Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2014 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | package com.android.internal.os; |
| 18 | |
| 19 | |
| 20 | import dalvik.system.ZygoteHooks; |
Elliott Hughes | 860c591 | 2014-04-28 19:19:13 -0700 | [diff] [blame] | 21 | import android.system.ErrnoException; |
| 22 | import android.system.Os; |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 23 | |
| 24 | /** @hide */ |
| 25 | public final class Zygote { |
| 26 | /* |
| 27 | * Bit values for "debugFlags" argument. The definitions are duplicated |
| 28 | * in the native code. |
| 29 | */ |
| 30 | |
| 31 | /** enable debugging over JDWP */ |
| 32 | public static final int DEBUG_ENABLE_DEBUGGER = 1; |
| 33 | /** enable JNI checks */ |
| 34 | public static final int DEBUG_ENABLE_CHECKJNI = 1 << 1; |
| 35 | /** enable Java programming language "assert" statements */ |
| 36 | public static final int DEBUG_ENABLE_ASSERT = 1 << 2; |
| 37 | /** disable the JIT compiler */ |
| 38 | public static final int DEBUG_ENABLE_SAFEMODE = 1 << 3; |
| 39 | /** Enable logging of third-party JNI activity. */ |
| 40 | public static final int DEBUG_ENABLE_JNI_LOGGING = 1 << 4; |
| 41 | |
| 42 | /** No external storage should be mounted. */ |
| 43 | public static final int MOUNT_EXTERNAL_NONE = 0; |
| 44 | /** Single-user external storage should be mounted. */ |
| 45 | public static final int MOUNT_EXTERNAL_SINGLEUSER = 1; |
| 46 | /** Multi-user external storage should be mounted. */ |
| 47 | public static final int MOUNT_EXTERNAL_MULTIUSER = 2; |
| 48 | /** All multi-user external storage should be mounted. */ |
| 49 | public static final int MOUNT_EXTERNAL_MULTIUSER_ALL = 3; |
| 50 | |
| 51 | private static final ZygoteHooks VM_HOOKS = new ZygoteHooks(); |
| 52 | |
| 53 | private Zygote() {} |
| 54 | |
| 55 | /** |
| 56 | * Forks a new VM instance. The current VM must have been started |
| 57 | * with the -Xzygote flag. <b>NOTE: new instance keeps all |
| 58 | * root capabilities. The new process is expected to call capset()</b>. |
| 59 | * |
| 60 | * @param uid the UNIX uid that the new process should setuid() to after |
| 61 | * fork()ing and and before spawning any threads. |
| 62 | * @param gid the UNIX gid that the new process should setgid() to after |
| 63 | * fork()ing and and before spawning any threads. |
| 64 | * @param gids null-ok; a list of UNIX gids that the new process should |
| 65 | * setgroups() to after fork and before spawning any threads. |
| 66 | * @param debugFlags bit flags that enable debugging features. |
| 67 | * @param rlimits null-ok an array of rlimit tuples, with the second |
| 68 | * dimension having a length of 3 and representing |
| 69 | * (resource, rlim_cur, rlim_max). These are set via the posix |
| 70 | * setrlimit(2) call. |
| 71 | * @param seInfo null-ok a string specifying SELinux information for |
| 72 | * the new process. |
| 73 | * @param niceName null-ok a string specifying the process name. |
| 74 | * @param fdsToClose an array of ints, holding one or more POSIX |
| 75 | * file descriptor numbers that are to be closed by the child |
| 76 | * (and replaced by /dev/null) after forking. An integer value |
| 77 | * of -1 in any entry in the array means "ignore this one". |
Andreas Gampe | aec67dc | 2014-09-02 21:23:06 -0700 | [diff] [blame] | 78 | * @param instructionSet null-ok the instruction set to use. |
jgu21 | 2eacd06 | 2014-09-10 06:55:07 -0400 | [diff] [blame] | 79 | * @param appDataDir null-ok the data directory of the app. |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 80 | * |
| 81 | * @return 0 if this is the child, pid of the child |
| 82 | * if this is the parent, or -1 on error. |
| 83 | */ |
| 84 | public static int forkAndSpecialize(int uid, int gid, int[] gids, int debugFlags, |
Andreas Gampe | aec67dc | 2014-09-02 21:23:06 -0700 | [diff] [blame] | 85 | int[][] rlimits, int mountExternal, String seInfo, String niceName, int[] fdsToClose, |
jgu21 | 2eacd06 | 2014-09-10 06:55:07 -0400 | [diff] [blame] | 86 | String instructionSet, String appDataDir) { |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 87 | VM_HOOKS.preFork(); |
| 88 | int pid = nativeForkAndSpecialize( |
Andreas Gampe | aec67dc | 2014-09-02 21:23:06 -0700 | [diff] [blame] | 89 | uid, gid, gids, debugFlags, rlimits, mountExternal, seInfo, niceName, fdsToClose, |
