blob: c6366777285cbe8932e6467eea3e3fe6efed5431 [file] [log] [blame]
Tom Cherrybac32992015-07-31 12:45:25 -07001/*
2 * Copyright (C) 2015 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17#include "service.h"
18
19#include <fcntl.h>
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -070020#include <sched.h>
21#include <sys/mount.h>
22#include <sys/prctl.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070023#include <sys/resource.h>
Tom Cherrybac32992015-07-31 12:45:25 -070024#include <sys/stat.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070025#include <sys/time.h>
Tom Cherrybac32992015-07-31 12:45:25 -070026#include <sys/types.h>
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -080027#include <sys/wait.h>
Tom Cherrybac32992015-07-31 12:45:25 -070028#include <termios.h>
Dan Albertaf9ba4d2015-08-11 16:37:04 -070029#include <unistd.h>
Tom Cherrybac32992015-07-31 12:45:25 -070030
31#include <selinux/selinux.h>
32
Elliott Hughes4f713192015-12-04 22:00:26 -080033#include <android-base/file.h>
34#include <android-base/stringprintf.h>
Elliott Hughesf86b5a62016-06-24 15:12:21 -070035#include <android-base/strings.h>
Tom Cherrybac32992015-07-31 12:45:25 -070036#include <cutils/android_reboot.h>
37#include <cutils/sockets.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070038#include <system/thread_defs.h>
Tom Cherrybac32992015-07-31 12:45:25 -070039
Collin Mullinerf7e79b92016-06-01 21:03:55 +000040#include <processgroup/processgroup.h>
41
Tom Cherrybac32992015-07-31 12:45:25 -070042#include "action.h"
43#include "init.h"
44#include "init_parser.h"
Tom Cherrybac32992015-07-31 12:45:25 -070045#include "log.h"
46#include "property_service.h"
47#include "util.h"
48
Tom Cherryb7349902015-08-26 11:43:36 -070049using android::base::StringPrintf;
50using android::base::WriteStringToFile;
51
Tom Cherrybac32992015-07-31 12:45:25 -070052#define CRITICAL_CRASH_THRESHOLD 4 // if we crash >4 times ...
53#define CRITICAL_CRASH_WINDOW (4*60) // ... in 4 minutes, goto recovery
54
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -040055static std::string ComputeContextFromExecutable(std::string& service_name,
56 const std::string& service_path) {
57 std::string computed_context;
58
59 char* raw_con = nullptr;
60 char* raw_filecon = nullptr;
61
62 if (getcon(&raw_con) == -1) {
63 LOG(ERROR) << "could not get context while starting '" << service_name << "'";
64 return "";
65 }
66 std::unique_ptr<char> mycon(raw_con);
67
68 if (getfilecon(service_path.c_str(), &raw_filecon) == -1) {
69 LOG(ERROR) << "could not get file context while starting '" << service_name << "'";
70 return "";
71 }
72 std::unique_ptr<char> filecon(raw_filecon);
73
74 char* new_con = nullptr;
75 int rc = security_compute_create(mycon.get(), filecon.get(),
76 string_to_security_class("process"), &new_con);
77 if (rc == 0) {
78 computed_context = new_con;
79 free(new_con);
80 }
81 if (rc == 0 && computed_context == mycon.get()) {
82 LOG(ERROR) << "service " << service_name << " does not have a SELinux domain defined";
83 return "";
84 }
85 if (rc < 0) {
86 LOG(ERROR) << "could not get context while starting '" << service_name << "'";
87 return "";
88 }
89 return computed_context;
90}
91
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -070092static void SetUpPidNamespace(const std::string& service_name) {
93 constexpr unsigned int kSafeFlags = MS_NODEV | MS_NOEXEC | MS_NOSUID;
94
95 // It's OK to LOG(FATAL) in this function since it's running in the first
96 // child process.
97 if (mount("", "/proc", "proc", kSafeFlags | MS_REMOUNT, "") == -1) {
98 PLOG(FATAL) << "couldn't remount(/proc)";
99 }
100
101 if (prctl(PR_SET_NAME, service_name.c_str()) == -1) {
102 PLOG(FATAL) << "couldn't set name";
103 }
104
105 pid_t child_pid = fork();
106 if (child_pid == -1) {
107 PLOG(FATAL) << "couldn't fork init inside the PID namespace";
108 }
109
110 if (child_pid > 0) {
111 // So that we exit with the right status.
112 static int init_exitstatus = 0;
113 signal(SIGTERM, [](int) { _exit(init_exitstatus); });
114
115 pid_t waited_pid;
116 int status;
117 while ((waited_pid = wait(&status)) > 0) {
118 // This loop will end when there are no processes left inside the
119 // PID namespace or when the init process inside the PID namespace
120 // gets a signal.
