blob: 7cff348d67723b431b875f87e415018de8b6172f [file] [log] [blame]
Tom Cherrybac32992015-07-31 12:45:25 -07001/*
2 * Copyright (C) 2015 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17#include "service.h"
18
19#include <fcntl.h>
Elliott Hughes9605a942016-11-10 17:43:47 -080020#include <inttypes.h>
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -040021#include <linux/securebits.h>
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -070022#include <sched.h>
23#include <sys/mount.h>
24#include <sys/prctl.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070025#include <sys/resource.h>
Tom Cherrybac32992015-07-31 12:45:25 -070026#include <sys/stat.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070027#include <sys/time.h>
Tom Cherrybac32992015-07-31 12:45:25 -070028#include <sys/types.h>
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -080029#include <sys/wait.h>
Tom Cherrybac32992015-07-31 12:45:25 -070030#include <termios.h>
Dan Albertaf9ba4d2015-08-11 16:37:04 -070031#include <unistd.h>
Tom Cherrybac32992015-07-31 12:45:25 -070032
33#include <selinux/selinux.h>
34
Elliott Hughes4f713192015-12-04 22:00:26 -080035#include <android-base/file.h>
Elliott Hughesda46b392016-10-11 17:09:00 -070036#include <android-base/parseint.h>
Elliott Hughes4f713192015-12-04 22:00:26 -080037#include <android-base/stringprintf.h>
Elliott Hughesf86b5a62016-06-24 15:12:21 -070038#include <android-base/strings.h>
Vitalii Tomkiv081705c2016-05-18 17:36:30 -070039#include <system/thread_defs.h>
Tom Cherrybac32992015-07-31 12:45:25 -070040
Collin Mullinerf7e79b92016-06-01 21:03:55 +000041#include <processgroup/processgroup.h>
42
Tom Cherrybac32992015-07-31 12:45:25 -070043#include "action.h"
44#include "init.h"
45#include "init_parser.h"
Tom Cherrybac32992015-07-31 12:45:25 -070046#include "log.h"
47#include "property_service.h"
48#include "util.h"
49
Elliott Hughesda46b392016-10-11 17:09:00 -070050using android::base::ParseInt;
Tom Cherryb7349902015-08-26 11:43:36 -070051using android::base::StringPrintf;
52using android::base::WriteStringToFile;
53
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -040054static std::string ComputeContextFromExecutable(std::string& service_name,
55 const std::string& service_path) {
56 std::string computed_context;
57
58 char* raw_con = nullptr;
59 char* raw_filecon = nullptr;
60
61 if (getcon(&raw_con) == -1) {
62 LOG(ERROR) << "could not get context while starting '" << service_name << "'";
63 return "";
64 }
65 std::unique_ptr<char> mycon(raw_con);
66
67 if (getfilecon(service_path.c_str(), &raw_filecon) == -1) {
68 LOG(ERROR) << "could not get file context while starting '" << service_name << "'";
69 return "";
70 }
71 std::unique_ptr<char> filecon(raw_filecon);
72
73 char* new_con = nullptr;
74 int rc = security_compute_create(mycon.get(), filecon.get(),
75 string_to_security_class("process"), &new_con);
76 if (rc == 0) {
77 computed_context = new_con;
78 free(new_con);
79 }
80 if (rc == 0 && computed_context == mycon.get()) {
81 LOG(ERROR) << "service " << service_name << " does not have a SELinux domain defined";
82 return "";
83 }
84 if (rc < 0) {
85 LOG(ERROR) << "could not get context while starting '" << service_name << "'";
86 return "";
87 }
88 return computed_context;
89}
90
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -070091static void SetUpPidNamespace(const std::string& service_name) {
92 constexpr unsigned int kSafeFlags = MS_NODEV | MS_NOEXEC | MS_NOSUID;
93
94 // It's OK to LOG(FATAL) in this function since it's running in the first
95 // child process.
96 if (mount("", "/proc", "proc", kSafeFlags | MS_REMOUNT, "") == -1) {
Elliott Hughese18e7e52016-07-25 18:18:16 -070097 PLOG(FATAL) << "couldn't remount(/proc) for " << service_name;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -070098 }
99
100 if (prctl(PR_SET_NAME, service_name.c_str()) == -1) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700101 PLOG(FATAL) << "couldn't set name for " << service_name;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700102 }
103
104 pid_t child_pid = fork();
105 if (child_pid == -1) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700106 PLOG(FATAL) << "couldn't fork init inside the PID namespace for " << service_name;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700107 }
108
109 if (child_pid > 0) {
110 // So that we exit with the right status.
111 static int init_exitstatus = 0;
112 signal(SIGTERM, [](int) { _exit(init_exitstatus); });
113
114 pid_t waited_pid;
115 int status;
116 while ((waited_pid = wait(&status)) > 0) {
117 // This loop will end when there are no processes left inside the
118 // PID namespace or when the init process inside the PID namespace
119 // gets a signal.
