Merge changes from topic 'am-295882f6444845b0a2bcae920cb1f84d' into nyc-mr2-dev-plus-aosp
* changes: Switch android.os.Debug to libdebuggerd_client. am:3ce369601eam:18e852e9aaam:e84a027259app_process: don't use PR_SET_NO_NEW_PRIVS. am:92517e4c03am:b6025a2be1am:f442f1bd66Remove peercred check from NativeCrashListener. am:b9eb093c3cam:9e5ef0e5d7am:3fa69351b8
This commit is contained in:
committed by
Android (Google) Code Review
commit
b49dd83efc
@@ -184,10 +184,6 @@ static const char ZYGOTE_NICE_NAME[] = "zygote";
|
|||||||
|
|
||||||
int main(int argc, char* const argv[])
|
int main(int argc, char* const argv[])
|
||||||
{
|
{
|
||||||
if (prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) < 0) {
|
|
||||||
LOG_ALWAYS_FATAL("PR_SET_NO_NEW_PRIVS failed: %s", strerror(errno));
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!LOG_NDEBUG) {
|
if (!LOG_NDEBUG) {
|
||||||
String8 argv_String;
|
String8 argv_String;
|
||||||
for (int i = 0; i < argc; ++i) {
|
for (int i = 0; i < argc; ++i) {
|
||||||
|
|||||||
@@ -224,6 +224,7 @@ LOCAL_SHARED_LIBRARIES := \
|
|||||||
libnativehelper \
|
libnativehelper \
|
||||||
liblog \
|
liblog \
|
||||||
libcutils \
|
libcutils \
|
||||||
|
libdebuggerd_client \
|
||||||
libutils \
|
libutils \
|
||||||
libbinder \
|
libbinder \
|
||||||
libnetutils \
|
libnetutils \
|
||||||
|
|||||||
@@ -33,7 +33,7 @@
|
|||||||
#include <string>
|
#include <string>
|
||||||
|
|
||||||
#include <android-base/stringprintf.h>
|
#include <android-base/stringprintf.h>
|
||||||
#include <cutils/debugger.h>
|
#include <debuggerd/client.h>
|
||||||
#include <log/log.h>
|
#include <log/log.h>
|
||||||
#include <utils/misc.h>
|
#include <utils/misc.h>
|
||||||
#include <utils/String8.h>
|
#include <utils/String8.h>
|
||||||
|
|||||||
@@ -20,7 +20,6 @@ import android.app.ApplicationErrorReport.CrashInfo;
|
|||||||
import android.system.ErrnoException;
|
import android.system.ErrnoException;
|
||||||
import android.system.Os;
|
import android.system.Os;
|
||||||
import android.system.StructTimeval;
|
import android.system.StructTimeval;
|
||||||
import android.system.StructUcred;
|
|
||||||
import android.system.UnixSocketAddress;
|
import android.system.UnixSocketAddress;
|
||||||
import android.util.Slog;
|
import android.util.Slog;
|
||||||
|
|
||||||
@@ -105,9 +104,9 @@ final class NativeCrashListener extends Thread {
|
|||||||
|
|
||||||
if (DEBUG) Slog.i(TAG, "Starting up");
|
if (DEBUG) Slog.i(TAG, "Starting up");
|
||||||
|
|
||||||
// The file system entity for this socket is created with 0700 perms, owned
|
// The file system entity for this socket is created with 0777 perms, owned
|
||||||
// by system:system. debuggerd runs as root, so is capable of connecting to
|
// by system:system. selinux restricts things so that only crash_dump can
|
||||||
// it, but 3rd party apps cannot.
|
// access it.
