blob: 03e5667666c1bf65f95b80418c3a0a5e76e28c95 [file] [log] [blame]
Narayan Kamath973b4662014-03-31 13:41:26 +01001/*
2 * Copyright (C) 2014 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.internal.os;
18
19
Narayan Kamathfbb32f62015-06-12 15:34:35 +010020import android.os.Trace;
Narayan Kamath973b4662014-03-31 13:41:26 +010021import dalvik.system.ZygoteHooks;
Elliott Hughes860c5912014-04-28 19:19:13 -070022import android.system.ErrnoException;
23import android.system.Os;
Narayan Kamath973b4662014-03-31 13:41:26 +010024
Tobias Sargeantb9679dc2016-01-19 16:34:54 +000025import java.lang.reflect.InvocationTargetException;
26import java.lang.reflect.Method;
27
Narayan Kamath973b4662014-03-31 13:41:26 +010028/** @hide */
29public final class Zygote {
30 /*
Nicolas Geoffray81edac42017-09-07 14:13:29 +010031 * Bit values for "runtimeFlags" argument. The definitions are duplicated
Narayan Kamath973b4662014-03-31 13:41:26 +010032 * in the native code.
33 */
34
35 /** enable debugging over JDWP */
Nicolas Geoffray347b1df2016-12-20 14:05:05 +000036 public static final int DEBUG_ENABLE_JDWP = 1;
Narayan Kamath973b4662014-03-31 13:41:26 +010037 /** enable JNI checks */
38 public static final int DEBUG_ENABLE_CHECKJNI = 1 << 1;
39 /** enable Java programming language "assert" statements */
40 public static final int DEBUG_ENABLE_ASSERT = 1 << 2;
Mathieu Chartier7a490282015-03-17 09:51:36 -070041 /** disable the AOT compiler and JIT */
Narayan Kamath973b4662014-03-31 13:41:26 +010042 public static final int DEBUG_ENABLE_SAFEMODE = 1 << 3;
43 /** Enable logging of third-party JNI activity. */
44 public static final int DEBUG_ENABLE_JNI_LOGGING = 1 << 4;
David Srbecky065075e2015-05-28 17:16:09 +010045 /** Force generation of native debugging information. */
Nicolas Geoffray9abbf452015-11-05 11:29:42 +000046 public static final int DEBUG_GENERATE_DEBUG_INFO = 1 << 5;
Tamas Berghammerdf6cb282016-01-29 12:07:00 +000047 /** Always use JIT-ed code. */
48 public static final int DEBUG_ALWAYS_JIT = 1 << 6;
Nicolas Geoffray347b1df2016-12-20 14:05:05 +000049 /** Make the code native debuggable by turning off some optimizations. */
Tamas Berghammerdf6cb282016-01-29 12:07:00 +000050 public static final int DEBUG_NATIVE_DEBUGGABLE = 1 << 7;
Nicolas Geoffray347b1df2016-12-20 14:05:05 +000051 /** Make the code Java debuggable by turning off some optimizations. */
52 public static final int DEBUG_JAVA_DEBUGGABLE = 1 << 8;
Mathieu Chartier7a490282015-03-17 09:51:36 -070053
Nicolas Geoffray1f88ad62017-09-13 14:21:00 +010054 /** Turn off the verifier. */
55 public static final int DISABLE_VERIFIER = 1 << 9;
56 /** Only use oat files located in /system. Otherwise use dex/jar/apk . */
57 public static final int ONLY_USE_SYSTEM_OAT_FILES = 1 << 10;
David Brazdil071bcaa2018-01-17 18:06:47 +000058 /** Do not enfore hidden API access restrictions. */
59 public static final int DISABLE_HIDDEN_API_CHECKS = 1 << 11;
David Srbecky156ed922018-01-30 14:37:37 +000060 /** Force generation of native debugging information for backtraces. */
61 public static final int DEBUG_GENERATE_MINI_DEBUG_INFO = 1 << 12;
Nicolas Geoffray1f88ad62017-09-13 14:21:00 +010062
Narayan Kamath973b4662014-03-31 13:41:26 +010063 /** No external storage should be mounted. */
64 public static final int MOUNT_EXTERNAL_NONE = 0;