120 if (waited_pid == child_pid) {
121 init_exitstatus = status;
122 }
123 }
124 if (!WIFEXITED(init_exitstatus)) {
125 _exit(EXIT_FAILURE);
126 }
127 _exit(WEXITSTATUS(init_exitstatus));
128 }
129}
130
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400131static void ExpandArgs(const std::vector<std::string>& args, std::vector<char*>* strs) {
132 std::vector<std::string> expanded_args;
133 expanded_args.resize(args.size());
134 strs->push_back(const_cast<char*>(args[0].c_str()));
135 for (std::size_t i = 1; i < args.size(); ++i) {
136 if (!expand_props(args[i], &expanded_args[i])) {
137 LOG(FATAL) << args[0] << ": cannot expand '" << args[i] << "'";
138 }
139 strs->push_back(const_cast<char*>(expanded_args[i].c_str()));
140 }
141 strs->push_back(nullptr);
142}
143
Tom Cherrybac32992015-07-31 12:45:25 -0700144ServiceEnvironmentInfo::ServiceEnvironmentInfo() {
145}
146
147ServiceEnvironmentInfo::ServiceEnvironmentInfo(const std::string& name,
148 const std::string& value)
149 : name(name), value(value) {
150}
151
152Service::Service(const std::string& name, const std::string& classname,
153 const std::vector<std::string>& args)
Elliott Hughes9605a942016-11-10 17:43:47 -0800154 : name_(name), classname_(classname), flags_(0), pid_(0),
155 crash_count_(0), uid_(0), gid_(0), namespace_flags_(0),
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700156 seclabel_(""), ioprio_class_(IoSchedClass_NONE), ioprio_pri_(0),
Marco Nelissen310f6702016-07-22 12:07:06 -0700157 priority_(0), oom_score_adjust_(-1000), args_(args) {
Tom Cherrybac32992015-07-31 12:45:25 -0700158 onrestart_.InitSingleTrigger("onrestart");
159}
160
161Service::Service(const std::string& name, const std::string& classname,
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700162 unsigned flags, uid_t uid, gid_t gid,
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400163 const std::vector<gid_t>& supp_gids,
164 const CapSet& capabilities, unsigned namespace_flags,
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700165 const std::string& seclabel,
166 const std::vector<std::string>& args)
167 : name_(name), classname_(classname), flags_(flags), pid_(0),
Elliott Hughes9605a942016-11-10 17:43:47 -0800168 crash_count_(0), uid_(uid), gid_(gid),
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400169 supp_gids_(supp_gids), capabilities_(capabilities),
170 namespace_flags_(namespace_flags), seclabel_(seclabel),
171 ioprio_class_(IoSchedClass_NONE), ioprio_pri_(0), priority_(0),
172 oom_score_adjust_(-1000), args_(args) {
Tom Cherrybac32992015-07-31 12:45:25 -0700173 onrestart_.InitSingleTrigger("onrestart");
174}
175
176void Service::NotifyStateChange(const std::string& new_state) const {
Tom Cherrybac32992015-07-31 12:45:25 -0700177 if ((flags_ & SVC_EXEC) != 0) {
178 // 'exec' commands don't have properties tracking their state.
179 return;
180 }
181
Tom Cherryb7349902015-08-26 11:43:36 -0700182 std::string prop_name = StringPrintf("init.svc.%s", name_.c_str());
Tom Cherrybac32992015-07-31 12:45:25 -0700183 if (prop_name.length() >= PROP_NAME_MAX) {
184 // If the property name would be too long, we can't set it.
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700185 LOG(ERROR) << "Property name \"init.svc." << name_ << "\" too long; not setting to " << new_state;
Tom Cherrybac32992015-07-31 12:45:25 -0700186 return;
187 }
188
189 property_set(prop_name.c_str(), new_state.c_str());
Elliott Hughes9605a942016-11-10 17:43:47 -0800190
191 if (new_state == "running") {
Elliott Hughes9605a942016-11-10 17:43:47 -0800192 uint64_t start_ns = time_started_.time_since_epoch().count();
Elliott Hughes331cf2f2016-11-29 19:20:58 +0000193 property_set(StringPrintf("ro.boottime.%s", name_.c_str()).c_str(),
194 StringPrintf("%" PRIu64, start_ns).c_str());
Elliott Hughes9605a942016-11-10 17:43:47 -0800195 }
Tom Cherrybac32992015-07-31 12:45:25 -0700196}
197
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700198void Service::KillProcessGroup(int signal) {
Elliott Hughes1e730242016-08-02 14:20:40 -0700199 LOG(INFO) << "Sending signal " << signal
200 << " to service '" << name_
201 << "' (pid " << pid_ << ") process group...";
202 if (killProcessGroup(uid_, pid_, signal) == -1) {
203 PLOG(ERROR) << "killProcessGroup(" << uid_ << ", " << pid_ << ", " << signal << ") failed";
204 }
205 if (kill(-pid_, signal) == -1) {
206 PLOG(ERROR) << "kill(" << pid_ << ", " << signal << ") failed";
207 }
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700208}
209
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400210void Service::SetProcessAttributes() {
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400211 // Keep capabilites on uid change.
212 if (capabilities_.any() && uid_) {
213 if (prctl(PR_SET_SECUREBITS, SECBIT_KEEP_CAPS | SECBIT_KEEP_CAPS_LOCKED) != 0) {
214 PLOG(FATAL) << "prtcl(PR_SET_KEEPCAPS) failed for " << name_;
215 }
216 }
217
Elliott Hughese18e7e52016-07-25 18:18:16 -0700218 // TODO: work out why this fails for `console` then upgrade to FATAL.
219 if (setpgid(0, getpid()) == -1) PLOG(ERROR) << "setpgid failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400220
221 if (gid_) {
222 if (setgid(gid_) != 0) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700223 PLOG(FATAL) << "setgid failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400224 }
225 }
Nick Kralevich80960d22016-10-29 12:20:00 -0700226 if (setgroups(supp_gids_.size(), &supp_gids_[0]) != 0) {
227 PLOG(FATAL) << "setgroups failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400228 }
229 if (uid_) {
230 if (setuid(uid_) != 0) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700231 PLOG(FATAL) << "setuid failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400232 }
233 }
234 if (!seclabel_.empty()) {
235 if (setexeccon(seclabel_.c_str()) < 0) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700236 PLOG(FATAL) << "cannot setexeccon('" << seclabel_ << "') for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400237 }
238 }
239 if (priority_ != 0) {
240 if (setpriority(PRIO_PROCESS, 0, priority_) != 0) {
Elliott Hughese18e7e52016-07-25 18:18:16 -0700241 PLOG(FATAL) << "setpriority failed for " << name_;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400242 }
243 }
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400244 if (capabilities_.any()) {
245 if (!SetCapsForExec(capabilities_)) {
246 LOG(FATAL) << "cannot set capabilities for " << name_;
247 }
248 }
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400249}
250
Tom Cherrybac32992015-07-31 12:45:25 -0700251bool Service::Reap() {
252 if (!(flags_ & SVC_ONESHOT) || (flags_ & SVC_RESTART)) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700253 KillProcessGroup(SIGKILL);
Tom Cherrybac32992015-07-31 12:45:25 -0700254 }
255
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700256 // Remove any descriptor resources we may have created.
