ipc_object_stub.cpp 23.2 KB
Newer Older
M
mamingshuai 已提交
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
/*
 * Copyright (C) 2021 Huawei Device Co., Ltd.
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

#include "ipc_object_stub.h"
L
libaoping 已提交
17 18 19

#include <cstdint>
#include <ctime>
M
mamingshuai 已提交
20
#include <string>
L
libaoping 已提交
21 22 23 24

#include "hilog/log_c.h"
#include "hilog/log_cpp.h"
#include "iosfwd"
M
mamingshuai 已提交
25 26
#include "ipc_debug.h"
#include "ipc_process_skeleton.h"
L
libaoping 已提交
27
#include "ipc_skeleton.h"
M
mamingshuai 已提交
28
#include "ipc_thread_skeleton.h"
L
libaoping 已提交
29 30 31
#include "ipc_types.h"
#include "iremote_invoker.h"
#include "iremote_object.h"
M
mamingshuai 已提交
32
#include "log_tags.h"
L
libaoping 已提交
33 34 35 36 37 38 39
#include "message_option.h"
#include "message_parcel.h"
#include "refbase.h"
#include "string_ex.h"
#include "sys_binder.h"
#include "unistd.h"
#include "vector"
M
mamingshuai 已提交
40 41

#ifndef CONFIG_IPC_SINGLE
Y
yangguangzhao 已提交
42 43
#include "accesstoken_kit.h"
#include "access_token_adapter.h"
M
mamingshuai 已提交
44 45 46 47 48 49 50 51 52 53 54 55 56
#include "dbinder_databus_invoker.h"
#include "dbinder_error_code.h"
#include "ISessionService.h"
#endif

namespace OHOS {
#ifdef CONFIG_IPC_SINGLE
using namespace IPC_SINGLE;
#endif

using namespace OHOS::HiviewDFX;
static constexpr HiLogLabel LABEL = { LOG_CORE, LOG_ID_IPC, "IPCObjectStub" };
#ifndef CONFIG_IPC_SINGLE
Y
yangguangzhao 已提交
57
using namespace OHOS::Security;
M
mamingshuai 已提交
58 59
// Authentication information can be added only for processes with system permission.
static constexpr pid_t ALLOWED_UID = 10000;
L
lutao 已提交
60 61
static constexpr pid_t SHELL_UID = 2000;
static constexpr int APL_BASIC = 2;
M
mamingshuai 已提交
62
// Only the samgr can obtain the UID and PID.
Y
yangguangzhao 已提交
63
static const std::string SAMGR_PROCESS_NAME = "samgr";
M
mamingshuai 已提交
64 65
#endif

66 67 68
IPCObjectStub::IPCObjectStub(std::u16string descriptor) : IRemoteObject(descriptor)
{
}
M
mamingshuai 已提交
69 70 71

IPCObjectStub::~IPCObjectStub()
{
F
fanxiaoyu 已提交
72
    ZLOGD(LABEL, "destroy, desc: %{public}s", Str16ToStr8(descriptor_).c_str());
M
mamingshuai 已提交
73 74 75 76 77 78 79 80 81 82 83 84
}

bool IPCObjectStub::IsDeviceIdIllegal(const std::string &deviceID)
{
    if (deviceID.empty() || deviceID.length() > DEVICEID_LENGTH) {
        return true;
    }
    return false;
}

int32_t IPCObjectStub::GetObjectRefCount()
{
F
fanxiaoyu 已提交
85
    return GetSptrRefCount();
M
mamingshuai 已提交
86 87 88 89 90 91 92 93 94 95 96 97 98 99 100
}

int IPCObjectStub::Dump(int fd, const std::vector<std::u16string> &args)
{
    const size_t numArgs = args.size();
    ZLOGE(LABEL, "Invalid call on Stub:fd:%d, args:%zu", fd, numArgs);
    return ERR_NONE;
}

