Merge "Disable ptrace debugging by default on userdebug" into main

This commit is contained in:
Colin Cross
2023-08-03 00:15:23 +00:00
committed by Gerrit Code Review

View File

@@ -196,7 +196,8 @@ public final class Zygote {
public static final int PROFILEABLE = 1 << 24; public static final int PROFILEABLE = 1 << 24;
/** /**
* Enable ptrace. This is enabled on eng or userdebug builds, or if the app is debuggable. * Enable ptrace. This is enabled on eng, if the app is debuggable, or if
* the persist.debug.ptrace.enabled property is set.
*/ */
public static final int DEBUG_ENABLE_PTRACE = 1 << 25; public static final int DEBUG_ENABLE_PTRACE = 1 << 25;
@@ -1019,21 +1020,36 @@ public final class Zygote {
private static final boolean ENABLE_JDWP = SystemProperties.get( private static final boolean ENABLE_JDWP = SystemProperties.get(
"persist.debug.dalvik.vm.jdwp.enabled").equals("1"); "persist.debug.dalvik.vm.jdwp.enabled").equals("1");
/**
* This will enable ptrace by default for all apps. It is OK to cache this property
* because we expect to reboot the system whenever this property changes
*/
private static final boolean ENABLE_PTRACE = SystemProperties.get(
"persist.debug.ptrace.enabled").equals("1");
/** /**
* Applies debugger system properties to the zygote arguments. * Applies debugger system properties to the zygote arguments.
* *
* For eng builds all apps are debuggable. On userdebug and user builds * For eng builds all apps are debuggable with JDWP and ptrace.
* if persist.debug.dalvik.vm.jdwp.enabled is 1 all apps are *
* debuggable. Otherwise, the debugger state is specified via the * On userdebug builds if persist.debug.dalvik.vm.jdwp.enabled
* "--enable-jdwp" flag in the spawn request. * is 1 all apps are debuggable with JDWP and ptrace. Otherwise, the
* debugger state is specified via the "--enable-jdwp" flag in the
* spawn request.
*
* On userdebug builds if persist.debug.ptrace.enabled is 1 all
* apps are debuggable with ptrace.
* *
* @param args non-null; zygote spawner args * @param args non-null; zygote spawner args
*/ */
static void applyDebuggerSystemProperty(ZygoteArguments args) { static void applyDebuggerSystemProperty(ZygoteArguments args) {
if (Build.IS_ENG || ENABLE_JDWP) { if (Build.IS_ENG || (Build.IS_USERDEBUG && ENABLE_JDWP)) {
args.mRuntimeFlags |= Zygote.DEBUG_ENABLE_JDWP; args.mRuntimeFlags |= Zygote.DEBUG_ENABLE_JDWP;
// Also enable ptrace when JDWP is enabled for consistency with
// before persist.debug.ptrace.enabled existed.
args.mRuntimeFlags |= Zygote.DEBUG_ENABLE_PTRACE;
} }
if (RoSystemProperties.DEBUGGABLE) { if (Build.IS_ENG || (Build.IS_USERDEBUG && ENABLE_PTRACE)) {
args.mRuntimeFlags |= Zygote.DEBUG_ENABLE_PTRACE; args.mRuntimeFlags |= Zygote.DEBUG_ENABLE_PTRACE;
} }
} }
@@ -1057,7 +1073,8 @@ public final class Zygote {
int peerUid = peer.getUid(); int peerUid = peer.getUid();
if (args.mInvokeWith != null && peerUid != 0 if (args.mInvokeWith != null && peerUid != 0
&& (args.mRuntimeFlags & Zygote.DEBUG_ENABLE_JDWP) == 0) { && (args.mRuntimeFlags
& (Zygote.DEBUG_ENABLE_JDWP | Zygote.DEBUG_ENABLE_PTRACE)) == 0) {
throw new ZygoteSecurityException("Peer is permitted to specify an " throw new ZygoteSecurityException("Peer is permitted to specify an "
+ "explicit invoke-with wrapper command only for debuggable " + "explicit invoke-with wrapper command only for debuggable "
+ "applications."); + "applications.");