121 if (waited_pid == child_pid) {
122 init_exitstatus = status;
123 }
124 }
125 if (!WIFEXITED(init_exitstatus)) {
126 _exit(EXIT_FAILURE);
127 }
128 _exit(WEXITSTATUS(init_exitstatus));
129 }
130}
131
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400132static void ExpandArgs(const std::vector<std::string>& args, std::vector<char*>* strs) {
133 std::vector<std::string> expanded_args;
134 expanded_args.resize(args.size());
135 strs->push_back(const_cast<char*>(args[0].c_str()));
136 for (std::size_t i = 1; i < args.size(); ++i) {
137 if (!expand_props(args[i], &expanded_args[i])) {
138 LOG(FATAL) << args[0] << ": cannot expand '" << args[i] << "'";
139 }
140 strs->push_back(const_cast<char*>(expanded_args[i].c_str()));
141 }
142 strs->push_back(nullptr);
143}
144
Tom Cherrybac32992015-07-31 12:45:25 -0700145SocketInfo::SocketInfo() : uid(0), gid(0), perm(0) {
146}
147
148SocketInfo::SocketInfo(const std::string& name, const std::string& type, uid_t uid,
149 gid_t gid, int perm, const std::string& socketcon)
150 : name(name), type(type), uid(uid), gid(gid), perm(perm), socketcon(socketcon) {
151}
152
153ServiceEnvironmentInfo::ServiceEnvironmentInfo() {
154}
155
156ServiceEnvironmentInfo::ServiceEnvironmentInfo(const std::string& name,
157 const std::string& value)
158 : name(name), value(value) {
159}
160
161Service::Service(const std::string& name, const std::string& classname,
162 const std::vector<std::string>& args)
163 : name_(name), classname_(classname), flags_(0), pid_(0), time_started_(0),
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700164 time_crashed_(0), nr_crashed_(0), uid_(0), gid_(0), namespace_flags_(0),
165 seclabel_(""), ioprio_class_(IoSchedClass_NONE), ioprio_pri_(0),
166 priority_(0), args_(args) {
Tom Cherrybac32992015-07-31 12:45:25 -0700167 onrestart_.InitSingleTrigger("onrestart");
168}
169
170Service::Service(const std::string& name, const std::string& classname,
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700171 unsigned flags, uid_t uid, gid_t gid,
172 const std::vector<gid_t>& supp_gids, unsigned namespace_flags,
173 const std::string& seclabel,
174 const std::vector<std::string>& args)
175 : name_(name), classname_(classname), flags_(flags), pid_(0),
176 time_started_(0), time_crashed_(0), nr_crashed_(0), uid_(uid), gid_(gid),
177 supp_gids_(supp_gids), namespace_flags_(namespace_flags),
178 seclabel_(seclabel), ioprio_class_(IoSchedClass_NONE), ioprio_pri_(0),
179 priority_(0), args_(args) {
Tom Cherrybac32992015-07-31 12:45:25 -0700180 onrestart_.InitSingleTrigger("onrestart");
181}
182
183void Service::NotifyStateChange(const std::string& new_state) const {
Tom Cherrybac32992015-07-31 12:45:25 -0700184 if ((flags_ & SVC_EXEC) != 0) {
185 // 'exec' commands don't have properties tracking their state.
186 return;
187 }
188
Tom Cherryb7349902015-08-26 11:43:36 -0700189 std::string prop_name = StringPrintf("init.svc.%s", name_.c_str());
Tom Cherrybac32992015-07-31 12:45:25 -0700190 if (prop_name.length() >= PROP_NAME_MAX) {
191 // If the property name would be too long, we can't set it.
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700192 LOG(ERROR) << "Property name \"init.svc." << name_ << "\" too long; not setting to " << new_state;
Tom Cherrybac32992015-07-31 12:45:25 -0700193 return;
194 }
195
196 property_set(prop_name.c_str(), new_state.c_str());
197}
198
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700199void Service::KillProcessGroup(int signal) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700200 LOG(VERBOSE) << "Sending signal " << signal
201 << " to service '" << name_
202 << "' (pid " << pid_ << ") process group...\n",
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700203 kill(pid_, signal);
204 killProcessGroup(uid_, pid_, signal);
205}
206
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400207void Service::CreateSockets(const std::string& context) {
208 for (const auto& si : sockets_) {
209 int socket_type = ((si.type == "stream" ? SOCK_STREAM :
210 (si.type == "dgram" ? SOCK_DGRAM :
211 SOCK_SEQPACKET)));
212 const char* socketcon = !si.socketcon.empty() ? si.socketcon.c_str() : context.c_str();
213
214 int s = create_socket(si.name.c_str(), socket_type, si.perm, si.uid, si.gid, socketcon);
215 if (s >= 0) {
216 PublishSocket(si.name, s);
217 }
218 }
219}
220
221void Service::SetProcessAttributes() {
222 setpgid(0, getpid());
223
224 if (gid_) {
225 if (setgid(gid_) != 0) {
226 PLOG(FATAL) << "setgid failed";
227 }
228 }
229 if (!supp_gids_.empty()) {
230 if (setgroups(supp_gids_.size(), &supp_gids_[0]) != 0) {
231 PLOG(FATAL) << "setgroups failed";
232 }
233 }
234 if (uid_) {
235 if (setuid(uid_) != 0) {
236 PLOG(FATAL) << "setuid failed";
237 }
238 }
239 if (!seclabel_.empty()) {
240 if (setexeccon(seclabel_.c_str()) < 0) {
241 PLOG(FATAL) << "cannot setexeccon('" << seclabel_ << "')";
242 }
243 }
244 if (priority_ != 0) {
245 if (setpriority(PRIO_PROCESS, 0, priority_) != 0) {
246 PLOG(FATAL) << "setpriority failed";
247 }
248 }
249}
250
Tom Cherrybac32992015-07-31 12:45:25 -0700251bool Service::Reap() {
252 if (!(flags_ & SVC_ONESHOT) || (flags_ & SVC_RESTART)) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700253 KillProcessGroup(SIGKILL);
Tom Cherrybac32992015-07-31 12:45:25 -0700254 }
255
256 // Remove any sockets we may have created.