int IPCObjectStub::OnRemoteRequest(uint32_t code, MessageParcel &data, MessageParcel &reply, MessageOption &option)
{
    int result = ERR_NONE;
    switch (code) {
#ifndef CONFIG_IPC_SINGLE
        case DBINDER_OBITUARY_TRANSACTION: {
Y
yangguangzhao 已提交
101
            if (!IsSamgrCall(IPCSkeleton::GetCallingTokenID())) {
M
mamingshuai 已提交
102 103 104 105 106 107 108 109 110 111 112 113 114 115
                ZLOGE(LABEL, "%s: DBINDER_OBITUARY_TRANSACTION unauthenticated user ", __func__);
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
            if (data.ReadInt32() == IRemoteObject::DeathRecipient::NOTICE_DEATH_RECIPIENT) {
                result = NoticeServiceDie(data, reply, option);
            } else {
                result = IPC_STUB_INVALID_DATA_ERR;
            }
            break;
        }
#endif
        default:
            result = IPC_STUB_UNKNOW_TRANS_ERR;
F
fanxiaoyu 已提交
116 117
            ZLOGE(LABEL, "unknown OnRemoteRequest code = %{public}u, descriptor: %{public}s", code,
                Str16ToStr8(descriptor_).c_str());
M
mamingshuai 已提交
118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161
            break;
    }
    return result;
}

int IPCObjectStub::OnRemoteDump(uint32_t code, MessageParcel &data, MessageParcel &reply, MessageOption &option)
{
    int result = ERR_NONE;
    int fd = data.ReadFileDescriptor();
    std::vector<std::u16string> args;
    if (fd != INVALID_FD) {
        if (data.ReadString16Vector(&args)) {
            result = Dump(fd, args);
        }
        ::close(fd);
    } else {
        result = IPC_STUB_INVALID_DATA_ERR;
    }
    return result;
}

