Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2014 The Android Open Source Project |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | package com.android.internal.os; |
| 18 | |
Jeff Sharkey | ace874b | 2017-09-07 15:27:33 -0600 | [diff] [blame] | 19 | import android.os.IVold; |
Narayan Kamath | fbb32f6 | 2015-06-12 15:34:35 +0100 | [diff] [blame] | 20 | import android.os.Trace; |
Elliott Hughes | 860c591 | 2014-04-28 19:19:13 -0700 | [diff] [blame] | 21 | import android.system.ErrnoException; |
| 22 | import android.system.Os; |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 23 | |
Jeff Sharkey | ace874b | 2017-09-07 15:27:33 -0600 | [diff] [blame] | 24 | import dalvik.system.ZygoteHooks; |
Tobias Sargeant | b9679dc | 2016-01-19 16:34:54 +0000 | [diff] [blame] | 25 | |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 26 | /** @hide */ |
| 27 | public final class Zygote { |
| 28 | /* |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 29 | * Bit values for "runtimeFlags" argument. The definitions are duplicated |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 30 | * in the native code. |
| 31 | */ |
| 32 | |
| 33 | /** enable debugging over JDWP */ |
Nicolas Geoffray | 347b1df | 2016-12-20 14:05:05 +0000 | [diff] [blame] | 34 | public static final int DEBUG_ENABLE_JDWP = 1; |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 35 | /** enable JNI checks */ |
| 36 | public static final int DEBUG_ENABLE_CHECKJNI = 1 << 1; |
| 37 | /** enable Java programming language "assert" statements */ |
| 38 | public static final int DEBUG_ENABLE_ASSERT = 1 << 2; |
Mathieu Chartier | 7a49028 | 2015-03-17 09:51:36 -0700 | [diff] [blame] | 39 | /** disable the AOT compiler and JIT */ |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 40 | public static final int DEBUG_ENABLE_SAFEMODE = 1 << 3; |
| 41 | /** Enable logging of third-party JNI activity. */ |
| 42 | public static final int DEBUG_ENABLE_JNI_LOGGING = 1 << 4; |
David Srbecky | 065075e | 2015-05-28 17:16:09 +0100 | [diff] [blame] | 43 | /** Force generation of native debugging information. */ |
Nicolas Geoffray | 9abbf45 | 2015-11-05 11:29:42 +0000 | [diff] [blame] | 44 | public static final int DEBUG_GENERATE_DEBUG_INFO = 1 << 5; |
Tamas Berghammer | df6cb28 | 2016-01-29 12:07:00 +0000 | [diff] [blame] | 45 | /** Always use JIT-ed code. */ |
| 46 | public static final int DEBUG_ALWAYS_JIT = 1 << 6; |
Nicolas Geoffray | 347b1df | 2016-12-20 14:05:05 +0000 | [diff] [blame] | 47 | /** Make the code native debuggable by turning off some optimizations. */ |
Tamas Berghammer | df6cb28 | 2016-01-29 12:07:00 +0000 | [diff] [blame] | 48 | public static final int DEBUG_NATIVE_DEBUGGABLE = 1 << 7; |
Nicolas Geoffray | 347b1df | 2016-12-20 14:05:05 +0000 | [diff] [blame] | 49 | /** Make the code Java debuggable by turning off some optimizations. */ |
| 50 | public static final int DEBUG_JAVA_DEBUGGABLE = 1 << 8; |
Mathieu Chartier | 7a49028 | 2015-03-17 09:51:36 -0700 | [diff] [blame] | 51 | |
Nicolas Geoffray | 1f88ad6 | 2017-09-13 14:21:00 +0100 | [diff] [blame] | 52 | /** Turn off the verifier. */ |
| 53 | public static final int DISABLE_VERIFIER = 1 << 9; |
| 54 | /** Only use oat files located in /system. Otherwise use dex/jar/apk . */ |
| 55 | public static final int ONLY_USE_SYSTEM_OAT_FILES = 1 << 10; |
David Srbecky | 156ed92 | 2018-01-30 14:37:37 +0000 | [diff] [blame] | 56 | /** Force generation of native debugging information for backtraces. */ |
