1 /**
2  * Copyright (c) 2016, The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *     http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #define LOG_TAG "dumpstate"
18 
19 #include "DumpstateService.h"
20 
21 #include <memory>
22 
23 #include <android-base/stringprintf.h>
24 #include "android/os/BnDumpstate.h"
25 
26 #include "DumpstateInternal.h"
27 
28 using android::base::StringPrintf;
29 
30 namespace android {
31 namespace os {
32 
33 namespace {
34 
35 struct DumpstateInfo {
36   public:
37     Dumpstate* ds = nullptr;
38     int32_t calling_uid = -1;
39     std::string calling_package;
40     int32_t user_id = -1;
41     bool keep_bugreport_on_retrieval = false;
42     bool skip_user_consent = false;
43 };
44 
exception(uint32_t code,const std::string & msg,const std::string & extra_msg="")45 static binder::Status exception(uint32_t code, const std::string& msg,
46                                 const std::string& extra_msg = "") {
47     if (extra_msg.empty()) {
48         MYLOGE("%s (%d) ", msg.c_str(), code);
49     } else {
50         MYLOGE("%s %s (%d) ", msg.c_str(), extra_msg.c_str(), code);
51     }
52     return binder::Status::fromExceptionCode(code, String8(msg.c_str()));
53 }
54 
55 // Creates a bugreport and exits, thus preserving the oneshot nature of the service.
56 // Note: takes ownership of data.
dumpstate_thread_bugreport(void * data)57 [[noreturn]] static void* dumpstate_thread_bugreport(void* data) {
58     std::unique_ptr<DumpstateInfo> ds_info(static_cast<DumpstateInfo*>(data));
59     ds_info->ds->Run(ds_info->calling_uid, ds_info->calling_package);
60     MYLOGD("Finished taking a bugreport. Exiting.\n");
61     exit(0);
62 }
63 
dumpstate_thread_retrieve(void * data)64 [[noreturn]] static void* dumpstate_thread_retrieve(void* data) {
65     std::unique_ptr<DumpstateInfo> ds_info(static_cast<DumpstateInfo*>(data));
66     ds_info->ds->Retrieve(ds_info->calling_uid, ds_info->calling_package,
67     ds_info->keep_bugreport_on_retrieval, ds_info->skip_user_consent);
68     MYLOGD("Finished retrieving a bugreport. Exiting.\n");
69     exit(0);
70 }
71 
signalErrorAndExit(sp<IDumpstateListener> listener,int error_code)72 [[noreturn]] static void signalErrorAndExit(sp<IDumpstateListener> listener, int error_code) {
73     listener->onError(error_code);
74     exit(0);
75 }
76 
77 }  // namespace
78 
DumpstateService()79 DumpstateService::DumpstateService() : ds_(nullptr), calling_uid_(-1), calling_package_() {
80 }
81 
getServiceName()82 char const* DumpstateService::getServiceName() {
83     return "dumpstate";
84 }
85 
Start()86 status_t DumpstateService::Start() {
87     IPCThreadState::self()->disableBackgroundScheduling(true);
88     status_t ret = BinderService<DumpstateService>::publish();
89     if (ret != android::OK) {
90         return ret;
91     }
92     sp<ProcessState> ps(ProcessState::self());
93     ps->startThreadPool();
94     ps->giveThreadPoolName();
95     return android::OK;
96 }
97 
preDumpUiData(const std::string &)98 binder::Status DumpstateService::preDumpUiData(const std::string&) {
99     std::lock_guard<std::mutex> lock(lock_);
100     MYLOGI("preDumpUiData()");
101 
102     if (ds_ != nullptr) {
103         MYLOGE("Error! DumpstateService is currently already being used. Returning.");
104         return exception(binder::Status::EX_SERVICE_SPECIFIC,
105                          "DumpstateService is already being used");
106     }
107 
108     ds_ = &(Dumpstate::GetInstance());
109     ds_->PreDumpUiData();
110 
111     return binder::Status::ok();
112 }
113 
startBugreport(int32_t calling_uid,const std::string & calling_package,android::base::unique_fd bugreport_fd,android::base::unique_fd screenshot_fd,int bugreport_mode,int bugreport_flags,const sp<IDumpstateListener> & listener,bool is_screenshot_requested,bool skip_user_consent)114 binder::Status DumpstateService::startBugreport(int32_t calling_uid,
115                                                 const std::string& calling_package,
116                                                 android::base::unique_fd bugreport_fd,
117                                                 android::base::unique_fd screenshot_fd,
118                                                 int bugreport_mode,
119                                                 int bugreport_flags,
120                                                 const sp<IDumpstateListener>& listener,
121                                                 bool is_screenshot_requested,
122                                                 bool skip_user_consent) {
123     MYLOGI("startBugreport() with mode: %d\n", bugreport_mode);
124 
125     // Ensure there is only one bugreport in progress at a time.