int IPCObjectStub::SendRequest(uint32_t code, MessageParcel &data, MessageParcel &reply, MessageOption &option)
{
    int result = ERR_NONE;
    switch (code) {
        case PING_TRANSACTION: {
            if (!reply.WriteInt32(ERR_NONE)) {
                result = IPC_STUB_WRITE_PARCEL_ERR;
            }
            break;
        }
        case INTERFACE_TRANSACTION: {
            std::u16string descriptor = GetObjectDescriptor();
            if (!reply.WriteString16(descriptor)) {
                ZLOGE(LABEL, "write to parcel fail");
                result = IPC_STUB_WRITE_PARCEL_ERR;
            }
            break;
        }
        case SYNCHRONIZE_REFERENCE: {
            int refCount = GetObjectRefCount();
            // when handle transaction the invoker would try to acquire
            // the object's reference to defense the object being released
            // so the actual we should decrement the temporary reference.
F
fanxiaoyu 已提交
162 163 164
            if (IPCSkeleton::IsLocalCalling()) {
                --refCount;
            }
M
mamingshuai 已提交
165 166 167
            reply.WriteInt32(refCount);
            break;
        }
L
lutao 已提交
168
#ifndef CONFIG_IPC_SINGLE
M
mamingshuai 已提交
169 170
        case DUMP_TRANSACTION: {
            pid_t uid = IPCSkeleton::GetCallingUid();
L
lutao 已提交
171 172
            uint32_t calllingTokenID = IPCSkeleton::GetFirstTokenID();
            calllingTokenID = calllingTokenID == 0 ? IPCSkeleton::GetCallingTokenID() : calllingTokenID;
L
lutao 已提交
173 174
            if (!IPCSkeleton::IsLocalCalling() ||
                (uid != 0 && uid != SHELL_UID && !HasDumpPermission(calllingTokenID))) {
M
mamingshuai 已提交
175 176 177 178 179 180
                ZLOGE(LABEL, "do not allow dump");
                break;
            }
            result = OnRemoteDump(code, data, reply, option);
            break;
        }
L
lutao 已提交
181
#endif
182 183 184 185
        case GET_PROTO_INFO: {
            result = ProcessProto(code, data, reply, option);
            break;
        }
M
mamingshuai 已提交
186 187 188
#ifndef CONFIG_IPC_SINGLE
        case INVOKE_LISTEN_THREAD: {
            if (!IPCSkeleton::IsLocalCalling() || IPCSkeleton::GetCallingUid() >= ALLOWED_UID) {
H
heyingjiao 已提交
189
                ZLOGE(LABEL, "%{public}s: INVOKE_LISTEN_THREAD unauthenticated user ", __func__);
M
mamingshuai 已提交
190 191 192 193 194 195 196 197
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
            result = InvokerThread(code, data, reply, option);
            break;
        }
        case DBINDER_INCREFS_TRANSACTION: {
            if (IPCSkeleton::IsLocalCalling()) {
H
heyingjiao 已提交
198
                ZLOGE(LABEL, "dbinder incref in the same device is invalid");
M
mamingshuai 已提交
199 200 201
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
H
heyingjiao 已提交
202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218
            pid_t callerPid = IPCSkeleton::GetCallingPid();
            pid_t callerUid = IPCSkeleton::GetCallingUid();
            uint32_t tokenId = IPCSkeleton::GetCallingTokenID();
            std::string callerDevId = IPCSkeleton::GetCallingDeviceID();
            IPCProcessSkeleton *current = IPCProcessSkeleton::GetCurrent();
            uint64_t stubIndex = current->QueryStubIndex(this);
            DBinderDatabusInvoker *invoker = reinterpret_cast<DBinderDatabusInvoker *>(
                IPCThreadSkeleton::GetRemoteInvoker(IRemoteObject::IF_PROT_DATABUS));
            if (invoker == nullptr) {
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
            uint32_t listenFd = invoker->GetClientFd();
            // update listenFd
            ZLOGW(LABEL, "update app info listenFd: %{public}u, stubIndex: %{public}" PRIu64 ", tokenId: %{public}u",
                listenFd, stubIndex, tokenId);
            current->AttachAppInfoToStubIndex(callerPid, callerUid, tokenId, callerDevId, stubIndex, listenFd);
M
mamingshuai 已提交
219 220 221 222
            break;
        }
        case DBINDER_DECREFS_TRANSACTION: {
            if (IPCSkeleton::IsLocalCalling()) {
H
heyingjiao 已提交
223 224 225 226 227 228 229 230 231 232 233 234 235 236 237
                ZLOGE(LABEL, "dbinder decref in the same device is invalid");
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
            // stub's refcount will be decreased either in this case or OnSessionClosed callback
            // we may race with OnSessionClosed callback, thus dec refcount only when removing appInfo sucessfully
            pid_t callerPid = IPCSkeleton::GetCallingPid();
            pid_t callerUid = IPCSkeleton::GetCallingUid();
            uint32_t tokenId = IPCSkeleton::GetCallingTokenID();
            std::string callerDevId = IPCSkeleton::GetCallingDeviceID();
            IPCProcessSkeleton *current = IPCProcessSkeleton::GetCurrent();
            uint64_t stubIndex = current->QueryStubIndex(this);
            DBinderDatabusInvoker *invoker = reinterpret_cast<DBinderDatabusInvoker *>(
                IPCThreadSkeleton::GetRemoteInvoker(IRemoteObject::IF_PROT_DATABUS));
            if (invoker == nullptr) {
M
mamingshuai 已提交
238 239 240
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
H
heyingjiao 已提交
241 242 243 244 245 246
            uint32_t listenFd = invoker->GetClientFd();
            // detach info whose listen fd equals the given one
            if (current->DetachAppInfoToStubIndex(callerPid, callerUid, tokenId, callerDevId, stubIndex, listenFd)) {
                current->DetachCommAuthInfo(this, callerPid, callerUid, tokenId, callerDevId);
                DecStrongRef(this);
            }
M
mamingshuai 已提交
247 248
            break;
        }
H
heyingjiao 已提交
249
        case DBINDER_ADD_COMMAUTH: {
M
mamingshuai 已提交
250
            if (IPCSkeleton::IsLocalCalling() || IPCSkeleton::GetCallingUid() >= ALLOWED_UID) {
H
heyingjiao 已提交
251
                ZLOGE(LABEL, "DBINDER_ADD_COMMAUTH unauthenticated user ");
M
mamingshuai 已提交
252 253 254
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
Z
zgit2021 已提交
255
            result = AddAuthInfo(data, reply, code);
M
mamingshuai 已提交
256 257
            break;
        }
H
heyingjiao 已提交
258
        case GET_SESSION_NAME: {
M
mamingshuai 已提交
259 260 261 262 263
            if (!IPCSkeleton::IsLocalCalling()) {
                ZLOGE(LABEL, "GET_UIDPID_INFO message is not from sa manager");
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
H
heyingjiao 已提交
264
            std::string sessionName = GetSessionName();
M
mamingshuai 已提交
265 266 267 268 269 270 271 272 273 274 275 276
            if (sessionName.empty()) {
                ZLOGE(LABEL, "sessionName is empty");
                result = IPC_STUB_CREATE_BUS_SERVER_ERR;
                break;
            }
            if (!reply.WriteString(sessionName)) {
                ZLOGE(LABEL, "write to parcel fail");
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
            break;
        }
H
heyingjiao 已提交
277 278 279
        case GET_GRANTED_SESSION_NAME: {
            if (!IPCSkeleton::IsLocalCalling() ||
                !IsSamgrCall(static_cast<uint32_t>(IPCSkeleton::GetSelfTokenID()))) {
M
mamingshuai 已提交
280 281 282 283
                ZLOGE(LABEL, "GRANT_DATABUS_NAME message is excluded in sa manager");
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
H
heyingjiao 已提交
284
            result = GetGrantedSessionName(code, data, reply, option);
M
mamingshuai 已提交
285 286
            break;
        }
H
heyingjiao 已提交
287 288 289
        case GET_SESSION_NAME_PID_UID: {
            if (!IPCSkeleton::IsLocalCalling() ||
                !IsSamgrCall(static_cast<uint32_t>(IPCSkeleton::GetSelfTokenID()))) {
Z
zgit2021 已提交
290 291 292 293
                ZLOGE(LABEL, "TRANS_DATABUS_NAME message is excluded in sa manager");
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
H
heyingjiao 已提交
294 295 296 297 298 299 300 301 302
            result = GetSessionNameForPidUid(code, data, reply, option);
            break;
        }
        case GET_PID_UID: {
            if (!IPCSkeleton::IsLocalCalling()) {
                result = IPC_STUB_INVALID_DATA_ERR;
                break;
            }
            result = GetPidUid(data, reply);
Z
zgit2021 已提交
303 304
            break;
        }
M
mamingshuai 已提交
305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329
#endif
        default:
            result = OnRemoteRequest(code, data, reply, option);
            break;
    }