Mathew Inwood | e329953 | 2018-02-22 13:19:53 +0000 | [diff] [blame] | 57 | public static final int DEBUG_GENERATE_MINI_DEBUG_INFO = 1 << 11; |
| 58 | /** |
| 59 | * Hidden API access restrictions. This is a mask for bits representing the API enforcement |
| 60 | * policy, defined by {@code @ApplicationInfo.HiddenApiEnforcementPolicy}. |
| 61 | */ |
| 62 | public static final int API_ENFORCEMENT_POLICY_MASK = (1 << 12) | (1 << 13); |
| 63 | /** |
| 64 | * Bit shift for use with {@link #API_ENFORCEMENT_POLICY_MASK}. |
| 65 | * |
| 66 | * (flags & API_ENFORCEMENT_POLICY_MASK) >> API_ENFORCEMENT_POLICY_SHIFT gives |
| 67 | * @ApplicationInfo.ApiEnforcementPolicy values. |
| 68 | */ |
| 69 | public static final int API_ENFORCEMENT_POLICY_SHIFT = |
| 70 | Integer.numberOfTrailingZeros(API_ENFORCEMENT_POLICY_MASK); |
Nicolas Geoffray | 1f88ad6 | 2017-09-13 14:21:00 +0100 | [diff] [blame] | 71 | |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 72 | /** No external storage should be mounted. */ |
Jeff Sharkey | ace874b | 2017-09-07 15:27:33 -0600 | [diff] [blame] | 73 | public static final int MOUNT_EXTERNAL_NONE = IVold.REMOUNT_MODE_NONE; |
Jeff Sharkey | 9527b22 | 2015-06-24 15:24:48 -0700 | [diff] [blame] | 74 | /** Default external storage should be mounted. */ |
Jeff Sharkey | ace874b | 2017-09-07 15:27:33 -0600 | [diff] [blame] | 75 | public static final int MOUNT_EXTERNAL_DEFAULT = IVold.REMOUNT_MODE_DEFAULT; |
Jeff Sharkey | 9527b22 | 2015-06-24 15:24:48 -0700 | [diff] [blame] | 76 | /** Read-only external storage should be mounted. */ |
Jeff Sharkey | ace874b | 2017-09-07 15:27:33 -0600 | [diff] [blame] | 77 | public static final int MOUNT_EXTERNAL_READ = IVold.REMOUNT_MODE_READ; |
Jeff Sharkey | 9527b22 | 2015-06-24 15:24:48 -0700 | [diff] [blame] | 78 | /** Read-write external storage should be mounted. */ |
Jeff Sharkey | ace874b | 2017-09-07 15:27:33 -0600 | [diff] [blame] | 79 | public static final int MOUNT_EXTERNAL_WRITE = IVold.REMOUNT_MODE_WRITE; |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 80 | |
| 81 | private static final ZygoteHooks VM_HOOKS = new ZygoteHooks(); |
| 82 | |
Robert Sesek | d0a190df | 2018-02-12 18:46:01 -0500 | [diff] [blame] | 83 | /** |
| 84 | * An extraArg passed when a zygote process is forking a child-zygote, specifying a name |
| 85 | * in the abstract socket namespace. This socket name is what the new child zygote |
| 86 | * should listen for connections on. |
| 87 | */ |
| 88 | public static final String CHILD_ZYGOTE_SOCKET_NAME_ARG = "--zygote-socket="; |
| 89 | |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 90 | private Zygote() {} |
| 91 | |
Victor Hsieh | c8176ef | 2018-01-08 12:43:00 -0800 | [diff] [blame] | 92 | /** Called for some security initialization before any fork. */ |
| 93 | native static void nativeSecurityInit(); |
| 94 | |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 95 | /** |
| 96 | * Forks a new VM instance. The current VM must have been started |
| 97 | * with the -Xzygote flag. <b>NOTE: new instance keeps all |
| 98 | * root capabilities. The new process is expected to call capset()</b>. |
| 99 | * |
| 100 | * @param uid the UNIX uid that the new process should setuid() to after |
| 101 | * fork()ing and and before spawning any threads. |
| 102 | * @param gid the UNIX gid that the new process should setgid() to after |
| 103 | * fork()ing and and before spawning any threads. |
| 104 | * @param gids null-ok; a list of UNIX gids that the new process should |