257 std::for_each(descriptors_.begin(), descriptors_.end(),
258 std::bind(&DescriptorInfo::Clean, std::placeholders::_1));
Tom Cherrybac32992015-07-31 12:45:25 -0700259
260 if (flags_ & SVC_EXEC) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700261 LOG(INFO) << "SVC_EXEC pid " << pid_ << " finished...";
Tom Cherrybac32992015-07-31 12:45:25 -0700262 return true;
263 }
264
265 pid_ = 0;
266 flags_ &= (~SVC_RUNNING);
267
268 // Oneshot processes go into the disabled state on exit,
269 // except when manually restarted.
270 if ((flags_ & SVC_ONESHOT) && !(flags_ & SVC_RESTART)) {
271 flags_ |= SVC_DISABLED;
272 }
273
274 // Disabled and reset processes do not get restarted automatically.
275 if (flags_ & (SVC_DISABLED | SVC_RESET)) {
276 NotifyStateChange("stopped");
277 return false;
278 }
279
Elliott Hughes9605a942016-11-10 17:43:47 -0800280 // If we crash > 4 times in 4 minutes, reboot into recovery.
281 boot_clock::time_point now = boot_clock::now();
Tom Cherrybac32992015-07-31 12:45:25 -0700282 if ((flags_ & SVC_CRITICAL) && !(flags_ & SVC_RESTART)) {
Elliott Hughes9605a942016-11-10 17:43:47 -0800283 if (now < time_crashed_ + 4min) {
284 if (++crash_count_ > 4) {
Elliott Hughes331cf2f2016-11-29 19:20:58 +0000285 LOG(ERROR) << "critical process '" << name_ << "' exited 4 times in 4 minutes";
286 panic();
Tom Cherrybac32992015-07-31 12:45:25 -0700287 }
288 } else {
289 time_crashed_ = now;
Elliott Hughes9605a942016-11-10 17:43:47 -0800290 crash_count_ = 1;
Tom Cherrybac32992015-07-31 12:45:25 -0700291 }
292 }
293
294 flags_ &= (~SVC_RESTART);
295 flags_ |= SVC_RESTARTING;
296
297 // Execute all onrestart commands for this service.
298 onrestart_.ExecuteAllCommands();
299
300 NotifyStateChange("restarting");
301 return false;
302}
303
304void Service::DumpState() const {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700305 LOG(INFO) << "service " << name_;
306 LOG(INFO) << " class '" << classname_ << "'";
307 LOG(INFO) << " exec "<< android::base::Join(args_, " ");
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700308 std::for_each(descriptors_.begin(), descriptors_.end(),
309 [] (const auto& info) { LOG(INFO) << *info; });
Tom Cherrybac32992015-07-31 12:45:25 -0700310}
311
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400312bool Service::ParseCapabilities(const std::vector<std::string>& args, std::string* err) {
313 capabilities_ = 0;
314
Jorge Lucangeli Obesf3f824e2016-12-15 12:13:38 -0500315 if (!CapAmbientSupported()) {
316 *err = "capabilities requested but the kernel does not support ambient capabilities";
317 return false;
318 }
319
320 unsigned int last_valid_cap = GetLastValidCap();
321 if (last_valid_cap >= capabilities_.size()) {
322 LOG(WARNING) << "last valid run-time capability is larger than CAP_LAST_CAP";
323 }
324
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400325 for (size_t i = 1; i < args.size(); i++) {
326 const std::string& arg = args[i];
Jorge Lucangeli Obesf3f824e2016-12-15 12:13:38 -0500327 int res = LookupCap(arg);
328 if (res < 0) {
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400329 *err = StringPrintf("invalid capability '%s'", arg.c_str());
330 return false;
331 }
Jorge Lucangeli Obesf3f824e2016-12-15 12:13:38 -0500332 unsigned int cap = static_cast<unsigned int>(res); // |res| is >= 0.
333 if (cap > last_valid_cap) {
334 *err = StringPrintf("capability '%s' not supported by the kernel", arg.c_str());
335 return false;
336 }
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400337 capabilities_[cap] = true;
338 }
339 return true;
340}
341
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400342bool Service::ParseClass(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700343 classname_ = args[1];
344 return true;
345}
Tom Cherrybac32992015-07-31 12:45:25 -0700346
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400347bool Service::ParseConsole(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700348 flags_ |= SVC_CONSOLE;
Viorel Suman70daa672016-03-21 10:08:07 +0200349 console_ = args.size() > 1 ? "/dev/" + args[1] : "";
Tom Cherryb7349902015-08-26 11:43:36 -0700350 return true;
351}
Tom Cherrybac32992015-07-31 12:45:25 -0700352
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400353bool Service::ParseCritical(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700354 flags_ |= SVC_CRITICAL;
355 return true;
356}
Tom Cherrybac32992015-07-31 12:45:25 -0700357
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400358bool Service::ParseDisabled(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700359 flags_ |= SVC_DISABLED;
360 flags_ |= SVC_RC_DISABLED;
361 return true;
362}
Tom Cherrybac32992015-07-31 12:45:25 -0700363
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400364bool Service::ParseGroup(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700365 gid_ = decode_uid(args[1].c_str());
366 for (std::size_t n = 2; n < args.size(); n++) {
367 supp_gids_.emplace_back(decode_uid(args[n].c_str()));
Tom Cherrybac32992015-07-31 12:45:25 -0700368 }
369 return true;
370}
371
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400372bool Service::ParsePriority(const std::vector<std::string>& args, std::string* err) {
Elliott Hughesda46b392016-10-11 17:09:00 -0700373 priority_ = 0;
374 if (!ParseInt(args[1], &priority_,
Keun-young Parkdd34ca42016-11-11 18:06:31 -0800375 static_cast<int>(ANDROID_PRIORITY_HIGHEST), // highest is negative
376 static_cast<int>(ANDROID_PRIORITY_LOWEST))) {
Vitalii Tomkiv081705c2016-05-18 17:36:30 -0700377 *err = StringPrintf("process priority value must be range %d - %d",
378 ANDROID_PRIORITY_HIGHEST, ANDROID_PRIORITY_LOWEST);
379 return false;
380 }