|
||||||
{
|
{
|
||||||
File socketFile = new File(DEBUGGERD_SOCKET_PATH);
|
File socketFile = new File(DEBUGGERD_SOCKET_PATH);
|
||||||
if (socketFile.exists()) {
|
if (socketFile.exists()) {
|
||||||
@@ -121,6 +120,7 @@ final class NativeCrashListener extends Thread {
|
|||||||
DEBUGGERD_SOCKET_PATH);
|
DEBUGGERD_SOCKET_PATH);
|
||||||
Os.bind(serverFd, sockAddr);
|
Os.bind(serverFd, sockAddr);
|
||||||
Os.listen(serverFd, 1);
|
Os.listen(serverFd, 1);
|
||||||
|
Os.chmod(DEBUGGERD_SOCKET_PATH, 0777);
|
||||||
|
|
||||||
while (true) {
|
while (true) {
|
||||||
FileDescriptor peerFd = null;
|
FileDescriptor peerFd = null;
|
||||||
@@ -129,19 +129,14 @@ final class NativeCrashListener extends Thread {
|
|||||||
peerFd = Os.accept(serverFd, null /* peerAddress */);
|
peerFd = Os.accept(serverFd, null /* peerAddress */);
|
||||||
if (MORE_DEBUG) Slog.v(TAG, "Got debuggerd socket " + peerFd);
|
if (MORE_DEBUG) Slog.v(TAG, "Got debuggerd socket " + peerFd);
|
||||||
if (peerFd != null) {
|
if (peerFd != null) {
|
||||||
// Only the superuser is allowed to talk to us over this socket
|
|
||||||
StructUcred credentials =
|
|
||||||
Os.getsockoptUcred(peerFd, SOL_SOCKET, SO_PEERCRED);
|
|
||||||
if (credentials.uid == 0) {
|
|
||||||
// the reporting thread may take responsibility for
|
// the reporting thread may take responsibility for
|
||||||
// acking the debugger; make sure we play along.
|
// acking the debugger; make sure we play along.
|
||||||
consumeNativeCrashData(peerFd);
|
consumeNativeCrashData(peerFd);
|
||||||
}
|
}
|
||||||
}
|
|
||||||
} catch (Exception e) {
|
} catch (Exception e) {
|
||||||
Slog.w(TAG, "Error handling connection", e);
|
Slog.w(TAG, "Error handling connection", e);
|
||||||
} finally {
|
} finally {
|
||||||
// Always ack debuggerd's connection to us. The actual
|
// Always ack crash_dump's connection to us. The actual
|
||||||
// byte written is irrelevant.
|
// byte written is irrelevant.
|
||||||
if (peerFd != null) {
|
if (peerFd != null) {
|
||||||
try {
|
try {
|
||||||
@@ -194,7 +189,7 @@ final class NativeCrashListener extends Thread {
|
|||||||
return totalRead;
|
return totalRead;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Read the crash report from the debuggerd connection
|
// Read a crash report from the connection
|
||||||
void consumeNativeCrashData(FileDescriptor fd) {
|
void consumeNativeCrashData(FileDescriptor fd) {
|
||||||
if (MORE_DEBUG) Slog.i(TAG, "debuggerd connected");
|
if (MORE_DEBUG) Slog.i(TAG, "debuggerd connected");
|
||||||
final byte[] buf = new byte[4096];
|
final byte[] buf = new byte[4096];
|
||||||
@@ -205,6 +200,10 @@ final class NativeCrashListener extends Thread {
|
|||||||
Os.setsockoptTimeval(fd, SOL_SOCKET, SO_RCVTIMEO, timeout);
|
Os.setsockoptTimeval(fd, SOL_SOCKET, SO_RCVTIMEO, timeout);
|
||||||
Os.setsockoptTimeval(fd, SOL_SOCKET, SO_SNDTIMEO, timeout);
|
Os.setsockoptTimeval(fd, SOL_SOCKET, SO_SNDTIMEO, timeout);
|
||||||
|
|
||||||
|
// The socket is guarded by an selinux neverallow rule that only
|
||||||
|
// permits crash_dump to connect to it. This allows us to trust the
|
||||||
|
// received values.
|
||||||
|
|
||||||
// first, the pid and signal number
|
// first, the pid and signal number
|
||||||
int headerBytes = readExactly(fd, buf, 0, 8);
|
int headerBytes = readExactly(fd, buf, 0, 8);
|
||||||
if (headerBytes != 8) {
|
if (headerBytes != 8) {
|
||||||
|
|||||||
Reference in New Issue
Block a user