| 105 | * setgroups() to after fork and before spawning any threads. |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 106 | * @param runtimeFlags bit flags that enable ART features. |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 107 | * @param rlimits null-ok an array of rlimit tuples, with the second |
| 108 | * dimension having a length of 3 and representing |
| 109 | * (resource, rlim_cur, rlim_max). These are set via the posix |
| 110 | * setrlimit(2) call. |
| 111 | * @param seInfo null-ok a string specifying SELinux information for |
| 112 | * the new process. |
| 113 | * @param niceName null-ok a string specifying the process name. |
| 114 | * @param fdsToClose an array of ints, holding one or more POSIX |
| 115 | * file descriptor numbers that are to be closed by the child |
| 116 | * (and replaced by /dev/null) after forking. An integer value |
| 117 | * of -1 in any entry in the array means "ignore this one". |
Andreas Gampe | 8dfa178 | 2017-01-05 12:45:58 -0800 | [diff] [blame] | 118 | * @param fdsToIgnore null-ok an array of ints, either null or holding |
| 119 | * one or more POSIX file descriptor numbers that are to be ignored |
| 120 | * in the file descriptor table check. |
Robert Sesek | d0a190df | 2018-02-12 18:46:01 -0500 | [diff] [blame] | 121 | * @param startChildZygote if true, the new child process will itself be a |
| 122 | * new zygote process. |
Andreas Gampe | aec67dc | 2014-09-02 21:23:06 -0700 | [diff] [blame] | 123 | * @param instructionSet null-ok the instruction set to use. |
jgu21 | 2eacd06 | 2014-09-10 06:55:07 -0400 | [diff] [blame] | 124 | * @param appDataDir null-ok the data directory of the app. |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 125 | * |
| 126 | * @return 0 if this is the child, pid of the child |
| 127 | * if this is the parent, or -1 on error. |
| 128 | */ |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 129 | public static int forkAndSpecialize(int uid, int gid, int[] gids, int runtimeFlags, |
Andreas Gampe | aec67dc | 2014-09-02 21:23:06 -0700 | [diff] [blame] | 130 | int[][] rlimits, int mountExternal, String seInfo, String niceName, int[] fdsToClose, |
Robert Sesek | d0a190df | 2018-02-12 18:46:01 -0500 | [diff] [blame] | 131 | int[] fdsToIgnore, boolean startChildZygote, String instructionSet, String appDataDir) { |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 132 | VM_HOOKS.preFork(); |
Hiroshi Yamauchi | 1e3db87 | 2017-03-02 13:39:07 -0800 | [diff] [blame] | 133 | // Resets nice priority for zygote process. |
| 134 | resetNicePriority(); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 135 | int pid = nativeForkAndSpecialize( |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 136 | uid, gid, gids, runtimeFlags, rlimits, mountExternal, seInfo, niceName, fdsToClose, |
Robert Sesek | d0a190df | 2018-02-12 18:46:01 -0500 | [diff] [blame] | 137 | fdsToIgnore, startChildZygote, instructionSet, appDataDir); |
Narayan Kamath | fbb32f6 | 2015-06-12 15:34:35 +0100 | [diff] [blame] | 138 | // Enable tracing as soon as possible for the child process. |
| 139 | if (pid == 0) { |
Andreas Gampe | 8f4eab2 | 2017-09-13 18:16:13 -0700 | [diff] [blame] | 140 | Trace.setTracingEnabled(true, runtimeFlags); |
Narayan Kamath | fbb32f6 | 2015-06-12 15:34:35 +0100 | [diff] [blame] | 141 | |
| 142 | // Note that this event ends at the end of handleChildProc, |
| 143 | Trace.traceBegin(Trace.TRACE_TAG_ACTIVITY_MANAGER, "PostFork"); |
| 144 | } |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 145 | VM_HOOKS.postForkCommon(); |
| 146 | return pid; |