    return result;
}

void IPCObjectStub::OnFirstStrongRef(const void *objectId)
{
    IPCProcessSkeleton *current = IPCProcessSkeleton::GetCurrent();

    if (current != nullptr) {
        current->AttachObject(this);
    }
}

void IPCObjectStub::OnLastStrongRef(const void *objectId)
{
    IPCProcessSkeleton *current = IPCProcessSkeleton::GetCurrent();

    if (current != nullptr) {
        current->DetachObject(this);
#ifndef CONFIG_IPC_SINGLE
H
heyingjiao 已提交
330 331 332
        // we only need to erase stub index here, commAuth and appInfo
        // has already been removed either in dbinder dec refcount case
        // or OnSessionClosed, we also remove commAuth and appInfo in case of leak 
M
mamingshuai 已提交
333
        current->DetachCommAuthInfoByStub(this);
H
heyingjiao 已提交
334
        uint64_t stubIndex = current->EraseStubIndex(this);
M
mamingshuai 已提交
335 336 337 338 339 340 341
        current->DetachAppInfoToStubIndex(stubIndex);
#endif
    }
}

bool IPCObjectStub::AddDeathRecipient(const sptr<DeathRecipient> &recipient)
{
342
    (void)recipient;
M
mamingshuai 已提交
343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360
    return false;
}

bool IPCObjectStub::RemoveDeathRecipient(const sptr<DeathRecipient> &recipient)
{
    return false;
}

pid_t IPCObjectStub::GetCallingPid()
{
    return IPCSkeleton::GetCallingPid();
}

pid_t IPCObjectStub::GetCallingUid()
{
    return IPCSkeleton::GetCallingUid();
}

