Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 1 | // Copyright 2019 The Chromium OS Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 5 | #include "patchpanel/adb_proxy.h" |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 6 | |
jasongustaman | 1407628 | 2019-05-20 15:38:41 +0900 | [diff] [blame] | 7 | #include <linux/vm_sockets.h> |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 8 | #include <sys/socket.h> |
| 9 | #include <sys/types.h> |
Jason Jeremy Iman | f4156cb | 2019-11-14 15:36:22 +0900 | [diff] [blame] | 10 | #include <sys/un.h> |
Garrick Evans | aa4f1ce | 2019-11-29 13:25:39 +0900 | [diff] [blame] | 11 | #include <sysexits.h> |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 12 | |
Jason Jeremy Iman | 510bd3d | 2019-12-16 13:05:30 +0900 | [diff] [blame] | 13 | #include <set> |
Jason Jeremy Iman | f4156cb | 2019-11-14 15:36:22 +0900 | [diff] [blame] | 14 | #include <string> |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 15 | #include <utility> |
Jason Jeremy Iman | f4156cb | 2019-11-14 15:36:22 +0900 | [diff] [blame] | 16 | #include <vector> |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 17 | |
| 18 | #include <base/bind.h> |
| 19 | #include <base/logging.h> |
Jason Jeremy Iman | f4156cb | 2019-11-14 15:36:22 +0900 | [diff] [blame] | 20 | #include <base/strings/string_number_conversions.h> |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 21 | #include <base/strings/stringprintf.h> |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 22 | #include <base/threading/thread_task_runner_handle.h> |
Jason Jeremy Iman | f4156cb | 2019-11-14 15:36:22 +0900 | [diff] [blame] | 23 | #include <brillo/key_value_store.h> |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 24 | #include <chromeos/dbus/service_constants.h> |
| 25 | #include <dbus/message.h> |
| 26 | #include <dbus/object_path.h> |
| 27 | #include <vboot/crossystem.h> |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 28 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 29 | #include "patchpanel/manager.h" |
| 30 | #include "patchpanel/minijailed_process_runner.h" |
| 31 | #include "patchpanel/net_util.h" |
Hugo Benichi | 2ac4d07 | 2019-05-28 14:51:23 +0900 | [diff] [blame] | 32 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 33 | namespace patchpanel { |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 34 | namespace { |
Jason Jeremy Iman | fa8b6d2 | 2020-02-20 03:44:21 +0000 | [diff] [blame] | 35 | // adb-proxy will connect to adbd on its standard TCP port. |
Garrick Evans | a7556db | 2019-05-07 11:22:40 +0900 | [diff] [blame] | 36 | constexpr uint16_t kTcpConnectPort = 5555; |
Hugo Benichi | 2ac4d07 | 2019-05-28 14:51:23 +0900 | [diff] [blame] | 37 | constexpr uint32_t kTcpAddr = Ipv4Addr(100, 115, 92, 2); |
jasongustaman | 1407628 | 2019-05-20 15:38:41 +0900 | [diff] [blame] | 38 | constexpr uint32_t kVsockPort = 5555; |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 39 | constexpr int kMaxConn = 16; |
Jason Jeremy Iman | f4156cb | 2019-11-14 15:36:22 +0900 | [diff] [blame] | 40 | // Reference: "device/google/cheets2/init.usb.rc". |
| 41 | constexpr char kUnixConnectAddr[] = "/run/arc/adb/adb.sock"; |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 42 | constexpr int kDbusTimeoutMs = 200; |
