538 {"capabilities",
539 {1, kMax, &Service::ParseCapabilities}},
Wei Wang641ff0a2017-03-27 10:59:11 -0700540 {"class", {1, kMax, &Service::ParseClass}},
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400541 {"console", {0, 1, &Service::ParseConsole}},
542 {"critical", {0, 0, &Service::ParseCritical}},
543 {"disabled", {0, 0, &Service::ParseDisabled}},
544 {"group", {1, NR_SVC_SUPP_GIDS + 1, &Service::ParseGroup}},
545 {"ioprio", {2, 2, &Service::ParseIoprio}},
546 {"priority", {1, 1, &Service::ParsePriority}},
547 {"keycodes", {1, kMax, &Service::ParseKeycodes}},
548 {"oneshot", {0, 0, &Service::ParseOneshot}},
549 {"onrestart", {1, kMax, &Service::ParseOnrestart}},
Marco Nelissen310f6702016-07-22 12:07:06 -0700550 {"oom_score_adjust",
551 {1, 1, &Service::ParseOomScoreAdjust}},
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400552 {"namespace", {1, 2, &Service::ParseNamespace}},
553 {"seclabel", {1, 1, &Service::ParseSeclabel}},
554 {"setenv", {2, 2, &Service::ParseSetenv}},
555 {"socket", {3, 6, &Service::ParseSocket}},
Mark Salyzyn978fd0e2016-12-02 08:05:22 -0800556 {"file", {2, 2, &Service::ParseFile}},
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400557 {"user", {1, 1, &Service::ParseUser}},
558 {"writepid", {1, kMax, &Service::ParseWritepid}},
Tom Cherryb7349902015-08-26 11:43:36 -0700559 };
Wei Wang641ff0a2017-03-27 10:59:11 -0700560 // clang-format on
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400561 return option_parsers;
Tom Cherryb7349902015-08-26 11:43:36 -0700562}
563
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400564bool Service::ParseLine(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700565 if (args.empty()) {
566 *err = "option needed, but not provided";
567 return false;
568 }
569
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400570 static const OptionParserMap parser_map;
571 auto parser = parser_map.FindFunction(args[0], args.size() - 1, err);
Tom Cherryb7349902015-08-26 11:43:36 -0700572
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400573 if (!parser) {
Tom Cherryb7349902015-08-26 11:43:36 -0700574 return false;
575 }
576
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400577 return (this->*parser)(args, err);
Tom Cherryb7349902015-08-26 11:43:36 -0700578}
579
Elliott Hughesbdeac392016-04-12 15:38:27 -0700580bool Service::Start() {
Tom Cherrybac32992015-07-31 12:45:25 -0700581 // Starting a service removes it from the disabled or reset state and
582 // immediately takes it out of the restarting state if it was in there.
583 flags_ &= (~(SVC_DISABLED|SVC_RESTARTING|SVC_RESET|SVC_RESTART|SVC_DISABLED_START));
Tom Cherrybac32992015-07-31 12:45:25 -0700584
585 // Running processes require no additional work --- if they're in the
586 // process of exiting, we've ensured that they will immediately restart
587 // on exit, unless they are ONESHOT.