| 147 | } |
| 148 | |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 149 | native private static int nativeForkAndSpecialize(int uid, int gid, int[] gids,int runtimeFlags, |
Andreas Gampe | aec67dc | 2014-09-02 21:23:06 -0700 | [diff] [blame] | 150 | int[][] rlimits, int mountExternal, String seInfo, String niceName, int[] fdsToClose, |
Robert Sesek | d0a190df | 2018-02-12 18:46:01 -0500 | [diff] [blame] | 151 | int[] fdsToIgnore, boolean startChildZygote, String instructionSet, String appDataDir); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 152 | |
| 153 | /** |
Christopher Ferris | 2980de4 | 2017-06-20 16:13:40 -0700 | [diff] [blame] | 154 | * Called to do any initialization before starting an application. |
| 155 | */ |
| 156 | native static void nativePreApplicationInit(); |
| 157 | |
| 158 | /** |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 159 | * Special method to start the system server process. In addition to the |
| 160 | * common actions performed in forkAndSpecialize, the pid of the child |
| 161 | * process is recorded such that the death of the child process will cause |
| 162 | * zygote to exit. |
| 163 | * |
| 164 | * @param uid the UNIX uid that the new process should setuid() to after |
| 165 | * fork()ing and and before spawning any threads. |
| 166 | * @param gid the UNIX gid that the new process should setgid() to after |
| 167 | * fork()ing and and before spawning any threads. |
| 168 | * @param gids null-ok; a list of UNIX gids that the new process should |
| 169 | * setgroups() to after fork and before spawning any threads. |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 170 | * @param runtimeFlags bit flags that enable ART features. |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 171 | * @param rlimits null-ok an array of rlimit tuples, with the second |
| 172 | * dimension having a length of 3 and representing |
| 173 | * (resource, rlim_cur, rlim_max). These are set via the posix |
| 174 | * setrlimit(2) call. |
| 175 | * @param permittedCapabilities argument for setcap() |
| 176 | * @param effectiveCapabilities argument for setcap() |
| 177 | * |
| 178 | * @return 0 if this is the child, pid of the child |
| 179 | * if this is the parent, or -1 on error. |
| 180 | */ |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 181 | public static int forkSystemServer(int uid, int gid, int[] gids, int runtimeFlags, |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 182 | int[][] rlimits, long permittedCapabilities, long effectiveCapabilities) { |
| 183 | VM_HOOKS.preFork(); |
Hiroshi Yamauchi | 1e3db87 | 2017-03-02 13:39:07 -0800 | [diff] [blame] | 184 | // Resets nice priority for zygote process. |
| 185 | resetNicePriority(); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 186 | int pid = nativeForkSystemServer( |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 187 | uid, gid, gids, runtimeFlags, rlimits, permittedCapabilities, effectiveCapabilities); |
Narayan Kamath | fbb32f6 | 2015-06-12 15:34:35 +0100 | [diff] [blame] | 188 | // Enable tracing as soon as we enter the system_server. |
| 189 | if (pid == 0) { |
Andreas Gampe | 8f4eab2 | 2017-09-13 18:16:13 -0700 | [diff] [blame] | 190 | Trace.setTracingEnabled(true, runtimeFlags); |
Narayan Kamath | fbb32f6 | 2015-06-12 15:34:35 +0100 | [diff] [blame] | 191 | } |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 192 | VM_HOOKS.postForkCommon(); |
| 193 | return pid; |
| 194 | } |