| 43 | // The maximum number of ADB sideloading query failures before stopping. |
| 44 | constexpr int kAdbSideloadMaxTry = 5; |
| 45 | constexpr base::TimeDelta kAdbSideloadUpdateDelay = |
| 46 | base::TimeDelta::FromMilliseconds(5000); |
Jason Jeremy Iman | f4156cb | 2019-11-14 15:36:22 +0900 | [diff] [blame] | 47 | |
Garrick Evans | b05a7ff | 2020-02-18 12:59:55 +0900 | [diff] [blame] | 48 | const std::set<GuestMessage::GuestType> kArcGuestTypes{GuestMessage::ARC, |
| 49 | GuestMessage::ARC_VM}; |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 50 | |
| 51 | bool IsDevModeEnabled() { |
| 52 | return VbGetSystemPropertyInt("cros_debug") == 1; |
| 53 | } |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 54 | } // namespace |
| 55 | |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 56 | AdbProxy::AdbProxy(base::ScopedFD control_fd) |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 57 | : msg_dispatcher_(std::move(control_fd)), |
Garrick Evans | 1cce71a | 2019-06-21 10:43:14 +0900 | [diff] [blame] | 58 | arc_type_(GuestMessage::UNKNOWN_GUEST), |
| 59 | arcvm_vsock_cid_(-1) { |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 60 | msg_dispatcher_.RegisterFailureHandler( |
| 61 | base::Bind(&AdbProxy::OnParentProcessExit, weak_factory_.GetWeakPtr())); |
| 62 | |
| 63 | msg_dispatcher_.RegisterGuestMessageHandler( |
| 64 | base::Bind(&AdbProxy::OnGuestMessage, weak_factory_.GetWeakPtr())); |
| 65 | } |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 66 | |
Hidehiko Abe | de12922 | 2019-08-16 00:55:04 +0900 | [diff] [blame] | 67 | AdbProxy::~AdbProxy() = default; |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 68 | |
| 69 | int AdbProxy::OnInit() { |
| 70 | // Prevent the main process from sending us any signals. |
| 71 | if (setsid() < 0) { |
| 72 | PLOG(ERROR) << "Failed to created a new session with setsid; exiting"; |
Garrick Evans | aa4f1ce | 2019-11-29 13:25:39 +0900 | [diff] [blame] | 73 | return EX_OSERR; |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 74 | } |
Jason Jeremy Iman | d89b5f5 | 2019-10-24 10:39:17 +0900 | [diff] [blame] | 75 | EnterChildProcessJail(); |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 76 | // Run after DBusDaemon::OnInit(). |
| 77 | base::ThreadTaskRunnerHandle::Get()->PostTask( |
| 78 | FROM_HERE, |
| 79 | base::Bind(&AdbProxy::InitialSetup, weak_factory_.GetWeakPtr())); |
| 80 | return DBusDaemon::OnInit(); |
| 81 | } |
| 82 | |
| 83 | void AdbProxy::InitialSetup() { |
| 84 | dev_mode_enabled_ = IsDevModeEnabled(); |
| 85 | if (dev_mode_enabled_) { |
| 86 | return; |
| 87 | } |
| 88 | CheckAdbSideloadingStatus(0 /*num_try*/); |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 89 | } |
| 90 | |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 91 | void AdbProxy::Reset() { |
Hidehiko Abe | de12922 | 2019-08-16 00:55:04 +0900 | [diff] [blame] | 92 | src_watcher_.reset(); |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 93 | src_.reset(); |
| 94 | fwd_.clear(); |
Garrick Evans | 1cce71a | 2019-06-21 10:43:14 +0900 | [diff] [blame] | 95 | arcvm_vsock_cid_ = -1; |
| 96 | arc_type_ = GuestMessage::UNKNOWN_GUEST; |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 97 | } |
| 98 | |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 99 | void AdbProxy::OnParentProcessExit() { |