588 if (flags_ & SVC_RUNNING) {
589 return false;
590 }
591
592 bool needs_console = (flags_ & SVC_CONSOLE);
Viorel Suman70daa672016-03-21 10:08:07 +0200593 if (needs_console) {
594 if (console_.empty()) {
595 console_ = default_console;
596 }
597
Adrian Salido24ef8602016-12-20 15:52:15 -0800598 // Make sure that open call succeeds to ensure a console driver is
599 // properly registered for the device node
600 int console_fd = open(console_.c_str(), O_RDWR | O_CLOEXEC);
601 if (console_fd < 0) {
602 PLOG(ERROR) << "service '" << name_ << "' couldn't open console '" << console_ << "'";
Viorel Suman70daa672016-03-21 10:08:07 +0200603 flags_ |= SVC_DISABLED;
604 return false;
605 }
Adrian Salido24ef8602016-12-20 15:52:15 -0800606 close(console_fd);
Tom Cherrybac32992015-07-31 12:45:25 -0700607 }
608
609 struct stat sb;
610 if (stat(args_[0].c_str(), &sb) == -1) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700611 PLOG(ERROR) << "cannot find '" << args_[0] << "', disabling '" << name_ << "'";
Tom Cherrybac32992015-07-31 12:45:25 -0700612 flags_ |= SVC_DISABLED;
613 return false;
614 }
615
Tom Cherrybac32992015-07-31 12:45:25 -0700616 std::string scon;
617 if (!seclabel_.empty()) {
618 scon = seclabel_;
619 } else {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400620 LOG(INFO) << "computing context for service '" << name_ << "'";
621 scon = ComputeContextFromExecutable(name_, args_[0]);
622 if (scon == "") {
Tom Cherrybac32992015-07-31 12:45:25 -0700623 return false;
624 }
625 }
626
Wei Wanga285dac2016-10-04 14:05:39 -0700627 LOG(INFO) << "starting service '" << name_ << "'...";
Tom Cherrybac32992015-07-31 12:45:25 -0700628
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700629 pid_t pid = -1;
630 if (namespace_flags_) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400631 pid = clone(nullptr, nullptr, namespace_flags_ | SIGCHLD, nullptr);
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700632 } else {
633 pid = fork();
634 }
635
Tom Cherrybac32992015-07-31 12:45:25 -0700636 if (pid == 0) {
Tom Cherrybac32992015-07-31 12:45:25 -0700637 umask(077);
Tom Cherrybac32992015-07-31 12:45:25 -0700638
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700639 if (namespace_flags_ & CLONE_NEWPID) {
640 // This will fork again to run an init process inside the PID
641 // namespace.
642 SetUpPidNamespace(name_);
643 }
644
Tom Cherrybac32992015-07-31 12:45:25 -0700645 for (const auto& ei : envvars_) {
646 add_environment(ei.name.c_str(), ei.value.c_str());
647 }
648
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700649 std::for_each(descriptors_.begin(), descriptors_.end(),
650 std::bind(&DescriptorInfo::CreateAndPublish, std::placeholders::_1, scon));
Tom Cherrybac32992015-07-31 12:45:25 -0700651
Alex Vakulenko08286762016-05-03 12:00:00 -0700652 // See if there were "writepid" instructions to write to files under /dev/cpuset/.
653 auto cpuset_predicate = [](const std::string& path) {
654 return android::base::StartsWith(path, "/dev/cpuset/");
655 };
656 auto iter = std::find_if(writepid_files_.begin(), writepid_files_.end(), cpuset_predicate);
657 if (iter == writepid_files_.end()) {
658 // There were no "writepid" instructions for cpusets, check if the system default
659 // cpuset is specified to be used for the process.
660 std::string default_cpuset = property_get("ro.cpuset.default");
661 if (!default_cpuset.empty()) {
662 // Make sure the cpuset name starts and ends with '/'.
663 // A single '/' means the 'root' cpuset.
664 if (default_cpuset.front() != '/') {
665 default_cpuset.insert(0, 1, '/');
666 }
667 if (default_cpuset.back() != '/') {
668 default_cpuset.push_back('/');
669 }
670 writepid_files_.push_back(
671 StringPrintf("/dev/cpuset%stasks", default_cpuset.c_str()));
672 }
673 }
Anestis Bechtsoudisb702b462016-02-05 16:38:48 +0200674 std::string pid_str = StringPrintf("%d", getpid());
Tom Cherrybac32992015-07-31 12:45:25 -0700675 for (const auto& file : writepid_files_) {
Tom Cherryb7349902015-08-26 11:43:36 -0700676 if (!WriteStringToFile(pid_str, file)) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700677 PLOG(ERROR) << "couldn't write " << pid_str << " to " << file;
Tom Cherrybac32992015-07-31 12:45:25 -0700678 }
679 }
680
681 if (ioprio_class_ != IoSchedClass_NONE) {
682 if (android_set_ioprio(getpid(), ioprio_class_, ioprio_pri_)) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400683 PLOG(ERROR) << "failed to set pid " << getpid()
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700684 << " ioprio=" << ioprio_class_ << "," << ioprio_pri_;
Tom Cherrybac32992015-07-31 12:45:25 -0700685 }
686 }
687
688 if (needs_console) {
689 setsid();
690 OpenConsole();
691 } else {
692 ZapStdio();
693 }
694
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400695 // As requested, set our gid, supplemental gids, uid, context, and
696 // priority. Aborts on failure.