126     std::lock_guard<std::mutex> lock(lock_);
127     if (ds_ != nullptr) {
128         MYLOGE("Error! DumpstateService is currently already being used. Returning.");
129         if (listener != nullptr) {
130             listener->onError(IDumpstateListener::BUGREPORT_ERROR_ANOTHER_REPORT_IN_PROGRESS);
131         }
132         return exception(binder::Status::EX_SERVICE_SPECIFIC,
133                          "DumpstateService is already being used");
134     }
135 
136     // From here on, all conditions that indicate we are done with this incoming request should
137     // result in exiting the service to free it up for next invocation.
138     if (listener == nullptr) {
139         MYLOGE("Invalid input: no listener");
140         exit(0);
141     }
142 
143     if (bugreport_mode != Dumpstate::BugreportMode::BUGREPORT_FULL &&
144         bugreport_mode != Dumpstate::BugreportMode::BUGREPORT_INTERACTIVE &&
145         bugreport_mode != Dumpstate::BugreportMode::BUGREPORT_REMOTE &&
146         bugreport_mode != Dumpstate::BugreportMode::BUGREPORT_WEAR &&
147         bugreport_mode != Dumpstate::BugreportMode::BUGREPORT_TELEPHONY &&
148         bugreport_mode != Dumpstate::BugreportMode::BUGREPORT_WIFI &&
149         bugreport_mode != Dumpstate::BugreportMode::BUGREPORT_ONBOARDING &&
150         bugreport_mode != Dumpstate::BugreportMode::BUGREPORT_DEFAULT) {
151         MYLOGE("Invalid input: bad bugreport mode: %d", bugreport_mode);
152         signalErrorAndExit(listener, IDumpstateListener::BUGREPORT_ERROR_INVALID_INPUT);
153     }
154 
155     std::unique_ptr<Dumpstate::DumpOptions> options = std::make_unique<Dumpstate::DumpOptions>();
156     options->Initialize(static_cast<Dumpstate::BugreportMode>(bugreport_mode), bugreport_flags,
157                         bugreport_fd, screenshot_fd, is_screenshot_requested, skip_user_consent);
158 
159     if (bugreport_fd.get() == -1 || (options->do_screenshot && screenshot_fd.get() == -1)) {
160         MYLOGE("Invalid filedescriptor");
161         signalErrorAndExit(listener, IDumpstateListener::BUGREPORT_ERROR_INVALID_INPUT);
162     }
163 
164 
165     ds_ = &(Dumpstate::GetInstance());
166     ds_->SetOptions(std::move(options));
167     ds_->listener_ = listener;
168 
169     // Track caller info for cancellation purposes.
170     calling_uid_ = calling_uid;
171     calling_package_ = calling_package;
172 
173     DumpstateInfo* ds_info = new DumpstateInfo();
174     ds_info->ds = ds_;
175     ds_info->calling_uid = calling_uid;
176     ds_info->calling_package = calling_package;
177 
178     pthread_t thread;
179     // Initialize dumpstate
180     ds_->Initialize();
181     status_t err = pthread_create(&thread, nullptr, dumpstate_thread_bugreport, ds_info);
182     if (err != 0) {
183         delete ds_info;
184         MYLOGE("Could not create a thread");
185         signalErrorAndExit(listener, IDumpstateListener::BUGREPORT_ERROR_RUNTIME_ERROR);
186     }
187     return binder::Status::ok();
188 }
189 
cancelBugreport(int32_t calling_uid,const std::string & calling_package)190 binder::Status DumpstateService::cancelBugreport(int32_t calling_uid,
191                                                  const std::string& calling_package) {
192     std::lock_guard<std::mutex> lock(lock_);
193     if (calling_uid != calling_uid_ || calling_package != calling_package_) {
194         // Note: we use a SecurityException to prevent BugreportManagerServiceImpl from killing the
195         // report in progress (from another caller).
