blob: 72d1a22126e88c58a1c35c13e01961d0e193f851 [file] [log] [blame]
Alex Deymoaea4c1c2015-08-19 20:24:43 -07001//
2// Copyright (C) 2011 The Android Open Source Project
3//
4// Licensed under the Apache License, Version 2.0 (the "License");
5// you may not use this file except in compliance with the License.
6// You may obtain a copy of the License at
7//
8// http://www.apache.org/licenses/LICENSE-2.0
9//
10// Unless required by applicable law or agreed to in writing, software
11// distributed under the License is distributed on an "AS IS" BASIS,
12// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13// See the License for the specific language governing permissions and
14// limitations under the License.
15//
adlr@google.com3defe6a2009-12-04 20:57:17 +000016
Alex Deymo39910dc2015-11-09 17:04:30 -080017#include "update_engine/payload_consumer/postinstall_runner_action.h"
Jay Srinivasan1c0fe792013-03-28 16:45:25 -070018
Alex Deymo0d298542016-03-30 18:31:49 -070019#include <fcntl.h>
Alex Deymod15c5462016-03-09 18:11:12 -080020#include <signal.h>
adlr@google.com3defe6a2009-12-04 20:57:17 +000021#include <stdlib.h>
Alex Vakulenko44cab302014-07-23 13:12:15 -070022#include <sys/mount.h>
Alex Deymod15c5462016-03-09 18:11:12 -080023#include <sys/types.h>
Alex Deymo0d298542016-03-30 18:31:49 -070024#include <unistd.h>
Jay Srinivasan1c0fe792013-03-28 16:45:25 -070025
Alex Deymo44b35672016-04-05 17:57:48 -070026#include <cmath>
27
Alex Deymoe5e5fe92015-10-05 09:28:19 -070028#include <base/files/file_path.h>
29#include <base/files/file_util.h>
Alex Deymod15c5462016-03-09 18:11:12 -080030#include <base/logging.h>
hscham00b6aa22020-02-20 12:32:06 +090031#include <base/stl_util.h>
Alex Deymo0d298542016-03-30 18:31:49 -070032#include <base/strings/string_split.h>
Alex Deymo390efed2016-02-18 11:00:40 -080033#include <base/strings/string_util.h>
Alex Deymo461b2592015-07-24 20:10:52 -070034
Alex Deymo39910dc2015-11-09 17:04:30 -080035#include "update_engine/common/action_processor.h"
Alex Deymob15a0b82015-11-25 20:30:40 -030036#include "update_engine/common/boot_control_interface.h"
Alex Deymo14dbd332016-03-01 18:55:54 -080037#include "update_engine/common/platform_constants.h"
Alex Deymo39910dc2015-11-09 17:04:30 -080038#include "update_engine/common/subprocess.h"
39#include "update_engine/common/utils.h"
adlr@google.com3defe6a2009-12-04 20:57:17 +000040
Alex Deymo0d298542016-03-30 18:31:49 -070041namespace {
42
43// The file descriptor number from the postinstall program's perspective where
44// it can report status updates. This can be any number greater than 2 (stderr),
45// but must be kept in sync with the "bin/postinst_progress" defined in the
46// sample_images.sh file.
47const int kPostinstallStatusFd = 3;
48
49} // namespace
50
adlr@google.com3defe6a2009-12-04 20:57:17 +000051namespace chromeos_update_engine {
52
Alex Deymo0d298542016-03-30 18:31:49 -070053using brillo::MessageLoop;
adlr@google.com3defe6a2009-12-04 20:57:17 +000054using std::string;
Andrew de los Reyesf9714432010-05-04 10:21:23 -070055using std::vector;
adlr@google.com3defe6a2009-12-04 20:57:17 +000056
adlr@google.com3defe6a2009-12-04 20:57:17 +000057void PostinstallRunnerAction::PerformAction() {
58 CHECK(HasInputObject());
Chris Sosad317e402013-06-12 13:47:09 -070059 install_plan_ = GetInputObject();
Darin Petkov6f03a3b2010-11-10 14:27:14 -080060
Zentaro Kavanagh28def4f2019-01-15 17:15:01 -080061 // We always powerwash when rolling back, however policy can determine
62 // if this is a full/normal powerwash, or a special rollback powerwash
63 // that retains a small amount of system state such as enrollment and
64 // network configuration. In both cases all user accounts are deleted.