697 SetProcessAttributes();
Tom Cherrybac32992015-07-31 12:45:25 -0700698
Tom Cherrybac32992015-07-31 12:45:25 -0700699 std::vector<char*> strs;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400700 ExpandArgs(args_, &strs);
Tom Cherrybac35362016-06-07 11:22:00 -0700701 if (execve(strs[0], (char**) &strs[0], (char**) ENV) < 0) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700702 PLOG(ERROR) << "cannot execve('" << strs[0] << "')";
Tom Cherrybac32992015-07-31 12:45:25 -0700703 }
704
705 _exit(127);
706 }
707
708 if (pid < 0) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700709 PLOG(ERROR) << "failed to fork for '" << name_ << "'";
Tom Cherrybac32992015-07-31 12:45:25 -0700710 pid_ = 0;
711 return false;
712 }
713
Marco Nelissen310f6702016-07-22 12:07:06 -0700714 if (oom_score_adjust_ != -1000) {
715 std::string oom_str = StringPrintf("%d", oom_score_adjust_);
716 std::string oom_file = StringPrintf("/proc/%d/oom_score_adj", pid);
717 if (!WriteStringToFile(oom_str, oom_file)) {
718 PLOG(ERROR) << "couldn't write oom_score_adj: " << strerror(errno);
719 }
720 }
721
Elliott Hughes9605a942016-11-10 17:43:47 -0800722 time_started_ = boot_clock::now();
Tom Cherrybac32992015-07-31 12:45:25 -0700723 pid_ = pid;
724 flags_ |= SVC_RUNNING;
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700725
726 errno = -createProcessGroup(uid_, pid_);
727 if (errno != 0) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400728 PLOG(ERROR) << "createProcessGroup(" << uid_ << ", " << pid_ << ") failed for service '"
729 << name_ << "'";
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700730 }
Tom Cherrybac32992015-07-31 12:45:25 -0700731
732 if ((flags_ & SVC_EXEC) != 0) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400733 LOG(INFO) << android::base::StringPrintf(
734 "SVC_EXEC pid %d (uid %d gid %d+%zu context %s) started; waiting...", pid_, uid_, gid_,
735 supp_gids_.size(), !seclabel_.empty() ? seclabel_.c_str() : "default");
Tom Cherrybac32992015-07-31 12:45:25 -0700736 }
737
738 NotifyStateChange("running");
739 return true;
740}
741
Tom Cherrybac32992015-07-31 12:45:25 -0700742bool Service::StartIfNotDisabled() {
743 if (!(flags_ & SVC_DISABLED)) {
744 return Start();
745 } else {
746 flags_ |= SVC_DISABLED_START;
747 }
748 return true;
749}
750
751bool Service::Enable() {
752 flags_ &= ~(SVC_DISABLED | SVC_RC_DISABLED);
753 if (flags_ & SVC_DISABLED_START) {
754 return Start();
755 }
756 return true;
757}
758
759void Service::Reset() {
760 StopOrReset(SVC_RESET);
761}
762
763void Service::Stop() {
764 StopOrReset(SVC_DISABLED);
765}
766
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800767void Service::Terminate() {
768 flags_ &= ~(SVC_RESTARTING | SVC_DISABLED_START);
769 flags_ |= SVC_DISABLED;
770 if (pid_) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700771 KillProcessGroup(SIGTERM);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800772 NotifyStateChange("stopping");
773 }
774}
775
Tom Cherrybac32992015-07-31 12:45:25 -0700776void Service::Restart() {
777 if (flags_ & SVC_RUNNING) {
778 /* Stop, wait, then start the service. */
779 StopOrReset(SVC_RESTART);
780 } else if (!(flags_ & SVC_RESTARTING)) {
781 /* Just start the service since it's not running. */
782 Start();
783 } /* else: Service is restarting anyways. */
784}
785
Elliott Hughes9605a942016-11-10 17:43:47 -0800786void Service::RestartIfNeeded(time_t* process_needs_restart_at) {
787 boot_clock::time_point now = boot_clock::now();
788 boot_clock::time_point next_start = time_started_ + 5s;
789 if (now > next_start) {
Tom Cherrybac32992015-07-31 12:45:25 -0700790 flags_ &= (~SVC_RESTARTING);
791 Start();
792 return;
793 }
794
Elliott Hughes9605a942016-11-10 17:43:47 -0800795 time_t next_start_time_t = time(nullptr) +
796 time_t(std::chrono::duration_cast<std::chrono::seconds>(next_start - now).count());
797 if (next_start_time_t < *process_needs_restart_at || *process_needs_restart_at == 0) {
798 *process_needs_restart_at = next_start_time_t;
Tom Cherrybac32992015-07-31 12:45:25 -0700799 }
800}
801
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700802// The how field should be either SVC_DISABLED, SVC_RESET, or SVC_RESTART.