Vitalii Tomkiv081705c2016-05-18 17:36:30 -0700381 return true;
382}
383
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400384bool Service::ParseIoprio(const std::vector<std::string>& args, std::string* err) {
Elliott Hughesda46b392016-10-11 17:09:00 -0700385 if (!ParseInt(args[2], &ioprio_pri_, 0, 7)) {
Tom Cherryb7349902015-08-26 11:43:36 -0700386 *err = "priority value must be range 0 - 7";
387 return false;
388 }
389
390 if (args[1] == "rt") {
391 ioprio_class_ = IoSchedClass_RT;
392 } else if (args[1] == "be") {
393 ioprio_class_ = IoSchedClass_BE;
394 } else if (args[1] == "idle") {
395 ioprio_class_ = IoSchedClass_IDLE;
396 } else {
397 *err = "ioprio option usage: ioprio <rt|be|idle> <0-7>";
398 return false;
399 }
400
401 return true;
402}
403
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400404bool Service::ParseKeycodes(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700405 for (std::size_t i = 1; i < args.size(); i++) {
Elliott Hughesda46b392016-10-11 17:09:00 -0700406 int code;
407 if (ParseInt(args[i], &code)) {
408 keycodes_.emplace_back(code);
409 } else {
410 LOG(WARNING) << "ignoring invalid keycode: " << args[i];
411 }
Tom Cherryb7349902015-08-26 11:43:36 -0700412 }
413 return true;
414}
415
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400416bool Service::ParseOneshot(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700417 flags_ |= SVC_ONESHOT;
418 return true;
419}
420
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400421bool Service::ParseOnrestart(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700422 std::vector<std::string> str_args(args.begin() + 1, args.end());
423 onrestart_.AddCommand(str_args, "", 0, err);
424 return true;
425}
426
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400427bool Service::ParseNamespace(const std::vector<std::string>& args, std::string* err) {
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700428 for (size_t i = 1; i < args.size(); i++) {
429 if (args[i] == "pid") {
430 namespace_flags_ |= CLONE_NEWPID;
431 // PID namespaces require mount namespaces.
432 namespace_flags_ |= CLONE_NEWNS;
433 } else if (args[i] == "mnt") {
434 namespace_flags_ |= CLONE_NEWNS;
435 } else {
436 *err = "namespace must be 'pid' or 'mnt'";
437 return false;
438 }
439 }
440 return true;
441}
442
Marco Nelissen310f6702016-07-22 12:07:06 -0700443bool Service::ParseOomScoreAdjust(const std::vector<std::string>& args, std::string* err) {
Elliott Hughesda46b392016-10-11 17:09:00 -0700444 if (!ParseInt(args[1], &oom_score_adjust_, -1000, 1000)) {
Marco Nelissen310f6702016-07-22 12:07:06 -0700445 *err = "oom_score_adjust value must be in range -1000 - +1000";
446 return false;
447 }
Marco Nelissen310f6702016-07-22 12:07:06 -0700448 return true;
449}
450
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400451bool Service::ParseSeclabel(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700452 seclabel_ = args[1];
453 return true;
454}
455
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400456bool Service::ParseSetenv(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700457 envvars_.emplace_back(args[1], args[2]);
458 return true;
459}
460
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700461template <typename T>
462bool Service::AddDescriptor(const std::vector<std::string>& args, std::string* err) {
463 int perm = args.size() > 3 ? std::strtoul(args[3].c_str(), 0, 8) : -1;
464 uid_t uid = args.size() > 4 ? decode_uid(args[4].c_str()) : 0;
465 gid_t gid = args.size() > 5 ? decode_uid(args[5].c_str()) : 0;
466 std::string context = args.size() > 6 ? args[6] : "";
467
468 auto descriptor = std::make_unique<T>(args[1], args[2], uid, gid, perm, context);
469
470 auto old =
471 std::find_if(descriptors_.begin(), descriptors_.end(),
472 [&descriptor] (const auto& other) { return descriptor.get() == other.get(); });
473
474 if (old != descriptors_.end()) {
475 *err = "duplicate descriptor " + args[1] + " " + args[2];
476 return false;
477 }
478
479 descriptors_.emplace_back(std::move(descriptor));
480 return true;
481}
482
483// name type perm [ uid gid context ]
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400484bool Service::ParseSocket(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700485 if (args[2] != "dgram" && args[2] != "stream" && args[2] != "seqpacket") {
486 *err = "socket type must be 'dgram', 'stream' or 'seqpacket'";
487 return false;
488 }
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700489 return AddDescriptor<SocketInfo>(args, err);
490}
Tom Cherryb7349902015-08-26 11:43:36 -0700491
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700492// name type perm [ uid gid context ]
493bool Service::ParseFile(const std::vector<std::string>& args, std::string* err) {
494 if (args[2] != "r" && args[2] != "w" && args[2] != "rw") {
495 *err = "file type must be 'r', 'w' or 'rw'";
496 return false;
497 }
498 if ((args[1][0] != '/') || (args[1].find("../") != std::string::npos)) {
499 *err = "file name must not be relative";
500 return false;
501 }
502 return AddDescriptor<FileInfo>(args, err);
Tom Cherryb7349902015-08-26 11:43:36 -0700503}
504
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400505bool Service::ParseUser(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700506 uid_ = decode_uid(args[1].c_str());
507 return true;
508}
509
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400510bool Service::ParseWritepid(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700511 writepid_files_.assign(args.begin() + 1, args.end());
512 return true;
513}
514
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400515class Service::OptionParserMap : public KeywordMap<OptionParser> {