Marton Hunyady199152d2018-05-07 19:08:48 +020065 if (install_plan_.powerwash_required || install_plan_.is_rollback) {
Miriam Polzeraff72002020-08-27 08:20:39 +020066 if (hardware_->SchedulePowerwash(
67 install_plan_.rollback_data_save_requested)) {
Alex Deymofb905d92016-06-03 19:26:58 -070068 powerwash_scheduled_ = true;
Jay Srinivasan1c0fe792013-03-28 16:45:25 -070069 } else {
Alex Deymoe5e5fe92015-10-05 09:28:19 -070070 return CompletePostinstall(ErrorCode::kPostinstallPowerwashError);
Jay Srinivasan1c0fe792013-03-28 16:45:25 -070071 }
72 }
73
Alex Deymo0d298542016-03-30 18:31:49 -070074 // Initialize all the partition weights.
75 partition_weight_.resize(install_plan_.partitions.size());
76 total_weight_ = 0;
77 for (size_t i = 0; i < install_plan_.partitions.size(); ++i) {
Tianjie Xu087de9d2019-11-01 17:11:22 -070078 auto& partition = install_plan_.partitions[i];
79 if (!install_plan_.run_post_install && partition.postinstall_optional) {
80 partition.run_postinstall = false;
81 LOG(INFO) << "Skipping optional post-install for partition "
82 << partition.name << " according to install plan.";
83 }
84
Alex Deymo0d298542016-03-30 18:31:49 -070085 // TODO(deymo): This code sets the weight to all the postinstall commands,
86 // but we could remember how long they took in the past and use those
87 // values.
Tianjie Xu087de9d2019-11-01 17:11:22 -070088 partition_weight_[i] = partition.run_postinstall;
Alex Deymo0d298542016-03-30 18:31:49 -070089 total_weight_ += partition_weight_[i];
90 }
91 accumulated_weight_ = 0;
92 ReportProgress(0);
93
Alex Deymoe5e5fe92015-10-05 09:28:19 -070094 PerformPartitionPostinstall();
95}
96
97void PostinstallRunnerAction::PerformPartitionPostinstall() {
Alex Deymo390efed2016-02-18 11:00:40 -080098 if (install_plan_.download_url.empty()) {
99 LOG(INFO) << "Skipping post-install during rollback";
100 return CompletePostinstall(ErrorCode::kSuccess);
101 }
102
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700103 // Skip all the partitions that don't have a post-install step.
104 while (current_partition_ < install_plan_.partitions.size() &&
105 !install_plan_.partitions[current_partition_].run_postinstall) {
106 VLOG(1) << "Skipping post-install on partition "
107 << install_plan_.partitions[current_partition_].name;
108 current_partition_++;
109 }
110 if (current_partition_ == install_plan_.partitions.size())
111 return CompletePostinstall(ErrorCode::kSuccess);
112
113 const InstallPlan::Partition& partition =
114 install_plan_.partitions[current_partition_];
115
Brian Norris7b428f52019-06-26 10:03:35 -0700116 const string mountable_device = partition.target_path;
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700117 if (mountable_device.empty()) {
118 LOG(ERROR) << "Cannot make mountable device from " << partition.target_path;
119 return CompletePostinstall(ErrorCode::kPostinstallRunnerError);
120 }
121
122 // Perform post-install for the current_partition_ partition. At this point we
123 // need to call CompletePartitionPostinstall to complete the operation and
124 // cleanup.
