1*f40fafd4SAndroid Build Coastguard Worker /*
2*f40fafd4SAndroid Build Coastguard Worker * Copyright (C) 2008 The Android Open Source Project
3*f40fafd4SAndroid Build Coastguard Worker *
4*f40fafd4SAndroid Build Coastguard Worker * Licensed under the Apache License, Version 2.0 (the "License");
5*f40fafd4SAndroid Build Coastguard Worker * you may not use this file except in compliance with the License.
6*f40fafd4SAndroid Build Coastguard Worker * You may obtain a copy of the License at
7*f40fafd4SAndroid Build Coastguard Worker *
8*f40fafd4SAndroid Build Coastguard Worker * http://www.apache.org/licenses/LICENSE-2.0
9*f40fafd4SAndroid Build Coastguard Worker *
10*f40fafd4SAndroid Build Coastguard Worker * Unless required by applicable law or agreed to in writing, software
11*f40fafd4SAndroid Build Coastguard Worker * distributed under the License is distributed on an "AS IS" BASIS,
12*f40fafd4SAndroid Build Coastguard Worker * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13*f40fafd4SAndroid Build Coastguard Worker * See the License for the specific language governing permissions and
14*f40fafd4SAndroid Build Coastguard Worker * limitations under the License.
15*f40fafd4SAndroid Build Coastguard Worker */
16*f40fafd4SAndroid Build Coastguard Worker
17*f40fafd4SAndroid Build Coastguard Worker #define ATRACE_TAG ATRACE_TAG_PACKAGE_MANAGER
18*f40fafd4SAndroid Build Coastguard Worker
19*f40fafd4SAndroid Build Coastguard Worker #include <dirent.h>
20*f40fafd4SAndroid Build Coastguard Worker #include <errno.h>
21*f40fafd4SAndroid Build Coastguard Worker #include <fcntl.h>
22*f40fafd4SAndroid Build Coastguard Worker #include <limits.h>
23*f40fafd4SAndroid Build Coastguard Worker #include <mntent.h>
24*f40fafd4SAndroid Build Coastguard Worker #include <stdio.h>
25*f40fafd4SAndroid Build Coastguard Worker #include <stdlib.h>
26*f40fafd4SAndroid Build Coastguard Worker #include <string.h>
27*f40fafd4SAndroid Build Coastguard Worker #include <sys/ioctl.h>
28*f40fafd4SAndroid Build Coastguard Worker #include <sys/mount.h>
29*f40fafd4SAndroid Build Coastguard Worker #include <sys/stat.h>
30*f40fafd4SAndroid Build Coastguard Worker #include <sys/sysmacros.h>
31*f40fafd4SAndroid Build Coastguard Worker #include <sys/types.h>
32*f40fafd4SAndroid Build Coastguard Worker #include <sys/wait.h>
33*f40fafd4SAndroid Build Coastguard Worker #include <unistd.h>
34*f40fafd4SAndroid Build Coastguard Worker #include <array>
35*f40fafd4SAndroid Build Coastguard Worker
36*f40fafd4SAndroid Build Coastguard Worker #include <linux/kdev_t.h>
37*f40fafd4SAndroid Build Coastguard Worker
38*f40fafd4SAndroid Build Coastguard Worker #include <android-base/file.h>
39*f40fafd4SAndroid Build Coastguard Worker #include <android-base/logging.h>
40*f40fafd4SAndroid Build Coastguard Worker #include <android-base/parseint.h>
41*f40fafd4SAndroid Build Coastguard Worker #include <android-base/properties.h>
42*f40fafd4SAndroid Build Coastguard Worker #include <android-base/stringprintf.h>
43*f40fafd4SAndroid Build Coastguard Worker #include <android-base/strings.h>
44*f40fafd4SAndroid Build Coastguard Worker #include <async_safe/log.h>
45*f40fafd4SAndroid Build Coastguard Worker
46*f40fafd4SAndroid Build Coastguard Worker #include <cutils/fs.h>
47*f40fafd4SAndroid Build Coastguard Worker #include <utils/Trace.h>
48*f40fafd4SAndroid Build Coastguard Worker
49*f40fafd4SAndroid Build Coastguard Worker #include <selinux/android.h>
50*f40fafd4SAndroid Build Coastguard Worker
51*f40fafd4SAndroid Build Coastguard Worker #include <sysutils/NetlinkEvent.h>
52*f40fafd4SAndroid Build Coastguard Worker
53*f40fafd4SAndroid Build Coastguard Worker #include <private/android_filesystem_config.h>
54*f40fafd4SAndroid Build Coastguard Worker
55*f40fafd4SAndroid Build Coastguard Worker #include <fscrypt/fscrypt.h>
56*f40fafd4SAndroid Build Coastguard Worker #include <libdm/dm.h>
57*f40fafd4SAndroid Build Coastguard Worker
58*f40fafd4SAndroid Build Coastguard Worker #include "AppFuseUtil.h"
59*f40fafd4SAndroid Build Coastguard Worker #include "FsCrypt.h"
60*f40fafd4SAndroid Build Coastguard Worker #include "Loop.h"
61*f40fafd4SAndroid Build Coastguard Worker #include "NetlinkManager.h"
62*f40fafd4SAndroid Build Coastguard Worker #include "Process.h"
63*f40fafd4SAndroid Build Coastguard Worker #include "Utils.h"
64*f40fafd4SAndroid Build Coastguard Worker #include "VoldNativeService.h"
65*f40fafd4SAndroid Build Coastguard Worker #include "VoldUtil.h"
66*f40fafd4SAndroid Build Coastguard Worker #include "VolumeManager.h"
67*f40fafd4SAndroid Build Coastguard Worker #include "fs/Ext4.h"
68*f40fafd4SAndroid Build Coastguard Worker #include "fs/Vfat.h"
69*f40fafd4SAndroid Build Coastguard Worker #include "model/EmulatedVolume.h"
70*f40fafd4SAndroid Build Coastguard Worker #include "model/ObbVolume.h"
71*f40fafd4SAndroid Build Coastguard Worker #include "model/PrivateVolume.h"
72*f40fafd4SAndroid Build Coastguard Worker #include "model/PublicVolume.h"
73*f40fafd4SAndroid Build Coastguard Worker #include "model/StubVolume.h"
74*f40fafd4SAndroid Build Coastguard Worker
75*f40fafd4SAndroid Build Coastguard Worker using android::OK;
76*f40fafd4SAndroid Build Coastguard Worker using android::base::GetBoolProperty;
77*f40fafd4SAndroid Build Coastguard Worker using android::base::StartsWith;
78*f40fafd4SAndroid Build Coastguard Worker using android::base::StringAppendF;
79*f40fafd4SAndroid Build Coastguard Worker using android::base::StringPrintf;
80*f40fafd4SAndroid Build Coastguard Worker using android::base::unique_fd;
81*f40fafd4SAndroid Build Coastguard Worker using android::vold::BindMount;
82*f40fafd4SAndroid Build Coastguard Worker using android::vold::CreateDir;
83*f40fafd4SAndroid Build Coastguard Worker using android::vold::DeleteDirContents;
84*f40fafd4SAndroid Build Coastguard Worker using android::vold::DeleteDirContentsAndDir;
85*f40fafd4SAndroid Build Coastguard Worker using android::vold::EnsureDirExists;
86*f40fafd4SAndroid Build Coastguard Worker using android::vold::GetFuseMountPathForUser;
87*f40fafd4SAndroid Build Coastguard Worker using android::vold::IsFilesystemSupported;
88*f40fafd4SAndroid Build Coastguard Worker using android::vold::IsSdcardfsUsed;
89*f40fafd4SAndroid Build Coastguard Worker using android::vold::IsVirtioBlkDevice;
90*f40fafd4SAndroid Build Coastguard Worker using android::vold::PrepareAndroidDirs;
91*f40fafd4SAndroid Build Coastguard Worker using android::vold::PrepareAppDirFromRoot;
92*f40fafd4SAndroid Build Coastguard Worker using android::vold::PrivateVolume;
93*f40fafd4SAndroid Build Coastguard Worker using android::vold::PublicVolume;
94*f40fafd4SAndroid Build Coastguard Worker using android::vold::Symlink;
95*f40fafd4SAndroid Build Coastguard Worker using android::vold::Unlink;
96*f40fafd4SAndroid Build Coastguard Worker using android::vold::UnmountTree;
97*f40fafd4SAndroid Build Coastguard Worker using android::vold::VoldNativeService;
98*f40fafd4SAndroid Build Coastguard Worker using android::vold::VolumeBase;
99*f40fafd4SAndroid Build Coastguard Worker
100*f40fafd4SAndroid Build Coastguard Worker static const char* kPathVirtualDisk = "/data/misc/vold/virtual_disk";
101*f40fafd4SAndroid Build Coastguard Worker
102*f40fafd4SAndroid Build Coastguard Worker static const char* kPropVirtualDisk = "persist.sys.virtual_disk";
103*f40fafd4SAndroid Build Coastguard Worker
104*f40fafd4SAndroid Build Coastguard Worker /* 512MiB is large enough for testing purposes */
105*f40fafd4SAndroid Build Coastguard Worker static const unsigned int kSizeVirtualDisk = 536870912;
106*f40fafd4SAndroid Build Coastguard Worker
107*f40fafd4SAndroid Build Coastguard Worker static const unsigned int kMajorBlockMmc = 179;
108*f40fafd4SAndroid Build Coastguard Worker
109*f40fafd4SAndroid Build Coastguard Worker using ScanProcCallback = bool(*)(uid_t uid, pid_t pid, int nsFd, const char* name, void* params);
110*f40fafd4SAndroid Build Coastguard Worker
111*f40fafd4SAndroid Build Coastguard Worker VolumeManager* VolumeManager::sInstance = NULL;
112*f40fafd4SAndroid Build Coastguard Worker
Instance()113*f40fafd4SAndroid Build Coastguard Worker VolumeManager* VolumeManager::Instance() {
114*f40fafd4SAndroid Build Coastguard Worker if (!sInstance) sInstance = new VolumeManager();
115*f40fafd4SAndroid Build Coastguard Worker return sInstance;
116*f40fafd4SAndroid Build Coastguard Worker }
117*f40fafd4SAndroid Build Coastguard Worker
VolumeManager()118*f40fafd4SAndroid Build Coastguard Worker VolumeManager::VolumeManager() {
119*f40fafd4SAndroid Build Coastguard Worker mDebug = false;
120*f40fafd4SAndroid Build Coastguard Worker mNextObbId = 0;
121*f40fafd4SAndroid Build Coastguard Worker mNextStubId = 0;
122*f40fafd4SAndroid Build Coastguard Worker // For security reasons, assume that a secure keyguard is
123*f40fafd4SAndroid Build Coastguard Worker // showing until we hear otherwise
124*f40fafd4SAndroid Build Coastguard Worker mSecureKeyguardShowing = true;
125*f40fafd4SAndroid Build Coastguard Worker }
126*f40fafd4SAndroid Build Coastguard Worker
~VolumeManager()127*f40fafd4SAndroid Build Coastguard Worker VolumeManager::~VolumeManager() {}
128*f40fafd4SAndroid Build Coastguard Worker
updateVirtualDisk()129*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::updateVirtualDisk() {
130*f40fafd4SAndroid Build Coastguard Worker ATRACE_NAME("VolumeManager::updateVirtualDisk");
131*f40fafd4SAndroid Build Coastguard Worker if (GetBoolProperty(kPropVirtualDisk, false)) {
132*f40fafd4SAndroid Build Coastguard Worker if (access(kPathVirtualDisk, F_OK) != 0) {
133*f40fafd4SAndroid Build Coastguard Worker Loop::createImageFile(kPathVirtualDisk, kSizeVirtualDisk / 512);
134*f40fafd4SAndroid Build Coastguard Worker }
135*f40fafd4SAndroid Build Coastguard Worker
136*f40fafd4SAndroid Build Coastguard Worker if (mVirtualDisk == nullptr) {
137*f40fafd4SAndroid Build Coastguard Worker if (Loop::create(kPathVirtualDisk, mVirtualDiskPath) != 0) {
138*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "Failed to create virtual disk";
139*f40fafd4SAndroid Build Coastguard Worker return -1;
140*f40fafd4SAndroid Build Coastguard Worker }
141*f40fafd4SAndroid Build Coastguard Worker
142*f40fafd4SAndroid Build Coastguard Worker struct stat buf;
143*f40fafd4SAndroid Build Coastguard Worker if (stat(mVirtualDiskPath.c_str(), &buf) < 0) {
144*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Failed to stat " << mVirtualDiskPath;
145*f40fafd4SAndroid Build Coastguard Worker return -1;
146*f40fafd4SAndroid Build Coastguard Worker }
147*f40fafd4SAndroid Build Coastguard Worker
148*f40fafd4SAndroid Build Coastguard Worker auto disk = new android::vold::Disk(
149*f40fafd4SAndroid Build Coastguard Worker "virtual", buf.st_rdev, "virtual",
150*f40fafd4SAndroid Build Coastguard Worker android::vold::Disk::Flags::kAdoptable | android::vold::Disk::Flags::kSd);
151*f40fafd4SAndroid Build Coastguard Worker mVirtualDisk = std::shared_ptr<android::vold::Disk>(disk);
152*f40fafd4SAndroid Build Coastguard Worker handleDiskAdded(mVirtualDisk);
153*f40fafd4SAndroid Build Coastguard Worker }
154*f40fafd4SAndroid Build Coastguard Worker } else {
155*f40fafd4SAndroid Build Coastguard Worker if (mVirtualDisk != nullptr) {
156*f40fafd4SAndroid Build Coastguard Worker dev_t device = mVirtualDisk->getDevice();
157*f40fafd4SAndroid Build Coastguard Worker handleDiskRemoved(device);
158*f40fafd4SAndroid Build Coastguard Worker
159*f40fafd4SAndroid Build Coastguard Worker Loop::destroyByDevice(mVirtualDiskPath.c_str());
160*f40fafd4SAndroid Build Coastguard Worker mVirtualDisk = nullptr;
161*f40fafd4SAndroid Build Coastguard Worker }
162*f40fafd4SAndroid Build Coastguard Worker
163*f40fafd4SAndroid Build Coastguard Worker if (access(kPathVirtualDisk, F_OK) == 0) {
164*f40fafd4SAndroid Build Coastguard Worker unlink(kPathVirtualDisk);
165*f40fafd4SAndroid Build Coastguard Worker }
166*f40fafd4SAndroid Build Coastguard Worker }
167*f40fafd4SAndroid Build Coastguard Worker return 0;
168*f40fafd4SAndroid Build Coastguard Worker }
169*f40fafd4SAndroid Build Coastguard Worker
setDebug(bool enable)170*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::setDebug(bool enable) {
171*f40fafd4SAndroid Build Coastguard Worker mDebug = enable;
172*f40fafd4SAndroid Build Coastguard Worker return 0;
173*f40fafd4SAndroid Build Coastguard Worker }
174*f40fafd4SAndroid Build Coastguard Worker
start()175*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::start() {
176*f40fafd4SAndroid Build Coastguard Worker ATRACE_NAME("VolumeManager::start");
177*f40fafd4SAndroid Build Coastguard Worker
178*f40fafd4SAndroid Build Coastguard Worker // Always start from a clean slate by unmounting everything in
179*f40fafd4SAndroid Build Coastguard Worker // directories that we own, in case we crashed.