Tom Cherryb7349902015-08-26 11:43:36 -0700516public:
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400517 OptionParserMap() {
Tom Cherryb7349902015-08-26 11:43:36 -0700518 }
519private:
520 Map& map() const override;
521};
522
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400523Service::OptionParserMap::Map& Service::OptionParserMap::map() const {
Tom Cherryb7349902015-08-26 11:43:36 -0700524 constexpr std::size_t kMax = std::numeric_limits<std::size_t>::max();
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400525 static const Map option_parsers = {
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400526 {"capabilities",
527 {1, kMax, &Service::ParseCapabilities}},
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400528 {"class", {1, 1, &Service::ParseClass}},
529 {"console", {0, 1, &Service::ParseConsole}},
530 {"critical", {0, 0, &Service::ParseCritical}},
531 {"disabled", {0, 0, &Service::ParseDisabled}},
532 {"group", {1, NR_SVC_SUPP_GIDS + 1, &Service::ParseGroup}},
533 {"ioprio", {2, 2, &Service::ParseIoprio}},
534 {"priority", {1, 1, &Service::ParsePriority}},
535 {"keycodes", {1, kMax, &Service::ParseKeycodes}},
536 {"oneshot", {0, 0, &Service::ParseOneshot}},
537 {"onrestart", {1, kMax, &Service::ParseOnrestart}},
Marco Nelissen310f6702016-07-22 12:07:06 -0700538 {"oom_score_adjust",
539 {1, 1, &Service::ParseOomScoreAdjust}},
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400540 {"namespace", {1, 2, &Service::ParseNamespace}},
541 {"seclabel", {1, 1, &Service::ParseSeclabel}},
542 {"setenv", {2, 2, &Service::ParseSetenv}},
543 {"socket", {3, 6, &Service::ParseSocket}},
Mark Salyzyn978fd0e2016-12-02 08:05:22 -0800544 {"file", {2, 2, &Service::ParseFile}},
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400545 {"user", {1, 1, &Service::ParseUser}},
546 {"writepid", {1, kMax, &Service::ParseWritepid}},
Tom Cherryb7349902015-08-26 11:43:36 -0700547 };
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400548 return option_parsers;
Tom Cherryb7349902015-08-26 11:43:36 -0700549}
550
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400551bool Service::ParseLine(const std::vector<std::string>& args, std::string* err) {
Tom Cherryb7349902015-08-26 11:43:36 -0700552 if (args.empty()) {
553 *err = "option needed, but not provided";
554 return false;
555 }
556
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400557 static const OptionParserMap parser_map;
558 auto parser = parser_map.FindFunction(args[0], args.size() - 1, err);
Tom Cherryb7349902015-08-26 11:43:36 -0700559
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400560 if (!parser) {
Tom Cherryb7349902015-08-26 11:43:36 -0700561 return false;
562 }
563
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -0400564 return (this->*parser)(args, err);
Tom Cherryb7349902015-08-26 11:43:36 -0700565}
566
Elliott Hughesbdeac392016-04-12 15:38:27 -0700567bool Service::Start() {
Tom Cherrybac32992015-07-31 12:45:25 -0700568 // Starting a service removes it from the disabled or reset state and
569 // immediately takes it out of the restarting state if it was in there.
570 flags_ &= (~(SVC_DISABLED|SVC_RESTARTING|SVC_RESET|SVC_RESTART|SVC_DISABLED_START));
Tom Cherrybac32992015-07-31 12:45:25 -0700571
572 // Running processes require no additional work --- if they're in the
573 // process of exiting, we've ensured that they will immediately restart
574 // on exit, unless they are ONESHOT.
575 if (flags_ & SVC_RUNNING) {
576 return false;
577 }
578
579 bool needs_console = (flags_ & SVC_CONSOLE);
Viorel Suman70daa672016-03-21 10:08:07 +0200580 if (needs_console) {
581 if (console_.empty()) {
582 console_ = default_console;
583 }
584
Nick Kralevich9596d2b2016-12-10 12:17:32 -0800585 bool have_console = (access(console_.c_str(), R_OK | W_OK) != -1);
Viorel Suman70daa672016-03-21 10:08:07 +0200586 if (!have_console) {
Nick Kralevich9596d2b2016-12-10 12:17:32 -0800587 PLOG(ERROR) << "service '" << name_ << "' cannot gain read/write access to console '" << console_ << "'";
Viorel Suman70daa672016-03-21 10:08:07 +0200588 flags_ |= SVC_DISABLED;
589 return false;
590 }
Tom Cherrybac32992015-07-31 12:45:25 -0700591 }
592
593 struct stat sb;
594 if (stat(args_[0].c_str(), &sb) == -1) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700595 PLOG(ERROR) << "cannot find '" << args_[0] << "', disabling '" << name_ << "'";
Tom Cherrybac32992015-07-31 12:45:25 -0700596 flags_ |= SVC_DISABLED;
597 return false;
598 }
599
Tom Cherrybac32992015-07-31 12:45:25 -0700600 std::string scon;
601 if (!seclabel_.empty()) {
602 scon = seclabel_;
603 } else {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400604 LOG(INFO) << "computing context for service '" << name_ << "'";
605 scon = ComputeContextFromExecutable(name_, args_[0]);
606 if (scon == "") {
Tom Cherrybac32992015-07-31 12:45:25 -0700607 return false;
608 }
609 }
610
Wei Wanga285dac2016-10-04 14:05:39 -0700611 LOG(INFO) << "starting service '" << name_ << "'...";
Tom Cherrybac32992015-07-31 12:45:25 -0700612
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700613 pid_t pid = -1;
614 if (namespace_flags_) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400615 pid = clone(nullptr, nullptr, namespace_flags_ | SIGCHLD, nullptr);
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700616 } else {
617 pid = fork();
618 }
619
Tom Cherrybac32992015-07-31 12:45:25 -0700620 if (pid == 0) {
Tom Cherrybac32992015-07-31 12:45:25 -0700621 umask(077);
Tom Cherrybac32992015-07-31 12:45:25 -0700622
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700623 if (namespace_flags_ & CLONE_NEWPID) {
624 // This will fork again to run an init process inside the PID
625 // namespace.