257 for (const auto& si : sockets_) {
Tom Cherryb7349902015-08-26 11:43:36 -0700258 std::string tmp = StringPrintf(ANDROID_SOCKET_DIR "/%s", si.name.c_str());
Tom Cherrybac32992015-07-31 12:45:25 -0700259 unlink(tmp.c_str());
260 }
261
262 if (flags_ & SVC_EXEC) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700263 LOG(INFO) << "SVC_EXEC pid " << pid_ << " finished...";
Tom Cherrybac32992015-07-31 12:45:25 -0700264 return true;
265 }
266
267 pid_ = 0;
268 flags_ &= (~SVC_RUNNING);
269
270 // Oneshot processes go into the disabled state on exit,
271 // except when manually restarted.
272 if ((flags_ & SVC_ONESHOT) && !(flags_ & SVC_RESTART)) {
273 flags_ |= SVC_DISABLED;
274 }
275
276 // Disabled and reset processes do not get restarted automatically.
277 if (flags_ & (SVC_DISABLED | SVC_RESET)) {
278 NotifyStateChange("stopped");
279 return false;
280 }
281
282 time_t now = gettime();
283 if ((flags_ & SVC_CRITICAL) && !(flags_ & SVC_RESTART)) {
284 if (time_crashed_ + CRITICAL_CRASH_WINDOW >= now) {
285 if (++nr_crashed_ > CRITICAL_CRASH_THRESHOLD) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700286 LOG(ERROR) << "critical process '" << name_ << "' exited "
287 << CRITICAL_CRASH_THRESHOLD << " times in "
288 << (CRITICAL_CRASH_WINDOW / 60) << " minutes; "
289 << "rebooting into recovery mode";
Tom Cherrybac32992015-07-31 12:45:25 -0700290 android_reboot(ANDROID_RB_RESTART2, 0, "recovery");
291 return false;
292 }
293 } else {
294 time_crashed_ = now;
295 nr_crashed_ = 1;
296 }
297 }
298
299 flags_ &= (~SVC_RESTART);
300 flags_ |= SVC_RESTARTING;
301
302 // Execute all onrestart commands for this service.
303 onrestart_.ExecuteAllCommands();
304
305 NotifyStateChange("restarting");
306 return false;
307}
308
309void Service::DumpState() const {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700310 LOG(INFO) << "service " << name_;
311 LOG(INFO) << " class '" << classname_ << "'";
312 LOG(INFO) << " exec "<< android::base::Join(args_, " ");
Tom Cherrybac32992015-07-31 12:45:25 -0700313 for (const auto& si : sockets_) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700314 LOG(INFO) << " socket " << si.name << " " << si.type << " " << std::oct << si.perm;
Tom Cherrybac32992015-07-31 12:45:25 -0700315 }
316}
317
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400318bool Service::ParseClass(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700319 classname_ = args[1];
320 return true;
321}
Tom Cherrybac32992015-07-31 12:45:25 -0700322
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400323bool Service::ParseConsole(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700324 flags_ |= SVC_CONSOLE;
Viorel Suman70daa672016-03-21 10:08:07 +0200325 console_ = args.size() > 1 ? "/dev/" + args[1] : "";
Tom Cherryb7349902015-08-26 11:43:36 -0700326 return true;
327}
Tom Cherrybac32992015-07-31 12:45:25 -0700328
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400329bool Service::ParseCritical(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700330 flags_ |= SVC_CRITICAL;
331 return true;
332}
Tom Cherrybac32992015-07-31 12:45:25 -0700333
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400334bool Service::ParseDisabled(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700335 flags_ |= SVC_DISABLED;
336 flags_ |= SVC_RC_DISABLED;
337 return true;
338}
Tom Cherrybac32992015-07-31 12:45:25 -0700339
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400340bool Service::ParseGroup(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700341 gid_ = decode_uid(args[1].c_str());
342 for (std::size_t n = 2; n < args.size(); n++) {
343 supp_gids_.emplace_back(decode_uid(args[n].c_str()));
Tom Cherrybac32992015-07-31 12:45:25 -0700344 }
345 return true;
346}
347
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400348bool Service::ParsePriority(const std::vector<std::string>& args, std::string* err) {
Vitalii Tomkiv081705c2016-05-18 17:36:30 -0700349 priority_ = std::stoi(args[1]);
350
351 if (priority_ < ANDROID_PRIORITY_HIGHEST || priority_ > ANDROID_PRIORITY_LOWEST) {
352 priority_ = 0;
353 *err = StringPrintf("process priority value must be range %d - %d",
354 ANDROID_PRIORITY_HIGHEST, ANDROID_PRIORITY_LOWEST);
355 return false;
356 }
357
358 return true;
359}
360
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400361bool Service::ParseIoprio(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700362 ioprio_pri_ = std::stoul(args[2], 0, 8);
363
364 if (ioprio_pri_ < 0 || ioprio_pri_ > 7) {
365 *err = "priority value must be range 0 - 7";
366 return false;
367 }
368
369 if (args[1] == "rt") {
370 ioprio_class_ = IoSchedClass_RT;
371 } else if (args[1] == "be") {
372 ioprio_class_ = IoSchedClass_BE;
373 } else if (args[1] == "idle") {
374 ioprio_class_ = IoSchedClass_IDLE;
375 } else {
376 *err = "ioprio option usage: ioprio <rt|be|idle> <0-7>";
377 return false;
378 }
379
380 return true;
381}
382
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400383bool Service::ParseKeycodes(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700384 for (std::size_t i = 1; i < args.size(); i++) {
385 keycodes_.emplace_back(std::stoi(args[i]));
386 }
387 return true;
388}
389