X
Xi_Yuhao 已提交
361 362 363 364 365
uint32_t IPCObjectStub::GetCallingTokenID()
{
    return IPCSkeleton::GetCallingTokenID();
}

366 367 368 369 370
uint64_t IPCObjectStub::GetCallingFullTokenID()
{
    return IPCSkeleton::GetCallingFullTokenID();
}

X
Xi_Yuhao 已提交
371 372 373 374 375
uint32_t IPCObjectStub::GetFirstTokenID()
{
    return IPCSkeleton::GetFirstTokenID();
}

376 377 378 379 380
uint64_t IPCObjectStub::GetFirstFullTokenID()
{
    return IPCSkeleton::GetFirstFullTokenID();
}

381 382 383 384 385
int IPCObjectStub::GetObjectType() const
{
    return OBJECT_TYPE_NATIVE;
}

M
mamingshuai 已提交
386 387 388
int32_t IPCObjectStub::ProcessProto(uint32_t code, MessageParcel &data, MessageParcel &reply, MessageOption &option)
{
    int result = ERR_NONE;
389
    ZLOGD(LABEL, "IPCObjectStub::ProcessProto called, type = 0, normal stub object");
M
mamingshuai 已提交
390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423
    if (!reply.WriteUint32(IRemoteObject::IF_PROT_BINDER)) {
        ZLOGE(LABEL, "write to parcel fail");
        result = IPC_STUB_WRITE_PARCEL_ERR;
    }
    return result;
}

#ifndef CONFIG_IPC_SINGLE
int32_t IPCObjectStub::InvokerThread(uint32_t code, MessageParcel &data, MessageParcel &reply, MessageOption &option)
{
    switch (data.ReadUint32()) {
        case IRemoteObject::DATABUS_TYPE: {
            if (InvokerDataBusThread(data, reply) != ERR_NONE) {
                ZLOGE(LABEL, "Invoker databus thread fail");
                return IPC_STUB_INVOKE_THREAD_ERR;
            }
            break;
        }
        default: {
            ZLOGE(LABEL, "InvokerThread Invalid Type");
            return IPC_STUB_INVALID_DATA_ERR;
        }
    }

    return ERR_NONE;
}

int32_t IPCObjectStub::InvokerDataBusThread(MessageParcel &data, MessageParcel &reply)
{
    std::string deviceId = data.ReadString();
    uint32_t remotePid = data.ReadUint32();
    uint32_t remoteUid = data.ReadUint32();
    std::string remoteDeviceId = data.ReadString();
    std::string sessionName = data.ReadString();
H
heyingjiao 已提交
424
    uint32_t remoteTokenId = data.ReadUint32();
M
mamingshuai 已提交
425
    if (IsDeviceIdIllegal(deviceId) || IsDeviceIdIllegal(remoteDeviceId) || sessionName.empty()) {
H
heyingjiao 已提交
426
        ZLOGE(LABEL, "%{public}s: device ID is invalid or session name nil", __func__);
M
mamingshuai 已提交
427 428 429 430 431 432 433 434 435
        return IPC_STUB_INVALID_DATA_ERR;
    }

    IPCProcessSkeleton *current = IPCProcessSkeleton::GetCurrent();
    if (current == nullptr) {
        ZLOGE(LABEL, "IPCProcessSkeleton is nullptr");
        return IPC_STUB_CURRENT_NULL_ERR;
    }
    if (!current->CreateSoftbusServer(sessionName)) {
H
heyingjiao 已提交
436
        ZLOGE(LABEL, "%{public}s: fail to create databus server", __func__);
M
mamingshuai 已提交
437 438 439 440 441
        return IPC_STUB_CREATE_BUS_SERVER_ERR;
    }

    uint64_t stubIndex = current->AddStubByIndex(this);
    if (stubIndex == 0) {
H
heyingjiao 已提交
442
        ZLOGE(LABEL, "%{public}s: add stub fail", __func__);
M
mamingshuai 已提交
443 444
        return IPC_STUB_INVALID_DATA_ERR;
    }
H
heyingjiao 已提交
445 446 447 448 449 450 451 452 453 454