Jeff Sharkey9527b222015-06-24 15:24:48 -070065 /** Default external storage should be mounted. */
Jeff Sharkey48877892015-03-18 11:27:19 -070066 public static final int MOUNT_EXTERNAL_DEFAULT = 1;
Jeff Sharkey9527b222015-06-24 15:24:48 -070067 /** Read-only external storage should be mounted. */
68 public static final int MOUNT_EXTERNAL_READ = 2;
69 /** Read-write external storage should be mounted. */
70 public static final int MOUNT_EXTERNAL_WRITE = 3;
Narayan Kamath973b4662014-03-31 13:41:26 +010071
72 private static final ZygoteHooks VM_HOOKS = new ZygoteHooks();
73
74 private Zygote() {}
75
Victor Hsiehc8176ef2018-01-08 12:43:00 -080076 /** Called for some security initialization before any fork. */
77 native static void nativeSecurityInit();
78
Narayan Kamath973b4662014-03-31 13:41:26 +010079 /**
80 * Forks a new VM instance. The current VM must have been started
81 * with the -Xzygote flag. <b>NOTE: new instance keeps all
82 * root capabilities. The new process is expected to call capset()</b>.
83 *
84 * @param uid the UNIX uid that the new process should setuid() to after
85 * fork()ing and and before spawning any threads.
86 * @param gid the UNIX gid that the new process should setgid() to after
87 * fork()ing and and before spawning any threads.
88 * @param gids null-ok; a list of UNIX gids that the new process should
89 * setgroups() to after fork and before spawning any threads.
Nicolas Geoffray81edac42017-09-07 14:13:29 +010090 * @param runtimeFlags bit flags that enable ART features.
Narayan Kamath973b4662014-03-31 13:41:26 +010091 * @param rlimits null-ok an array of rlimit tuples, with the second
92 * dimension having a length of 3 and representing
93 * (resource, rlim_cur, rlim_max). These are set via the posix
94 * setrlimit(2) call.
95 * @param seInfo null-ok a string specifying SELinux information for
96 * the new process.
97 * @param niceName null-ok a string specifying the process name.
98 * @param fdsToClose an array of ints, holding one or more POSIX
99 * file descriptor numbers that are to be closed by the child
100 * (and replaced by /dev/null) after forking. An integer value
101 * of -1 in any entry in the array means "ignore this one".
Andreas Gampe8dfa1782017-01-05 12:45:58 -0800102 * @param fdsToIgnore null-ok an array of ints, either null or holding
103 * one or more POSIX file descriptor numbers that are to be ignored
104 * in the file descriptor table check.
Andreas Gampeaec67dc2014-09-02 21:23:06 -0700105 * @param instructionSet null-ok the instruction set to use.
jgu212eacd062014-09-10 06:55:07 -0400106 * @param appDataDir null-ok the data directory of the app.
Narayan Kamath973b4662014-03-31 13:41:26 +0100107 *
108 * @return 0 if this is the child, pid of the child
109 * if this is the parent, or -1 on error.
110 */
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100111 public static int forkAndSpecialize(int uid, int gid, int[] gids, int runtimeFlags,
Andreas Gampeaec67dc2014-09-02 21:23:06 -0700112 int[][] rlimits, int mountExternal, String seInfo, String niceName, int[] fdsToClose,
Andreas Gampe8dfa1782017-01-05 12:45:58 -0800113 int[] fdsToIgnore, String instructionSet, String appDataDir) {
Narayan Kamath973b4662014-03-31 13:41:26 +0100114 VM_HOOKS.preFork();
Hiroshi Yamauchi1e3db872017-03-02 13:39:07 -0800115 // Resets nice priority for zygote process.