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400390bool Service::ParseOneshot(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700391 flags_ |= SVC_ONESHOT;
392 return true;
393}
394
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400395bool Service::ParseOnrestart(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700396 std::vector<std::string> str_args(args.begin() + 1, args.end());
397 onrestart_.AddCommand(str_args, "", 0, err);
398 return true;
399}
400
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400401bool Service::ParseNamespace(const std::vector<std::string>& args, std::string* err) {
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700402 for (size_t i = 1; i < args.size(); i++) {
403 if (args[i] == "pid") {
404 namespace_flags_ |= CLONE_NEWPID;
405 // PID namespaces require mount namespaces.
406 namespace_flags_ |= CLONE_NEWNS;
407 } else if (args[i] == "mnt") {
408 namespace_flags_ |= CLONE_NEWNS;
409 } else {
410 *err = "namespace must be 'pid' or 'mnt'";
411 return false;
412 }
413 }
414 return true;
415}
416
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400417bool Service::ParseSeclabel(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700418 seclabel_ = args[1];
419 return true;
420}
421
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400422bool Service::ParseSetenv(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700423 envvars_.emplace_back(args[1], args[2]);
424 return true;
425}
426
427/* name type perm [ uid gid context ] */
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400428bool Service::ParseSocket(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700429 if (args[2] != "dgram" && args[2] != "stream" && args[2] != "seqpacket") {
430 *err = "socket type must be 'dgram', 'stream' or 'seqpacket'";
431 return false;
432 }
433
434 int perm = std::stoul(args[3], 0, 8);
435 uid_t uid = args.size() > 4 ? decode_uid(args[4].c_str()) : 0;
436 gid_t gid = args.size() > 5 ? decode_uid(args[5].c_str()) : 0;
437 std::string socketcon = args.size() > 6 ? args[6] : "";
438
439 sockets_.emplace_back(args[1], args[2], uid, gid, perm, socketcon);
440 return true;
441}
442
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400443bool Service::ParseUser(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700444 uid_ = decode_uid(args[1].c_str());
445 return true;
446}
447
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400448bool Service::ParseWritepid(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700449 writepid_files_.assign(args.begin() + 1, args.end());
450 return true;
451}
452
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400453class Service::OptionParserMap : public KeywordMap<OptionParser> {
Tom Cherryb7349902015-08-26 11:43:36 -0700454public:
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400455 OptionParserMap() {
Tom Cherryb7349902015-08-26 11:43:36 -0700456 }
457private:
458 Map& map() const override;
459};
460
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400461Service::OptionParserMap::Map& Service::OptionParserMap::map() const {
Tom Cherryb7349902015-08-26 11:43:36 -0700462 constexpr std::size_t kMax = std::numeric_limits<std::size_t>::max();
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400463 static const Map option_parsers = {
464 {"class", {1, 1, &Service::ParseClass}},
465 {"console", {0, 1, &Service::ParseConsole}},
466 {"critical", {0, 0, &Service::ParseCritical}},
467 {"disabled", {0, 0, &Service::ParseDisabled}},
468 {"group", {1, NR_SVC_SUPP_GIDS + 1, &Service::ParseGroup}},
469 {"ioprio", {2, 2, &Service::ParseIoprio}},
470 {"priority", {1, 1, &Service::ParsePriority}},
471 {"keycodes", {1, kMax, &Service::ParseKeycodes}},
472 {"oneshot", {0, 0, &Service::ParseOneshot}},
473 {"onrestart", {1, kMax, &Service::ParseOnrestart}},
474 {"namespace", {1, 2, &Service::ParseNamespace}},
475 {"seclabel", {1, 1, &Service::ParseSeclabel}},
476 {"setenv", {2, 2, &Service::ParseSetenv}},
477 {"socket", {3, 6, &Service::ParseSocket}},
478 {"user", {1, 1, &Service::ParseUser}},
479 {"writepid", {1, kMax, &Service::ParseWritepid}},
Tom Cherryb7349902015-08-26 11:43:36 -0700480 };
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400481 return option_parsers;
Tom Cherryb7349902015-08-26 11:43:36 -0700482}
483
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400484bool Service::ParseLine(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700485 if (args.empty()) {
486 *err = "option needed, but not provided";
487 return false;
488 }
489
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400490 static const OptionParserMap parser_map;
491 auto parser = parser_map.FindFunction(args[0], args.size() - 1, err);
Tom Cherryb7349902015-08-26 11:43:36 -0700492
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400493 if (!parser) {
Tom Cherryb7349902015-08-26 11:43:36 -0700494 return false;
495 }
496
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400497 return (this->*parser)(args, err);
Tom Cherryb7349902015-08-26 11:43:36 -0700498}
499
Elliott Hughesbdeac392016-04-12 15:38:27 -0700500bool Service::Start() {
Tom Cherrybac32992015-07-31 12:45:25 -0700501 // Starting a service removes it from the disabled or reset state and
502 // immediately takes it out of the restarting state if it was in there.