Tom Cherrybac32992015-07-31 12:45:25 -0700803void Service::StopOrReset(int how) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700804 // The service is still SVC_RUNNING until its process exits, but if it has
805 // already exited it shoudn't attempt a restart yet.
Tom Cherrybac32992015-07-31 12:45:25 -0700806 flags_ &= ~(SVC_RESTARTING | SVC_DISABLED_START);
807
808 if ((how != SVC_DISABLED) && (how != SVC_RESET) && (how != SVC_RESTART)) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700809 // An illegal flag: default to SVC_DISABLED.
Tom Cherrybac32992015-07-31 12:45:25 -0700810 how = SVC_DISABLED;
811 }
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700812
813 // If the service has not yet started, prevent it from auto-starting with its class.
Tom Cherrybac32992015-07-31 12:45:25 -0700814 if (how == SVC_RESET) {
815 flags_ |= (flags_ & SVC_RC_DISABLED) ? SVC_DISABLED : SVC_RESET;
816 } else {
817 flags_ |= how;
818 }
819
820 if (pid_) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700821 KillProcessGroup(SIGKILL);
Tom Cherrybac32992015-07-31 12:45:25 -0700822 NotifyStateChange("stopping");
823 } else {
824 NotifyStateChange("stopped");
825 }
826}
827
828void Service::ZapStdio() const {
829 int fd;
830 fd = open("/dev/null", O_RDWR);
831 dup2(fd, 0);
832 dup2(fd, 1);
833 dup2(fd, 2);
834 close(fd);
835}
836
837void Service::OpenConsole() const {
Viorel Suman70daa672016-03-21 10:08:07 +0200838 int fd = open(console_.c_str(), O_RDWR);
839 if (fd == -1) fd = open("/dev/null", O_RDWR);
Tom Cherrybac32992015-07-31 12:45:25 -0700840 ioctl(fd, TIOCSCTTY, 0);
841 dup2(fd, 0);
842 dup2(fd, 1);
843 dup2(fd, 2);
844 close(fd);
845}
846
Tom Cherrybac32992015-07-31 12:45:25 -0700847int ServiceManager::exec_count_ = 0;
848
849ServiceManager::ServiceManager() {
850}
851
852ServiceManager& ServiceManager::GetInstance() {
853 static ServiceManager instance;
854 return instance;
855}
856
Tom Cherryb7349902015-08-26 11:43:36 -0700857void ServiceManager::AddService(std::unique_ptr<Service> service) {
858 Service* old_service = FindServiceByName(service->name());
859 if (old_service) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700860 LOG(ERROR) << "ignored duplicate definition of service '" << service->name() << "'";
Tom Cherryb7349902015-08-26 11:43:36 -0700861 return;
Tom Cherrybac32992015-07-31 12:45:25 -0700862 }
Tom Cherryb7349902015-08-26 11:43:36 -0700863 services_.emplace_back(std::move(service));
Tom Cherrybac32992015-07-31 12:45:25 -0700864}
865
866Service* ServiceManager::MakeExecOneshotService(const std::vector<std::string>& args) {
867 // Parse the arguments: exec [SECLABEL [UID [GID]*] --] COMMAND ARGS...