Alex Deymo390efed2016-02-18 11:00:40 -0800125#ifdef __ANDROID__
126 fs_mount_dir_ = "/postinstall";
127#else // __ANDROID__
Sen Jiang371615b2016-04-13 15:54:29 -0700128 base::FilePath temp_dir;
129 TEST_AND_RETURN(base::CreateNewTempDirectory("au_postint_mount", &temp_dir));
130 fs_mount_dir_ = temp_dir.value();
Alex Deymo390efed2016-02-18 11:00:40 -0800131#endif // __ANDROID__
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700132
Alex Deymof4116502017-03-22 17:00:31 -0700133 // Double check that the fs_mount_dir is not busy with a previous mounted
134 // filesystem from a previous crashed postinstall step.
135 if (utils::IsMountpoint(fs_mount_dir_)) {
136 LOG(INFO) << "Found previously mounted filesystem at " << fs_mount_dir_;
137 utils::UnmountFilesystem(fs_mount_dir_);
138 }
139
Alex Deymocbc22742016-03-04 17:53:02 -0800140 base::FilePath postinstall_path(partition.postinstall_path);
141 if (postinstall_path.IsAbsolute()) {
142 LOG(ERROR) << "Invalid absolute path passed to postinstall, use a relative"
143 "path instead: "
144 << partition.postinstall_path;
145 return CompletePostinstall(ErrorCode::kPostinstallRunnerError);
146 }
147
148 string abs_path =
149 base::FilePath(fs_mount_dir_).Append(postinstall_path).value();
Alex Deymo390efed2016-02-18 11:00:40 -0800150 if (!base::StartsWith(
151 abs_path, fs_mount_dir_, base::CompareCase::SENSITIVE)) {
152 LOG(ERROR) << "Invalid relative postinstall path: "
153 << partition.postinstall_path;
154 return CompletePostinstall(ErrorCode::kPostinstallRunnerError);
155 }
156
Alex Deymo5fb356c2016-03-25 18:48:22 -0700157#ifdef __ANDROID__
158 // In Chromium OS, the postinstall step is allowed to write to the block
159 // device on the target image, so we don't mark it as read-only and should
160 // be read-write since we just wrote to it during the update.
161
162 // Mark the block device as read-only before mounting for post-install.
163 if (!utils::SetBlockDeviceReadOnly(mountable_device, true)) {
164 return CompletePartitionPostinstall(
165 1, "Error marking the device " + mountable_device + " read only.");
166 }
167#endif // __ANDROID__
168
Alex Deymo390efed2016-02-18 11:00:40 -0800169 if (!utils::MountFilesystem(mountable_device,
170 fs_mount_dir_,
171 MS_RDONLY,
Alex Deymo14dbd332016-03-01 18:55:54 -0800172 partition.filesystem_type,
173 constants::kPostinstallMountOptions)) {
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700174 return CompletePartitionPostinstall(
175 1, "Error mounting the device " + mountable_device);
176 }
177
Alex Deymo390efed2016-02-18 11:00:40 -0800178 LOG(INFO) << "Performing postinst (" << partition.postinstall_path << " at "
179 << abs_path << ") installed on device " << partition.target_path
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700180 << " and mountable device " << mountable_device;
181
Alex Deymo032e7722014-03-25 17:53:56 -0700182 // Logs the file format of the postinstall script we are about to run. This
183 // will help debug when the postinstall script doesn't match the architecture
184 // of our build.
Alex Deymo390efed2016-02-18 11:00:40 -0800185 LOG(INFO) << "Format file for new " << partition.postinstall_path
186 << " is: " << utils::GetFileFormat(abs_path);
Alex Deymo032e7722014-03-25 17:53:56 -0700187
Darin Petkov6f03a3b2010-11-10 14:27:14 -0800188 // Runs the postinstall script asynchronously to free up the main loop while
189 // it's running.
Alex Deymo0d298542016-03-30 18:31:49 -0700190 vector<string> command = {abs_path};
191#ifdef __ANDROID__
192 // In Brillo and Android, we pass the slot number and status fd.
193 command.push_back(std::to_string(install_plan_.target_slot));
194 command.push_back(std::to_string(kPostinstallStatusFd));
195#else
196 // Chrome OS postinstall expects the target rootfs as the first parameter.