116 resetNicePriority();
Narayan Kamath973b4662014-03-31 13:41:26 +0100117 int pid = nativeForkAndSpecialize(
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100118 uid, gid, gids, runtimeFlags, rlimits, mountExternal, seInfo, niceName, fdsToClose,
Andreas Gampe8dfa1782017-01-05 12:45:58 -0800119 fdsToIgnore, instructionSet, appDataDir);
Narayan Kamathfbb32f62015-06-12 15:34:35 +0100120 // Enable tracing as soon as possible for the child process.
121 if (pid == 0) {
Nicolas Geoffray1bf40f62017-09-13 12:59:21 +0100122 Trace.setTracingEnabled(true, runtimeFlags);
Narayan Kamathfbb32f62015-06-12 15:34:35 +0100123
124 // Note that this event ends at the end of handleChildProc,
125 Trace.traceBegin(Trace.TRACE_TAG_ACTIVITY_MANAGER, "PostFork");
126 }
Narayan Kamath973b4662014-03-31 13:41:26 +0100127 VM_HOOKS.postForkCommon();
128 return pid;
129 }
130
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100131 native private static int nativeForkAndSpecialize(int uid, int gid, int[] gids,int runtimeFlags,
Andreas Gampeaec67dc2014-09-02 21:23:06 -0700132 int[][] rlimits, int mountExternal, String seInfo, String niceName, int[] fdsToClose,
Andreas Gampe8dfa1782017-01-05 12:45:58 -0800133 int[] fdsToIgnore, String instructionSet, String appDataDir);
Narayan Kamath973b4662014-03-31 13:41:26 +0100134
135 /**
Christopher Ferris76de39e2017-06-20 16:13:40 -0700136 * Called to do any initialization before starting an application.
137 */
138 native static void nativePreApplicationInit();
139
140 /**
Narayan Kamath973b4662014-03-31 13:41:26 +0100141 * Special method to start the system server process. In addition to the
142 * common actions performed in forkAndSpecialize, the pid of the child
143 * process is recorded such that the death of the child process will cause
144 * zygote to exit.
145 *
146 * @param uid the UNIX uid that the new process should setuid() to after
147 * fork()ing and and before spawning any threads.
148 * @param gid the UNIX gid that the new process should setgid() to after
149 * fork()ing and and before spawning any threads.
150 * @param gids null-ok; a list of UNIX gids that the new process should
151 * setgroups() to after fork and before spawning any threads.
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100152 * @param runtimeFlags bit flags that enable ART features.
Narayan Kamath973b4662014-03-31 13:41:26 +0100153 * @param rlimits null-ok an array of rlimit tuples, with the second
154 * dimension having a length of 3 and representing
155 * (resource, rlim_cur, rlim_max). These are set via the posix
156 * setrlimit(2) call.
157 * @param permittedCapabilities argument for setcap()
158 * @param effectiveCapabilities argument for setcap()
159 *
160 * @return 0 if this is the child, pid of the child
161 * if this is the parent, or -1 on error.
162 */
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100163 public static int forkSystemServer(int uid, int gid, int[] gids, int runtimeFlags,
Narayan Kamath973b4662014-03-31 13:41:26 +0100164 int[][] rlimits, long permittedCapabilities, long effectiveCapabilities) {
David Brazdil071bcaa2018-01-17 18:06:47 +0000165 // SystemServer is always allowed to use hidden APIs.
166 runtimeFlags |= DISABLE_HIDDEN_API_CHECKS;
167
Narayan Kamath973b4662014-03-31 13:41:26 +0100168 VM_HOOKS.preFork();
Hiroshi Yamauchi1e3db872017-03-02 13:39:07 -0800169 // Resets nice priority for zygote process.