868 // SECLABEL can be a - to denote default
869 std::size_t command_arg = 1;
870 for (std::size_t i = 1; i < args.size(); ++i) {
871 if (args[i] == "--") {
872 command_arg = i + 1;
873 break;
874 }
875 }
876 if (command_arg > 4 + NR_SVC_SUPP_GIDS) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700877 LOG(ERROR) << "exec called with too many supplementary group ids";
Tom Cherrybac32992015-07-31 12:45:25 -0700878 return nullptr;
879 }
880
881 if (command_arg >= args.size()) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700882 LOG(ERROR) << "exec called without command";
Tom Cherrybac32992015-07-31 12:45:25 -0700883 return nullptr;
884 }
885 std::vector<std::string> str_args(args.begin() + command_arg, args.end());
886
887 exec_count_++;
Tom Cherryb7349902015-08-26 11:43:36 -0700888 std::string name = StringPrintf("exec %d (%s)", exec_count_, str_args[0].c_str());
Tom Cherrybac32992015-07-31 12:45:25 -0700889 unsigned flags = SVC_EXEC | SVC_ONESHOT;
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400890 CapSet no_capabilities;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700891 unsigned namespace_flags = 0;
Tom Cherrybac32992015-07-31 12:45:25 -0700892
893 std::string seclabel = "";
894 if (command_arg > 2 && args[1] != "-") {
895 seclabel = args[1];
896 }
897 uid_t uid = 0;
898 if (command_arg > 3) {
899 uid = decode_uid(args[2].c_str());
900 }
901 gid_t gid = 0;
902 std::vector<gid_t> supp_gids;
903 if (command_arg > 4) {
904 gid = decode_uid(args[3].c_str());
905 std::size_t nr_supp_gids = command_arg - 1 /* -- */ - 4 /* exec SECLABEL UID GID */;
906 for (size_t i = 0; i < nr_supp_gids; ++i) {
907 supp_gids.push_back(decode_uid(args[4 + i].c_str()));
908 }
909 }
910
Wei Wang641ff0a2017-03-27 10:59:11 -0700911 auto svc_p = std::make_unique<Service>(name, flags, uid, gid, supp_gids, no_capabilities,
912 namespace_flags, seclabel, str_args);
Tom Cherrybac32992015-07-31 12:45:25 -0700913 Service* svc = svc_p.get();
Tom Cherry9bdddd72017-03-23 16:07:51 -0700914 services_.emplace_back(std::move(svc_p));
Tom Cherrybac32992015-07-31 12:45:25 -0700915
916 return svc;
917}
918
919Service* ServiceManager::FindServiceByName(const std::string& name) const {
920 auto svc = std::find_if(services_.begin(), services_.end(),
921 [&name] (const std::unique_ptr<Service>& s) {
922 return name == s->name();
923 });
924 if (svc != services_.end()) {
925 return svc->get();
926 }
927 return nullptr;
928}
929
930Service* ServiceManager::FindServiceByPid(pid_t pid) const {
931 auto svc = std::find_if(services_.begin(), services_.end(),
932 [&pid] (const std::unique_ptr<Service>& s) {
933 return s->pid() == pid;
934 });
935 if (svc != services_.end()) {
936 return svc->get();
937 }
938 return nullptr;
939}
940
941Service* ServiceManager::FindServiceByKeychord(int keychord_id) const {
942 auto svc = std::find_if(services_.begin(), services_.end(),
943 [&keychord_id] (const std::unique_ptr<Service>& s) {
944 return s->keychord_id() == keychord_id;
945 });
946
947 if (svc != services_.end()) {
948 return svc->get();
949 }
950 return nullptr;
951}
952
Chih-Hung Hsieh8f7b9e32016-07-27 16:25:51 -0700953void ServiceManager::ForEachService(const std::function<void(Service*)>& callback) const {
Tom Cherrybac32992015-07-31 12:45:25 -0700954 for (const auto& s : services_) {
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800955 callback(s.get());
Tom Cherrybac32992015-07-31 12:45:25 -0700956 }
957}
958
959void ServiceManager::ForEachServiceInClass(const std::string& classname,
960 void (*func)(Service* svc)) const {
961 for (const auto& s : services_) {
Wei Wang641ff0a2017-03-27 10:59:11 -0700962 if (s->classnames().find(classname) != s->classnames().end()) {
Tom Cherrybac32992015-07-31 12:45:25 -0700963 func(s.get());
964 }
965 }
966}
967
968void ServiceManager::ForEachServiceWithFlags(unsigned matchflags,
969 void (*func)(Service* svc)) const {
970 for (const auto& s : services_) {
971 if (s->flags() & matchflags) {
972 func(s.get());
973 }
974 }
975}
976
Tom Cherryb7349902015-08-26 11:43:36 -0700977void ServiceManager::RemoveService(const Service& svc) {
