Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2012 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | package com.android.server.webkit; |
| 18 | |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 19 | import android.content.BroadcastReceiver; |
| 20 | import android.content.Context; |
| 21 | import android.content.Intent; |
| 22 | import android.content.IntentFilter; |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 23 | import android.content.pm.PackageManager; |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 24 | import android.os.Binder; |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 25 | import android.os.PatternMatcher; |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 26 | import android.os.Process; |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 27 | import android.os.ResultReceiver; |
Dianne Hackborn | 354736e | 2016-08-22 17:00:05 -0700 | [diff] [blame^] | 28 | import android.os.ShellCallback; |
Gustav Sennton | 23875b2 | 2016-02-09 14:11:33 +0000 | [diff] [blame] | 29 | import android.os.UserHandle; |
Primiano Tucci | 810c052 | 2014-07-25 18:03:16 +0100 | [diff] [blame] | 30 | import android.util.Slog; |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 31 | import android.webkit.IWebViewUpdateService; |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 32 | import android.webkit.WebViewProviderInfo; |
| 33 | import android.webkit.WebViewProviderResponse; |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 34 | |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 35 | import com.android.server.SystemService; |
| 36 | |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 37 | import java.io.FileDescriptor; |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 38 | import java.util.Arrays; |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 39 | |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 40 | /** |
| 41 | * Private service to wait for the updatable WebView to be ready for use. |
| 42 | * @hide |
| 43 | */ |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 44 | public class WebViewUpdateService extends SystemService { |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 45 | |
| 46 | private static final String TAG = "WebViewUpdateService"; |
Gustav Sennton | 6ce92c9 | 2015-10-23 11:10:39 +0100 | [diff] [blame] | 47 | |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 48 | private BroadcastReceiver mWebViewUpdatedReceiver; |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 49 | private WebViewUpdateServiceImpl mImpl; |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 50 | |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 51 | static final int PACKAGE_CHANGED = 0; |
| 52 | static final int PACKAGE_ADDED = 1; |
| 53 | static final int PACKAGE_ADDED_REPLACED = 2; |
| 54 | static final int PACKAGE_REMOVED = 3; |
| 55 | |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 56 | public WebViewUpdateService(Context context) { |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 57 | super(context); |
Hui Shu | 9455bd0 | 2016-04-08 13:25:26 -0700 | [diff] [blame] | 58 | mImpl = new WebViewUpdateServiceImpl(context, SystemImpl.getInstance()); |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 59 | } |
| 60 | |
| 61 | @Override |
| 62 | public void onStart() { |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 63 | mWebViewUpdatedReceiver = new BroadcastReceiver() { |
| 64 | @Override |
| 65 | public void onReceive(Context context, Intent intent) { |
Gustav Sennton | 0df2c55 | 2016-06-14 15:32:19 +0100 | [diff] [blame] | 66 | int userId = intent.getIntExtra(Intent.EXTRA_USER_HANDLE, UserHandle.USER_NULL); |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 67 | switch (intent.getAction()) { |
| 68 | case Intent.ACTION_PACKAGE_REMOVED: |
| 69 | // When a package is replaced we will receive two intents, one |
| 70 | // representing the removal of the old package and one representing the |
| 71 | // addition of the new package. |
| 72 | // In the case where we receive an intent to remove the old version of |
| 73 | // the package that is being replaced we early-out here so that we don't |
| 74 | // run the update-logic twice. |
| 75 | if (intent.getExtras().getBoolean(Intent.EXTRA_REPLACING)) return; |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 76 | mImpl.packageStateChanged(packageNameFromIntent(intent), |
Gustav Sennton | 0df2c55 | 2016-06-14 15:32:19 +0100 | [diff] [blame] | 77 | PACKAGE_REMOVED, userId); |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 78 | break; |
| 79 | case Intent.ACTION_PACKAGE_CHANGED: |
| 80 | // Ensure that we only heed PACKAGE_CHANGED intents if they change an |
| 81 | // entire package, not just a component |
| 82 | if (entirePackageChanged(intent)) { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 83 | mImpl.packageStateChanged(packageNameFromIntent(intent), |
Gustav Sennton | 0df2c55 | 2016-06-14 15:32:19 +0100 | [diff] [blame] | 84 | PACKAGE_CHANGED, userId); |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 85 | } |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 86 | break; |
| 87 | case Intent.ACTION_PACKAGE_ADDED: |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 88 | mImpl.packageStateChanged(packageNameFromIntent(intent), |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 89 | (intent.getExtras().getBoolean(Intent.EXTRA_REPLACING) |