| 195 | |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 196 | native private static int nativeForkSystemServer(int uid, int gid, int[] gids, int runtimeFlags, |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 197 | int[][] rlimits, long permittedCapabilities, long effectiveCapabilities); |
| 198 | |
doheon1.lee | 885b742 | 2016-01-20 13:07:27 +0900 | [diff] [blame] | 199 | /** |
Robert Sesek | 54e387d | 2016-12-02 17:27:50 -0500 | [diff] [blame] | 200 | * Lets children of the zygote inherit open file descriptors to this path. |
| 201 | */ |
| 202 | native protected static void nativeAllowFileAcrossFork(String path); |
| 203 | |
| 204 | /** |
doheon1.lee | 885b742 | 2016-01-20 13:07:27 +0900 | [diff] [blame] | 205 | * Zygote unmount storage space on initializing. |
| 206 | * This method is called once. |
| 207 | */ |
| 208 | native protected static void nativeUnmountStorageOnInit(); |
| 209 | |
Nicolas Geoffray | 81edac4 | 2017-09-07 14:13:29 +0100 | [diff] [blame] | 210 | private static void callPostForkChildHooks(int runtimeFlags, boolean isSystemServer, |
Robert Sesek | d0a190df | 2018-02-12 18:46:01 -0500 | [diff] [blame] | 211 | boolean isZygote, String instructionSet) { |
| 212 | VM_HOOKS.postForkChild(runtimeFlags, isSystemServer, isZygote, instructionSet); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 213 | } |
| 214 | |
Narayan Kamath | b49996d | 2017-02-06 20:24:08 +0000 | [diff] [blame] | 215 | /** |
Hiroshi Yamauchi | 1e3db87 | 2017-03-02 13:39:07 -0800 | [diff] [blame] | 216 | * Resets the calling thread priority to the default value (Thread.NORM_PRIORITY |
| 217 | * or nice value 0). This updates both the priority value in java.lang.Thread and |
| 218 | * the nice value (setpriority). |
Narayan Kamath | b49996d | 2017-02-06 20:24:08 +0000 | [diff] [blame] | 219 | */ |
Hiroshi Yamauchi | 1e3db87 | 2017-03-02 13:39:07 -0800 | [diff] [blame] | 220 | static void resetNicePriority() { |
| 221 | Thread.currentThread().setPriority(Thread.NORM_PRIORITY); |
| 222 | } |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 223 | |
| 224 | /** |
| 225 | * Executes "/system/bin/sh -c <command>" using the exec() system call. |
| 226 | * This method throws a runtime exception if exec() failed, otherwise, this |
| 227 | * method never returns. |
| 228 | * |
| 229 | * @param command The shell command to execute. |
| 230 | */ |
| 231 | public static void execShell(String command) { |
| 232 | String[] args = { "/system/bin/sh", "-c", command }; |
| 233 | try { |
Elliott Hughes | 860c591 | 2014-04-28 19:19:13 -0700 | [diff] [blame] | 234 | Os.execv(args[0], args); |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 235 | } catch (ErrnoException e) { |
| 236 | throw new RuntimeException(e); |
| 237 | } |
| 238 | } |
| 239 | |
| 240 | /** |
| 241 | * Appends quotes shell arguments to the specified string builder. |
| 242 | * The arguments are quoted using single-quotes, escaped if necessary, |
| 243 | * prefixed with a space, and appended to the command. |
| 244 | * |
| 245 | * @param command A string builder for the shell command being constructed. |
| 246 | * @param args An array of argument strings to be quoted and appended to the command. |
| 247 | * @see #execShell(String) |
| 248 | */ |
| 249 | public static void appendQuotedShellArgs(StringBuilder command, String[] args) { |
| 250 | for (String arg : args) { |
| 251 | command.append(" '").append(arg.replace("'", "'\\''")).append("'"); |
| 252 | } |
| 253 | } |
Narayan Kamath | 973b466 | 2014-03-31 13:41:26 +0100 | [diff] [blame] | 254 | } |