197 command.push_back(partition.target_path);
198#endif // __ANDROID__
199
200 current_command_ = Subprocess::Get().ExecFlags(
Alex Deymod15c5462016-03-09 18:11:12 -0800201 command,
Alex Deymo0d298542016-03-30 18:31:49 -0700202 Subprocess::kRedirectStderrToStdout,
203 {kPostinstallStatusFd},
Alex Deymod15c5462016-03-09 18:11:12 -0800204 base::Bind(&PostinstallRunnerAction::CompletePartitionPostinstall,
205 base::Unretained(this)));
206 // Subprocess::Exec should never return a negative process id.
207 CHECK_GE(current_command_, 0);
208
Alex Deymo0d298542016-03-30 18:31:49 -0700209 if (!current_command_) {
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700210 CompletePartitionPostinstall(1, "Postinstall didn't launch");
Alex Deymo0d298542016-03-30 18:31:49 -0700211 return;
212 }
213
214 // Monitor the status file descriptor.
215 progress_fd_ =
216 Subprocess::Get().GetPipeFd(current_command_, kPostinstallStatusFd);
217 int fd_flags = fcntl(progress_fd_, F_GETFL, 0) | O_NONBLOCK;
218 if (HANDLE_EINTR(fcntl(progress_fd_, F_SETFL, fd_flags)) < 0) {
219 PLOG(ERROR) << "Unable to set non-blocking I/O mode on fd " << progress_fd_;
220 }
221
Hidehiko Abe493fecb2019-07-10 23:30:50 +0900222 progress_controller_ = base::FileDescriptorWatcher::WatchReadable(
Alex Deymo0d298542016-03-30 18:31:49 -0700223 progress_fd_,
Hidehiko Abe493fecb2019-07-10 23:30:50 +0900224 base::BindRepeating(&PostinstallRunnerAction::OnProgressFdReady,
225 base::Unretained(this)));
Darin Petkov6f03a3b2010-11-10 14:27:14 -0800226}
227
Alex Deymo0d298542016-03-30 18:31:49 -0700228void PostinstallRunnerAction::OnProgressFdReady() {
229 char buf[1024];
230 size_t bytes_read;
231 do {
232 bytes_read = 0;
233 bool eof;
234 bool ok =
hscham00b6aa22020-02-20 12:32:06 +0900235 utils::ReadAll(progress_fd_, buf, base::size(buf), &bytes_read, &eof);
Alex Deymo0d298542016-03-30 18:31:49 -0700236 progress_buffer_.append(buf, bytes_read);
237 // Process every line.
238 vector<string> lines = base::SplitString(
239 progress_buffer_, "\n", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL);
240 if (!lines.empty()) {
241 progress_buffer_ = lines.back();
242 lines.pop_back();
243 for (const auto& line : lines) {
244 ProcessProgressLine(line);
245 }
246 }
247 if (!ok || eof) {
248 // There was either an error or an EOF condition, so we are done watching
249 // the file descriptor.
Hidehiko Abe493fecb2019-07-10 23:30:50 +0900250 progress_controller_.reset();
Alex Deymo0d298542016-03-30 18:31:49 -0700251 return;
252 }
253 } while (bytes_read);
254}
255
256bool PostinstallRunnerAction::ProcessProgressLine(const string& line) {
257 double frac = 0;
Alex Deymoa2ea1c22016-08-24 17:26:19 -0700258 if (sscanf(line.c_str(), "global_progress %lf", &frac) == 1 &&
259 !std::isnan(frac)) {
Alex Deymo0d298542016-03-30 18:31:49 -0700260 ReportProgress(frac);
261 return true;
262 }
263
264 return false;
265}
266
267void PostinstallRunnerAction::ReportProgress(double frac) {
268 if (!delegate_)
269 return;
Yoshitaka Ishida128936f2018-02-16 18:20:07 +0900270 if (current_partition_ >= partition_weight_.size() || total_weight_ == 0) {
Alex Deymo0d298542016-03-30 18:31:49 -0700271 delegate_->ProgressUpdate(1.);
272 return;
273 }
Alex Deymo44b35672016-04-05 17:57:48 -0700274 if (!std::isfinite(frac) || frac < 0)
Alex Deymo0d298542016-03-30 18:31:49 -0700275 frac = 0;
276 if (frac > 1)
277 frac = 1;
278 double postinst_action_progress =