Gustav Sennton | 0df2c55 | 2016-06-14 15:32:19 +0100 | [diff] [blame] | 90 | ? PACKAGE_ADDED_REPLACED : PACKAGE_ADDED), userId); |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 91 | break; |
| 92 | case Intent.ACTION_USER_ADDED: |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 93 | mImpl.handleNewUser(userId); |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 94 | break; |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 95 | } |
| 96 | } |
| 97 | }; |
| 98 | IntentFilter filter = new IntentFilter(); |
Gustav Sennton | 3098cf2 | 2015-11-10 03:33:09 +0000 | [diff] [blame] | 99 | filter.addAction(Intent.ACTION_PACKAGE_ADDED); |
| 100 | filter.addAction(Intent.ACTION_PACKAGE_REMOVED); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 101 | filter.addAction(Intent.ACTION_PACKAGE_CHANGED); |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 102 | filter.addDataScheme("package"); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 103 | // Make sure we only receive intents for WebView packages from our config file. |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 104 | for (WebViewProviderInfo provider : mImpl.getWebViewPackages()) { |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 105 | filter.addDataSchemeSpecificPart(provider.packageName, PatternMatcher.PATTERN_LITERAL); |
| 106 | } |
Gustav Sennton | 0df2c55 | 2016-06-14 15:32:19 +0100 | [diff] [blame] | 107 | |
| 108 | getContext().registerReceiverAsUser(mWebViewUpdatedReceiver, UserHandle.ALL, filter, |
| 109 | null /* broadcast permission */, null /* handler */); |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 110 | |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 111 | IntentFilter userAddedFilter = new IntentFilter(); |
| 112 | userAddedFilter.addAction(Intent.ACTION_USER_ADDED); |
Gustav Sennton | 0df2c55 | 2016-06-14 15:32:19 +0100 | [diff] [blame] | 113 | getContext().registerReceiverAsUser(mWebViewUpdatedReceiver, UserHandle.ALL, |
| 114 | userAddedFilter, null /* broadcast permission */, null /* handler */); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 115 | |
Torne (Richard Coles) | fc19b0a | 2016-02-01 16:16:57 +0000 | [diff] [blame] | 116 | publishBinderService("webviewupdate", new BinderService(), true /*allowIsolated*/); |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 117 | } |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 118 | |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 119 | public void prepareWebViewInSystemServer() { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 120 | mImpl.prepareWebViewInSystemServer(); |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 121 | } |
| 122 | |
| 123 | private static String packageNameFromIntent(Intent intent) { |
| 124 | return intent.getDataString().substring("package:".length()); |
| 125 | } |
| 126 | |
Gustav Sennton | 065b7e6 | 2016-04-01 15:11:43 +0100 | [diff] [blame] | 127 | /** |
| 128 | * Returns whether the entire package from an ACTION_PACKAGE_CHANGED intent was changed (rather |
| 129 | * than just one of its components). |
| 130 | * @hide |
| 131 | */ |
| 132 | public static boolean entirePackageChanged(Intent intent) { |
| 133 | String[] componentList = |
| 134 | intent.getStringArrayExtra(Intent.EXTRA_CHANGED_COMPONENT_NAME_LIST); |
| 135 | return Arrays.asList(componentList).contains( |
| 136 | intent.getDataString().substring("package:".length())); |
Gustav Sennton | dbf5eb0 | 2016-03-30 14:53:03 +0100 | [diff] [blame] | 137 | } |
| 138 | |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 139 | private class BinderService extends IWebViewUpdateService.Stub { |
| 140 | |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 141 | @Override |
| 142 | public void onShellCommand(FileDescriptor in, FileDescriptor out, |
Dianne Hackborn | 354736e | 2016-08-22 17:00:05 -0700 | [diff] [blame^] | 143 | FileDescriptor err, String[] args, ShellCallback callback, |
| 144 | ResultReceiver resultReceiver) { |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 145 | (new WebViewUpdateServiceShellCommand(this)).exec( |
Dianne Hackborn | 354736e | 2016-08-22 17:00:05 -0700 | [diff] [blame^] | 146 | this, in, out, err, args, callback, resultReceiver); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 147 | } |
| 148 | |
| 149 | |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 150 | /** |
| 151 | * The shared relro process calls this to notify us that it's done trying to create a relro |
| 152 | * file. This method gets called even if the relro creation has failed or the process |
| 153 | * crashed. |
| 154 | */ |
| 155 | @Override // Binder call |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 156 | public void notifyRelroCreationCompleted() { |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 157 | // Verify that the caller is either the shared relro process (nominal case) or the |
| 158 | // system server (only in the case the relro process crashes and we get here via the |
| 159 | // crashHandler). |
| 160 | if (Binder.getCallingUid() != Process.SHARED_RELRO_UID && |
| 161 | Binder.getCallingUid() != Process.SYSTEM_UID) { |
| 162 | return; |
| 163 | } |
| 164 | |
Gustav Sennton | 275d13c | 2016-02-24 10:58:09 +0000 | [diff] [blame] | 165 | long callingId = Binder.clearCallingIdentity(); |
| 166 | try { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 167 | WebViewUpdateService.this.mImpl.notifyRelroCreationCompleted(); |