503 flags_ &= (~(SVC_DISABLED|SVC_RESTARTING|SVC_RESET|SVC_RESTART|SVC_DISABLED_START));
504 time_started_ = 0;
505
506 // Running processes require no additional work --- if they're in the
507 // process of exiting, we've ensured that they will immediately restart
508 // on exit, unless they are ONESHOT.
509 if (flags_ & SVC_RUNNING) {
510 return false;
511 }
512
513 bool needs_console = (flags_ & SVC_CONSOLE);
Viorel Suman70daa672016-03-21 10:08:07 +0200514 if (needs_console) {
515 if (console_.empty()) {
516 console_ = default_console;
517 }
518
519 bool have_console = (open(console_.c_str(), O_RDWR | O_CLOEXEC) != -1);
520 if (!have_console) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700521 PLOG(ERROR) << "service '" << name_ << "' couldn't open console '" << console_ << "'";
Viorel Suman70daa672016-03-21 10:08:07 +0200522 flags_ |= SVC_DISABLED;
523 return false;
524 }
Tom Cherrybac32992015-07-31 12:45:25 -0700525 }
526
527 struct stat sb;
528 if (stat(args_[0].c_str(), &sb) == -1) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700529 PLOG(ERROR) << "cannot find '" << args_[0] << "', disabling '" << name_ << "'";
Tom Cherrybac32992015-07-31 12:45:25 -0700530 flags_ |= SVC_DISABLED;
531 return false;
532 }
533
Tom Cherrybac32992015-07-31 12:45:25 -0700534 std::string scon;
535 if (!seclabel_.empty()) {
536 scon = seclabel_;
537 } else {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400538 LOG(INFO) << "computing context for service '" << name_ << "'";
539 scon = ComputeContextFromExecutable(name_, args_[0]);
540 if (scon == "") {
Tom Cherrybac32992015-07-31 12:45:25 -0700541 return false;
542 }
543 }
544
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400545 LOG(VERBOSE) << "starting service '" << name_ << "'...";
Tom Cherrybac32992015-07-31 12:45:25 -0700546
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700547 pid_t pid = -1;
548 if (namespace_flags_) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400549 pid = clone(nullptr, nullptr, namespace_flags_ | SIGCHLD, nullptr);
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700550 } else {
551 pid = fork();
552 }
553
Tom Cherrybac32992015-07-31 12:45:25 -0700554 if (pid == 0) {
Tom Cherrybac32992015-07-31 12:45:25 -0700555 umask(077);
Tom Cherrybac32992015-07-31 12:45:25 -0700556
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700557 if (namespace_flags_ & CLONE_NEWPID) {
558 // This will fork again to run an init process inside the PID
559 // namespace.
560 SetUpPidNamespace(name_);
561 }
562
Tom Cherrybac32992015-07-31 12:45:25 -0700563 for (const auto& ei : envvars_) {
564 add_environment(ei.name.c_str(), ei.value.c_str());
565 }
566
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400567 CreateSockets(scon);
Tom Cherrybac32992015-07-31 12:45:25 -0700568
Anestis Bechtsoudisb702b462016-02-05 16:38:48 +0200569 std::string pid_str = StringPrintf("%d", getpid());
Tom Cherrybac32992015-07-31 12:45:25 -0700570 for (const auto& file : writepid_files_) {
Tom Cherryb7349902015-08-26 11:43:36 -0700571 if (!WriteStringToFile(pid_str, file)) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700572 PLOG(ERROR) << "couldn't write " << pid_str << " to " << file;
Tom Cherrybac32992015-07-31 12:45:25 -0700573 }
574 }
575
576 if (ioprio_class_ != IoSchedClass_NONE) {
577 if (android_set_ioprio(getpid(), ioprio_class_, ioprio_pri_)) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400578 PLOG(ERROR) << "failed to set pid " << getpid()
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700579 << " ioprio=" << ioprio_class_ << "," << ioprio_pri_;
Tom Cherrybac32992015-07-31 12:45:25 -0700580 }
581 }
582
583 if (needs_console) {
584 setsid();
585 OpenConsole();
586 } else {
587 ZapStdio();
588 }
589
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400590 // As requested, set our gid, supplemental gids, uid, context, and
591 // priority. Aborts on failure.