279 (accumulated_weight_ + partition_weight_[current_partition_] * frac) /
280 total_weight_;
281 delegate_->ProgressUpdate(postinst_action_progress);
282}
283
284void PostinstallRunnerAction::Cleanup() {
Alex Deymo390efed2016-02-18 11:00:40 -0800285 utils::UnmountFilesystem(fs_mount_dir_);
Alex Deymod15c5462016-03-09 18:11:12 -0800286#ifndef __ANDROID__
hscham043355b2020-11-17 16:50:10 +0900287 if (!base::DeleteFile(base::FilePath(fs_mount_dir_))) {
Alex Deymo390efed2016-02-18 11:00:40 -0800288 PLOG(WARNING) << "Not removing temporary mountpoint " << fs_mount_dir_;
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700289 }
Alex Deymod15c5462016-03-09 18:11:12 -0800290#endif // !__ANDROID__
Alex Deymo390efed2016-02-18 11:00:40 -0800291 fs_mount_dir_.clear();
Alex Deymo0d298542016-03-30 18:31:49 -0700292
293 progress_fd_ = -1;
Hidehiko Abe493fecb2019-07-10 23:30:50 +0900294 progress_controller_.reset();
Tianjie55abd3c2020-06-19 00:22:59 -0700295
Alex Deymo0d298542016-03-30 18:31:49 -0700296 progress_buffer_.clear();
Alex Deymod15c5462016-03-09 18:11:12 -0800297}
298
299void PostinstallRunnerAction::CompletePartitionPostinstall(
300 int return_code, const string& output) {
301 current_command_ = 0;
Alex Deymo0d298542016-03-30 18:31:49 -0700302 Cleanup();
Alex Deymo31d95ac2015-09-17 11:56:18 -0700303
Darin Petkov6f03a3b2010-11-10 14:27:14 -0800304 if (return_code != 0) {
305 LOG(ERROR) << "Postinst command failed with code: " << return_code;
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700306 ErrorCode error_code = ErrorCode::kPostinstallRunnerError;
Jay Srinivasan1c0fe792013-03-28 16:45:25 -0700307
Andrew de los Reyesfe57d542011-06-07 09:00:36 -0700308 if (return_code == 3) {
Andrew de los Reyesc1d5c932011-04-20 17:15:47 -0700309 // This special return code means that we tried to update firmware,
310 // but couldn't because we booted from FW B, and we need to reboot
311 // to get back to FW A.
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700312 error_code = ErrorCode::kPostinstallBootedFromFirmwareB;
Andrew de los Reyesc1d5c932011-04-20 17:15:47 -0700313 }
Don Garrett81018e02013-07-30 18:46:31 -0700314
315 if (return_code == 4) {
316 // This special return code means that we tried to update firmware,
317 // but couldn't because we booted from FW B, and we need to reboot
318 // to get back to FW A.
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700319 error_code = ErrorCode::kPostinstallFirmwareRONotUpdatable;
Don Garrett81018e02013-07-30 18:46:31 -0700320 }
Alex Deymo5b91c6b2016-08-04 20:33:36 -0700321
322 // If postinstall script for this partition is optional we can ignore the
323 // result.
324 if (install_plan_.partitions[current_partition_].postinstall_optional) {
325 LOG(INFO) << "Ignoring postinstall failure since it is optional";
326 } else {
327 return CompletePostinstall(error_code);
328 }
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700329 }
Alex Deymo0d298542016-03-30 18:31:49 -0700330 accumulated_weight_ += partition_weight_[current_partition_];
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700331 current_partition_++;
Alex Deymo0d298542016-03-30 18:31:49 -0700332 ReportProgress(0);
333
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700334 PerformPartitionPostinstall();
335}
336
337void PostinstallRunnerAction::CompletePostinstall(ErrorCode error_code) {
338 // We only attempt to mark the new slot as active if all the postinstall
339 // steps succeeded.