| 100 | LOG(ERROR) << "Quitting because the parent process died"; |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 101 | Reset(); |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 102 | Quit(); |
| 103 | } |
| 104 | |
Hidehiko Abe | de12922 | 2019-08-16 00:55:04 +0900 | [diff] [blame] | 105 | void AdbProxy::OnFileCanReadWithoutBlocking() { |
Hugo Benichi | dcc3239 | 2020-02-27 09:14:40 +0900 | [diff] [blame] | 106 | struct sockaddr_storage client_src = {}; |
| 107 | socklen_t sockaddr_len = sizeof(client_src); |
| 108 | if (auto client_conn = |
| 109 | src_->Accept((struct sockaddr*)&client_src, &sockaddr_len)) { |
| 110 | LOG(INFO) << "new adb connection from " << client_src; |
| 111 | if (auto adbd_conn = Connect()) { |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 112 | auto fwd = std::make_unique<SocketForwarder>( |
Hugo Benichi | dcc3239 | 2020-02-27 09:14:40 +0900 | [diff] [blame] | 113 | base::StringPrintf("adbp%d-%d", client_conn->fd(), adbd_conn->fd()), |
| 114 | std::move(client_conn), std::move(adbd_conn)); |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 115 | fwd->Start(); |
| 116 | fwd_.emplace_back(std::move(fwd)); |
| 117 | } |
| 118 | } |
| 119 | |
| 120 | // Cleanup any defunct forwarders. |
| 121 | for (auto it = fwd_.begin(); it != fwd_.end();) { |
Garrick Evans | 088cd0e | 2019-06-04 15:20:43 +0900 | [diff] [blame] | 122 | if (!(*it)->IsRunning() && (*it)->HasBeenStarted()) |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 123 | it = fwd_.erase(it); |
Garrick Evans | 4e96fad | 2019-05-17 10:19:38 +0900 | [diff] [blame] | 124 | else |
| 125 | ++it; |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 126 | } |
| 127 | } |
| 128 | |
| 129 | std::unique_ptr<Socket> AdbProxy::Connect() const { |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 130 | switch (arc_type_) { |
Jason Jeremy Iman | f4156cb | 2019-11-14 15:36:22 +0900 | [diff] [blame] | 131 | case GuestMessage::ARC: { |
Jason Jeremy Iman | e50426d | 2020-02-19 15:28:57 +0900 | [diff] [blame] | 132 | struct sockaddr_un addr_un = {0}; |
| 133 | addr_un.sun_family = AF_UNIX; |
| 134 | snprintf(addr_un.sun_path, sizeof(addr_un.sun_path), "%s", |
| 135 | kUnixConnectAddr); |
| 136 | auto dst = std::make_unique<Socket>(AF_UNIX, SOCK_STREAM); |
Hugo Benichi | dcc3239 | 2020-02-27 09:14:40 +0900 | [diff] [blame] | 137 | if (dst->Connect((const struct sockaddr*)&addr_un, sizeof(addr_un))) { |
| 138 | LOG(INFO) << "Established adbd connection to " << addr_un; |
Jason Jeremy Iman | e50426d | 2020-02-19 15:28:57 +0900 | [diff] [blame] | 139 | return dst; |
Hugo Benichi | dcc3239 | 2020-02-27 09:14:40 +0900 | [diff] [blame] | 140 | } |
Garrick Evans | b05a7ff | 2020-02-18 12:59:55 +0900 | [diff] [blame] | 141 | |
| 142 | LOG(WARNING) << "Failed to connect to UNIX domain socket: " |
| 143 | << kUnixConnectAddr << " - falling back to TCP"; |
| 144 | |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 145 | struct sockaddr_in addr_in = {0}; |
| 146 | addr_in.sin_family = AF_INET; |
| 147 | addr_in.sin_port = htons(kTcpConnectPort); |
| 148 | addr_in.sin_addr.s_addr = kTcpAddr; |
Garrick Evans | b05a7ff | 2020-02-18 12:59:55 +0900 | [diff] [blame] | 149 | dst = std::make_unique<Socket>(AF_INET, SOCK_STREAM); |