592 SetProcessAttributes();
Tom Cherrybac32992015-07-31 12:45:25 -0700593
Tom Cherrybac32992015-07-31 12:45:25 -0700594 std::vector<char*> strs;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400595 ExpandArgs(args_, &strs);
Tom Cherrybac35362016-06-07 11:22:00 -0700596 if (execve(strs[0], (char**) &strs[0], (char**) ENV) < 0) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700597 PLOG(ERROR) << "cannot execve('" << strs[0] << "')";
Tom Cherrybac32992015-07-31 12:45:25 -0700598 }
599
600 _exit(127);
601 }
602
603 if (pid < 0) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700604 PLOG(ERROR) << "failed to fork for '" << name_ << "'";
Tom Cherrybac32992015-07-31 12:45:25 -0700605 pid_ = 0;
606 return false;
607 }
608
609 time_started_ = gettime();
610 pid_ = pid;
611 flags_ |= SVC_RUNNING;
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700612
613 errno = -createProcessGroup(uid_, pid_);
614 if (errno != 0) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400615 PLOG(ERROR) << "createProcessGroup(" << uid_ << ", " << pid_ << ") failed for service '"
616 << name_ << "'";
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700617 }
Tom Cherrybac32992015-07-31 12:45:25 -0700618
619 if ((flags_ & SVC_EXEC) != 0) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400620 LOG(INFO) << android::base::StringPrintf(
621 "SVC_EXEC pid %d (uid %d gid %d+%zu context %s) started; waiting...", pid_, uid_, gid_,
622 supp_gids_.size(), !seclabel_.empty() ? seclabel_.c_str() : "default");
Tom Cherrybac32992015-07-31 12:45:25 -0700623 }
624
625 NotifyStateChange("running");
626 return true;
627}
628
Tom Cherrybac32992015-07-31 12:45:25 -0700629bool Service::StartIfNotDisabled() {
630 if (!(flags_ & SVC_DISABLED)) {
631 return Start();
632 } else {
633 flags_ |= SVC_DISABLED_START;
634 }
635 return true;
636}
637
638bool Service::Enable() {
639 flags_ &= ~(SVC_DISABLED | SVC_RC_DISABLED);
640 if (flags_ & SVC_DISABLED_START) {
641 return Start();
642 }
643 return true;
644}
645
646void Service::Reset() {
647 StopOrReset(SVC_RESET);
648}
649
650void Service::Stop() {
651 StopOrReset(SVC_DISABLED);
652}
653
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800654void Service::Terminate() {
655 flags_ &= ~(SVC_RESTARTING | SVC_DISABLED_START);
656 flags_ |= SVC_DISABLED;
657 if (pid_) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700658 KillProcessGroup(SIGTERM);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800659 NotifyStateChange("stopping");
660 }
661}
662
Tom Cherrybac32992015-07-31 12:45:25 -0700663void Service::Restart() {
664 if (flags_ & SVC_RUNNING) {
665 /* Stop, wait, then start the service. */
666 StopOrReset(SVC_RESTART);
667 } else if (!(flags_ & SVC_RESTARTING)) {
668 /* Just start the service since it's not running. */
669 Start();
670 } /* else: Service is restarting anyways. */
671}
672
673void Service::RestartIfNeeded(time_t& process_needs_restart) {
674 time_t next_start_time = time_started_ + 5;
675
676 if (next_start_time <= gettime()) {
677 flags_ &= (~SVC_RESTARTING);
678 Start();
679 return;
680 }
681
682 if ((next_start_time < process_needs_restart) ||
683 (process_needs_restart == 0)) {
684 process_needs_restart = next_start_time;
685 }
686}
687
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700688// The how field should be either SVC_DISABLED, SVC_RESET, or SVC_RESTART.
Tom Cherrybac32992015-07-31 12:45:25 -0700689void Service::StopOrReset(int how) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700690 // The service is still SVC_RUNNING until its process exits, but if it has
691 // already exited it shoudn't attempt a restart yet.
Tom Cherrybac32992015-07-31 12:45:25 -0700692 flags_ &= ~(SVC_RESTARTING | SVC_DISABLED_START);
693
694 if ((how != SVC_DISABLED) && (how != SVC_RESET) && (how != SVC_RESTART)) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700695 // An illegal flag: default to SVC_DISABLED.
Tom Cherrybac32992015-07-31 12:45:25 -0700696 how = SVC_DISABLED;
697 }
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700698
699 // If the service has not yet started, prevent it from auto-starting with its class.