Gustav Sennton | 275d13c | 2016-02-24 10:58:09 +0000 | [diff] [blame] | 168 | } finally { |
| 169 | Binder.restoreCallingIdentity(callingId); |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 170 | } |
| 171 | } |
| 172 | |
| 173 | /** |
| 174 | * WebViewFactory calls this to block WebView loading until the relro file is created. |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 175 | * Returns the WebView provider for which we create relro files. |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 176 | */ |
| 177 | @Override // Binder call |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 178 | public WebViewProviderResponse waitForAndGetProvider() { |
Primiano Tucci | e76e81a | 2014-07-29 16:38:33 +0100 | [diff] [blame] | 179 | // The WebViewUpdateService depends on the prepareWebViewInSystemServer call, which |
| 180 | // happens later (during the PHASE_ACTIVITY_MANAGER_READY) in SystemServer.java. If |
| 181 | // another service there tries to bring up a WebView in the between, the wait below |
| 182 | // would deadlock without the check below. |
| 183 | if (Binder.getCallingPid() == Process.myPid()) { |
| 184 | throw new IllegalStateException("Cannot create a WebView from the SystemServer"); |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 185 | } |
| 186 | |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 187 | return WebViewUpdateService.this.mImpl.waitForAndGetProvider(); |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 188 | } |
| 189 | |
| 190 | /** |
| 191 | * This is called from DeveloperSettings when the user changes WebView provider. |
| 192 | */ |
| 193 | @Override // Binder call |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 194 | public String changeProviderAndSetting(String newProvider) { |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 195 | if (getContext().checkCallingPermission( |
| 196 | android.Manifest.permission.WRITE_SECURE_SETTINGS) |
| 197 | != PackageManager.PERMISSION_GRANTED) { |
| 198 | String msg = "Permission Denial: changeProviderAndSetting() from pid=" |
| 199 | + Binder.getCallingPid() |
| 200 | + ", uid=" + Binder.getCallingUid() |
| 201 | + " requires " + android.Manifest.permission.WRITE_SECURE_SETTINGS; |
| 202 | Slog.w(TAG, msg); |
| 203 | throw new SecurityException(msg); |
| 204 | } |
| 205 | |
Gustav Sennton | ab3b6b1 | 2016-03-16 17:38:42 +0000 | [diff] [blame] | 206 | long callingId = Binder.clearCallingIdentity(); |
| 207 | try { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 208 | return WebViewUpdateService.this.mImpl.changeProviderAndSetting( |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 209 | newProvider); |
Gustav Sennton | ab3b6b1 | 2016-03-16 17:38:42 +0000 | [diff] [blame] | 210 | } finally { |
| 211 | Binder.restoreCallingIdentity(callingId); |
| 212 | } |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 213 | } |
| 214 | |
| 215 | @Override // Binder call |
| 216 | public WebViewProviderInfo[] getValidWebViewPackages() { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 217 | return WebViewUpdateService.this.mImpl.getValidWebViewPackages(); |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 218 | } |
| 219 | |
| 220 | @Override // Binder call |
Gustav Sennton | 8b17926 | 2016-03-14 11:31:14 +0000 | [diff] [blame] | 221 | public WebViewProviderInfo[] getAllWebViewPackages() { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 222 | return WebViewUpdateService.this.mImpl.getWebViewPackages(); |
Gustav Sennton | 8b17926 | 2016-03-14 11:31:14 +0000 | [diff] [blame] | 223 | } |
| 224 | |
| 225 | @Override // Binder call |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 226 | public String getCurrentWebViewPackageName() { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 227 | return WebViewUpdateService.this.mImpl.getCurrentWebViewPackageName(); |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 228 | } |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 229 | |
| 230 | @Override // Binder call |
| 231 | public boolean isFallbackPackage(String packageName) { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame] | 232 | return WebViewUpdateService.this.mImpl.isFallbackPackage(packageName); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 233 | } |
| 234 | |
| 235 | @Override // Binder call |
| 236 | public void enableFallbackLogic(boolean enable) { |
| 237 | if (getContext().checkCallingPermission( |
| 238 | android.Manifest.permission.WRITE_SECURE_SETTINGS) |
| 239 | != PackageManager.PERMISSION_GRANTED) { |
| 240 | String msg = "Permission Denial: enableFallbackLogic() from pid=" |
| 241 | + Binder.getCallingPid() |
| 242 | + ", uid=" + Binder.getCallingUid() |
| 243 | + " requires " + android.Manifest.permission.WRITE_SECURE_SETTINGS; |
| 244 | Slog.w(TAG, msg); |
| 245 | throw new SecurityException(msg); |
| 246 | } |
| 247 | |
Gustav Sennton | 6824c7c | 2016-04-04 14:07:23 +0100 | [diff] [blame] | 248 | long callingId = Binder.clearCallingIdentity(); |
| 249 | try { |
| 250 | WebViewUpdateService.this.mImpl.enableFallbackLogic(enable); |
| 251 | } finally { |
| 252 | Binder.restoreCallingIdentity(callingId); |
| 253 | } |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 254 | } |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 255 | } |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 256 | } |