180*f40fafd4SAndroid Build Coastguard Worker unmountAll();
181*f40fafd4SAndroid Build Coastguard Worker
182*f40fafd4SAndroid Build Coastguard Worker Loop::destroyAll();
183*f40fafd4SAndroid Build Coastguard Worker
184*f40fafd4SAndroid Build Coastguard Worker // Assume that we always have an emulated volume on internal
185*f40fafd4SAndroid Build Coastguard Worker // storage; the framework will decide if it should be mounted.
186*f40fafd4SAndroid Build Coastguard Worker CHECK(mInternalEmulatedVolumes.empty());
187*f40fafd4SAndroid Build Coastguard Worker
188*f40fafd4SAndroid Build Coastguard Worker auto vol = std::shared_ptr<android::vold::VolumeBase>(
189*f40fafd4SAndroid Build Coastguard Worker new android::vold::EmulatedVolume("/data/media", 0));
190*f40fafd4SAndroid Build Coastguard Worker vol->setMountUserId(0);
191*f40fafd4SAndroid Build Coastguard Worker vol->create();
192*f40fafd4SAndroid Build Coastguard Worker mInternalEmulatedVolumes.push_back(vol);
193*f40fafd4SAndroid Build Coastguard Worker
194*f40fafd4SAndroid Build Coastguard Worker // Consider creating a virtual disk
195*f40fafd4SAndroid Build Coastguard Worker updateVirtualDisk();
196*f40fafd4SAndroid Build Coastguard Worker
197*f40fafd4SAndroid Build Coastguard Worker return 0;
198*f40fafd4SAndroid Build Coastguard Worker }
199*f40fafd4SAndroid Build Coastguard Worker
handleBlockEvent(NetlinkEvent * evt)200*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::handleBlockEvent(NetlinkEvent* evt) {
201*f40fafd4SAndroid Build Coastguard Worker std::lock_guard<std::mutex> lock(mLock);
202*f40fafd4SAndroid Build Coastguard Worker
203*f40fafd4SAndroid Build Coastguard Worker if (mDebug) {
204*f40fafd4SAndroid Build Coastguard Worker LOG(DEBUG) << "----------------";
205*f40fafd4SAndroid Build Coastguard Worker LOG(DEBUG) << "handleBlockEvent with action " << (int)evt->getAction();
206*f40fafd4SAndroid Build Coastguard Worker evt->dump();
207*f40fafd4SAndroid Build Coastguard Worker }
208*f40fafd4SAndroid Build Coastguard Worker
209*f40fafd4SAndroid Build Coastguard Worker std::string eventPath(evt->findParam("DEVPATH") ? evt->findParam("DEVPATH") : "");
210*f40fafd4SAndroid Build Coastguard Worker std::string devType(evt->findParam("DEVTYPE") ? evt->findParam("DEVTYPE") : "");
211*f40fafd4SAndroid Build Coastguard Worker
212*f40fafd4SAndroid Build Coastguard Worker if (devType != "disk") return;
213*f40fafd4SAndroid Build Coastguard Worker
214*f40fafd4SAndroid Build Coastguard Worker int major = std::stoi(evt->findParam("MAJOR"));
215*f40fafd4SAndroid Build Coastguard Worker int minor = std::stoi(evt->findParam("MINOR"));
216*f40fafd4SAndroid Build Coastguard Worker dev_t device = makedev(major, minor);
217*f40fafd4SAndroid Build Coastguard Worker
218*f40fafd4SAndroid Build Coastguard Worker switch (evt->getAction()) {
219*f40fafd4SAndroid Build Coastguard Worker case NetlinkEvent::Action::kAdd: {
220*f40fafd4SAndroid Build Coastguard Worker for (const auto& source : mDiskSources) {
221*f40fafd4SAndroid Build Coastguard Worker if (source->matches(eventPath)) {
222*f40fafd4SAndroid Build Coastguard Worker // For now, assume that MMC and virtio-blk (the latter is
223*f40fafd4SAndroid Build Coastguard Worker // specific to virtual platforms; see Utils.cpp for details)
224*f40fafd4SAndroid Build Coastguard Worker // devices are SD, and that everything else is USB
225*f40fafd4SAndroid Build Coastguard Worker int flags = source->getFlags();
226*f40fafd4SAndroid Build Coastguard Worker if (major == kMajorBlockMmc || IsVirtioBlkDevice(major)) {
227*f40fafd4SAndroid Build Coastguard Worker flags |= android::vold::Disk::Flags::kSd;
228*f40fafd4SAndroid Build Coastguard Worker } else {
229*f40fafd4SAndroid Build Coastguard Worker flags |= android::vold::Disk::Flags::kUsb;
230*f40fafd4SAndroid Build Coastguard Worker }
231*f40fafd4SAndroid Build Coastguard Worker
232*f40fafd4SAndroid Build Coastguard Worker auto disk =
233*f40fafd4SAndroid Build Coastguard Worker new android::vold::Disk(eventPath, device, source->getNickname(), flags);
234*f40fafd4SAndroid Build Coastguard Worker handleDiskAdded(std::shared_ptr<android::vold::Disk>(disk));
235*f40fafd4SAndroid Build Coastguard Worker break;
236*f40fafd4SAndroid Build Coastguard Worker }
237*f40fafd4SAndroid Build Coastguard Worker }
238*f40fafd4SAndroid Build Coastguard Worker break;
239*f40fafd4SAndroid Build Coastguard Worker }
240*f40fafd4SAndroid Build Coastguard Worker case NetlinkEvent::Action::kChange: {
241*f40fafd4SAndroid Build Coastguard Worker LOG(VERBOSE) << "Disk at " << major << ":" << minor << " changed";
242*f40fafd4SAndroid Build Coastguard Worker handleDiskChanged(device);
243*f40fafd4SAndroid Build Coastguard Worker break;
244*f40fafd4SAndroid Build Coastguard Worker }
245*f40fafd4SAndroid Build Coastguard Worker case NetlinkEvent::Action::kRemove: {
246*f40fafd4SAndroid Build Coastguard Worker handleDiskRemoved(device);
247*f40fafd4SAndroid Build Coastguard Worker break;
248*f40fafd4SAndroid Build Coastguard Worker }
249*f40fafd4SAndroid Build Coastguard Worker default: {
250*f40fafd4SAndroid Build Coastguard Worker LOG(WARNING) << "Unexpected block event action " << (int)evt->getAction();
251*f40fafd4SAndroid Build Coastguard Worker break;
252*f40fafd4SAndroid Build Coastguard Worker }
253*f40fafd4SAndroid Build Coastguard Worker }
254*f40fafd4SAndroid Build Coastguard Worker }
255*f40fafd4SAndroid Build Coastguard Worker
handleDiskAdded(const std::shared_ptr<android::vold::Disk> & disk)256*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::handleDiskAdded(const std::shared_ptr<android::vold::Disk>& disk) {
257*f40fafd4SAndroid Build Coastguard Worker // For security reasons, if secure keyguard is showing, wait
258*f40fafd4SAndroid Build Coastguard Worker // until the user unlocks the device to actually touch it
259*f40fafd4SAndroid Build Coastguard Worker // Additionally, wait until user 0 is actually started, since we need
260*f40fafd4SAndroid Build Coastguard Worker // the user to be up before we can mount a FUSE daemon to handle the disk.
261*f40fafd4SAndroid Build Coastguard Worker bool userZeroStarted = mStartedUsers.find(0) != mStartedUsers.end();
262*f40fafd4SAndroid Build Coastguard Worker if (mSecureKeyguardShowing) {
263*f40fafd4SAndroid Build Coastguard Worker LOG(INFO) << "Found disk at " << disk->getEventPath()
264*f40fafd4SAndroid Build Coastguard Worker << " but delaying scan due to secure keyguard";
265*f40fafd4SAndroid Build Coastguard Worker mPendingDisks.push_back(disk);
266*f40fafd4SAndroid Build Coastguard Worker } else if (!userZeroStarted) {
267*f40fafd4SAndroid Build Coastguard Worker LOG(INFO) << "Found disk at " << disk->getEventPath()
268*f40fafd4SAndroid Build Coastguard Worker << " but delaying scan due to user zero not having started";
269*f40fafd4SAndroid Build Coastguard Worker mPendingDisks.push_back(disk);
270*f40fafd4SAndroid Build Coastguard Worker } else {
271*f40fafd4SAndroid Build Coastguard Worker disk->create();
272*f40fafd4SAndroid Build Coastguard Worker mDisks.push_back(disk);
273*f40fafd4SAndroid Build Coastguard Worker }
274*f40fafd4SAndroid Build Coastguard Worker }
275*f40fafd4SAndroid Build Coastguard Worker
handleDiskChanged(dev_t device)276*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::handleDiskChanged(dev_t device) {
277*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
278*f40fafd4SAndroid Build Coastguard Worker if (disk->getDevice() == device) {
279*f40fafd4SAndroid Build Coastguard Worker disk->readMetadata();
280*f40fafd4SAndroid Build Coastguard Worker disk->readPartitions();
281*f40fafd4SAndroid Build Coastguard Worker }
282*f40fafd4SAndroid Build Coastguard Worker }
283*f40fafd4SAndroid Build Coastguard Worker
284*f40fafd4SAndroid Build Coastguard Worker // For security reasons, we ignore all pending disks, since
285*f40fafd4SAndroid Build Coastguard Worker // we'll scan them once the device is unlocked
286*f40fafd4SAndroid Build Coastguard Worker }
287*f40fafd4SAndroid Build Coastguard Worker
handleDiskRemoved(dev_t device)288*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::handleDiskRemoved(dev_t device) {
289*f40fafd4SAndroid Build Coastguard Worker auto i = mDisks.begin();
290*f40fafd4SAndroid Build Coastguard Worker while (i != mDisks.end()) {
291*f40fafd4SAndroid Build Coastguard Worker if ((*i)->getDevice() == device) {
292*f40fafd4SAndroid Build Coastguard Worker (*i)->destroy();
293*f40fafd4SAndroid Build Coastguard Worker i = mDisks.erase(i);
294*f40fafd4SAndroid Build Coastguard Worker } else {
295*f40fafd4SAndroid Build Coastguard Worker ++i;
296*f40fafd4SAndroid Build Coastguard Worker }
297*f40fafd4SAndroid Build Coastguard Worker }
298*f40fafd4SAndroid Build Coastguard Worker auto j = mPendingDisks.begin();
299*f40fafd4SAndroid Build Coastguard Worker while (j != mPendingDisks.end()) {
300*f40fafd4SAndroid Build Coastguard Worker if ((*j)->getDevice() == device) {
301*f40fafd4SAndroid Build Coastguard Worker j = mPendingDisks.erase(j);
302*f40fafd4SAndroid Build Coastguard Worker } else {
303*f40fafd4SAndroid Build Coastguard Worker ++j;
304*f40fafd4SAndroid Build Coastguard Worker }
305*f40fafd4SAndroid Build Coastguard Worker }
306*f40fafd4SAndroid Build Coastguard Worker }
307*f40fafd4SAndroid Build Coastguard Worker
addDiskSource(const std::shared_ptr<DiskSource> & diskSource)308*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::addDiskSource(const std::shared_ptr<DiskSource>& diskSource) {
309*f40fafd4SAndroid Build Coastguard Worker std::lock_guard<std::mutex> lock(mLock);
310*f40fafd4SAndroid Build Coastguard Worker mDiskSources.push_back(diskSource);
311*f40fafd4SAndroid Build Coastguard Worker }
312*f40fafd4SAndroid Build Coastguard Worker
findDisk(const std::string & id)313*f40fafd4SAndroid Build Coastguard Worker std::shared_ptr<android::vold::Disk> VolumeManager::findDisk(const std::string& id) {
314*f40fafd4SAndroid Build Coastguard Worker for (auto disk : mDisks) {
315*f40fafd4SAndroid Build Coastguard Worker if (disk->getId() == id) {
316*f40fafd4SAndroid Build Coastguard Worker return disk;
317*f40fafd4SAndroid Build Coastguard Worker }
318*f40fafd4SAndroid Build Coastguard Worker }
319*f40fafd4SAndroid Build Coastguard Worker return nullptr;
320*f40fafd4SAndroid Build Coastguard Worker }
321*f40fafd4SAndroid Build Coastguard Worker
findVolume(const std::string & id)322*f40fafd4SAndroid Build Coastguard Worker std::shared_ptr<android::vold::VolumeBase> VolumeManager::findVolume(const std::string& id) {
323*f40fafd4SAndroid Build Coastguard Worker for (const auto& vol : mInternalEmulatedVolumes) {
324*f40fafd4SAndroid Build Coastguard Worker if (vol->getId() == id) {
325*f40fafd4SAndroid Build Coastguard Worker return vol;
326*f40fafd4SAndroid Build Coastguard Worker }
327*f40fafd4SAndroid Build Coastguard Worker }
328*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
329*f40fafd4SAndroid Build Coastguard Worker auto vol = disk->findVolume(id);
330*f40fafd4SAndroid Build Coastguard Worker if (vol != nullptr) {
331*f40fafd4SAndroid Build Coastguard Worker return vol;
332*f40fafd4SAndroid Build Coastguard Worker }
333*f40fafd4SAndroid Build Coastguard Worker }