    uint32_t selfTokenId = static_cast<uint32_t>(IPCSkeleton::GetSelfTokenID());
    ZLOGW(LABEL,
        "invoke databus thread, local deviceId: %{public}s, remotePid: %{public}u, remoteUid: %{public}u, "
        "stubIndex: %{public}" PRIu64 ", remote deviceId: %{public}s, tokenId: %{public}u, selfTokenId: %{public}u",
        IPCProcessSkeleton::ConvertToSecureString(deviceId).c_str(), remotePid, remoteUid, stubIndex,
        IPCProcessSkeleton::ConvertToSecureString(remoteDeviceId).c_str(), remoteTokenId, selfTokenId);
    if (!reply.WriteUint64(stubIndex) || !reply.WriteString(sessionName) || !reply.WriteString(deviceId) ||
        !reply.WriteUint32(selfTokenId)) {
        ZLOGE(LABEL, "%{public}s: write to parcel fail", __func__);
M
mamingshuai 已提交
455 456
        return IPC_STUB_INVALID_DATA_ERR;
    }
H
heyingjiao 已提交
457 458 459
    // mark listen fd as 0
    if (!current->AttachAppInfoToStubIndex(remotePid, remoteUid, remoteTokenId, remoteDeviceId, stubIndex, 0)) {
        ZLOGW(LABEL, "app info already existed, replace with 0");
M
mamingshuai 已提交
460
    }
H
heyingjiao 已提交
461 462 463 464
    if (current->AttachCommAuthInfo(this, remotePid, remoteUid, remoteTokenId, remoteDeviceId)) {
        IncStrongRef(this);
    } else {
        ZLOGW(LABEL, "comm auth info attached already");
M
mamingshuai 已提交
465 466 467 468 469 470 471 472 473
    }

    return ERR_NONE;
}

int32_t IPCObjectStub::NoticeServiceDie(MessageParcel &data, MessageParcel &reply, MessageOption &option)
{
    IPCProcessSkeleton *current = IPCProcessSkeleton::GetCurrent();
    if (current == nullptr) {
H
heyingjiao 已提交
474
        ZLOGE(LABEL, "%{public}s: current is null", __func__);
M
mamingshuai 已提交
475 476 477
        return IPC_STUB_CURRENT_NULL_ERR;
    }

H
heyingjiao 已提交
478
    sptr<IPCObjectProxy> ipcProxy = current->QueryCallbackProxy(this);
M
mamingshuai 已提交
479
    if (ipcProxy == nullptr) {
H
heyingjiao 已提交
480
        ZLOGE(LABEL, "%{public}s: ipc proxy is null", __func__);
M
mamingshuai 已提交
481 482 483 484 485 486 487
        return IPC_STUB_INVALID_DATA_ERR;
    }

    ipcProxy->SendObituary();
    return ERR_NONE;
}

Z
zgit2021 已提交
488
int32_t IPCObjectStub::AddAuthInfo(MessageParcel &data, MessageParcel &reply, uint32_t code)
M
mamingshuai 已提交
489 490 491 492
{
    uint32_t remotePid = data.ReadUint32();
    uint32_t remoteUid = data.ReadUint32();
    std::string remoteDeviceId = data.ReadString();
H
heyingjiao 已提交
493 494
    uint64_t stubIndex = data.ReadUint64();
    uint32_t tokenId = data.ReadUint32();
M
mamingshuai 已提交
495
    if (IsDeviceIdIllegal(remoteDeviceId)) {
H
heyingjiao 已提交
496
        ZLOGE(LABEL, "%{public}s: remote deviceId is null", __func__);
M
mamingshuai 已提交
497 498 499 500 501
        return IPC_STUB_INVALID_DATA_ERR;
    }

    IPCProcessSkeleton *current = IPCProcessSkeleton::GetCurrent();
    if (current == nullptr) {
H
heyingjiao 已提交
502
        ZLOGE(LABEL, "%{public}s: current is null", __func__);
M
mamingshuai 已提交
503 504 505
        return IPC_STUB_CURRENT_NULL_ERR;
    }