Tom Cherrybac32992015-07-31 12:45:25 -0700700 if (how == SVC_RESET) {
701 flags_ |= (flags_ & SVC_RC_DISABLED) ? SVC_DISABLED : SVC_RESET;
702 } else {
703 flags_ |= how;
704 }
705
706 if (pid_) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700707 KillProcessGroup(SIGKILL);
Tom Cherrybac32992015-07-31 12:45:25 -0700708 NotifyStateChange("stopping");
709 } else {
710 NotifyStateChange("stopped");
711 }
712}
713
714void Service::ZapStdio() const {
715 int fd;
716 fd = open("/dev/null", O_RDWR);
717 dup2(fd, 0);
718 dup2(fd, 1);
719 dup2(fd, 2);
720 close(fd);
721}
722
723void Service::OpenConsole() const {
Viorel Suman70daa672016-03-21 10:08:07 +0200724 int fd = open(console_.c_str(), O_RDWR);
725 if (fd == -1) fd = open("/dev/null", O_RDWR);
Tom Cherrybac32992015-07-31 12:45:25 -0700726 ioctl(fd, TIOCSCTTY, 0);
727 dup2(fd, 0);
728 dup2(fd, 1);
729 dup2(fd, 2);
730 close(fd);
731}
732
733void Service::PublishSocket(const std::string& name, int fd) const {
Tom Cherryb7349902015-08-26 11:43:36 -0700734 std::string key = StringPrintf(ANDROID_SOCKET_ENV_PREFIX "%s", name.c_str());
735 std::string val = StringPrintf("%d", fd);
Tom Cherrybac32992015-07-31 12:45:25 -0700736 add_environment(key.c_str(), val.c_str());
737
738 /* make sure we don't close-on-exec */
739 fcntl(fd, F_SETFD, 0);
740}
741
742int ServiceManager::exec_count_ = 0;
743
744ServiceManager::ServiceManager() {
745}
746
747ServiceManager& ServiceManager::GetInstance() {
748 static ServiceManager instance;
749 return instance;
750}
751
Tom Cherryb7349902015-08-26 11:43:36 -0700752void ServiceManager::AddService(std::unique_ptr<Service> service) {
753 Service* old_service = FindServiceByName(service->name());
754 if (old_service) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700755 LOG(ERROR) << "ignored duplicate definition of service '" << service->name() << "'";
Tom Cherryb7349902015-08-26 11:43:36 -0700756 return;
Tom Cherrybac32992015-07-31 12:45:25 -0700757 }
Tom Cherryb7349902015-08-26 11:43:36 -0700758 services_.emplace_back(std::move(service));
Tom Cherrybac32992015-07-31 12:45:25 -0700759}
760
761Service* ServiceManager::MakeExecOneshotService(const std::vector<std::string>& args) {
762 // Parse the arguments: exec [SECLABEL [UID [GID]*] --] COMMAND ARGS...
763 // SECLABEL can be a - to denote default
764 std::size_t command_arg = 1;
765 for (std::size_t i = 1; i < args.size(); ++i) {
766 if (args[i] == "--") {
767 command_arg = i + 1;
768 break;
769 }
770 }
771 if (command_arg > 4 + NR_SVC_SUPP_GIDS) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700772 LOG(ERROR) << "exec called with too many supplementary group ids";
Tom Cherrybac32992015-07-31 12:45:25 -0700773 return nullptr;
774 }
775
776 if (command_arg >= args.size()) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700777 LOG(ERROR) << "exec called without command";
Tom Cherrybac32992015-07-31 12:45:25 -0700778 return nullptr;
779 }
780 std::vector<std::string> str_args(args.begin() + command_arg, args.end());
781
782 exec_count_++;
Tom Cherryb7349902015-08-26 11:43:36 -0700783 std::string name = StringPrintf("exec %d (%s)", exec_count_, str_args[0].c_str());
Tom Cherrybac32992015-07-31 12:45:25 -0700784 unsigned flags = SVC_EXEC | SVC_ONESHOT;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700785 unsigned namespace_flags = 0;
Tom Cherrybac32992015-07-31 12:45:25 -0700786
787 std::string seclabel = "";
788 if (command_arg > 2 && args[1] != "-") {
789 seclabel = args[1];
790 }
791 uid_t uid = 0;
792 if (command_arg > 3) {
793 uid = decode_uid(args[2].c_str());
794 }
795 gid_t gid = 0;
796 std::vector<gid_t> supp_gids;
797 if (command_arg > 4) {
798 gid = decode_uid(args[3].c_str());
799 std::size_t nr_supp_gids = command_arg - 1 /* -- */ - 4 /* exec SECLABEL UID GID */;
800 for (size_t i = 0; i < nr_supp_gids; ++i) {
801 supp_gids.push_back(decode_uid(args[4 + i].c_str()));
802 }
803 }
804
805 std::unique_ptr<Service> svc_p(new Service(name, "default", flags, uid, gid,
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700806 supp_gids, namespace_flags,
807 seclabel, str_args));
Tom Cherrybac32992015-07-31 12:45:25 -0700808 if (!svc_p) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700809 LOG(ERROR) << "Couldn't allocate service for exec of '" << str_args[0] << "'";
Tom Cherrybac32992015-07-31 12:45:25 -0700810 return nullptr;
811 }
812 Service* svc = svc_p.get();
813 services_.push_back(std::move(svc_p));
814
815 return svc;
816}
817
818Service* ServiceManager::FindServiceByName(const std::string& name) const {
819 auto svc = std::find_if(services_.begin(), services_.end(),
820 [&name] (const std::unique_ptr<Service>& s) {
821 return name == s->name();
822 });
823 if (svc != services_.end()) {
824 return svc->get();
825 }
826 return nullptr;
827}
828
829Service* ServiceManager::FindServiceByPid(pid_t pid) const {
830 auto svc = std::find_if(services_.begin(), services_.end(),
831 [&pid] (const std::unique_ptr<Service>& s) {
