Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2012 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | package com.android.server.webkit; |
| 18 | |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 19 | import android.content.BroadcastReceiver; |
| 20 | import android.content.Context; |
| 21 | import android.content.Intent; |
| 22 | import android.content.IntentFilter; |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 23 | import android.content.pm.PackageManager; |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 24 | import android.os.Binder; |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 25 | import android.os.PatternMatcher; |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 26 | import android.os.Process; |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 27 | import android.os.ResultReceiver; |
Gustav Sennton | 23875b2 | 2016-02-09 14:11:33 +0000 | [diff] [blame] | 28 | import android.os.UserHandle; |
Primiano Tucci | 810c052 | 2014-07-25 18:03:16 +0100 | [diff] [blame] | 29 | import android.util.Slog; |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 30 | import android.webkit.IWebViewUpdateService; |
Gustav Sennton | 8b17926 | 2016-03-14 11:31:14 +0000 | [diff] [blame] | 31 | import android.webkit.WebViewFactory; |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 32 | import android.webkit.WebViewProviderInfo; |
| 33 | import android.webkit.WebViewProviderResponse; |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 34 | |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 35 | import com.android.server.SystemService; |
| 36 | |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 37 | import java.io.FileDescriptor; |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 38 | import java.util.Arrays; |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 39 | |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 40 | /** |
| 41 | * Private service to wait for the updatable WebView to be ready for use. |
| 42 | * @hide |
| 43 | */ |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 44 | public class WebViewUpdateService extends SystemService { |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 45 | |
| 46 | private static final String TAG = "WebViewUpdateService"; |
Gustav Sennton | 6ce92c9 | 2015-10-23 11:10:39 +0100 | [diff] [blame] | 47 | |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 48 | private BroadcastReceiver mWebViewUpdatedReceiver; |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 49 | private WebViewUpdateServiceImpl mImpl; |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 50 | |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 51 | static final int PACKAGE_CHANGED = 0; |
| 52 | static final int PACKAGE_ADDED = 1; |
| 53 | static final int PACKAGE_ADDED_REPLACED = 2; |
| 54 | static final int PACKAGE_REMOVED = 3; |
| 55 | |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 56 | public WebViewUpdateService(Context context) { |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 57 | super(context); |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 58 | mImpl = new WebViewUpdateServiceImpl(context, new SystemImpl()); |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 59 | } |
| 60 | |
| 61 | @Override |
| 62 | public void onStart() { |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 63 | mWebViewUpdatedReceiver = new BroadcastReceiver() { |
| 64 | @Override |
| 65 | public void onReceive(Context context, Intent intent) { |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 66 | switch (intent.getAction()) { |
| 67 | case Intent.ACTION_PACKAGE_REMOVED: |
| 68 | // When a package is replaced we will receive two intents, one |
| 69 | // representing the removal of the old package and one representing the |
| 70 | // addition of the new package. |
| 71 | // In the case where we receive an intent to remove the old version of |
| 72 | // the package that is being replaced we early-out here so that we don't |
| 73 | // run the update-logic twice. |
| 74 | if (intent.getExtras().getBoolean(Intent.EXTRA_REPLACING)) return; |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 75 | mImpl.packageStateChanged(packageNameFromIntent(intent), |
| 76 | PACKAGE_REMOVED); |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 77 | break; |
| 78 | case Intent.ACTION_PACKAGE_CHANGED: |
| 79 | // Ensure that we only heed PACKAGE_CHANGED intents if they change an |
| 80 | // entire package, not just a component |
| 81 | if (entirePackageChanged(intent)) { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 82 | mImpl.packageStateChanged(packageNameFromIntent(intent), |
| 83 | PACKAGE_CHANGED); |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 84 | } |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 85 | break; |
| 86 | case Intent.ACTION_PACKAGE_ADDED: |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 87 | mImpl.packageStateChanged(packageNameFromIntent(intent), |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 88 | (intent.getExtras().getBoolean(Intent.EXTRA_REPLACING) |