334*f40fafd4SAndroid Build Coastguard Worker for (const auto& vol : mObbVolumes) {
335*f40fafd4SAndroid Build Coastguard Worker if (vol->getId() == id) {
336*f40fafd4SAndroid Build Coastguard Worker return vol;
337*f40fafd4SAndroid Build Coastguard Worker }
338*f40fafd4SAndroid Build Coastguard Worker }
339*f40fafd4SAndroid Build Coastguard Worker return nullptr;
340*f40fafd4SAndroid Build Coastguard Worker }
341*f40fafd4SAndroid Build Coastguard Worker
listVolumes(android::vold::VolumeBase::Type type,std::list<std::string> & list) const342*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::listVolumes(android::vold::VolumeBase::Type type,
343*f40fafd4SAndroid Build Coastguard Worker std::list<std::string>& list) const {
344*f40fafd4SAndroid Build Coastguard Worker list.clear();
345*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
346*f40fafd4SAndroid Build Coastguard Worker disk->listVolumes(type, list);
347*f40fafd4SAndroid Build Coastguard Worker }
348*f40fafd4SAndroid Build Coastguard Worker }
349*f40fafd4SAndroid Build Coastguard Worker
forgetPartition(const std::string & partGuid,const std::string & fsUuid)350*f40fafd4SAndroid Build Coastguard Worker bool VolumeManager::forgetPartition(const std::string& partGuid, const std::string& fsUuid) {
351*f40fafd4SAndroid Build Coastguard Worker std::string normalizedGuid;
352*f40fafd4SAndroid Build Coastguard Worker if (android::vold::NormalizeHex(partGuid, normalizedGuid)) {
353*f40fafd4SAndroid Build Coastguard Worker LOG(WARNING) << "Invalid GUID " << partGuid;
354*f40fafd4SAndroid Build Coastguard Worker return false;
355*f40fafd4SAndroid Build Coastguard Worker }
356*f40fafd4SAndroid Build Coastguard Worker
357*f40fafd4SAndroid Build Coastguard Worker std::string keyPath = android::vold::BuildKeyPath(normalizedGuid);
358*f40fafd4SAndroid Build Coastguard Worker if (unlink(keyPath.c_str()) != 0) {
359*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "Failed to unlink " << keyPath;
360*f40fafd4SAndroid Build Coastguard Worker return false;
361*f40fafd4SAndroid Build Coastguard Worker }
362*f40fafd4SAndroid Build Coastguard Worker return true;
363*f40fafd4SAndroid Build Coastguard Worker }
364*f40fafd4SAndroid Build Coastguard Worker
destroyEmulatedVolumesForUser(userid_t userId)365*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::destroyEmulatedVolumesForUser(userid_t userId) {
366*f40fafd4SAndroid Build Coastguard Worker // Destroy and remove all unstacked EmulatedVolumes for the user
367*f40fafd4SAndroid Build Coastguard Worker auto i = mInternalEmulatedVolumes.begin();
368*f40fafd4SAndroid Build Coastguard Worker while (i != mInternalEmulatedVolumes.end()) {
369*f40fafd4SAndroid Build Coastguard Worker auto vol = *i;
370*f40fafd4SAndroid Build Coastguard Worker if (vol->getMountUserId() == userId) {
371*f40fafd4SAndroid Build Coastguard Worker vol->destroy();
372*f40fafd4SAndroid Build Coastguard Worker i = mInternalEmulatedVolumes.erase(i);
373*f40fafd4SAndroid Build Coastguard Worker } else {
374*f40fafd4SAndroid Build Coastguard Worker i++;
375*f40fafd4SAndroid Build Coastguard Worker }
376*f40fafd4SAndroid Build Coastguard Worker }
377*f40fafd4SAndroid Build Coastguard Worker
378*f40fafd4SAndroid Build Coastguard Worker // Destroy and remove all stacked EmulatedVolumes for the user on each mounted private volume
379*f40fafd4SAndroid Build Coastguard Worker std::list<std::string> private_vols;
380*f40fafd4SAndroid Build Coastguard Worker listVolumes(VolumeBase::Type::kPrivate, private_vols);
381*f40fafd4SAndroid Build Coastguard Worker for (const std::string& id : private_vols) {
382*f40fafd4SAndroid Build Coastguard Worker PrivateVolume* pvol = static_cast<PrivateVolume*>(findVolume(id).get());
383*f40fafd4SAndroid Build Coastguard Worker std::list<std::shared_ptr<VolumeBase>> vols_to_remove;
384*f40fafd4SAndroid Build Coastguard Worker if (pvol->getState() == VolumeBase::State::kMounted) {
385*f40fafd4SAndroid Build Coastguard Worker for (const auto& vol : pvol->getVolumes()) {
386*f40fafd4SAndroid Build Coastguard Worker if (vol->getMountUserId() == userId) {
387*f40fafd4SAndroid Build Coastguard Worker vols_to_remove.push_back(vol);
388*f40fafd4SAndroid Build Coastguard Worker }
389*f40fafd4SAndroid Build Coastguard Worker }
390*f40fafd4SAndroid Build Coastguard Worker for (const auto& vol : vols_to_remove) {
391*f40fafd4SAndroid Build Coastguard Worker vol->destroy();
392*f40fafd4SAndroid Build Coastguard Worker pvol->removeVolume(vol);
393*f40fafd4SAndroid Build Coastguard Worker }
394*f40fafd4SAndroid Build Coastguard Worker } // else EmulatedVolumes will be destroyed on VolumeBase#unmount
395*f40fafd4SAndroid Build Coastguard Worker }
396*f40fafd4SAndroid Build Coastguard Worker }
397*f40fafd4SAndroid Build Coastguard Worker
createEmulatedVolumesForUser(userid_t userId)398*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::createEmulatedVolumesForUser(userid_t userId) {
399*f40fafd4SAndroid Build Coastguard Worker // Create unstacked EmulatedVolumes for the user
400*f40fafd4SAndroid Build Coastguard Worker auto vol = std::shared_ptr<android::vold::VolumeBase>(
401*f40fafd4SAndroid Build Coastguard Worker new android::vold::EmulatedVolume("/data/media", userId));
402*f40fafd4SAndroid Build Coastguard Worker vol->setMountUserId(userId);
403*f40fafd4SAndroid Build Coastguard Worker mInternalEmulatedVolumes.push_back(vol);
404*f40fafd4SAndroid Build Coastguard Worker vol->create();
405*f40fafd4SAndroid Build Coastguard Worker
406*f40fafd4SAndroid Build Coastguard Worker // Create stacked EmulatedVolumes for the user on each PrivateVolume
407*f40fafd4SAndroid Build Coastguard Worker std::list<std::string> private_vols;
408*f40fafd4SAndroid Build Coastguard Worker listVolumes(VolumeBase::Type::kPrivate, private_vols);
409*f40fafd4SAndroid Build Coastguard Worker for (const std::string& id : private_vols) {
410*f40fafd4SAndroid Build Coastguard Worker PrivateVolume* pvol = static_cast<PrivateVolume*>(findVolume(id).get());
411*f40fafd4SAndroid Build Coastguard Worker if (pvol->getState() == VolumeBase::State::kMounted) {
412*f40fafd4SAndroid Build Coastguard Worker auto evol =
413*f40fafd4SAndroid Build Coastguard Worker std::shared_ptr<android::vold::VolumeBase>(new android::vold::EmulatedVolume(
414*f40fafd4SAndroid Build Coastguard Worker pvol->getPath() + "/media", pvol->getRawDevice(), pvol->getFsUuid(),
415*f40fafd4SAndroid Build Coastguard Worker userId));
416*f40fafd4SAndroid Build Coastguard Worker evol->setMountUserId(userId);
417*f40fafd4SAndroid Build Coastguard Worker pvol->addVolume(evol);
418*f40fafd4SAndroid Build Coastguard Worker evol->create();
419*f40fafd4SAndroid Build Coastguard Worker } // else EmulatedVolumes will be created per user when on PrivateVolume#doMount
420*f40fafd4SAndroid Build Coastguard Worker }
421*f40fafd4SAndroid Build Coastguard Worker }
422*f40fafd4SAndroid Build Coastguard Worker
getSharedStorageUser(userid_t userId)423*f40fafd4SAndroid Build Coastguard Worker userid_t VolumeManager::getSharedStorageUser(userid_t userId) {
424*f40fafd4SAndroid Build Coastguard Worker if (mSharedStorageUser.find(userId) == mSharedStorageUser.end()) {
425*f40fafd4SAndroid Build Coastguard Worker return USER_UNKNOWN;
426*f40fafd4SAndroid Build Coastguard Worker }
427*f40fafd4SAndroid Build Coastguard Worker return mSharedStorageUser.at(userId);
428*f40fafd4SAndroid Build Coastguard Worker }
429*f40fafd4SAndroid Build Coastguard Worker
onUserAdded(userid_t userId,int userSerialNumber,userid_t sharesStorageWithUserId)430*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::onUserAdded(userid_t userId, int userSerialNumber,
431*f40fafd4SAndroid Build Coastguard Worker userid_t sharesStorageWithUserId) {
432*f40fafd4SAndroid Build Coastguard Worker LOG(INFO) << "onUserAdded: " << userId;
433*f40fafd4SAndroid Build Coastguard Worker
434*f40fafd4SAndroid Build Coastguard Worker mAddedUsers[userId] = userSerialNumber;
435*f40fafd4SAndroid Build Coastguard Worker if (sharesStorageWithUserId != USER_UNKNOWN) {
436*f40fafd4SAndroid Build Coastguard Worker mSharedStorageUser[userId] = sharesStorageWithUserId;
437*f40fafd4SAndroid Build Coastguard Worker }
438*f40fafd4SAndroid Build Coastguard Worker return 0;
439*f40fafd4SAndroid Build Coastguard Worker }
440*f40fafd4SAndroid Build Coastguard Worker
onUserRemoved(userid_t userId)441*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::onUserRemoved(userid_t userId) {
442*f40fafd4SAndroid Build Coastguard Worker LOG(INFO) << "onUserRemoved: " << userId;
443*f40fafd4SAndroid Build Coastguard Worker
444*f40fafd4SAndroid Build Coastguard Worker onUserStopped(userId);
445*f40fafd4SAndroid Build Coastguard Worker mAddedUsers.erase(userId);
446*f40fafd4SAndroid Build Coastguard Worker mSharedStorageUser.erase(userId);
447*f40fafd4SAndroid Build Coastguard Worker return 0;
448*f40fafd4SAndroid Build Coastguard Worker }
449*f40fafd4SAndroid Build Coastguard Worker
onUserStarted(userid_t userId)450*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::onUserStarted(userid_t userId) {
451*f40fafd4SAndroid Build Coastguard Worker LOG(INFO) << "onUserStarted: " << userId;
452*f40fafd4SAndroid Build Coastguard Worker
453*f40fafd4SAndroid Build Coastguard Worker if (mStartedUsers.find(userId) == mStartedUsers.end()) {
454*f40fafd4SAndroid Build Coastguard Worker createEmulatedVolumesForUser(userId);
455*f40fafd4SAndroid Build Coastguard Worker std::list<std::string> public_vols;
456*f40fafd4SAndroid Build Coastguard Worker listVolumes(VolumeBase::Type::kPublic, public_vols);
457*f40fafd4SAndroid Build Coastguard Worker for (const std::string& id : public_vols) {
458*f40fafd4SAndroid Build Coastguard Worker PublicVolume* pvol = static_cast<PublicVolume*>(findVolume(id).get());
459*f40fafd4SAndroid Build Coastguard Worker if (pvol->getState() != VolumeBase::State::kMounted) {
460*f40fafd4SAndroid Build Coastguard Worker continue;
461*f40fafd4SAndroid Build Coastguard Worker }
462*f40fafd4SAndroid Build Coastguard Worker if (pvol->isVisible() == 0) {
463*f40fafd4SAndroid Build Coastguard Worker continue;
464*f40fafd4SAndroid Build Coastguard Worker }
465*f40fafd4SAndroid Build Coastguard Worker userid_t mountUserId = pvol->getMountUserId();
466*f40fafd4SAndroid Build Coastguard Worker if (userId == mountUserId) {
467*f40fafd4SAndroid Build Coastguard Worker // No need to bind mount for the user that owns the mount
468*f40fafd4SAndroid Build Coastguard Worker continue;
469*f40fafd4SAndroid Build Coastguard Worker }
470*f40fafd4SAndroid Build Coastguard Worker if (mountUserId != VolumeManager::Instance()->getSharedStorageUser(userId)) {
471*f40fafd4SAndroid Build Coastguard Worker // No need to bind if the user does not share storage with the mount owner
472*f40fafd4SAndroid Build Coastguard Worker continue;
473*f40fafd4SAndroid Build Coastguard Worker }
474*f40fafd4SAndroid Build Coastguard Worker // Create mount directory for the user as there is a chance that no other Volume is
475*f40fafd4SAndroid Build Coastguard Worker // mounted for the user (ex: if the user is just started), so /mnt/user/user_id does
476*f40fafd4SAndroid Build Coastguard Worker // not exist yet.