Hugo Benichi | dcc3239 | 2020-02-27 09:14:40 +0900 | [diff] [blame] | 150 | if (!dst->Connect((const struct sockaddr*)&addr_in, sizeof(addr_in))) |
| 151 | return nullptr; |
| 152 | LOG(INFO) << "Established adbd connection to " << addr_in; |
| 153 | return dst; |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 154 | } |
| 155 | case GuestMessage::ARC_VM: { |
| 156 | struct sockaddr_vm addr_vm = {0}; |
| 157 | addr_vm.svm_family = AF_VSOCK; |
| 158 | addr_vm.svm_port = kVsockPort; |
Garrick Evans | 1cce71a | 2019-06-21 10:43:14 +0900 | [diff] [blame] | 159 | addr_vm.svm_cid = arcvm_vsock_cid_; |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 160 | auto dst = std::make_unique<Socket>(AF_VSOCK, SOCK_STREAM); |
Hugo Benichi | dcc3239 | 2020-02-27 09:14:40 +0900 | [diff] [blame] | 161 | if (!dst->Connect((const struct sockaddr*)&addr_vm, sizeof(addr_vm))) |
| 162 | return nullptr; |
| 163 | LOG(INFO) << "Established adbd connection to " << addr_vm; |
| 164 | return dst; |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 165 | } |
| 166 | default: |
| 167 | LOG(DFATAL) << "Unexpected connect - no ARC guest"; |
| 168 | return nullptr; |
| 169 | } |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 170 | } |
| 171 | |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 172 | void AdbProxy::OnGuestMessage(const GuestMessage& msg) { |
Garrick Evans | 1cce71a | 2019-06-21 10:43:14 +0900 | [diff] [blame] | 173 | if (msg.type() == GuestMessage::UNKNOWN_GUEST) { |
| 174 | LOG(DFATAL) << "Unexpected message from unknown guest"; |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 175 | return; |
Garrick Evans | 1cce71a | 2019-06-21 10:43:14 +0900 | [diff] [blame] | 176 | } |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 177 | |
Jason Jeremy Iman | 510bd3d | 2019-12-16 13:05:30 +0900 | [diff] [blame] | 178 | if (kArcGuestTypes.find(msg.type()) == kArcGuestTypes.end()) { |
| 179 | return; |
| 180 | } |
| 181 | |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 182 | // On ARC down, cull any open connections and stop listening. |
| 183 | if (msg.event() == GuestMessage::STOP) { |
| 184 | Reset(); |
| 185 | return; |
| 186 | } |
| 187 | |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 188 | arc_type_ = msg.type(); |
Garrick Evans | 1cce71a | 2019-06-21 10:43:14 +0900 | [diff] [blame] | 189 | arcvm_vsock_cid_ = msg.arcvm_vsock_cid(); |
Garrick Evans | bdf1f98 | 2019-06-07 09:46:49 +0900 | [diff] [blame] | 190 | |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 191 | // On ARC up, start accepting connections. |
| 192 | if (msg.event() == GuestMessage::START) { |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 193 | Listen(); |
| 194 | } |
| 195 | } |
Garrick Evans | 584210b | 2019-05-27 14:25:43 +0900 | [diff] [blame] | 196 | |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 197 | void AdbProxy::Listen() { |
| 198 | // Only start listening on either developer mode or sideloading on. |
| 199 | if (!dev_mode_enabled_ && !adb_sideloading_enabled_) { |
| 200 | return; |
| 201 | } |
| 202 | // ADB proxy is already listening. |
| 203 | if (src_) { |
| 204 | return; |
| 205 | } |
| 206 | // Listen on IPv4 and IPv6. Listening on AF_INET explicitly is not needed |
| 207 | // because net.ipv6.bindv6only sysctl is defaulted to 0 and is not |