Sen Jiang02c49422017-10-31 15:14:11 -0700340 if (error_code == ErrorCode::kSuccess) {
341 if (install_plan_.switch_slot_on_reboot) {
Yifan Hong7b3910a2020-03-24 17:47:32 -0700342 if (!boot_control_->GetDynamicPartitionControl()->FinishUpdate(
343 install_plan_.powerwash_required) ||
Yifan Honge8583622019-11-07 11:36:31 -0800344 !boot_control_->SetActiveBootSlot(install_plan_.target_slot)) {
Sen Jiang02c49422017-10-31 15:14:11 -0700345 error_code = ErrorCode::kPostinstallRunnerError;
Tianjie Xud6aa91f2019-11-14 11:55:10 -0800346 } else {
347 // Schedules warm reset on next reboot, ignores the error.
348 hardware_->SetWarmReset(true);
Sen Jiang02c49422017-10-31 15:14:11 -0700349 }
350 } else {
351 error_code = ErrorCode::kUpdatedButNotActive;
352 }
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700353 }
354
355 ScopedActionCompleter completer(processor_, this);
Alex Deymocbc22742016-03-04 17:53:02 -0800356 completer.set_code(error_code);
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700357
Sen Jiang02c49422017-10-31 15:14:11 -0700358 if (error_code != ErrorCode::kSuccess &&
359 error_code != ErrorCode::kUpdatedButNotActive) {
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700360 LOG(ERROR) << "Postinstall action failed.";
361
Alex Deymofb905d92016-06-03 19:26:58 -0700362 // Undo any changes done to trigger Powerwash.
363 if (powerwash_scheduled_)
364 hardware_->CancelPowerwash();
Don Garrett81018e02013-07-30 18:46:31 -0700365
Darin Petkov6f03a3b2010-11-10 14:27:14 -0800366 return;
367 }
Jay Srinivasanae4697c2013-03-18 17:08:08 -0700368
Alex Deymoe5e5fe92015-10-05 09:28:19 -0700369 LOG(INFO) << "All post-install commands succeeded";
Chris Sosad317e402013-06-12 13:47:09 -0700370 if (HasOutputPipe()) {
371 SetOutputObject(install_plan_);
372 }
adlr@google.com3defe6a2009-12-04 20:57:17 +0000373}
374
Alex Deymod15c5462016-03-09 18:11:12 -0800375void PostinstallRunnerAction::SuspendAction() {
376 if (!current_command_)
377 return;
378 if (kill(current_command_, SIGSTOP) != 0) {
379 PLOG(ERROR) << "Couldn't pause child process " << current_command_;
Ben Chan7f4bc3f2017-01-10 15:32:11 -0800380 } else {
381 is_current_command_suspended_ = true;
Alex Deymod15c5462016-03-09 18:11:12 -0800382 }
383}
384
385void PostinstallRunnerAction::ResumeAction() {
386 if (!current_command_)
387 return;
388 if (kill(current_command_, SIGCONT) != 0) {
389 PLOG(ERROR) << "Couldn't resume child process " << current_command_;
Ben Chan7f4bc3f2017-01-10 15:32:11 -0800390 } else {
391 is_current_command_suspended_ = false;
Alex Deymod15c5462016-03-09 18:11:12 -0800392 }
393}
394
395void PostinstallRunnerAction::TerminateProcessing() {
396 if (!current_command_)
397 return;
398 // Calling KillExec() will discard the callback we registered and therefore
399 // the unretained reference to this object.
400 Subprocess::Get().KillExec(current_command_);
Ben Chan7f4bc3f2017-01-10 15:32:11 -0800401
402 // If the command has been suspended, resume it after KillExec() so that the
403 // process can process the SIGTERM sent by KillExec().
404 if (is_current_command_suspended_) {
405 ResumeAction();
406 }
407
Alex Deymod15c5462016-03-09 18:11:12 -0800408 current_command_ = 0;
Alex Deymo0d298542016-03-30 18:31:49 -0700409 Cleanup();
Alex Deymod15c5462016-03-09 18:11:12 -0800410}
411
adlr@google.com3defe6a2009-12-04 20:57:17 +0000412} // namespace chromeos_update_engine