477*f40fafd4SAndroid Build Coastguard Worker auto mountDirStatus = android::vold::PrepareMountDirForUser(userId);
478*f40fafd4SAndroid Build Coastguard Worker if (mountDirStatus != OK) {
479*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "Failed to create Mount Directory for user " << userId;
480*f40fafd4SAndroid Build Coastguard Worker }
481*f40fafd4SAndroid Build Coastguard Worker auto bindMountStatus = pvol->bindMountForUser(userId);
482*f40fafd4SAndroid Build Coastguard Worker if (bindMountStatus != OK) {
483*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "Bind Mounting Public Volume: " << pvol << " for user: " << userId
484*f40fafd4SAndroid Build Coastguard Worker << "Failed. Error: " << bindMountStatus;
485*f40fafd4SAndroid Build Coastguard Worker }
486*f40fafd4SAndroid Build Coastguard Worker }
487*f40fafd4SAndroid Build Coastguard Worker }
488*f40fafd4SAndroid Build Coastguard Worker
489*f40fafd4SAndroid Build Coastguard Worker mStartedUsers.insert(userId);
490*f40fafd4SAndroid Build Coastguard Worker
491*f40fafd4SAndroid Build Coastguard Worker createPendingDisksIfNeeded();
492*f40fafd4SAndroid Build Coastguard Worker return 0;
493*f40fafd4SAndroid Build Coastguard Worker }
494*f40fafd4SAndroid Build Coastguard Worker
onUserStopped(userid_t userId)495*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::onUserStopped(userid_t userId) {
496*f40fafd4SAndroid Build Coastguard Worker LOG(VERBOSE) << "onUserStopped: " << userId;
497*f40fafd4SAndroid Build Coastguard Worker
498*f40fafd4SAndroid Build Coastguard Worker if (mStartedUsers.find(userId) != mStartedUsers.end()) {
499*f40fafd4SAndroid Build Coastguard Worker destroyEmulatedVolumesForUser(userId);
500*f40fafd4SAndroid Build Coastguard Worker }
501*f40fafd4SAndroid Build Coastguard Worker
502*f40fafd4SAndroid Build Coastguard Worker mStartedUsers.erase(userId);
503*f40fafd4SAndroid Build Coastguard Worker return 0;
504*f40fafd4SAndroid Build Coastguard Worker }
505*f40fafd4SAndroid Build Coastguard Worker
createPendingDisksIfNeeded()506*f40fafd4SAndroid Build Coastguard Worker void VolumeManager::createPendingDisksIfNeeded() {
507*f40fafd4SAndroid Build Coastguard Worker bool userZeroStarted = mStartedUsers.find(0) != mStartedUsers.end();
508*f40fafd4SAndroid Build Coastguard Worker if (!mSecureKeyguardShowing && userZeroStarted) {
509*f40fafd4SAndroid Build Coastguard Worker // Now that secure keyguard has been dismissed and user 0 has
510*f40fafd4SAndroid Build Coastguard Worker // started, process any pending disks
511*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mPendingDisks) {
512*f40fafd4SAndroid Build Coastguard Worker disk->create();
513*f40fafd4SAndroid Build Coastguard Worker mDisks.push_back(disk);
514*f40fafd4SAndroid Build Coastguard Worker }
515*f40fafd4SAndroid Build Coastguard Worker mPendingDisks.clear();
516*f40fafd4SAndroid Build Coastguard Worker }
517*f40fafd4SAndroid Build Coastguard Worker }
518*f40fafd4SAndroid Build Coastguard Worker
onSecureKeyguardStateChanged(bool isShowing)519*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::onSecureKeyguardStateChanged(bool isShowing) {
520*f40fafd4SAndroid Build Coastguard Worker mSecureKeyguardShowing = isShowing;
521*f40fafd4SAndroid Build Coastguard Worker createPendingDisksIfNeeded();
522*f40fafd4SAndroid Build Coastguard Worker return 0;
523*f40fafd4SAndroid Build Coastguard Worker }
524*f40fafd4SAndroid Build Coastguard Worker
525*f40fafd4SAndroid Build Coastguard Worker // This code is executed after a fork so it's very important that the set of
526*f40fafd4SAndroid Build Coastguard Worker // methods we call here is strictly limited.
527*f40fafd4SAndroid Build Coastguard Worker //
528*f40fafd4SAndroid Build Coastguard Worker // TODO: Get rid of this guesswork altogether and instead exec a process
529*f40fafd4SAndroid Build Coastguard Worker // immediately after fork to do our bindding for us.
childProcess(const char * storageSource,const char * userSource,int nsFd,const char * name)530*f40fafd4SAndroid Build Coastguard Worker static bool childProcess(const char* storageSource, const char* userSource, int nsFd,
531*f40fafd4SAndroid Build Coastguard Worker const char* name) {
532*f40fafd4SAndroid Build Coastguard Worker if (setns(nsFd, CLONE_NEWNS) != 0) {
533*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to setns for %s :%s", name,
534*f40fafd4SAndroid Build Coastguard Worker strerror(errno));
535*f40fafd4SAndroid Build Coastguard Worker return false;
536*f40fafd4SAndroid Build Coastguard Worker }
537*f40fafd4SAndroid Build Coastguard Worker
538*f40fafd4SAndroid Build Coastguard Worker // NOTE: Inlined from vold::UnmountTree here to avoid using PLOG methods and
539*f40fafd4SAndroid Build Coastguard Worker // to also protect against future changes that may cause issues across a
540*f40fafd4SAndroid Build Coastguard Worker // fork.
541*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(umount2("/storage/", MNT_DETACH)) < 0 && errno != EINVAL &&
542*f40fafd4SAndroid Build Coastguard Worker errno != ENOENT) {
543*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to unmount /storage/ :%s",
544*f40fafd4SAndroid Build Coastguard Worker strerror(errno));
545*f40fafd4SAndroid Build Coastguard Worker return false;
546*f40fafd4SAndroid Build Coastguard Worker }
547*f40fafd4SAndroid Build Coastguard Worker
548*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(mount(storageSource, "/storage", NULL, MS_BIND | MS_REC, NULL)) == -1) {
549*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to mount %s for %s :%s",
550*f40fafd4SAndroid Build Coastguard Worker storageSource, name, strerror(errno));
551*f40fafd4SAndroid Build Coastguard Worker return false;
552*f40fafd4SAndroid Build Coastguard Worker }
553*f40fafd4SAndroid Build Coastguard Worker
554*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(mount(NULL, "/storage", NULL, MS_REC | MS_SLAVE, NULL)) == -1) {
555*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold",
556*f40fafd4SAndroid Build Coastguard Worker "Failed to set MS_SLAVE to /storage for %s :%s", name,
557*f40fafd4SAndroid Build Coastguard Worker strerror(errno));
558*f40fafd4SAndroid Build Coastguard Worker return false;
559*f40fafd4SAndroid Build Coastguard Worker }
560*f40fafd4SAndroid Build Coastguard Worker
561*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(mount(userSource, "/storage/self", NULL, MS_BIND, NULL)) == -1) {
562*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to mount %s for %s :%s",
563*f40fafd4SAndroid Build Coastguard Worker userSource, name, strerror(errno));
564*f40fafd4SAndroid Build Coastguard Worker return false;
565*f40fafd4SAndroid Build Coastguard Worker }
566*f40fafd4SAndroid Build Coastguard Worker
567*f40fafd4SAndroid Build Coastguard Worker return true;
568*f40fafd4SAndroid Build Coastguard Worker }
569*f40fafd4SAndroid Build Coastguard Worker
570*f40fafd4SAndroid Build Coastguard Worker // Fork the process and remount storage
forkAndRemountChild(uid_t uid,pid_t pid,int nsFd,const char * name,void * params)571*f40fafd4SAndroid Build Coastguard Worker bool forkAndRemountChild(uid_t uid, pid_t pid, int nsFd, const char* name, void* params) {
572*f40fafd4SAndroid Build Coastguard Worker int32_t mountMode = *static_cast<int32_t*>(params);
573*f40fafd4SAndroid Build Coastguard Worker std::string userSource;
574*f40fafd4SAndroid Build Coastguard Worker std::string storageSource;
575*f40fafd4SAndroid Build Coastguard Worker pid_t child;
576*f40fafd4SAndroid Build Coastguard Worker // Need to fix these paths to account for when sdcardfs is gone
577*f40fafd4SAndroid Build Coastguard Worker switch (mountMode) {
578*f40fafd4SAndroid Build Coastguard Worker case VoldNativeService::REMOUNT_MODE_NONE:
579*f40fafd4SAndroid Build Coastguard Worker return true;
580*f40fafd4SAndroid Build Coastguard Worker case VoldNativeService::REMOUNT_MODE_DEFAULT:
581*f40fafd4SAndroid Build Coastguard Worker storageSource = "/mnt/runtime/default";
582*f40fafd4SAndroid Build Coastguard Worker break;
583*f40fafd4SAndroid Build Coastguard Worker case VoldNativeService::REMOUNT_MODE_ANDROID_WRITABLE:
584*f40fafd4SAndroid Build Coastguard Worker case VoldNativeService::REMOUNT_MODE_INSTALLER:
585*f40fafd4SAndroid Build Coastguard Worker storageSource = "/mnt/runtime/write";
586*f40fafd4SAndroid Build Coastguard Worker break;
587*f40fafd4SAndroid Build Coastguard Worker case VoldNativeService::REMOUNT_MODE_PASS_THROUGH:
588*f40fafd4SAndroid Build Coastguard Worker return true;
589*f40fafd4SAndroid Build Coastguard Worker default:
590*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Unknown mode " << std::to_string(mountMode);
591*f40fafd4SAndroid Build Coastguard Worker return false;
592*f40fafd4SAndroid Build Coastguard Worker }
593*f40fafd4SAndroid Build Coastguard Worker LOG(DEBUG) << "Remounting " << uid << " as " << storageSource;
594*f40fafd4SAndroid Build Coastguard Worker
595*f40fafd4SAndroid Build Coastguard Worker // Fork a child to mount user-specific symlink helper into place
596*f40fafd4SAndroid Build Coastguard Worker userSource = StringPrintf("/mnt/user/%d", multiuser_get_user_id(uid));
597*f40fafd4SAndroid Build Coastguard Worker if (!(child = fork())) {
598*f40fafd4SAndroid Build Coastguard Worker if (childProcess(storageSource.c_str(), userSource.c_str(), nsFd, name)) {
599*f40fafd4SAndroid Build Coastguard Worker _exit(0);
600*f40fafd4SAndroid Build Coastguard Worker } else {
601*f40fafd4SAndroid Build Coastguard Worker _exit(1);
602*f40fafd4SAndroid Build Coastguard Worker }
603*f40fafd4SAndroid Build Coastguard Worker }
604*f40fafd4SAndroid Build Coastguard Worker
605*f40fafd4SAndroid Build Coastguard Worker if (child == -1) {
606*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Failed to fork";
607*f40fafd4SAndroid Build Coastguard Worker return false;
608*f40fafd4SAndroid Build Coastguard Worker } else {
609*f40fafd4SAndroid Build Coastguard Worker TEMP_FAILURE_RETRY(waitpid(child, nullptr, 0));
610*f40fafd4SAndroid Build Coastguard Worker }
611*f40fafd4SAndroid Build Coastguard Worker return true;
612*f40fafd4SAndroid Build Coastguard Worker }
613*f40fafd4SAndroid Build Coastguard Worker
614*f40fafd4SAndroid Build Coastguard Worker // Helper function to scan all processes in /proc and call the callback if:
615*f40fafd4SAndroid Build Coastguard Worker // 1). pid belongs to an app process
616*f40fafd4SAndroid Build Coastguard Worker // 2). If input uid is 0 or it matches the process uid
617*f40fafd4SAndroid Build Coastguard Worker // 3). If userId is not -1 or userId matches the process userId
scanProcProcesses(uid_t uid,userid_t userId,ScanProcCallback callback,void * params)618*f40fafd4SAndroid Build Coastguard Worker bool scanProcProcesses(uid_t uid, userid_t userId, ScanProcCallback callback, void* params) {
619*f40fafd4SAndroid Build Coastguard Worker DIR* dir;
620*f40fafd4SAndroid Build Coastguard Worker struct dirent* de;
621*f40fafd4SAndroid Build Coastguard Worker std::string rootName;
622*f40fafd4SAndroid Build Coastguard Worker std::string pidName;
623*f40fafd4SAndroid Build Coastguard Worker std::string exeName;
624*f40fafd4SAndroid Build Coastguard Worker int pidFd;
625*f40fafd4SAndroid Build Coastguard Worker int nsFd;
626*f40fafd4SAndroid Build Coastguard Worker struct stat sb;
627*f40fafd4SAndroid Build Coastguard Worker
628*f40fafd4SAndroid Build Coastguard Worker if (!(dir = opendir("/proc"))) {
629*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to opendir");
630*f40fafd4SAndroid Build Coastguard Worker return false;
631*f40fafd4SAndroid Build Coastguard Worker }
632*f40fafd4SAndroid Build Coastguard Worker
633*f40fafd4SAndroid Build Coastguard Worker // Figure out root namespace to compare against below
634*f40fafd4SAndroid Build Coastguard Worker if (!android::vold::Readlinkat(dirfd(dir), "1/ns/mnt", &rootName)) {
635*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to read root namespace");
636*f40fafd4SAndroid Build Coastguard Worker closedir(dir);
637*f40fafd4SAndroid Build Coastguard Worker return false;
638*f40fafd4SAndroid Build Coastguard Worker }
639*f40fafd4SAndroid Build Coastguard Worker
640*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_INFO, "vold", "Start scanning all processes");
641*f40fafd4SAndroid Build Coastguard Worker // Poke through all running PIDs look for apps running as UID
642*f40fafd4SAndroid Build Coastguard Worker while ((de = readdir(dir))) {
643*f40fafd4SAndroid Build Coastguard Worker pid_t pid;
644*f40fafd4SAndroid Build Coastguard Worker if (de->d_type != DT_DIR) continue;
645*f40fafd4SAndroid Build Coastguard Worker if (!android::base::ParseInt(de->d_name, &pid)) continue;
646*f40fafd4SAndroid Build Coastguard Worker
647*f40fafd4SAndroid Build Coastguard Worker pidFd = -1;
648*f40fafd4SAndroid Build Coastguard Worker nsFd = -1;
649*f40fafd4SAndroid Build Coastguard Worker
650*f40fafd4SAndroid Build Coastguard Worker pidFd = openat(dirfd(dir), de->d_name, O_RDONLY | O_DIRECTORY | O_CLOEXEC);
651*f40fafd4SAndroid Build Coastguard Worker if (pidFd < 0) {
652*f40fafd4SAndroid Build Coastguard Worker goto next;
653*f40fafd4SAndroid Build Coastguard Worker }
654*f40fafd4SAndroid Build Coastguard Worker if (fstat(pidFd, &sb) != 0) {
655*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to stat %s", de->d_name);
656*f40fafd4SAndroid Build Coastguard Worker goto next;
657*f40fafd4SAndroid Build Coastguard Worker }
658*f40fafd4SAndroid Build Coastguard Worker if (uid != 0 && sb.st_uid != uid) {
659*f40fafd4SAndroid Build Coastguard Worker goto next;
660*f40fafd4SAndroid Build Coastguard Worker }
661*f40fafd4SAndroid Build Coastguard Worker if (userId != static_cast<userid_t>(-1) && multiuser_get_user_id(sb.st_uid) != userId) {
662*f40fafd4SAndroid Build Coastguard Worker goto next;
663*f40fafd4SAndroid Build Coastguard Worker }
664*f40fafd4SAndroid Build Coastguard Worker
665*f40fafd4SAndroid Build Coastguard Worker // Matches so far, but refuse to touch if in root namespace
666*f40fafd4SAndroid Build Coastguard Worker if (!android::vold::Readlinkat(pidFd, "ns/mnt", &pidName)) {
667*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold",
668*f40fafd4SAndroid Build Coastguard Worker "Failed to read namespacefor %s", de->d_name);
669*f40fafd4SAndroid Build Coastguard Worker goto next;
670*f40fafd4SAndroid Build Coastguard Worker }
671*f40fafd4SAndroid Build Coastguard Worker if (rootName == pidName) {
672*f40fafd4SAndroid Build Coastguard Worker goto next;
673*f40fafd4SAndroid Build Coastguard Worker }
674*f40fafd4SAndroid Build Coastguard Worker
675*f40fafd4SAndroid Build Coastguard Worker // Some early native processes have mount namespaces that are different
676*f40fafd4SAndroid Build Coastguard Worker // from that of the init. Therefore, above check can't filter them out.