196         return exception(
197             binder::Status::EX_SECURITY,
198             StringPrintf("Cancellation requested by %d/%s does not match report in "
199                          "progress",
200                          calling_uid, calling_package.c_str()),
201             // Sharing the owner of the BR is a (minor) leak, so leave it out of the app's exception
202             StringPrintf("started by %d/%s", calling_uid_, calling_package_.c_str()));
203     }
204     ds_->Cancel();
205     return binder::Status::ok();
206 }
207 
retrieveBugreport(int32_t calling_uid,const std::string & calling_package,int32_t user_id,android::base::unique_fd bugreport_fd,const std::string & bugreport_file,const bool keep_bugreport_on_retrieval,const bool skip_user_consent,const sp<IDumpstateListener> & listener)208 binder::Status DumpstateService::retrieveBugreport(
209     int32_t calling_uid, const std::string& calling_package, int32_t user_id,
210     android::base::unique_fd bugreport_fd,
211     const std::string& bugreport_file,
212     const bool keep_bugreport_on_retrieval,
213     const bool skip_user_consent,
214     const sp<IDumpstateListener>& listener) {
215 
216     ds_ = &(Dumpstate::GetInstance());
217     DumpstateInfo* ds_info = new DumpstateInfo();
218     ds_info->ds = ds_;
219     ds_info->calling_uid = calling_uid;
220     ds_info->calling_package = calling_package;
221     ds_info->user_id = user_id;
222     ds_info->keep_bugreport_on_retrieval = keep_bugreport_on_retrieval;
223     ds_info->skip_user_consent = skip_user_consent;
224     ds_->listener_ = listener;
225     std::unique_ptr<Dumpstate::DumpOptions> options = std::make_unique<Dumpstate::DumpOptions>();
226     // Use a /dev/null FD when initializing options since none is provided.
227     android::base::unique_fd devnull_fd(
228         TEMP_FAILURE_RETRY(open("/dev/null", O_WRONLY | O_CLOEXEC)));
229 
230     options->Initialize(Dumpstate::BugreportMode::BUGREPORT_DEFAULT,
231                         0, bugreport_fd, devnull_fd, false, skip_user_consent);
232 
233     if (bugreport_fd.get() == -1) {
234         MYLOGE("Invalid filedescriptor");
235         signalErrorAndExit(listener, IDumpstateListener::BUGREPORT_ERROR_INVALID_INPUT);
236     }
237     ds_->SetOptions(std::move(options));
238     ds_->path_ = bugreport_file;
239     pthread_t thread;
240     status_t err = pthread_create(&thread, nullptr, dumpstate_thread_retrieve, ds_info);
241     if (err != 0) {
242         MYLOGE("Could not create a thread");
243         signalErrorAndExit(listener, IDumpstateListener::BUGREPORT_ERROR_RUNTIME_ERROR);
244     }
245     return binder::Status::ok();
246 }
247 
dump(int fd,const Vector<String16> &)248 status_t DumpstateService::dump(int fd, const Vector<String16>&) {
249     std::lock_guard<std::mutex> lock(lock_);
250     if (ds_ == nullptr) {
251         dprintf(fd, "Bugreport not in progress yet");
252         return NO_ERROR;
253     }
254     std::string destination = ds_->options_->bugreport_fd.get() != -1
255                                   ? StringPrintf("[fd:%d]", ds_->options_->bugreport_fd.get())
256                                   : ds_->bugreport_internal_dir_.c_str();
257     dprintf(fd, "id: %d\n", ds_->id_);
258     dprintf(fd, "pid: %d\n", ds_->pid_);
259     dprintf(fd, "update_progress: %s\n", ds_->options_->do_progress_updates ? "true" : "false");
260     dprintf(fd, "last_percent_progress: %d\n", ds_->last_reported_percent_progress_);
261     dprintf(fd, "progress:\n");
262     ds_->progress_->Dump(fd, "  ");
263     dprintf(fd, "args: %s\n", ds_->options_->args.c_str());
264     dprintf(fd, "bugreport_mode: %s\n", ds_->options_->bugreport_mode_string.c_str());
265     dprintf(fd, "version: %s\n", ds_->version_.c_str());
266     dprintf(fd, "bugreport_dir: %s\n", destination.c_str());
267     dprintf(fd, "screenshot_path: %s\n", ds_->screenshot_path_.c_str());
268     dprintf(fd, "log_path: %s\n", ds_->log_path_.c_str());
269     dprintf(fd, "tmp_path: %s\n", ds_->tmp_path_.c_str());
270     dprintf(fd, "path: %s\n", ds_->path_.c_str());
271     dprintf(fd, "base_name: %s\n", ds_->base_name_.c_str());
272     dprintf(fd, "name: %s\n", ds_->name_.c_str());
273     dprintf(fd, "now: %ld\n", ds_->now_);
274     dprintf(fd, "notification title: %s\n", ds_->options_->notification_title.c_str());
275     dprintf(fd, "notification description: %s\n", ds_->options_->notification_description.c_str());
276 
277     return NO_ERROR;
278 }
279 }  // namespace os
280 }  // namespace android
281