Tom Cherrybac32992015-07-31 12:45:25 -0700978 auto svc_it = std::find_if(services_.begin(), services_.end(),
979 [&svc] (const std::unique_ptr<Service>& s) {
980 return svc.name() == s->name();
981 });
982 if (svc_it == services_.end()) {
983 return;
984 }
985
986 services_.erase(svc_it);
987}
988
Tom Cherryb7349902015-08-26 11:43:36 -0700989void ServiceManager::DumpState() const {
990 for (const auto& s : services_) {
991 s->DumpState();
992 }
Tom Cherryb7349902015-08-26 11:43:36 -0700993}
994
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800995bool ServiceManager::ReapOneProcess() {
996 int status;
997 pid_t pid = TEMP_FAILURE_RETRY(waitpid(-1, &status, WNOHANG));
998 if (pid == 0) {
999 return false;
1000 } else if (pid == -1) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -07001001 PLOG(ERROR) << "waitpid failed";
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -08001002 return false;
1003 }
1004
1005 Service* svc = FindServiceByPid(pid);
1006
1007 std::string name;
1008 if (svc) {
1009 name = android::base::StringPrintf("Service '%s' (pid %d)",
1010 svc->name().c_str(), pid);
1011 } else {
1012 name = android::base::StringPrintf("Untracked pid %d", pid);
1013 }
1014
1015 if (WIFEXITED(status)) {
Wei Wanga285dac2016-10-04 14:05:39 -07001016 LOG(INFO) << name << " exited with status " << WEXITSTATUS(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -08001017 } else if (WIFSIGNALED(status)) {
Wei Wanga285dac2016-10-04 14:05:39 -07001018 LOG(INFO) << name << " killed by signal " << WTERMSIG(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -08001019 } else if (WIFSTOPPED(status)) {
Wei Wanga285dac2016-10-04 14:05:39 -07001020 LOG(INFO) << name << " stopped by signal " << WSTOPSIG(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -08001021 } else {
Wei Wanga285dac2016-10-04 14:05:39 -07001022 LOG(INFO) << name << " state changed";
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -08001023 }
1024
1025 if (!svc) {
1026 return true;
1027 }
1028
1029 if (svc->Reap()) {
Wei Wang2d0fdaa2017-02-02 10:52:39 -08001030 stop_waiting_for_exec();
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -08001031 RemoveService(*svc);
1032 }
1033
1034 return true;
1035}
1036
1037void ServiceManager::ReapAnyOutstandingChildren() {
1038 while (ReapOneProcess()) {
1039 }
1040}
1041
Tom Cherryb7349902015-08-26 11:43:36 -07001042bool ServiceParser::ParseSection(const std::vector<std::string>& args,
1043 std::string* err) {
1044 if (args.size() < 3) {
1045 *err = "services must have a name and a program";
1046 return false;
1047 }
1048
1049 const std::string& name = args[1];
1050 if (!IsValidName(name)) {
1051 *err = StringPrintf("invalid service name '%s'", name.c_str());
1052 return false;
1053 }
1054
1055 std::vector<std::string> str_args(args.begin() + 2, args.end());
Wei Wang641ff0a2017-03-27 10:59:11 -07001056 service_ = std::make_unique<Service>(name, str_args);
Tom Cherryb7349902015-08-26 11:43:36 -07001057 return true;
1058}
1059
1060bool ServiceParser::ParseLineSection(const std::vector<std::string>& args,
1061 const std::string& filename, int line,
1062 std::string* err) const {
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -04001063 return service_ ? service_->ParseLine(args, err) : false;
Tom Cherryb7349902015-08-26 11:43:36 -07001064}
1065
1066void ServiceParser::EndSection() {
1067 if (service_) {
1068 ServiceManager::GetInstance().AddService(std::move(service_));
1069 }
1070}
1071
1072bool ServiceParser::IsValidName(const std::string& name) const {
Elliott Hughesb7788fd2017-02-28 09:54:36 -08001073 // Property names can be any length, but may only contain certain characters.
1074 // Property values can contain any characters, but may only be a certain length.
1075 // (The latter restriction is needed because `start` and `stop` work by writing
1076 // the service name to the "ctl.start" and "ctl.stop" properties.)
1077 return is_legal_property_name("init.svc." + name) && name.size() <= PROP_VALUE_MAX;
Tom Cherrybac32992015-07-31 12:45:25 -07001078}