677*f40fafd4SAndroid Build Coastguard Worker // Since the propagation type of / is 'shared', unmounting /storage
678*f40fafd4SAndroid Build Coastguard Worker // for the early native processes affects other processes including
679*f40fafd4SAndroid Build Coastguard Worker // init. Filter out such processes by skipping if a process is a
680*f40fafd4SAndroid Build Coastguard Worker // non-Java process whose UID is < AID_APP_START. (The UID condition
681*f40fafd4SAndroid Build Coastguard Worker // is required to not filter out child processes spawned by apps.)
682*f40fafd4SAndroid Build Coastguard Worker if (!android::vold::Readlinkat(pidFd, "exe", &exeName)) {
683*f40fafd4SAndroid Build Coastguard Worker goto next;
684*f40fafd4SAndroid Build Coastguard Worker }
685*f40fafd4SAndroid Build Coastguard Worker if (!StartsWith(exeName, "/system/bin/app_process") && sb.st_uid < AID_APP_START) {
686*f40fafd4SAndroid Build Coastguard Worker goto next;
687*f40fafd4SAndroid Build Coastguard Worker }
688*f40fafd4SAndroid Build Coastguard Worker
689*f40fafd4SAndroid Build Coastguard Worker // We purposefully leave the namespace open across the fork
690*f40fafd4SAndroid Build Coastguard Worker // NOLINTNEXTLINE(android-cloexec-open): Deliberately not O_CLOEXEC
691*f40fafd4SAndroid Build Coastguard Worker nsFd = openat(pidFd, "ns/mnt", O_RDONLY);
692*f40fafd4SAndroid Build Coastguard Worker if (nsFd < 0) {
693*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold",
694*f40fafd4SAndroid Build Coastguard Worker "Failed to open namespace for %s", de->d_name);
695*f40fafd4SAndroid Build Coastguard Worker goto next;
696*f40fafd4SAndroid Build Coastguard Worker }
697*f40fafd4SAndroid Build Coastguard Worker
698*f40fafd4SAndroid Build Coastguard Worker if (!callback(sb.st_uid, pid, nsFd, de->d_name, params)) {
699*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed in callback");
700*f40fafd4SAndroid Build Coastguard Worker }
701*f40fafd4SAndroid Build Coastguard Worker
702*f40fafd4SAndroid Build Coastguard Worker next:
703*f40fafd4SAndroid Build Coastguard Worker close(nsFd);
704*f40fafd4SAndroid Build Coastguard Worker close(pidFd);
705*f40fafd4SAndroid Build Coastguard Worker }
706*f40fafd4SAndroid Build Coastguard Worker closedir(dir);
707*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_INFO, "vold", "Finished scanning all processes");
708*f40fafd4SAndroid Build Coastguard Worker return true;
709*f40fafd4SAndroid Build Coastguard Worker }
710*f40fafd4SAndroid Build Coastguard Worker
711*f40fafd4SAndroid Build Coastguard Worker // In each app's namespace, unmount obb and data dirs
umountStorageDirs(int nsFd,const char * android_data_dir,const char * android_obb_dir,int uid,const char * targets[],int size)712*f40fafd4SAndroid Build Coastguard Worker static bool umountStorageDirs(int nsFd, const char* android_data_dir, const char* android_obb_dir,
713*f40fafd4SAndroid Build Coastguard Worker int uid, const char* targets[], int size) {
714*f40fafd4SAndroid Build Coastguard Worker // This code is executed after a fork so it's very important that the set of
715*f40fafd4SAndroid Build Coastguard Worker // methods we call here is strictly limited.
716*f40fafd4SAndroid Build Coastguard Worker if (setns(nsFd, CLONE_NEWNS) != 0) {
717*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to setns %s", strerror(errno));
718*f40fafd4SAndroid Build Coastguard Worker return false;
719*f40fafd4SAndroid Build Coastguard Worker }
720*f40fafd4SAndroid Build Coastguard Worker
721*f40fafd4SAndroid Build Coastguard Worker // Unmount of Android/data/foo needs to be done before Android/data below.
722*f40fafd4SAndroid Build Coastguard Worker bool result = true;
723*f40fafd4SAndroid Build Coastguard Worker for (int i = 0; i < size; i++) {
724*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(umount2(targets[i], MNT_DETACH)) < 0 && errno != EINVAL &&
725*f40fafd4SAndroid Build Coastguard Worker errno != ENOENT) {
726*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to umount %s: %s",
727*f40fafd4SAndroid Build Coastguard Worker targets[i], strerror(errno));
728*f40fafd4SAndroid Build Coastguard Worker result = false;
729*f40fafd4SAndroid Build Coastguard Worker }
730*f40fafd4SAndroid Build Coastguard Worker }
731*f40fafd4SAndroid Build Coastguard Worker
732*f40fafd4SAndroid Build Coastguard Worker // Mount tmpfs on Android/data and Android/obb
733*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(umount2(android_data_dir, MNT_DETACH)) < 0 && errno != EINVAL &&
734*f40fafd4SAndroid Build Coastguard Worker errno != ENOENT) {
735*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to umount %s :%s",
736*f40fafd4SAndroid Build Coastguard Worker android_data_dir, strerror(errno));
737*f40fafd4SAndroid Build Coastguard Worker result = false;
738*f40fafd4SAndroid Build Coastguard Worker }
739*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(umount2(android_obb_dir, MNT_DETACH)) < 0 && errno != EINVAL &&
740*f40fafd4SAndroid Build Coastguard Worker errno != ENOENT) {
741*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to umount %s :%s",
742*f40fafd4SAndroid Build Coastguard Worker android_obb_dir, strerror(errno));
743*f40fafd4SAndroid Build Coastguard Worker result = false;
744*f40fafd4SAndroid Build Coastguard Worker }
745*f40fafd4SAndroid Build Coastguard Worker return result;
746*f40fafd4SAndroid Build Coastguard Worker }
747*f40fafd4SAndroid Build Coastguard Worker
748*f40fafd4SAndroid Build Coastguard Worker // In each app's namespace, mount tmpfs on obb and data dir, and bind mount obb and data
749*f40fafd4SAndroid Build Coastguard Worker // package dirs.
remountStorageDirs(int nsFd,const char * android_data_dir,const char * android_obb_dir,int uid,const char * sources[],const char * targets[],int size)750*f40fafd4SAndroid Build Coastguard Worker static bool remountStorageDirs(int nsFd, const char* android_data_dir, const char* android_obb_dir,
751*f40fafd4SAndroid Build Coastguard Worker int uid, const char* sources[], const char* targets[], int size) {
752*f40fafd4SAndroid Build Coastguard Worker // This code is executed after a fork so it's very important that the set of
753*f40fafd4SAndroid Build Coastguard Worker // methods we call here is strictly limited.
754*f40fafd4SAndroid Build Coastguard Worker if (setns(nsFd, CLONE_NEWNS) != 0) {
755*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to setns %s", strerror(errno));
756*f40fafd4SAndroid Build Coastguard Worker return false;
757*f40fafd4SAndroid Build Coastguard Worker }
758*f40fafd4SAndroid Build Coastguard Worker
759*f40fafd4SAndroid Build Coastguard Worker // Mount tmpfs on Android/data and Android/obb
760*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(mount("tmpfs", android_data_dir, "tmpfs",
761*f40fafd4SAndroid Build Coastguard Worker MS_NOSUID | MS_NODEV | MS_NOEXEC, "uid=0,gid=0,mode=0751")) == -1) {
762*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to mount tmpfs to %s :%s",
763*f40fafd4SAndroid Build Coastguard Worker android_data_dir, strerror(errno));
764*f40fafd4SAndroid Build Coastguard Worker return false;
765*f40fafd4SAndroid Build Coastguard Worker }
766*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(mount("tmpfs", android_obb_dir, "tmpfs",
767*f40fafd4SAndroid Build Coastguard Worker MS_NOSUID | MS_NODEV | MS_NOEXEC, "uid=0,gid=0,mode=0751")) == -1) {
768*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to mount tmpfs to %s :%s",
769*f40fafd4SAndroid Build Coastguard Worker android_obb_dir, strerror(errno));
770*f40fafd4SAndroid Build Coastguard Worker return false;
771*f40fafd4SAndroid Build Coastguard Worker }
772*f40fafd4SAndroid Build Coastguard Worker
773*f40fafd4SAndroid Build Coastguard Worker for (int i = 0; i < size; i++) {
774*f40fafd4SAndroid Build Coastguard Worker // Create package dir and bind mount it to the actual one.
775*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(mkdir(targets[i], 0700)) == -1) {
776*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to mkdir %s %s",
777*f40fafd4SAndroid Build Coastguard Worker targets[i], strerror(errno));
778*f40fafd4SAndroid Build Coastguard Worker return false;
779*f40fafd4SAndroid Build Coastguard Worker }
780*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(mount(sources[i], targets[i], NULL, MS_BIND | MS_REC, NULL)) == -1) {
781*f40fafd4SAndroid Build Coastguard Worker async_safe_format_log(ANDROID_LOG_ERROR, "vold", "Failed to mount %s to %s :%s",
782*f40fafd4SAndroid Build Coastguard Worker sources[i], targets[i], strerror(errno));
783*f40fafd4SAndroid Build Coastguard Worker return false;
784*f40fafd4SAndroid Build Coastguard Worker }
785*f40fafd4SAndroid Build Coastguard Worker }
786*f40fafd4SAndroid Build Coastguard Worker return true;
787*f40fafd4SAndroid Build Coastguard Worker }
788*f40fafd4SAndroid Build Coastguard Worker
getStorageDirSrc(userid_t userId,const std::string & dirName,const std::string & packageName)789*f40fafd4SAndroid Build Coastguard Worker static std::string getStorageDirSrc(userid_t userId, const std::string& dirName,
790*f40fafd4SAndroid Build Coastguard Worker const std::string& packageName) {
791*f40fafd4SAndroid Build Coastguard Worker if (IsSdcardfsUsed()) {
792*f40fafd4SAndroid Build Coastguard Worker return StringPrintf("/mnt/runtime/default/emulated/%d/%s/%s",
793*f40fafd4SAndroid Build Coastguard Worker userId, dirName.c_str(), packageName.c_str());
794*f40fafd4SAndroid Build Coastguard Worker } else {
795*f40fafd4SAndroid Build Coastguard Worker return StringPrintf("/mnt/pass_through/%d/emulated/%d/%s/%s",
796*f40fafd4SAndroid Build Coastguard Worker userId, userId, dirName.c_str(), packageName.c_str());
797*f40fafd4SAndroid Build Coastguard Worker }
798*f40fafd4SAndroid Build Coastguard Worker }
799*f40fafd4SAndroid Build Coastguard Worker
getStorageDirTarget(userid_t userId,std::string dirName,std::string packageName)800*f40fafd4SAndroid Build Coastguard Worker static std::string getStorageDirTarget(userid_t userId, std::string dirName,
801*f40fafd4SAndroid Build Coastguard Worker std::string packageName) {
802*f40fafd4SAndroid Build Coastguard Worker return StringPrintf("/storage/emulated/%d/%s/%s",
803*f40fafd4SAndroid Build Coastguard Worker userId, dirName.c_str(), packageName.c_str());
804*f40fafd4SAndroid Build Coastguard Worker }
805*f40fafd4SAndroid Build Coastguard Worker
806*f40fafd4SAndroid Build Coastguard Worker // Fork the process and remount / unmount app data and obb dirs
forkAndRemountStorage(int uid,int pid,bool doUnmount,const std::vector<std::string> & packageNames)807*f40fafd4SAndroid Build Coastguard Worker bool VolumeManager::forkAndRemountStorage(int uid, int pid, bool doUnmount,
808*f40fafd4SAndroid Build Coastguard Worker const std::vector<std::string>& packageNames) {
809*f40fafd4SAndroid Build Coastguard Worker userid_t userId = multiuser_get_user_id(uid);
810*f40fafd4SAndroid Build Coastguard Worker std::string mnt_path = StringPrintf("/proc/%d/ns/mnt", pid);
811*f40fafd4SAndroid Build Coastguard Worker android::base::unique_fd nsFd(
812*f40fafd4SAndroid Build Coastguard Worker TEMP_FAILURE_RETRY(open(mnt_path.c_str(), O_RDONLY | O_CLOEXEC)));
813*f40fafd4SAndroid Build Coastguard Worker if (nsFd == -1) {
814*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Unable to open " << mnt_path.c_str();
815*f40fafd4SAndroid Build Coastguard Worker return false;
816*f40fafd4SAndroid Build Coastguard Worker }
817*f40fafd4SAndroid Build Coastguard Worker // Storing both Android/obb and Android/data paths.
818*f40fafd4SAndroid Build Coastguard Worker int size = packageNames.size() * 2;
819*f40fafd4SAndroid Build Coastguard Worker
820*f40fafd4SAndroid Build Coastguard Worker std::unique_ptr<std::string[]> sources(new std::string[size]);
821*f40fafd4SAndroid Build Coastguard Worker std::unique_ptr<std::string[]> targets(new std::string[size]);
822*f40fafd4SAndroid Build Coastguard Worker std::unique_ptr<const char*[]> sources_uptr(new const char*[size]);
823*f40fafd4SAndroid Build Coastguard Worker std::unique_ptr<const char*[]> targets_uptr(new const char*[size]);
824*f40fafd4SAndroid Build Coastguard Worker const char** sources_cstr = sources_uptr.get();
825*f40fafd4SAndroid Build Coastguard Worker const char** targets_cstr = targets_uptr.get();
826*f40fafd4SAndroid Build Coastguard Worker
827*f40fafd4SAndroid Build Coastguard Worker for (int i = 0; i < size; i += 2) {
828*f40fafd4SAndroid Build Coastguard Worker std::string const& packageName = packageNames[i/2];
829*f40fafd4SAndroid Build Coastguard Worker sources[i] = getStorageDirSrc(userId, "Android/data", packageName);
830*f40fafd4SAndroid Build Coastguard Worker targets[i] = getStorageDirTarget(userId, "Android/data", packageName);
831*f40fafd4SAndroid Build Coastguard Worker sources[i+1] = getStorageDirSrc(userId, "Android/obb", packageName);
832*f40fafd4SAndroid Build Coastguard Worker targets[i+1] = getStorageDirTarget(userId, "Android/obb", packageName);
833*f40fafd4SAndroid Build Coastguard Worker
834*f40fafd4SAndroid Build Coastguard Worker sources_cstr[i] = sources[i].c_str();
835*f40fafd4SAndroid Build Coastguard Worker targets_cstr[i] = targets[i].c_str();
836*f40fafd4SAndroid Build Coastguard Worker sources_cstr[i+1] = sources[i+1].c_str();
837*f40fafd4SAndroid Build Coastguard Worker targets_cstr[i+1] = targets[i+1].c_str();
838*f40fafd4SAndroid Build Coastguard Worker }
839*f40fafd4SAndroid Build Coastguard Worker
840*f40fafd4SAndroid Build Coastguard Worker for (int i = 0; i < size; i++) {
841*f40fafd4SAndroid Build Coastguard Worker // Make sure /storage/emulated/... paths are setup correctly
842*f40fafd4SAndroid Build Coastguard Worker // This needs to be done before EnsureDirExists to ensure Android/ is created.