626 SetUpPidNamespace(name_);
627 }
628
Tom Cherrybac32992015-07-31 12:45:25 -0700629 for (const auto& ei : envvars_) {
630 add_environment(ei.name.c_str(), ei.value.c_str());
631 }
632
Mark Salyzyn62767fe2016-10-27 07:45:34 -0700633 std::for_each(descriptors_.begin(), descriptors_.end(),
634 std::bind(&DescriptorInfo::CreateAndPublish, std::placeholders::_1, scon));
Tom Cherrybac32992015-07-31 12:45:25 -0700635
Anestis Bechtsoudisb702b462016-02-05 16:38:48 +0200636 std::string pid_str = StringPrintf("%d", getpid());
Tom Cherrybac32992015-07-31 12:45:25 -0700637 for (const auto& file : writepid_files_) {
Tom Cherryb7349902015-08-26 11:43:36 -0700638 if (!WriteStringToFile(pid_str, file)) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700639 PLOG(ERROR) << "couldn't write " << pid_str << " to " << file;
Tom Cherrybac32992015-07-31 12:45:25 -0700640 }
641 }
642
643 if (ioprio_class_ != IoSchedClass_NONE) {
644 if (android_set_ioprio(getpid(), ioprio_class_, ioprio_pri_)) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400645 PLOG(ERROR) << "failed to set pid " << getpid()
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700646 << " ioprio=" << ioprio_class_ << "," << ioprio_pri_;
Tom Cherrybac32992015-07-31 12:45:25 -0700647 }
648 }
649
650 if (needs_console) {
651 setsid();
652 OpenConsole();
653 } else {
654 ZapStdio();
655 }
656
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400657 // As requested, set our gid, supplemental gids, uid, context, and
658 // priority. Aborts on failure.
659 SetProcessAttributes();
Tom Cherrybac32992015-07-31 12:45:25 -0700660
Tom Cherrybac32992015-07-31 12:45:25 -0700661 std::vector<char*> strs;
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400662 ExpandArgs(args_, &strs);
Tom Cherrybac35362016-06-07 11:22:00 -0700663 if (execve(strs[0], (char**) &strs[0], (char**) ENV) < 0) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700664 PLOG(ERROR) << "cannot execve('" << strs[0] << "')";
Tom Cherrybac32992015-07-31 12:45:25 -0700665 }
666
667 _exit(127);
668 }
669
670 if (pid < 0) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700671 PLOG(ERROR) << "failed to fork for '" << name_ << "'";
Tom Cherrybac32992015-07-31 12:45:25 -0700672 pid_ = 0;
673 return false;
674 }
675
Marco Nelissen310f6702016-07-22 12:07:06 -0700676 if (oom_score_adjust_ != -1000) {
677 std::string oom_str = StringPrintf("%d", oom_score_adjust_);
678 std::string oom_file = StringPrintf("/proc/%d/oom_score_adj", pid);
679 if (!WriteStringToFile(oom_str, oom_file)) {
680 PLOG(ERROR) << "couldn't write oom_score_adj: " << strerror(errno);
681 }
682 }
683
Elliott Hughes9605a942016-11-10 17:43:47 -0800684 time_started_ = boot_clock::now();
Tom Cherrybac32992015-07-31 12:45:25 -0700685 pid_ = pid;
686 flags_ |= SVC_RUNNING;
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700687
688 errno = -createProcessGroup(uid_, pid_);
689 if (errno != 0) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400690 PLOG(ERROR) << "createProcessGroup(" << uid_ << ", " << pid_ << ") failed for service '"
691 << name_ << "'";
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700692 }
Tom Cherrybac32992015-07-31 12:45:25 -0700693
694 if ((flags_ & SVC_EXEC) != 0) {
Jorge Lucangeli Obes344d01f2016-07-08 13:32:26 -0400695 LOG(INFO) << android::base::StringPrintf(
696 "SVC_EXEC pid %d (uid %d gid %d+%zu context %s) started; waiting...", pid_, uid_, gid_,
697 supp_gids_.size(), !seclabel_.empty() ? seclabel_.c_str() : "default");
Tom Cherrybac32992015-07-31 12:45:25 -0700698 }
699
700 NotifyStateChange("running");
701 return true;
702}
703
Tom Cherrybac32992015-07-31 12:45:25 -0700704bool Service::StartIfNotDisabled() {
705 if (!(flags_ & SVC_DISABLED)) {
706 return Start();
707 } else {
708 flags_ |= SVC_DISABLED_START;
709 }
710 return true;
711}
712
713bool Service::Enable() {
714 flags_ &= ~(SVC_DISABLED | SVC_RC_DISABLED);
715 if (flags_ & SVC_DISABLED_START) {
716 return Start();
717 }
718 return true;
719}
720
721void Service::Reset() {
722 StopOrReset(SVC_RESET);
723}
724
725void Service::Stop() {
726 StopOrReset(SVC_DISABLED);
727}
728
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800729void Service::Terminate() {
730 flags_ &= ~(SVC_RESTARTING | SVC_DISABLED_START);
731 flags_ |= SVC_DISABLED;
732 if (pid_) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700733 KillProcessGroup(SIGTERM);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800734 NotifyStateChange("stopping");
735 }
736}
737
Tom Cherrybac32992015-07-31 12:45:25 -0700738void Service::Restart() {
739 if (flags_ & SVC_RUNNING) {
740 /* Stop, wait, then start the service. */
741 StopOrReset(SVC_RESTART);
742 } else if (!(flags_ & SVC_RESTARTING)) {
743 /* Just start the service since it's not running. */
744 Start();
745 } /* else: Service is restarting anyways. */
746}
747
Elliott Hughes9605a942016-11-10 17:43:47 -0800748void Service::RestartIfNeeded(time_t* process_needs_restart_at) {
749 boot_clock::time_point now = boot_clock::now();
750 boot_clock::time_point next_start = time_started_ + 5s;
751 if (now > next_start) {
Tom Cherrybac32992015-07-31 12:45:25 -0700752 flags_ &= (~SVC_RESTARTING);
753 Start();
754 return;
755 }
756
Elliott Hughes9605a942016-11-10 17:43:47 -0800757 time_t next_start_time_t = time(nullptr) +
758 time_t(std::chrono::duration_cast<std::chrono::seconds>(next_start - now).count());
759 if (next_start_time_t < *process_needs_restart_at || *process_needs_restart_at == 0) {
760 *process_needs_restart_at = next_start_time_t;
Tom Cherrybac32992015-07-31 12:45:25 -0700761 }
762}
763
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700764// The how field should be either SVC_DISABLED, SVC_RESET, or SVC_RESTART.