| 89 | ? PACKAGE_ADDED_REPLACED : PACKAGE_ADDED)); |
| 90 | break; |
| 91 | case Intent.ACTION_USER_ADDED: |
| 92 | int userId = |
| 93 | intent.getIntExtra(Intent.EXTRA_USER_HANDLE, UserHandle.USER_NULL); |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 94 | mImpl.handleNewUser(userId); |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 95 | break; |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 96 | } |
| 97 | } |
| 98 | }; |
| 99 | IntentFilter filter = new IntentFilter(); |
Gustav Sennton | 3098cf2 | 2015-11-10 03:33:09 +0000 | [diff] [blame] | 100 | filter.addAction(Intent.ACTION_PACKAGE_ADDED); |
| 101 | filter.addAction(Intent.ACTION_PACKAGE_REMOVED); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 102 | filter.addAction(Intent.ACTION_PACKAGE_CHANGED); |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 103 | filter.addDataScheme("package"); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 104 | // Make sure we only receive intents for WebView packages from our config file. |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 105 | for (WebViewProviderInfo provider : mImpl.getWebViewPackages()) { |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 106 | filter.addDataSchemeSpecificPart(provider.packageName, PatternMatcher.PATTERN_LITERAL); |
| 107 | } |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 108 | getContext().registerReceiver(mWebViewUpdatedReceiver, filter); |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 109 | |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 110 | IntentFilter userAddedFilter = new IntentFilter(); |
| 111 | userAddedFilter.addAction(Intent.ACTION_USER_ADDED); |
| 112 | getContext().registerReceiver(mWebViewUpdatedReceiver, userAddedFilter); |
| 113 | |
Torne (Richard Coles) | fc19b0a | 2016-02-01 16:16:57 +0000 | [diff] [blame] | 114 | publishBinderService("webviewupdate", new BinderService(), true /*allowIsolated*/); |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 115 | } |
Ben Murdoch | dc00a84 | 2014-07-17 14:55:00 +0100 | [diff] [blame] | 116 | |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 117 | public void prepareWebViewInSystemServer() { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 118 | mImpl.prepareWebViewInSystemServer(); |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 119 | } |
| 120 | |
| 121 | private static String packageNameFromIntent(Intent intent) { |
| 122 | return intent.getDataString().substring("package:".length()); |
| 123 | } |
| 124 | |
Gustav Sennton | 065b7e6 | 2016-04-01 15:11:43 +0100 | [diff] [blame] | 125 | /** |
| 126 | * Returns whether the entire package from an ACTION_PACKAGE_CHANGED intent was changed (rather |
| 127 | * than just one of its components). |
| 128 | * @hide |
| 129 | */ |
| 130 | public static boolean entirePackageChanged(Intent intent) { |
| 131 | String[] componentList = |
| 132 | intent.getStringArrayExtra(Intent.EXTRA_CHANGED_COMPONENT_NAME_LIST); |
| 133 | return Arrays.asList(componentList).contains( |
| 134 | intent.getDataString().substring("package:".length())); |
Gustav Sennton | dbf5eb0 | 2016-03-30 14:53:03 +0100 | [diff] [blame] | 135 | } |
| 136 | |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 137 | private class BinderService extends IWebViewUpdateService.Stub { |
| 138 | |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 139 | @Override |
| 140 | public void onShellCommand(FileDescriptor in, FileDescriptor out, |
| 141 | FileDescriptor err, String[] args, ResultReceiver resultReceiver) { |
| 142 | (new WebViewUpdateServiceShellCommand(this)).exec( |
| 143 | this, in, out, err, args, resultReceiver); |
| 144 | } |
| 145 | |
| 146 | |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 147 | /** |
| 148 | * The shared relro process calls this to notify us that it's done trying to create a relro |
| 149 | * file. This method gets called even if the relro creation has failed or the process |
| 150 | * crashed. |
| 151 | */ |
| 152 | @Override // Binder call |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 153 | public void notifyRelroCreationCompleted() { |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 154 | // Verify that the caller is either the shared relro process (nominal case) or the |
| 155 | // system server (only in the case the relro process crashes and we get here via the |
| 156 | // crashHandler). |
| 157 | if (Binder.getCallingUid() != Process.SHARED_RELRO_UID && |
| 158 | Binder.getCallingUid() != Process.SYSTEM_UID) { |
| 159 | return; |
| 160 | } |
| 161 | |
Gustav Sennton | 275d13c | 2016-02-24 10:58:09 +0000 | [diff] [blame] | 162 | long callingId = Binder.clearCallingIdentity(); |
| 163 | try { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 164 | WebViewUpdateService.this.mImpl.notifyRelroCreationCompleted(); |
Gustav Sennton | 275d13c | 2016-02-24 10:58:09 +0000 | [diff] [blame] | 165 | } finally { |
| 166 | Binder.restoreCallingIdentity(callingId); |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 167 | } |
| 168 | } |
| 169 | |