| 208 | // explicitly turned on in the codebase. |
| 209 | std::unique_ptr<Socket> src = |
| 210 | std::make_unique<Socket>(AF_INET6, SOCK_STREAM | SOCK_NONBLOCK); |
| 211 | // Need to set this to reuse the port. |
| 212 | int on = 1; |
| 213 | if (setsockopt(src->fd(), SOL_SOCKET, SO_REUSEADDR, &on, sizeof(int)) < 0) { |
| 214 | PLOG(ERROR) << "setsockopt(SO_REUSEADDR) failed"; |
| 215 | return; |
| 216 | } |
| 217 | struct sockaddr_in6 addr = {0}; |
| 218 | addr.sin6_family = AF_INET6; |
| 219 | addr.sin6_port = htons(kAdbProxyTcpListenPort); |
| 220 | addr.sin6_addr = in6addr_any; |
| 221 | if (!src->Bind((const struct sockaddr*)&addr, sizeof(addr))) { |
| 222 | LOG(ERROR) << "Cannot bind source socket to " << addr; |
Garrick Evans | 96e0304 | 2019-05-28 14:30:52 +0900 | [diff] [blame] | 223 | return; |
Garrick Evans | 584210b | 2019-05-27 14:25:43 +0900 | [diff] [blame] | 224 | } |
| 225 | |
Jason Jeremy Iman | 378930a | 2020-12-11 05:40:08 +0900 | [diff] [blame^] | 226 | if (!src->Listen(kMaxConn)) { |
| 227 | LOG(ERROR) << "Cannot listen on " << addr; |
| 228 | return; |
| 229 | } |
| 230 | |
| 231 | src_ = std::move(src); |
| 232 | |
| 233 | // Run the accept loop. |
| 234 | LOG(INFO) << "Accepting connections on " << addr; |
| 235 | src_watcher_ = base::FileDescriptorWatcher::WatchReadable( |
| 236 | src_->fd(), base::BindRepeating(&AdbProxy::OnFileCanReadWithoutBlocking, |
| 237 | base::Unretained(this))); |
| 238 | return; |
| 239 | } |
| 240 | |
| 241 | void AdbProxy::CheckAdbSideloadingStatus(int num_try) { |
| 242 | if (num_try >= kAdbSideloadMaxTry) { |
| 243 | LOG(WARNING) << "Failed to get ADB sideloading status after " << num_try |
| 244 | << " tries. ADB sideloading will not work"; |
| 245 | return; |
| 246 | } |
| 247 | |
| 248 | dbus::ObjectProxy* proxy = bus_->GetObjectProxy( |
| 249 | login_manager::kSessionManagerServiceName, |
| 250 | dbus::ObjectPath(login_manager::kSessionManagerServicePath)); |
| 251 | dbus::MethodCall method_call(login_manager::kSessionManagerInterface, |
| 252 | login_manager::kSessionManagerQueryAdbSideload); |
| 253 | std::unique_ptr<dbus::Response> dbus_response = |
| 254 | proxy->CallMethodAndBlock(&method_call, kDbusTimeoutMs); |
| 255 | |
| 256 | if (!dbus_response) { |
| 257 | base::ThreadTaskRunnerHandle::Get()->PostDelayedTask( |
| 258 | FROM_HERE, |
| 259 | base::BindOnce(&AdbProxy::CheckAdbSideloadingStatus, |
| 260 | weak_factory_.GetWeakPtr(), num_try + 1), |
| 261 | kAdbSideloadUpdateDelay); |
| 262 | return; |
| 263 | } |
| 264 | |
| 265 | dbus::MessageReader reader(dbus_response.get()); |
| 266 | reader.PopBool(&adb_sideloading_enabled_); |
| 267 | if (!adb_sideloading_enabled_) { |
| 268 | LOG(INFO) << "Chrome OS is not in developer mode and ADB sideloading is " |
| 269 | "not enabled. ADB proxy is not listening"; |
| 270 | return; |
| 271 | } |
| 272 | |
| 273 | // If ADB sideloading is enabled and ARC guest is started, start listening. |
| 274 | if (arc_type_ != GuestMessage::UNKNOWN_GUEST) { |
| 275 | Listen(); |
Garrick Evans | 584210b | 2019-05-27 14:25:43 +0900 | [diff] [blame] | 276 | } |
Garrick Evans | 3cbac7c | 2019-04-18 15:31:31 +0900 | [diff] [blame] | 277 | } |
| 278 | |
Garrick Evans | 3388a03 | 2020-03-24 11:25:55 +0900 | [diff] [blame] | 279 | } // namespace patchpanel |