170 resetNicePriority();
Narayan Kamath973b4662014-03-31 13:41:26 +0100171 int pid = nativeForkSystemServer(
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100172 uid, gid, gids, runtimeFlags, rlimits, permittedCapabilities, effectiveCapabilities);
Narayan Kamathfbb32f62015-06-12 15:34:35 +0100173 // Enable tracing as soon as we enter the system_server.
174 if (pid == 0) {
Nicolas Geoffray1bf40f62017-09-13 12:59:21 +0100175 Trace.setTracingEnabled(true, runtimeFlags);
Narayan Kamathfbb32f62015-06-12 15:34:35 +0100176 }
Narayan Kamath973b4662014-03-31 13:41:26 +0100177 VM_HOOKS.postForkCommon();
178 return pid;
179 }
180
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100181 native private static int nativeForkSystemServer(int uid, int gid, int[] gids, int runtimeFlags,
Narayan Kamath973b4662014-03-31 13:41:26 +0100182 int[][] rlimits, long permittedCapabilities, long effectiveCapabilities);
183
doheon1.lee885b7422016-01-20 13:07:27 +0900184 /**
Robert Sesek54e387d2016-12-02 17:27:50 -0500185 * Lets children of the zygote inherit open file descriptors to this path.
186 */
187 native protected static void nativeAllowFileAcrossFork(String path);
188
189 /**
doheon1.lee885b7422016-01-20 13:07:27 +0900190 * Zygote unmount storage space on initializing.
191 * This method is called once.
192 */
193 native protected static void nativeUnmountStorageOnInit();
194
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100195 private static void callPostForkChildHooks(int runtimeFlags, boolean isSystemServer,
Nicolas Geoffray3c43b382015-12-11 15:01:04 +0000196 String instructionSet) {
Nicolas Geoffray81edac42017-09-07 14:13:29 +0100197 VM_HOOKS.postForkChild(runtimeFlags, isSystemServer, instructionSet);
Narayan Kamath973b4662014-03-31 13:41:26 +0100198 }
199
Narayan Kamathb49996d2017-02-06 20:24:08 +0000200 /**
Hiroshi Yamauchi1e3db872017-03-02 13:39:07 -0800201 * Resets the calling thread priority to the default value (Thread.NORM_PRIORITY
202 * or nice value 0). This updates both the priority value in java.lang.Thread and
203 * the nice value (setpriority).
Narayan Kamathb49996d2017-02-06 20:24:08 +0000204 */
Hiroshi Yamauchi1e3db872017-03-02 13:39:07 -0800205 static void resetNicePriority() {
206 Thread.currentThread().setPriority(Thread.NORM_PRIORITY);
207 }
Narayan Kamath973b4662014-03-31 13:41:26 +0100208
209 /**
210 * Executes "/system/bin/sh -c &lt;command&gt;" using the exec() system call.
211 * This method throws a runtime exception if exec() failed, otherwise, this
212 * method never returns.
213 *
214 * @param command The shell command to execute.
215 */
216 public static void execShell(String command) {
217 String[] args = { "/system/bin/sh", "-c", command };
218 try {
Elliott Hughes860c5912014-04-28 19:19:13 -0700219 Os.execv(args[0], args);
Narayan Kamath973b4662014-03-31 13:41:26 +0100220 } catch (ErrnoException e) {
221 throw new RuntimeException(e);
222 }
223 }
224
225 /**
226 * Appends quotes shell arguments to the specified string builder.
227 * The arguments are quoted using single-quotes, escaped if necessary,
228 * prefixed with a space, and appended to the command.
229 *
230 * @param command A string builder for the shell command being constructed.
231 * @param args An array of argument strings to be quoted and appended to the command.
232 * @see #execShell(String)
233 */
234 public static void appendQuotedShellArgs(StringBuilder command, String[] args) {
235 for (String arg : args) {
236 command.append(" '").append(arg.replace("'", "'\\''")).append("'");
237 }
238 }
Narayan Kamath973b4662014-03-31 13:41:26 +0100239}