jgu21 | 2eacd06 | 2014-09-10 06:55:07 -0400 | [diff] [blame] | 90 | instructionSet, appDataDir); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 91 | VM_HOOKS.postForkCommon(); |
| 92 | return pid; |
| 93 | } |
| 94 | |
| 95 | native private static int nativeForkAndSpecialize(int uid, int gid, int[] gids,int debugFlags, |
Andreas Gampe | aec67dc | 2014-09-02 21:23:06 -0700 | [diff] [blame] | 96 | int[][] rlimits, int mountExternal, String seInfo, String niceName, int[] fdsToClose, |
jgu21 | 2eacd06 | 2014-09-10 06:55:07 -0400 | [diff] [blame] | 97 | String instructionSet, String appDataDir); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 98 | |
| 99 | /** |
| 100 | * Special method to start the system server process. In addition to the |
| 101 | * common actions performed in forkAndSpecialize, the pid of the child |
| 102 | * process is recorded such that the death of the child process will cause |
| 103 | * zygote to exit. |
| 104 | * |
| 105 | * @param uid the UNIX uid that the new process should setuid() to after |
| 106 | * fork()ing and and before spawning any threads. |
| 107 | * @param gid the UNIX gid that the new process should setgid() to after |
| 108 | * fork()ing and and before spawning any threads. |
| 109 | * @param gids null-ok; a list of UNIX gids that the new process should |
| 110 | * setgroups() to after fork and before spawning any threads. |
| 111 | * @param debugFlags bit flags that enable debugging features. |
| 112 | * @param rlimits null-ok an array of rlimit tuples, with the second |
| 113 | * dimension having a length of 3 and representing |
| 114 | * (resource, rlim_cur, rlim_max). These are set via the posix |
| 115 | * setrlimit(2) call. |
| 116 | * @param permittedCapabilities argument for setcap() |
| 117 | * @param effectiveCapabilities argument for setcap() |
| 118 | * |
| 119 | * @return 0 if this is the child, pid of the child |
| 120 | * if this is the parent, or -1 on error. |
| 121 | */ |
| 122 | public static int forkSystemServer(int uid, int gid, int[] gids, int debugFlags, |
| 123 | int[][] rlimits, long permittedCapabilities, long effectiveCapabilities) { |
| 124 | VM_HOOKS.preFork(); |
| 125 | int pid = nativeForkSystemServer( |
| 126 | uid, gid, gids, debugFlags, rlimits, permittedCapabilities, effectiveCapabilities); |
| 127 | VM_HOOKS.postForkCommon(); |
| 128 | return pid; |
| 129 | } |
| 130 | |
| 131 | native private static int nativeForkSystemServer(int uid, int gid, int[] gids, int debugFlags, |
| 132 | int[][] rlimits, long permittedCapabilities, long effectiveCapabilities); |
| 133 | |
Andreas Gampe | aec67dc | 2014-09-02 21:23:06 -0700 | [diff] [blame] | 134 | private static void callPostForkChildHooks(int debugFlags, String instructionSet) { |
| 135 | VM_HOOKS.postForkChild(debugFlags, instructionSet); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 136 | } |
| 137 | |
| 138 | |
| 139 | /** |
| 140 | * Executes "/system/bin/sh -c <command>" using the exec() system call. |
| 141 | * This method throws a runtime exception if exec() failed, otherwise, this |
| 142 | * method never returns. |
| 143 | * |
| 144 | * @param command The shell command to execute. |
| 145 | */ |
| 146 | public static void execShell(String command) { |
| 147 | String[] args = { "/system/bin/sh", "-c", command }; |
| 148 | try { |
Elliott Hughes | 860c591 | 2014-04-28 19:19:13 -0700 | [diff] [blame] | 149 | Os.execv(args[0], args); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 150 | } catch (ErrnoException e) { |
| 151 | throw new RuntimeException(e); |
| 152 | } |
| 153 | } |
| 154 | |
| 155 | /** |
| 156 | * Appends quotes shell arguments to the specified string builder. |
| 157 | * The arguments are quoted using single-quotes, escaped if necessary, |
| 158 | * prefixed with a space, and appended to the command. |
| 159 | * |
| 160 | * @param command A string builder for the shell command being constructed. |
| 161 | * @param args An array of argument strings to be quoted and appended to the command. |
| 162 | * @see #execShell(String) |
| 163 | */ |
| 164 | public static void appendQuotedShellArgs(StringBuilder command, String[] args) { |
| 165 | for (String arg : args) { |
| 166 | command.append(" '").append(arg.replace("'", "'\\''")).append("'"); |
| 167 | } |
| 168 | } |
| 169 | } |