Tom Cherrybac32992015-07-31 12:45:25 -0700765void Service::StopOrReset(int how) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700766 // The service is still SVC_RUNNING until its process exits, but if it has
767 // already exited it shoudn't attempt a restart yet.
Tom Cherrybac32992015-07-31 12:45:25 -0700768 flags_ &= ~(SVC_RESTARTING | SVC_DISABLED_START);
769
770 if ((how != SVC_DISABLED) && (how != SVC_RESET) && (how != SVC_RESTART)) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700771 // An illegal flag: default to SVC_DISABLED.
Tom Cherrybac32992015-07-31 12:45:25 -0700772 how = SVC_DISABLED;
773 }
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700774
775 // If the service has not yet started, prevent it from auto-starting with its class.
Tom Cherrybac32992015-07-31 12:45:25 -0700776 if (how == SVC_RESET) {
777 flags_ |= (flags_ & SVC_RC_DISABLED) ? SVC_DISABLED : SVC_RESET;
778 } else {
779 flags_ |= how;
780 }
781
782 if (pid_) {
Elliott Hughesad8e94e2016-06-15 14:49:57 -0700783 KillProcessGroup(SIGKILL);
Tom Cherrybac32992015-07-31 12:45:25 -0700784 NotifyStateChange("stopping");
785 } else {
786 NotifyStateChange("stopped");
787 }
788}
789
790void Service::ZapStdio() const {
791 int fd;
792 fd = open("/dev/null", O_RDWR);
793 dup2(fd, 0);
794 dup2(fd, 1);
795 dup2(fd, 2);
796 close(fd);
797}
798
799void Service::OpenConsole() const {
Viorel Suman70daa672016-03-21 10:08:07 +0200800 int fd = open(console_.c_str(), O_RDWR);
801 if (fd == -1) fd = open("/dev/null", O_RDWR);
Tom Cherrybac32992015-07-31 12:45:25 -0700802 ioctl(fd, TIOCSCTTY, 0);
803 dup2(fd, 0);
804 dup2(fd, 1);
805 dup2(fd, 2);
806 close(fd);
807}
808
Tom Cherrybac32992015-07-31 12:45:25 -0700809int ServiceManager::exec_count_ = 0;
810
811ServiceManager::ServiceManager() {
812}
813
814ServiceManager& ServiceManager::GetInstance() {
815 static ServiceManager instance;
816 return instance;
817}
818
Tom Cherryb7349902015-08-26 11:43:36 -0700819void ServiceManager::AddService(std::unique_ptr<Service> service) {
820 Service* old_service = FindServiceByName(service->name());
821 if (old_service) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700822 LOG(ERROR) << "ignored duplicate definition of service '" << service->name() << "'";
Tom Cherryb7349902015-08-26 11:43:36 -0700823 return;
Tom Cherrybac32992015-07-31 12:45:25 -0700824 }
Tom Cherryb7349902015-08-26 11:43:36 -0700825 services_.emplace_back(std::move(service));
Tom Cherrybac32992015-07-31 12:45:25 -0700826}
827
828Service* ServiceManager::MakeExecOneshotService(const std::vector<std::string>& args) {
829 // Parse the arguments: exec [SECLABEL [UID [GID]*] --] COMMAND ARGS...
830 // SECLABEL can be a - to denote default
831 std::size_t command_arg = 1;
832 for (std::size_t i = 1; i < args.size(); ++i) {
833 if (args[i] == "--") {
834 command_arg = i + 1;
835 break;
836 }
837 }
838 if (command_arg > 4 + NR_SVC_SUPP_GIDS) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700839 LOG(ERROR) << "exec called with too many supplementary group ids";
Tom Cherrybac32992015-07-31 12:45:25 -0700840 return nullptr;
841 }
842
843 if (command_arg >= args.size()) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700844 LOG(ERROR) << "exec called without command";
Tom Cherrybac32992015-07-31 12:45:25 -0700845 return nullptr;
846 }
847 std::vector<std::string> str_args(args.begin() + command_arg, args.end());
848
849 exec_count_++;
Tom Cherryb7349902015-08-26 11:43:36 -0700850 std::string name = StringPrintf("exec %d (%s)", exec_count_, str_args[0].c_str());
Tom Cherrybac32992015-07-31 12:45:25 -0700851 unsigned flags = SVC_EXEC | SVC_ONESHOT;
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400852 CapSet no_capabilities;
Jorge Lucangeli Obes1b3fa3d2016-04-21 15:35:09 -0700853 unsigned namespace_flags = 0;
Tom Cherrybac32992015-07-31 12:45:25 -0700854
855 std::string seclabel = "";
856 if (command_arg > 2 && args[1] != "-") {
857 seclabel = args[1];
858 }
859 uid_t uid = 0;
860 if (command_arg > 3) {
861 uid = decode_uid(args[2].c_str());
862 }
863 gid_t gid = 0;
864 std::vector<gid_t> supp_gids;
865 if (command_arg > 4) {
866 gid = decode_uid(args[3].c_str());
867 std::size_t nr_supp_gids = command_arg - 1 /* -- */ - 4 /* exec SECLABEL UID GID */;
868 for (size_t i = 0; i < nr_supp_gids; ++i) {
869 supp_gids.push_back(decode_uid(args[4 + i].c_str()));
870 }
871 }
872
Jorge Lucangeli Obes24b29132016-10-27 10:33:03 -0400873 std::unique_ptr<Service> svc_p(new Service(name, "default", flags, uid, gid, supp_gids,
874 no_capabilities, namespace_flags, seclabel,
875 str_args));
Tom Cherrybac32992015-07-31 12:45:25 -0700876 if (!svc_p) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700877 LOG(ERROR) << "Couldn't allocate service for exec of '" << str_args[0] << "'";
Tom Cherrybac32992015-07-31 12:45:25 -0700878 return nullptr;
879 }
880 Service* svc = svc_p.get();
881 services_.push_back(std::move(svc_p));
882
883 return svc;
884}
885
886Service* ServiceManager::FindServiceByName(const std::string& name) const {
887 auto svc = std::find_if(services_.begin(), services_.end(),
888 [&name] (const std::unique_ptr<Service>& s) {