832 return s->pid() == pid;
833 });
834 if (svc != services_.end()) {
835 return svc->get();
836 }
837 return nullptr;
838}
839
840Service* ServiceManager::FindServiceByKeychord(int keychord_id) const {
841 auto svc = std::find_if(services_.begin(), services_.end(),
842 [&keychord_id] (const std::unique_ptr<Service>& s) {
843 return s->keychord_id() == keychord_id;
844 });
845
846 if (svc != services_.end()) {
847 return svc->get();
848 }
849 return nullptr;
850}
851
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800852void ServiceManager::ForEachService(std::function<void(Service*)> callback) const {
Tom Cherrybac32992015-07-31 12:45:25 -0700853 for (const auto& s : services_) {
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800854 callback(s.get());
Tom Cherrybac32992015-07-31 12:45:25 -0700855 }
856}
857
858void ServiceManager::ForEachServiceInClass(const std::string& classname,
859 void (*func)(Service* svc)) const {
860 for (const auto& s : services_) {
861 if (classname == s->classname()) {
862 func(s.get());
863 }
864 }
865}
866
867void ServiceManager::ForEachServiceWithFlags(unsigned matchflags,
868 void (*func)(Service* svc)) const {
869 for (const auto& s : services_) {
870 if (s->flags() & matchflags) {
871 func(s.get());
872 }
873 }
874}
875
Tom Cherryb7349902015-08-26 11:43:36 -0700876void ServiceManager::RemoveService(const Service& svc) {
Tom Cherrybac32992015-07-31 12:45:25 -0700877 auto svc_it = std::find_if(services_.begin(), services_.end(),
878 [&svc] (const std::unique_ptr<Service>& s) {
879 return svc.name() == s->name();
880 });
881 if (svc_it == services_.end()) {
882 return;
883 }
884
885 services_.erase(svc_it);
886}
887
Tom Cherryb7349902015-08-26 11:43:36 -0700888void ServiceManager::DumpState() const {
889 for (const auto& s : services_) {
890 s->DumpState();
891 }
Tom Cherryb7349902015-08-26 11:43:36 -0700892}
893
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800894bool ServiceManager::ReapOneProcess() {
895 int status;
896 pid_t pid = TEMP_FAILURE_RETRY(waitpid(-1, &status, WNOHANG));
897 if (pid == 0) {
898 return false;
899 } else if (pid == -1) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700900 PLOG(ERROR) << "waitpid failed";
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800901 return false;
902 }
903
904 Service* svc = FindServiceByPid(pid);
905
906 std::string name;
907 if (svc) {
908 name = android::base::StringPrintf("Service '%s' (pid %d)",
909 svc->name().c_str(), pid);
910 } else {
911 name = android::base::StringPrintf("Untracked pid %d", pid);
912 }
913
914 if (WIFEXITED(status)) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700915 LOG(VERBOSE) << name << " exited with status " << WEXITSTATUS(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800916 } else if (WIFSIGNALED(status)) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700917 LOG(VERBOSE) << name << " killed by signal " << WTERMSIG(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800918 } else if (WIFSTOPPED(status)) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700919 LOG(VERBOSE) << name << " stopped by signal " << WSTOPSIG(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800920 } else {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700921 LOG(VERBOSE) << name << " state changed";
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800922 }
923
924 if (!svc) {
925 return true;
926 }
927
928 if (svc->Reap()) {
929 waiting_for_exec = false;
930 RemoveService(*svc);
931 }
932
933 return true;
934}
935
936void ServiceManager::ReapAnyOutstandingChildren() {
937 while (ReapOneProcess()) {
938 }
939}
940
Tom Cherryb7349902015-08-26 11:43:36 -0700941bool ServiceParser::ParseSection(const std::vector<std::string>& args,
942 std::string* err) {
943 if (args.size() < 3) {
944 *err = "services must have a name and a program";
945 return false;
946 }
947
948 const std::string& name = args[1];
949 if (!IsValidName(name)) {
950 *err = StringPrintf("invalid service name '%s'", name.c_str());
951 return false;
952 }
953
954 std::vector<std::string> str_args(args.begin() + 2, args.end());
955 service_ = std::make_unique<Service>(name, "default", str_args);
956 return true;
957}
958
959bool ServiceParser::ParseLineSection(const std::vector<std::string>& args,
960 const std::string& filename, int line,
961 std::string* err) const {
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400962 return service_ ? service_->ParseLine(args, err) : false;
Tom Cherryb7349902015-08-26 11:43:36 -0700963}
964
965void ServiceParser::EndSection() {
966 if (service_) {
967 ServiceManager::GetInstance().AddService(std::move(service_));
968 }
969}
970
971bool ServiceParser::IsValidName(const std::string& name) const {
Tom Cherrybac32992015-07-31 12:45:25 -0700972 if (name.size() > 16) {
973 return false;
974 }
975 for (const auto& c : name) {
976 if (!isalnum(c) && (c != '_') && (c != '-')) {
977 return false;
978 }
979 }
980 return true;
981}