| 170 | /** |
| 171 | * WebViewFactory calls this to block WebView loading until the relro file is created. |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 172 | * Returns the WebView provider for which we create relro files. |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 173 | */ |
| 174 | @Override // Binder call |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 175 | public WebViewProviderResponse waitForAndGetProvider() { |
Primiano Tucci | e76e81a | 2014-07-29 16:38:33 +0100 | [diff] [blame] | 176 | // The WebViewUpdateService depends on the prepareWebViewInSystemServer call, which |
| 177 | // happens later (during the PHASE_ACTIVITY_MANAGER_READY) in SystemServer.java. If |
| 178 | // another service there tries to bring up a WebView in the between, the wait below |
| 179 | // would deadlock without the check below. |
| 180 | if (Binder.getCallingPid() == Process.myPid()) { |
| 181 | throw new IllegalStateException("Cannot create a WebView from the SystemServer"); |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 182 | } |
| 183 | |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 184 | return WebViewUpdateService.this.mImpl.waitForAndGetProvider(); |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 185 | } |
| 186 | |
| 187 | /** |
| 188 | * This is called from DeveloperSettings when the user changes WebView provider. |
| 189 | */ |
| 190 | @Override // Binder call |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 191 | public String changeProviderAndSetting(String newProvider) { |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 192 | if (getContext().checkCallingPermission( |
| 193 | android.Manifest.permission.WRITE_SECURE_SETTINGS) |
| 194 | != PackageManager.PERMISSION_GRANTED) { |
| 195 | String msg = "Permission Denial: changeProviderAndSetting() from pid=" |
| 196 | + Binder.getCallingPid() |
| 197 | + ", uid=" + Binder.getCallingUid() |
| 198 | + " requires " + android.Manifest.permission.WRITE_SECURE_SETTINGS; |
| 199 | Slog.w(TAG, msg); |
| 200 | throw new SecurityException(msg); |
| 201 | } |
| 202 | |
Gustav Sennton | ab3b6b1 | 2016-03-16 17:38:42 +0000 | [diff] [blame] | 203 | long callingId = Binder.clearCallingIdentity(); |
| 204 | try { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 205 | return WebViewUpdateService.this.mImpl.changeProviderAndSetting( |
Gustav Sennton | 3a6e6b2 | 2016-04-05 14:09:09 +0100 | [diff] [blame] | 206 | newProvider); |
Gustav Sennton | ab3b6b1 | 2016-03-16 17:38:42 +0000 | [diff] [blame] | 207 | } finally { |
| 208 | Binder.restoreCallingIdentity(callingId); |
| 209 | } |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 210 | } |
| 211 | |
| 212 | @Override // Binder call |
| 213 | public WebViewProviderInfo[] getValidWebViewPackages() { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 214 | return WebViewUpdateService.this.mImpl.getValidWebViewPackages(); |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 215 | } |
| 216 | |
| 217 | @Override // Binder call |
Gustav Sennton | 8b17926 | 2016-03-14 11:31:14 +0000 | [diff] [blame] | 218 | public WebViewProviderInfo[] getAllWebViewPackages() { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 219 | return WebViewUpdateService.this.mImpl.getWebViewPackages(); |
Gustav Sennton | 8b17926 | 2016-03-14 11:31:14 +0000 | [diff] [blame] | 220 | } |
| 221 | |
| 222 | @Override // Binder call |
Gustav Sennton | 6258dcd | 2015-10-30 19:25:37 +0000 | [diff] [blame] | 223 | public String getCurrentWebViewPackageName() { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 224 | return WebViewUpdateService.this.mImpl.getCurrentWebViewPackageName(); |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 225 | } |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 226 | |
| 227 | @Override // Binder call |
| 228 | public boolean isFallbackPackage(String packageName) { |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 229 | return WebViewUpdateService.this.mImpl.isFallbackPackage(packageName); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 230 | } |
| 231 | |
| 232 | @Override // Binder call |
| 233 | public void enableFallbackLogic(boolean enable) { |
| 234 | if (getContext().checkCallingPermission( |
| 235 | android.Manifest.permission.WRITE_SECURE_SETTINGS) |
| 236 | != PackageManager.PERMISSION_GRANTED) { |
| 237 | String msg = "Permission Denial: enableFallbackLogic() from pid=" |
| 238 | + Binder.getCallingPid() |
| 239 | + ", uid=" + Binder.getCallingUid() |
| 240 | + " requires " + android.Manifest.permission.WRITE_SECURE_SETTINGS; |
| 241 | Slog.w(TAG, msg); |
| 242 | throw new SecurityException(msg); |
| 243 | } |
| 244 | |
Gustav Sennton | 79fea48 | 2016-04-07 14:22:56 +0100 | [diff] [blame^] | 245 | WebViewUpdateService.this.mImpl.enableFallbackLogic(enable); |
Gustav Sennton | c83e3fa | 2016-02-18 12:19:13 +0000 | [diff] [blame] | 246 | } |
Torne (Richard Coles) | 4dbeb35 | 2014-07-29 19:14:24 +0100 | [diff] [blame] | 247 | } |
Torne (Richard Coles) | 08cfaf6 | 2014-05-08 16:07:05 +0100 | [diff] [blame] | 248 | } |