843*f40fafd4SAndroid Build Coastguard Worker auto status = setupAppDir(targets_cstr[i], uid, false /* fixupExistingOnly */);
844*f40fafd4SAndroid Build Coastguard Worker if (status != OK) {
845*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Failed to create dir: " << targets_cstr[i];
846*f40fafd4SAndroid Build Coastguard Worker return false;
847*f40fafd4SAndroid Build Coastguard Worker }
848*f40fafd4SAndroid Build Coastguard Worker status = EnsureDirExists(sources_cstr[i], 0771, AID_MEDIA_RW, AID_MEDIA_RW);
849*f40fafd4SAndroid Build Coastguard Worker if (status != OK) {
850*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Failed to create dir: " << sources_cstr[i];
851*f40fafd4SAndroid Build Coastguard Worker return false;
852*f40fafd4SAndroid Build Coastguard Worker }
853*f40fafd4SAndroid Build Coastguard Worker }
854*f40fafd4SAndroid Build Coastguard Worker
855*f40fafd4SAndroid Build Coastguard Worker char android_data_dir[PATH_MAX];
856*f40fafd4SAndroid Build Coastguard Worker char android_obb_dir[PATH_MAX];
857*f40fafd4SAndroid Build Coastguard Worker snprintf(android_data_dir, PATH_MAX, "/storage/emulated/%d/Android/data", userId);
858*f40fafd4SAndroid Build Coastguard Worker snprintf(android_obb_dir, PATH_MAX, "/storage/emulated/%d/Android/obb", userId);
859*f40fafd4SAndroid Build Coastguard Worker
860*f40fafd4SAndroid Build Coastguard Worker pid_t child;
861*f40fafd4SAndroid Build Coastguard Worker // Fork a child to mount Android/obb android Android/data dirs, as we don't want it to affect
862*f40fafd4SAndroid Build Coastguard Worker // original vold process mount namespace.
863*f40fafd4SAndroid Build Coastguard Worker if (!(child = fork())) {
864*f40fafd4SAndroid Build Coastguard Worker if (doUnmount) {
865*f40fafd4SAndroid Build Coastguard Worker if (umountStorageDirs(nsFd, android_data_dir, android_obb_dir, uid,
866*f40fafd4SAndroid Build Coastguard Worker targets_cstr, size)) {
867*f40fafd4SAndroid Build Coastguard Worker _exit(0);
868*f40fafd4SAndroid Build Coastguard Worker } else {
869*f40fafd4SAndroid Build Coastguard Worker _exit(1);
870*f40fafd4SAndroid Build Coastguard Worker }
871*f40fafd4SAndroid Build Coastguard Worker } else {
872*f40fafd4SAndroid Build Coastguard Worker if (remountStorageDirs(nsFd, android_data_dir, android_obb_dir, uid,
873*f40fafd4SAndroid Build Coastguard Worker sources_cstr, targets_cstr, size)) {
874*f40fafd4SAndroid Build Coastguard Worker _exit(0);
875*f40fafd4SAndroid Build Coastguard Worker } else {
876*f40fafd4SAndroid Build Coastguard Worker _exit(1);
877*f40fafd4SAndroid Build Coastguard Worker }
878*f40fafd4SAndroid Build Coastguard Worker }
879*f40fafd4SAndroid Build Coastguard Worker }
880*f40fafd4SAndroid Build Coastguard Worker
881*f40fafd4SAndroid Build Coastguard Worker if (child == -1) {
882*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Failed to fork";
883*f40fafd4SAndroid Build Coastguard Worker return false;
884*f40fafd4SAndroid Build Coastguard Worker } else {
885*f40fafd4SAndroid Build Coastguard Worker int status;
886*f40fafd4SAndroid Build Coastguard Worker if (TEMP_FAILURE_RETRY(waitpid(child, &status, 0)) == -1) {
887*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Failed to waitpid: " << child;
888*f40fafd4SAndroid Build Coastguard Worker return false;
889*f40fafd4SAndroid Build Coastguard Worker }
890*f40fafd4SAndroid Build Coastguard Worker if (!WIFEXITED(status)) {
891*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Process did not exit normally, status: " << status;
892*f40fafd4SAndroid Build Coastguard Worker return false;
893*f40fafd4SAndroid Build Coastguard Worker }
894*f40fafd4SAndroid Build Coastguard Worker if (WEXITSTATUS(status)) {
895*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Process exited with code: " << WEXITSTATUS(status);
896*f40fafd4SAndroid Build Coastguard Worker return false;
897*f40fafd4SAndroid Build Coastguard Worker }
898*f40fafd4SAndroid Build Coastguard Worker }
899*f40fafd4SAndroid Build Coastguard Worker return true;
900*f40fafd4SAndroid Build Coastguard Worker }
901*f40fafd4SAndroid Build Coastguard Worker
handleAppStorageDirs(int uid,int pid,bool doUnmount,const std::vector<std::string> & packageNames)902*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::handleAppStorageDirs(int uid, int pid,
903*f40fafd4SAndroid Build Coastguard Worker bool doUnmount, const std::vector<std::string>& packageNames) {
904*f40fafd4SAndroid Build Coastguard Worker // Only run the remount if fuse is mounted for that user.
905*f40fafd4SAndroid Build Coastguard Worker userid_t userId = multiuser_get_user_id(uid);
906*f40fafd4SAndroid Build Coastguard Worker bool fuseMounted = false;
907*f40fafd4SAndroid Build Coastguard Worker for (auto& vol : mInternalEmulatedVolumes) {
908*f40fafd4SAndroid Build Coastguard Worker if (vol->getMountUserId() == userId && vol->getState() == VolumeBase::State::kMounted) {
909*f40fafd4SAndroid Build Coastguard Worker auto* emulatedVol = static_cast<android::vold::EmulatedVolume*>(vol.get());
910*f40fafd4SAndroid Build Coastguard Worker if (emulatedVol) {
911*f40fafd4SAndroid Build Coastguard Worker fuseMounted = emulatedVol->isFuseMounted();
912*f40fafd4SAndroid Build Coastguard Worker }
913*f40fafd4SAndroid Build Coastguard Worker break;
914*f40fafd4SAndroid Build Coastguard Worker }
915*f40fafd4SAndroid Build Coastguard Worker }
916*f40fafd4SAndroid Build Coastguard Worker if (fuseMounted) {
917*f40fafd4SAndroid Build Coastguard Worker forkAndRemountStorage(uid, pid, doUnmount, packageNames);
918*f40fafd4SAndroid Build Coastguard Worker }
919*f40fafd4SAndroid Build Coastguard Worker return 0;
920*f40fafd4SAndroid Build Coastguard Worker }
921*f40fafd4SAndroid Build Coastguard Worker
abortFuse()922*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::abortFuse() {
923*f40fafd4SAndroid Build Coastguard Worker return android::vold::AbortFuseConnections();
924*f40fafd4SAndroid Build Coastguard Worker }
925*f40fafd4SAndroid Build Coastguard Worker
reset()926*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::reset() {
927*f40fafd4SAndroid Build Coastguard Worker // Tear down all existing disks/volumes and start from a blank slate so
928*f40fafd4SAndroid Build Coastguard Worker // newly connected framework hears all events.
929*f40fafd4SAndroid Build Coastguard Worker
930*f40fafd4SAndroid Build Coastguard Worker // Destroy StubVolume disks. This needs to be done before destroying
931*f40fafd4SAndroid Build Coastguard Worker // EmulatedVolumes because in ARC (Android on ChromeOS), ChromeOS Downloads
932*f40fafd4SAndroid Build Coastguard Worker // directory (which is in a StubVolume) is bind-mounted to
933*f40fafd4SAndroid Build Coastguard Worker // /data/media/0/Download.
934*f40fafd4SAndroid Build Coastguard Worker // We do not recreate StubVolumes here because they are managed from outside
935*f40fafd4SAndroid Build Coastguard Worker // Android (e.g. from ChromeOS) and their disk recreation on reset events
936*f40fafd4SAndroid Build Coastguard Worker // should be handled from outside by calling createStubVolume() again.
937*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
938*f40fafd4SAndroid Build Coastguard Worker if (disk->isStub()) {
939*f40fafd4SAndroid Build Coastguard Worker disk->destroy();
940*f40fafd4SAndroid Build Coastguard Worker }
941*f40fafd4SAndroid Build Coastguard Worker }
942*f40fafd4SAndroid Build Coastguard Worker // Remove StubVolume from both mDisks and mPendingDisks.
943*f40fafd4SAndroid Build Coastguard Worker const auto isStub = [](const auto& disk) { return disk->isStub(); };
944*f40fafd4SAndroid Build Coastguard Worker mDisks.remove_if(isStub);
945*f40fafd4SAndroid Build Coastguard Worker mPendingDisks.remove_if(isStub);
946*f40fafd4SAndroid Build Coastguard Worker
947*f40fafd4SAndroid Build Coastguard Worker for (const auto& vol : mInternalEmulatedVolumes) {
948*f40fafd4SAndroid Build Coastguard Worker vol->destroy();
949*f40fafd4SAndroid Build Coastguard Worker }
950*f40fafd4SAndroid Build Coastguard Worker mInternalEmulatedVolumes.clear();
951*f40fafd4SAndroid Build Coastguard Worker
952*f40fafd4SAndroid Build Coastguard Worker // Destroy and recreate non-StubVolume disks.
953*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
954*f40fafd4SAndroid Build Coastguard Worker disk->destroy();
955*f40fafd4SAndroid Build Coastguard Worker disk->create();
956*f40fafd4SAndroid Build Coastguard Worker }
957*f40fafd4SAndroid Build Coastguard Worker
958*f40fafd4SAndroid Build Coastguard Worker updateVirtualDisk();
959*f40fafd4SAndroid Build Coastguard Worker mAddedUsers.clear();
960*f40fafd4SAndroid Build Coastguard Worker mStartedUsers.clear();
961*f40fafd4SAndroid Build Coastguard Worker mSharedStorageUser.clear();
962*f40fafd4SAndroid Build Coastguard Worker
963*f40fafd4SAndroid Build Coastguard Worker // Abort all FUSE connections to avoid deadlocks if the FUSE daemon was killed
964*f40fafd4SAndroid Build Coastguard Worker // with FUSE fds open.
965*f40fafd4SAndroid Build Coastguard Worker abortFuse();
966*f40fafd4SAndroid Build Coastguard Worker return 0;
967*f40fafd4SAndroid Build Coastguard Worker }
968*f40fafd4SAndroid Build Coastguard Worker
969*f40fafd4SAndroid Build Coastguard Worker // Can be called twice (sequentially) during shutdown. should be safe for that.
shutdown()970*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::shutdown() {
971*f40fafd4SAndroid Build Coastguard Worker if (mInternalEmulatedVolumes.empty()) {
972*f40fafd4SAndroid Build Coastguard Worker return 0; // already shutdown
973*f40fafd4SAndroid Build Coastguard Worker }
974*f40fafd4SAndroid Build Coastguard Worker android::vold::sSleepOnUnmount = false;
975*f40fafd4SAndroid Build Coastguard Worker // Destroy StubVolume disks before destroying EmulatedVolumes (see the
976*f40fafd4SAndroid Build Coastguard Worker // comment in VolumeManager::reset()).
977*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
978*f40fafd4SAndroid Build Coastguard Worker if (disk->isStub()) {
979*f40fafd4SAndroid Build Coastguard Worker disk->destroy();
980*f40fafd4SAndroid Build Coastguard Worker }
981*f40fafd4SAndroid Build Coastguard Worker }
982*f40fafd4SAndroid Build Coastguard Worker for (const auto& vol : mInternalEmulatedVolumes) {
983*f40fafd4SAndroid Build Coastguard Worker vol->destroy();
984*f40fafd4SAndroid Build Coastguard Worker }
985*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
986*f40fafd4SAndroid Build Coastguard Worker if (!disk->isStub()) {
987*f40fafd4SAndroid Build Coastguard Worker disk->destroy();
988*f40fafd4SAndroid Build Coastguard Worker }
989*f40fafd4SAndroid Build Coastguard Worker }
990*f40fafd4SAndroid Build Coastguard Worker
991*f40fafd4SAndroid Build Coastguard Worker mInternalEmulatedVolumes.clear();
992*f40fafd4SAndroid Build Coastguard Worker mDisks.clear();
993*f40fafd4SAndroid Build Coastguard Worker mPendingDisks.clear();
994*f40fafd4SAndroid Build Coastguard Worker android::vold::sSleepOnUnmount = true;
995*f40fafd4SAndroid Build Coastguard Worker
996*f40fafd4SAndroid Build Coastguard Worker return 0;
997*f40fafd4SAndroid Build Coastguard Worker }
998*f40fafd4SAndroid Build Coastguard Worker
unmountAll()999*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::unmountAll() {
1000*f40fafd4SAndroid Build Coastguard Worker std::lock_guard<std::mutex> lock(mLock);
1001*f40fafd4SAndroid Build Coastguard Worker ATRACE_NAME("VolumeManager::unmountAll()");
1002*f40fafd4SAndroid Build Coastguard Worker
1003*f40fafd4SAndroid Build Coastguard Worker // First, try gracefully unmounting all known devices
1004*f40fafd4SAndroid Build Coastguard Worker // Unmount StubVolume disks before unmounting EmulatedVolumes (see the
1005*f40fafd4SAndroid Build Coastguard Worker // comment in VolumeManager::reset()).