889 return name == s->name();
890 });
891 if (svc != services_.end()) {
892 return svc->get();
893 }
894 return nullptr;
895}
896
897Service* ServiceManager::FindServiceByPid(pid_t pid) const {
898 auto svc = std::find_if(services_.begin(), services_.end(),
899 [&pid] (const std::unique_ptr<Service>& s) {
900 return s->pid() == pid;
901 });
902 if (svc != services_.end()) {
903 return svc->get();
904 }
905 return nullptr;
906}
907
908Service* ServiceManager::FindServiceByKeychord(int keychord_id) const {
909 auto svc = std::find_if(services_.begin(), services_.end(),
910 [&keychord_id] (const std::unique_ptr<Service>& s) {
911 return s->keychord_id() == keychord_id;
912 });
913
914 if (svc != services_.end()) {
915 return svc->get();
916 }
917 return nullptr;
918}
919
Chih-Hung Hsieh8f7b9e32016-07-27 16:25:51 -0700920void ServiceManager::ForEachService(const std::function<void(Service*)>& callback) const {
Tom Cherrybac32992015-07-31 12:45:25 -0700921 for (const auto& s : services_) {
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800922 callback(s.get());
Tom Cherrybac32992015-07-31 12:45:25 -0700923 }
924}
925
926void ServiceManager::ForEachServiceInClass(const std::string& classname,
927 void (*func)(Service* svc)) const {
928 for (const auto& s : services_) {
929 if (classname == s->classname()) {
930 func(s.get());
931 }
932 }
933}
934
935void ServiceManager::ForEachServiceWithFlags(unsigned matchflags,
936 void (*func)(Service* svc)) const {
937 for (const auto& s : services_) {
938 if (s->flags() & matchflags) {
939 func(s.get());
940 }
941 }
942}
943
Tom Cherryb7349902015-08-26 11:43:36 -0700944void ServiceManager::RemoveService(const Service& svc) {
Tom Cherrybac32992015-07-31 12:45:25 -0700945 auto svc_it = std::find_if(services_.begin(), services_.end(),
946 [&svc] (const std::unique_ptr<Service>& s) {
947 return svc.name() == s->name();
948 });
949 if (svc_it == services_.end()) {
950 return;
951 }
952
953 services_.erase(svc_it);
954}
955
Tom Cherryb7349902015-08-26 11:43:36 -0700956void ServiceManager::DumpState() const {
957 for (const auto& s : services_) {
958 s->DumpState();
959 }
Tom Cherryb7349902015-08-26 11:43:36 -0700960}
961
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800962bool ServiceManager::ReapOneProcess() {
963 int status;
964 pid_t pid = TEMP_FAILURE_RETRY(waitpid(-1, &status, WNOHANG));
965 if (pid == 0) {
966 return false;
967 } else if (pid == -1) {
Elliott Hughesf86b5a62016-06-24 15:12:21 -0700968 PLOG(ERROR) << "waitpid failed";
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800969 return false;
970 }
971
972 Service* svc = FindServiceByPid(pid);
973
974 std::string name;
975 if (svc) {
976 name = android::base::StringPrintf("Service '%s' (pid %d)",
977 svc->name().c_str(), pid);
978 } else {
979 name = android::base::StringPrintf("Untracked pid %d", pid);
980 }
981
982 if (WIFEXITED(status)) {
Wei Wanga285dac2016-10-04 14:05:39 -0700983 LOG(INFO) << name << " exited with status " << WEXITSTATUS(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800984 } else if (WIFSIGNALED(status)) {
Wei Wanga285dac2016-10-04 14:05:39 -0700985 LOG(INFO) << name << " killed by signal " << WTERMSIG(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800986 } else if (WIFSTOPPED(status)) {
Wei Wanga285dac2016-10-04 14:05:39 -0700987 LOG(INFO) << name << " stopped by signal " << WSTOPSIG(status);
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800988 } else {
Wei Wanga285dac2016-10-04 14:05:39 -0700989 LOG(INFO) << name << " state changed";
Bertrand SIMONNETb7e03e82015-12-18 11:39:59 -0800990 }
991
992 if (!svc) {
993 return true;
994 }
995
996 if (svc->Reap()) {
997 waiting_for_exec = false;
998 RemoveService(*svc);
999 }
1000
1001 return true;
1002}
1003
1004void ServiceManager::ReapAnyOutstandingChildren() {
1005 while (ReapOneProcess()) {
1006 }
1007}
1008
Tom Cherryb7349902015-08-26 11:43:36 -07001009bool ServiceParser::ParseSection(const std::vector<std::string>& args,
1010 std::string* err) {
1011 if (args.size() < 3) {
1012 *err = "services must have a name and a program";
1013 return false;
1014 }
1015
1016 const std::string& name = args[1];
1017 if (!IsValidName(name)) {
1018 *err = StringPrintf("invalid service name '%s'", name.c_str());
1019 return false;
1020 }
1021
1022 std::vector<std::string> str_args(args.begin() + 2, args.end());
1023 service_ = std::make_unique<Service>(name, "default", str_args);
1024 return true;
1025}
1026
1027bool ServiceParser::ParseLineSection(const std::vector<std::string>& args,
1028 const std::string& filename, int line,
1029 std::string* err) const {
Jorge Lucangeli Obes177b27d2016-06-29 14:32:49 -04001030 return service_ ? service_->ParseLine(args, err) : false;
Tom Cherryb7349902015-08-26 11:43:36 -07001031}
1032
1033void ServiceParser::EndSection() {
1034 if (service_) {
1035 ServiceManager::GetInstance().AddService(std::move(service_));
1036 }
1037}
1038
1039bool ServiceParser::IsValidName(const std::string& name) const {
Iliyan Malchevf6554802016-09-19 20:58:20 -07001040 return is_legal_property_name("init.svc." + name);
Tom Cherrybac32992015-07-31 12:45:25 -07001041}