1006*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
1007*f40fafd4SAndroid Build Coastguard Worker if (disk->isStub()) {
1008*f40fafd4SAndroid Build Coastguard Worker disk->unmountAll();
1009*f40fafd4SAndroid Build Coastguard Worker }
1010*f40fafd4SAndroid Build Coastguard Worker }
1011*f40fafd4SAndroid Build Coastguard Worker for (const auto& vol : mInternalEmulatedVolumes) {
1012*f40fafd4SAndroid Build Coastguard Worker vol->unmount();
1013*f40fafd4SAndroid Build Coastguard Worker }
1014*f40fafd4SAndroid Build Coastguard Worker for (const auto& disk : mDisks) {
1015*f40fafd4SAndroid Build Coastguard Worker if (!disk->isStub()) {
1016*f40fafd4SAndroid Build Coastguard Worker disk->unmountAll();
1017*f40fafd4SAndroid Build Coastguard Worker }
1018*f40fafd4SAndroid Build Coastguard Worker }
1019*f40fafd4SAndroid Build Coastguard Worker
1020*f40fafd4SAndroid Build Coastguard Worker // Worst case we might have some stale mounts lurking around, so
1021*f40fafd4SAndroid Build Coastguard Worker // force unmount those just to be safe.
1022*f40fafd4SAndroid Build Coastguard Worker FILE* fp = setmntent("/proc/mounts", "re");
1023*f40fafd4SAndroid Build Coastguard Worker if (fp == NULL) {
1024*f40fafd4SAndroid Build Coastguard Worker PLOG(ERROR) << "Failed to open /proc/mounts";
1025*f40fafd4SAndroid Build Coastguard Worker return -errno;
1026*f40fafd4SAndroid Build Coastguard Worker }
1027*f40fafd4SAndroid Build Coastguard Worker
1028*f40fafd4SAndroid Build Coastguard Worker // Some volumes can be stacked on each other, so force unmount in
1029*f40fafd4SAndroid Build Coastguard Worker // reverse order to give us the best chance of success.
1030*f40fafd4SAndroid Build Coastguard Worker std::list<std::string> toUnmount;
1031*f40fafd4SAndroid Build Coastguard Worker mntent* mentry;
1032*f40fafd4SAndroid Build Coastguard Worker while ((mentry = getmntent(fp)) != NULL) {
1033*f40fafd4SAndroid Build Coastguard Worker auto test = std::string(mentry->mnt_dir);
1034*f40fafd4SAndroid Build Coastguard Worker if ((StartsWith(test, "/mnt/") &&
1035*f40fafd4SAndroid Build Coastguard Worker #ifdef __ANDROID_DEBUGGABLE__
1036*f40fafd4SAndroid Build Coastguard Worker !StartsWith(test, "/mnt/scratch") &&
1037*f40fafd4SAndroid Build Coastguard Worker #endif
1038*f40fafd4SAndroid Build Coastguard Worker !StartsWith(test, "/mnt/vendor") && !StartsWith(test, "/mnt/product") &&
1039*f40fafd4SAndroid Build Coastguard Worker !StartsWith(test, "/mnt/installer") && !StartsWith(test, "/mnt/androidwritable") &&
1040*f40fafd4SAndroid Build Coastguard Worker !StartsWith(test, "/mnt/vm")) ||
1041*f40fafd4SAndroid Build Coastguard Worker StartsWith(test, "/storage/")) {
1042*f40fafd4SAndroid Build Coastguard Worker toUnmount.push_front(test);
1043*f40fafd4SAndroid Build Coastguard Worker }
1044*f40fafd4SAndroid Build Coastguard Worker }
1045*f40fafd4SAndroid Build Coastguard Worker endmntent(fp);
1046*f40fafd4SAndroid Build Coastguard Worker
1047*f40fafd4SAndroid Build Coastguard Worker for (const auto& path : toUnmount) {
1048*f40fafd4SAndroid Build Coastguard Worker LOG(DEBUG) << "Tearing down stale mount " << path;
1049*f40fafd4SAndroid Build Coastguard Worker android::vold::ForceUnmount(path);
1050*f40fafd4SAndroid Build Coastguard Worker }
1051*f40fafd4SAndroid Build Coastguard Worker
1052*f40fafd4SAndroid Build Coastguard Worker return 0;
1053*f40fafd4SAndroid Build Coastguard Worker }
1054*f40fafd4SAndroid Build Coastguard Worker
ensureAppDirsCreated(const std::vector<std::string> & paths,int32_t appUid)1055*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::ensureAppDirsCreated(const std::vector<std::string>& paths, int32_t appUid) {
1056*f40fafd4SAndroid Build Coastguard Worker int size = paths.size();
1057*f40fafd4SAndroid Build Coastguard Worker for (int i = 0; i < size; i++) {
1058*f40fafd4SAndroid Build Coastguard Worker int result = setupAppDir(paths[i], appUid, false /* fixupExistingOnly */,
1059*f40fafd4SAndroid Build Coastguard Worker true /* skipIfDirExists */);
1060*f40fafd4SAndroid Build Coastguard Worker if (result != OK) {
1061*f40fafd4SAndroid Build Coastguard Worker return result;
1062*f40fafd4SAndroid Build Coastguard Worker }
1063*f40fafd4SAndroid Build Coastguard Worker }
1064*f40fafd4SAndroid Build Coastguard Worker return OK;
1065*f40fafd4SAndroid Build Coastguard Worker }
1066*f40fafd4SAndroid Build Coastguard Worker
setupAppDir(const std::string & path,int32_t appUid,bool fixupExistingOnly,bool skipIfDirExists)1067*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::setupAppDir(const std::string& path, int32_t appUid, bool fixupExistingOnly,
1068*f40fafd4SAndroid Build Coastguard Worker bool skipIfDirExists) {
1069*f40fafd4SAndroid Build Coastguard Worker // Only offer to create directories for paths managed by vold
1070*f40fafd4SAndroid Build Coastguard Worker if (!StartsWith(path, "/storage/")) {
1071*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "Failed to find mounted volume for " << path;
1072*f40fafd4SAndroid Build Coastguard Worker return -EINVAL;
1073*f40fafd4SAndroid Build Coastguard Worker }
1074*f40fafd4SAndroid Build Coastguard Worker
1075*f40fafd4SAndroid Build Coastguard Worker // Find the volume it belongs to
1076*f40fafd4SAndroid Build Coastguard Worker auto filter_fn = [&](const VolumeBase& vol) {
1077*f40fafd4SAndroid Build Coastguard Worker if (vol.getState() != VolumeBase::State::kMounted) {
1078*f40fafd4SAndroid Build Coastguard Worker // The volume must be mounted
1079*f40fafd4SAndroid Build Coastguard Worker return false;
1080*f40fafd4SAndroid Build Coastguard Worker }
1081*f40fafd4SAndroid Build Coastguard Worker if (!vol.isVisibleForWrite()) {
1082*f40fafd4SAndroid Build Coastguard Worker // App dirs should only be created for writable volumes.
1083*f40fafd4SAndroid Build Coastguard Worker return false;
1084*f40fafd4SAndroid Build Coastguard Worker }
1085*f40fafd4SAndroid Build Coastguard Worker if (vol.getInternalPath().empty()) {
1086*f40fafd4SAndroid Build Coastguard Worker return false;
1087*f40fafd4SAndroid Build Coastguard Worker }
1088*f40fafd4SAndroid Build Coastguard Worker if (vol.getMountUserId() != USER_UNKNOWN &&
1089*f40fafd4SAndroid Build Coastguard Worker vol.getMountUserId() != multiuser_get_user_id(appUid)) {
1090*f40fafd4SAndroid Build Coastguard Worker // The app dir must be created on a volume with the same user-id
1091*f40fafd4SAndroid Build Coastguard Worker return false;
1092*f40fafd4SAndroid Build Coastguard Worker }
1093*f40fafd4SAndroid Build Coastguard Worker if (!path.empty() && StartsWith(path, vol.getPath())) {
1094*f40fafd4SAndroid Build Coastguard Worker return true;
1095*f40fafd4SAndroid Build Coastguard Worker }
1096*f40fafd4SAndroid Build Coastguard Worker
1097*f40fafd4SAndroid Build Coastguard Worker return false;
1098*f40fafd4SAndroid Build Coastguard Worker };
1099*f40fafd4SAndroid Build Coastguard Worker auto volume = findVolumeWithFilter(filter_fn);
1100*f40fafd4SAndroid Build Coastguard Worker if (volume == nullptr) {
1101*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "Failed to find mounted volume for " << path;
1102*f40fafd4SAndroid Build Coastguard Worker return -EINVAL;
1103*f40fafd4SAndroid Build Coastguard Worker }
1104*f40fafd4SAndroid Build Coastguard Worker // Convert paths to lower filesystem paths to avoid making FUSE requests for these reasons:
1105*f40fafd4SAndroid Build Coastguard Worker // 1. A FUSE request from vold puts vold at risk of hanging if the FUSE daemon is down
1106*f40fafd4SAndroid Build Coastguard Worker // 2. The FUSE daemon prevents requests on /mnt/user/0/emulated/<userid != 0> and a request
1107*f40fafd4SAndroid Build Coastguard Worker // on /storage/emulated/10 means /mnt/user/0/emulated/10
1108*f40fafd4SAndroid Build Coastguard Worker const std::string lowerPath =
1109*f40fafd4SAndroid Build Coastguard Worker volume->getInternalPath() + path.substr(volume->getPath().length());
1110*f40fafd4SAndroid Build Coastguard Worker
1111*f40fafd4SAndroid Build Coastguard Worker const std::string volumeRoot = volume->getRootPath(); // eg /data/media/0
1112*f40fafd4SAndroid Build Coastguard Worker
1113*f40fafd4SAndroid Build Coastguard Worker const int access_result = access(lowerPath.c_str(), F_OK);
1114*f40fafd4SAndroid Build Coastguard Worker if (fixupExistingOnly && access_result != 0) {
1115*f40fafd4SAndroid Build Coastguard Worker // Nothing to fixup
1116*f40fafd4SAndroid Build Coastguard Worker return OK;
1117*f40fafd4SAndroid Build Coastguard Worker }
1118*f40fafd4SAndroid Build Coastguard Worker
1119*f40fafd4SAndroid Build Coastguard Worker if (skipIfDirExists && access_result == 0) {
1120*f40fafd4SAndroid Build Coastguard Worker // It's safe to assume it's ok as it will be used for zygote to bind mount dir only,
1121*f40fafd4SAndroid Build Coastguard Worker // which the dir doesn't need to have correct permission for now yet.
1122*f40fafd4SAndroid Build Coastguard Worker return OK;
1123*f40fafd4SAndroid Build Coastguard Worker }
1124*f40fafd4SAndroid Build Coastguard Worker
1125*f40fafd4SAndroid Build Coastguard Worker if (volume->getType() == VolumeBase::Type::kPublic) {
1126*f40fafd4SAndroid Build Coastguard Worker // On public volumes, we don't need to setup permissions, as everything goes through
1127*f40fafd4SAndroid Build Coastguard Worker // FUSE; just create the dirs and be done with it.
1128*f40fafd4SAndroid Build Coastguard Worker return fs_mkdirs(lowerPath.c_str(), 0700);
1129*f40fafd4SAndroid Build Coastguard Worker }
1130*f40fafd4SAndroid Build Coastguard Worker
1131*f40fafd4SAndroid Build Coastguard Worker // Create the app paths we need from the root
1132*f40fafd4SAndroid Build Coastguard Worker return PrepareAppDirFromRoot(lowerPath, volumeRoot, appUid, fixupExistingOnly);
1133*f40fafd4SAndroid Build Coastguard Worker }
1134*f40fafd4SAndroid Build Coastguard Worker
fixupAppDir(const std::string & path,int32_t appUid)1135*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::fixupAppDir(const std::string& path, int32_t appUid) {
1136*f40fafd4SAndroid Build Coastguard Worker if (IsSdcardfsUsed()) {
1137*f40fafd4SAndroid Build Coastguard Worker //sdcardfs magically does this for us
1138*f40fafd4SAndroid Build Coastguard Worker return OK;
1139*f40fafd4SAndroid Build Coastguard Worker }
1140*f40fafd4SAndroid Build Coastguard Worker return setupAppDir(path, appUid, true /* fixupExistingOnly */);
1141*f40fafd4SAndroid Build Coastguard Worker }
1142*f40fafd4SAndroid Build Coastguard Worker
createObb(const std::string & sourcePath,int32_t ownerGid,std::string * outVolId)1143*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::createObb(const std::string& sourcePath, int32_t ownerGid,
1144*f40fafd4SAndroid Build Coastguard Worker std::string* outVolId) {
1145*f40fafd4SAndroid Build Coastguard Worker int id = mNextObbId++;
1146*f40fafd4SAndroid Build Coastguard Worker
1147*f40fafd4SAndroid Build Coastguard Worker std::string lowerSourcePath;
1148*f40fafd4SAndroid Build Coastguard Worker
1149*f40fafd4SAndroid Build Coastguard Worker // Convert to lower filesystem path
1150*f40fafd4SAndroid Build Coastguard Worker if (StartsWith(sourcePath, "/storage/")) {
1151*f40fafd4SAndroid Build Coastguard Worker auto filter_fn = [&](const VolumeBase& vol) {
1152*f40fafd4SAndroid Build Coastguard Worker if (vol.getState() != VolumeBase::State::kMounted) {
1153*f40fafd4SAndroid Build Coastguard Worker // The volume must be mounted
1154*f40fafd4SAndroid Build Coastguard Worker return false;
1155*f40fafd4SAndroid Build Coastguard Worker }
1156*f40fafd4SAndroid Build Coastguard Worker if (!vol.isVisibleForWrite()) {
1157*f40fafd4SAndroid Build Coastguard Worker // Obb volume should only be created for writable volumes.
1158*f40fafd4SAndroid Build Coastguard Worker return false;
1159*f40fafd4SAndroid Build Coastguard Worker }
1160*f40fafd4SAndroid Build Coastguard Worker if (vol.getInternalPath().empty()) {
1161*f40fafd4SAndroid Build Coastguard Worker return false;
1162*f40fafd4SAndroid Build Coastguard Worker }
1163*f40fafd4SAndroid Build Coastguard Worker if (!sourcePath.empty() && StartsWith(sourcePath, vol.getPath())) {
1164*f40fafd4SAndroid Build Coastguard Worker return true;
1165*f40fafd4SAndroid Build Coastguard Worker }
1166*f40fafd4SAndroid Build Coastguard Worker
1167*f40fafd4SAndroid Build Coastguard Worker return false;
1168*f40fafd4SAndroid Build Coastguard Worker };
1169*f40fafd4SAndroid Build Coastguard Worker auto volume = findVolumeWithFilter(filter_fn);
1170*f40fafd4SAndroid Build Coastguard Worker if (volume == nullptr) {
1171*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "Failed to find mounted volume for " << sourcePath;
1172*f40fafd4SAndroid Build Coastguard Worker return -EINVAL;
1173*f40fafd4SAndroid Build Coastguard Worker } else {
1174*f40fafd4SAndroid Build Coastguard Worker lowerSourcePath =
1175*f40fafd4SAndroid Build Coastguard Worker volume->getInternalPath() + sourcePath.substr(volume->getPath().length());
1176*f40fafd4SAndroid Build Coastguard Worker }
1177*f40fafd4SAndroid Build Coastguard Worker } else {
1178*f40fafd4SAndroid Build Coastguard Worker lowerSourcePath = sourcePath;
1179*f40fafd4SAndroid Build Coastguard Worker }
1180*f40fafd4SAndroid Build Coastguard Worker
1181*f40fafd4SAndroid Build Coastguard Worker auto vol = std::shared_ptr<android::vold::VolumeBase>(
1182*f40fafd4SAndroid Build Coastguard Worker new android::vold::ObbVolume(id, lowerSourcePath, ownerGid));
1183*f40fafd4SAndroid Build Coastguard Worker vol->create();
1184*f40fafd4SAndroid Build Coastguard Worker
1185*f40fafd4SAndroid Build Coastguard Worker mObbVolumes.push_back(vol);
1186*f40fafd4SAndroid Build Coastguard Worker *outVolId = vol->getId();
1187*f40fafd4SAndroid Build Coastguard Worker return android::OK;
1188*f40fafd4SAndroid Build Coastguard Worker }
1189*f40fafd4SAndroid Build Coastguard Worker
destroyObb(const std::string & volId)1190*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::destroyObb(const std::string& volId) {
1191*f40fafd4SAndroid Build Coastguard Worker auto i = mObbVolumes.begin();
1192*f40fafd4SAndroid Build Coastguard Worker while (i != mObbVolumes.end()) {
1193*f40fafd4SAndroid Build Coastguard Worker if ((*i)->getId() == volId) {
1194*f40fafd4SAndroid Build Coastguard Worker (*i)->destroy();
1195*f40fafd4SAndroid Build Coastguard Worker i = mObbVolumes.erase(i);
1196*f40fafd4SAndroid Build Coastguard Worker } else {
1197*f40fafd4SAndroid Build Coastguard Worker ++i;
1198*f40fafd4SAndroid Build Coastguard Worker }
1199*f40fafd4SAndroid Build Coastguard Worker }
1200*f40fafd4SAndroid Build Coastguard Worker return android::OK;
1201*f40fafd4SAndroid Build Coastguard Worker }
1202*f40fafd4SAndroid Build Coastguard Worker
createStubVolume(const std::string & sourcePath,const std::string & mountPath,const std::string & fsType,const std::string & fsUuid,const std::string & fsLabel,int32_t flags,std::string * outVolId)1203*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::createStubVolume(const std::string& sourcePath, const std::string& mountPath,
1204*f40fafd4SAndroid Build Coastguard Worker const std::string& fsType, const std::string& fsUuid,
1205*f40fafd4SAndroid Build Coastguard Worker const std::string& fsLabel, int32_t flags,
1206*f40fafd4SAndroid Build Coastguard Worker std::string* outVolId) {
1207*f40fafd4SAndroid Build Coastguard Worker dev_t stubId = --mNextStubId;
1208*f40fafd4SAndroid Build Coastguard Worker auto vol = std::shared_ptr<android::vold::StubVolume>(
1209*f40fafd4SAndroid Build Coastguard Worker new android::vold::StubVolume(stubId, sourcePath, mountPath, fsType, fsUuid, fsLabel));
1210*f40fafd4SAndroid Build Coastguard Worker
1211*f40fafd4SAndroid Build Coastguard Worker int32_t passedFlags = 0;
1212*f40fafd4SAndroid Build Coastguard Worker passedFlags |= (flags & android::vold::Disk::Flags::kUsb);
1213*f40fafd4SAndroid Build Coastguard Worker passedFlags |= (flags & android::vold::Disk::Flags::kSd);
1214*f40fafd4SAndroid Build Coastguard Worker if (flags & android::vold::Disk::Flags::kStubVisible) {
1215*f40fafd4SAndroid Build Coastguard Worker passedFlags |= (flags & android::vold::Disk::Flags::kStubVisible);
1216*f40fafd4SAndroid Build Coastguard Worker } else {
1217*f40fafd4SAndroid Build Coastguard Worker passedFlags |= (flags & android::vold::Disk::Flags::kStubInvisible);
1218*f40fafd4SAndroid Build Coastguard Worker }
1219*f40fafd4SAndroid Build Coastguard Worker // StubDisk doesn't have device node corresponds to it. So, a fake device
1220*f40fafd4SAndroid Build Coastguard Worker // number is used.
1221*f40fafd4SAndroid Build Coastguard Worker auto disk = std::shared_ptr<android::vold::Disk>(
1222*f40fafd4SAndroid Build Coastguard Worker new android::vold::Disk("stub", stubId, "stub", passedFlags));
1223*f40fafd4SAndroid Build Coastguard Worker disk->initializePartition(vol);
1224*f40fafd4SAndroid Build Coastguard Worker handleDiskAdded(disk);
1225*f40fafd4SAndroid Build Coastguard Worker *outVolId = vol->getId();
1226*f40fafd4SAndroid Build Coastguard Worker return android::OK;
1227*f40fafd4SAndroid Build Coastguard Worker }
1228*f40fafd4SAndroid Build Coastguard Worker
destroyStubVolume(const std::string & volId)1229*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::destroyStubVolume(const std::string& volId) {
1230*f40fafd4SAndroid Build Coastguard Worker auto tokens = android::base::Split(volId, ":");
1231*f40fafd4SAndroid Build Coastguard Worker CHECK(tokens.size() == 2);
1232*f40fafd4SAndroid Build Coastguard Worker dev_t stubId;
1233*f40fafd4SAndroid Build Coastguard Worker CHECK(android::base::ParseUint(tokens[1], &stubId));
1234*f40fafd4SAndroid Build Coastguard Worker handleDiskRemoved(stubId);
1235*f40fafd4SAndroid Build Coastguard Worker return android::OK;
1236*f40fafd4SAndroid Build Coastguard Worker }
1237*f40fafd4SAndroid Build Coastguard Worker
mountAppFuse(uid_t uid,int mountId,unique_fd * device_fd)1238*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::mountAppFuse(uid_t uid, int mountId, unique_fd* device_fd) {
1239*f40fafd4SAndroid Build Coastguard Worker return android::vold::MountAppFuse(uid, mountId, device_fd);
1240*f40fafd4SAndroid Build Coastguard Worker }
1241*f40fafd4SAndroid Build Coastguard Worker
unmountAppFuse(uid_t uid,int mountId)1242*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::unmountAppFuse(uid_t uid, int mountId) {
1243*f40fafd4SAndroid Build Coastguard Worker return android::vold::UnmountAppFuse(uid, mountId);
1244*f40fafd4SAndroid Build Coastguard Worker }
1245*f40fafd4SAndroid Build Coastguard Worker
openAppFuseFile(uid_t uid,int mountId,int fileId,int flags)1246*f40fafd4SAndroid Build Coastguard Worker int VolumeManager::openAppFuseFile(uid_t uid, int mountId, int fileId, int flags) {
1247*f40fafd4SAndroid Build Coastguard Worker return android::vold::OpenAppFuseFile(uid, mountId, fileId, flags);
1248*f40fafd4SAndroid Build Coastguard Worker }
1249*f40fafd4SAndroid Build Coastguard Worker
getDeviceSize(std::string & device,int64_t * storageSize)1250*f40fafd4SAndroid Build Coastguard Worker static android::status_t getDeviceSize(std::string& device, int64_t* storageSize) {
1251*f40fafd4SAndroid Build Coastguard Worker // Follow any symbolic links
1252*f40fafd4SAndroid Build Coastguard Worker std::string dataDevice;
1253*f40fafd4SAndroid Build Coastguard Worker if (!android::base::Realpath(device, &dataDevice)) {
1254*f40fafd4SAndroid Build Coastguard Worker dataDevice = device;
1255*f40fafd4SAndroid Build Coastguard Worker }
1256*f40fafd4SAndroid Build Coastguard Worker
1257*f40fafd4SAndroid Build Coastguard Worker // Handle mapped volumes.
1258*f40fafd4SAndroid Build Coastguard Worker auto& dm = android::dm::DeviceMapper::Instance();
1259*f40fafd4SAndroid Build Coastguard Worker for (;;) {
1260*f40fafd4SAndroid Build Coastguard Worker auto parent = dm.GetParentBlockDeviceByPath(dataDevice);
1261*f40fafd4SAndroid Build Coastguard Worker if (!parent.has_value()) break;
1262*f40fafd4SAndroid Build Coastguard Worker dataDevice = *parent;
1263*f40fafd4SAndroid Build Coastguard Worker }
1264*f40fafd4SAndroid Build Coastguard Worker
1265*f40fafd4SAndroid Build Coastguard Worker // Get the potential /sys/block entry
1266*f40fafd4SAndroid Build Coastguard Worker std::size_t leaf = dataDevice.rfind('/');
1267*f40fafd4SAndroid Build Coastguard Worker if (leaf == std::string::npos) {
1268*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "data device " << dataDevice << " is not a path";
1269*f40fafd4SAndroid Build Coastguard Worker return EINVAL;
1270*f40fafd4SAndroid Build Coastguard Worker }
1271*f40fafd4SAndroid Build Coastguard Worker if (dataDevice.substr(0, leaf) != "/dev/block") {
1272*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "data device " << dataDevice << " is not a block device";
1273*f40fafd4SAndroid Build Coastguard Worker return EINVAL;
1274*f40fafd4SAndroid Build Coastguard Worker }
1275*f40fafd4SAndroid Build Coastguard Worker std::string sysfs = std::string() + "/sys/block/" + dataDevice.substr(leaf + 1);
1276*f40fafd4SAndroid Build Coastguard Worker
1277*f40fafd4SAndroid Build Coastguard Worker // Look for a directory in /sys/block containing size where the name is a shortened
1278*f40fafd4SAndroid Build Coastguard Worker // version of the name we now have
1279*f40fafd4SAndroid Build Coastguard Worker // Typically we start with something like /sys/block/sda2, and we want /sys/block/sda
1280*f40fafd4SAndroid Build Coastguard Worker // Note that this directory only contains actual disks, not partitions, so this is
1281*f40fafd4SAndroid Build Coastguard Worker // not going to find anything other than the disks
1282*f40fafd4SAndroid Build Coastguard Worker std::string size;
1283*f40fafd4SAndroid Build Coastguard Worker std::string sizeFile;
1284*f40fafd4SAndroid Build Coastguard Worker for (std::string sysfsDir = sysfs;; sysfsDir = sysfsDir.substr(0, sysfsDir.size() - 1)) {
1285*f40fafd4SAndroid Build Coastguard Worker if (sysfsDir.back() == '/') {
1286*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "Could not find valid block device from " << sysfs;
1287*f40fafd4SAndroid Build Coastguard Worker return EINVAL;
1288*f40fafd4SAndroid Build Coastguard Worker }
1289*f40fafd4SAndroid Build Coastguard Worker sizeFile = sysfsDir + "/size";
1290*f40fafd4SAndroid Build Coastguard Worker if (android::base::ReadFileToString(sizeFile, &size, true)) {
1291*f40fafd4SAndroid Build Coastguard Worker break;
1292*f40fafd4SAndroid Build Coastguard Worker }
1293*f40fafd4SAndroid Build Coastguard Worker }
1294*f40fafd4SAndroid Build Coastguard Worker
1295*f40fafd4SAndroid Build Coastguard Worker // Read the size file and be done
1296*f40fafd4SAndroid Build Coastguard Worker std::stringstream ssSize(size);
1297*f40fafd4SAndroid Build Coastguard Worker ssSize >> *storageSize;
1298*f40fafd4SAndroid Build Coastguard Worker if (ssSize.fail()) {
1299*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << sizeFile << " cannot be read as an integer";
1300*f40fafd4SAndroid Build Coastguard Worker return EINVAL;
1301*f40fafd4SAndroid Build Coastguard Worker }
1302*f40fafd4SAndroid Build Coastguard Worker
1303*f40fafd4SAndroid Build Coastguard Worker *storageSize *= 512;
1304*f40fafd4SAndroid Build Coastguard Worker return OK;
1305*f40fafd4SAndroid Build Coastguard Worker }
1306*f40fafd4SAndroid Build Coastguard Worker
GetStorageSize(int64_t * storageSize)1307*f40fafd4SAndroid Build Coastguard Worker android::status_t android::vold::GetStorageSize(int64_t* storageSize) {
1308*f40fafd4SAndroid Build Coastguard Worker android::status_t status;
1309*f40fafd4SAndroid Build Coastguard Worker // Start with the /data mount point from fs_mgr
1310*f40fafd4SAndroid Build Coastguard Worker auto entry = android::fs_mgr::GetEntryForMountPoint(&fstab_default, DATA_MNT_POINT);
1311*f40fafd4SAndroid Build Coastguard Worker if (entry == nullptr) {
1312*f40fafd4SAndroid Build Coastguard Worker LOG(ERROR) << "No mount point entry for " << DATA_MNT_POINT;
1313*f40fafd4SAndroid Build Coastguard Worker return EINVAL;
1314*f40fafd4SAndroid Build Coastguard Worker }
1315*f40fafd4SAndroid Build Coastguard Worker
1316*f40fafd4SAndroid Build Coastguard Worker status = getDeviceSize(entry->blk_device, storageSize);
1317*f40fafd4SAndroid Build Coastguard Worker if (status != OK) {
1318*f40fafd4SAndroid Build Coastguard Worker return status;
1319*f40fafd4SAndroid Build Coastguard Worker }
1320*f40fafd4SAndroid Build Coastguard Worker
1321*f40fafd4SAndroid Build Coastguard Worker for (auto device : entry->user_devices) {
1322*f40fafd4SAndroid Build Coastguard Worker int64_t deviceStorageSize;
1323*f40fafd4SAndroid Build Coastguard Worker status = getDeviceSize(device, &deviceStorageSize);
1324*f40fafd4SAndroid Build Coastguard Worker if (status != OK) {
1325*f40fafd4SAndroid Build Coastguard Worker return status;
1326*f40fafd4SAndroid Build Coastguard Worker }
1327*f40fafd4SAndroid Build Coastguard Worker *storageSize += deviceStorageSize;
1328*f40fafd4SAndroid Build Coastguard Worker }
1329*f40fafd4SAndroid Build Coastguard Worker
1330*f40fafd4SAndroid Build Coastguard Worker return OK;
1331*f40fafd4SAndroid Build Coastguard Worker }
1332