H
heyingjiao 已提交
506 507 508
    if (stubIndex == 0) {
        // keep compatible with proxy that doesn't write stubIndex when adding auth info to stub
        stubIndex = current->QueryStubIndex(this);
Z
zgit2021 已提交
509
        if (stubIndex == 0) {
H
heyingjiao 已提交
510
            ZLOGE(LABEL, "stub index is null");
Z
zgit2021 已提交
511 512
            return BINDER_CALLBACK_STUBINDEX_ERR;
        }
H
heyingjiao 已提交
513 514 515 516 517 518 519 520 521 522 523 524 525
    }

    ZLOGW(LABEL, "add auth info pid: %{public}u, uid: %{public}u, devId: %{public}s, stubIndex: %{public}" PRIu64
        ", tokenId: %{public}u", remotePid, remoteUid,
        IPCProcessSkeleton::ConvertToSecureString(remoteDeviceId).c_str(), stubIndex, tokenId);
    // mark listen fd as 0
    if (!current->AttachAppInfoToStubIndex(remotePid, remoteUid, tokenId, remoteDeviceId, stubIndex, 0)) {
        ZLOGW(LABEL, "app info already attached, replace with 0");
    }
    if (current->AttachCommAuthInfo(this, remotePid, remoteUid, tokenId, remoteDeviceId)) {
        IncStrongRef(this);
    } else {
        ZLOGW(LABEL, "comm auth info attached already");
Z
zgit2021 已提交
526
    }
M
mamingshuai 已提交
527 528 529
    return ERR_NONE;
}

H
heyingjiao 已提交
530
std::string IPCObjectStub::GetSessionName()
M
mamingshuai 已提交
531
{
Z
zgit2021 已提交
532 533 534 535 536 537
    IPCProcessSkeleton *current = IPCProcessSkeleton::GetCurrent();
    if (current == nullptr) {
        ZLOGE(LABEL, "get current is null");
        return std::string("");
    }
    sptr<IRemoteObject> object = current->GetSAMgrObject();
M
mamingshuai 已提交
538 539 540 541 542 543
    if (object == nullptr) {
        ZLOGE(LABEL, "get object is null");
        return std::string("");
    }

    IPCObjectProxy *samgr = reinterpret_cast<IPCObjectProxy *>(object.GetRefPtr());
H
heyingjiao 已提交
544
    return samgr->GetGrantedSessionName();
M
mamingshuai 已提交
545 546
}

H
heyingjiao 已提交
547 548
int32_t IPCObjectStub::GetGrantedSessionName(uint32_t code, MessageParcel &data, MessageParcel &reply,
    MessageOption &option)
M
mamingshuai 已提交
549 550 551
{
    int pid = IPCSkeleton::GetCallingPid();
    int uid = IPCSkeleton::GetCallingUid();
H
heyingjiao 已提交
552
    std::string sessionName = CreateSessionName(uid, pid);
M
mamingshuai 已提交
553
    if (sessionName.empty()) {
H
heyingjiao 已提交
554
        ZLOGE(LABEL, "pid/uid is invalid, pid = %{public}d, uid = %{public}d", pid, uid);
M
mamingshuai 已提交
555 556 557 558 559 560 561 562 563 564
        return IPC_STUB_INVALID_DATA_ERR;
    }
    if (!reply.WriteUint32(IRemoteObject::IF_PROT_DATABUS) || !reply.WriteString(sessionName)) {
        ZLOGE(LABEL, "write to parcel fail");
        return IPC_STUB_INVALID_DATA_ERR;
    }

    return ERR_NONE;
}

H
heyingjiao 已提交
565 566
int32_t IPCObjectStub::GetSessionNameForPidUid(uint32_t code, MessageParcel &data, MessageParcel &reply,
    MessageOption &option)
Z
zgit2021 已提交
567 568 569 570
{
    uint32_t remotePid = data.ReadUint32();
    uint32_t remoteUid = data.ReadUint32();
    if (remotePid == static_cast<uint32_t>(IPCSkeleton::GetCallingPid())) {
H
heyingjiao 已提交
571
        ZLOGE(LABEL, "pid/uid is invalid, pid = %{public}d, uid = %{public}d", remotePid, remoteUid);
Z
zgit2021 已提交
572 573
        return IPC_STUB_INVALID_DATA_ERR;
    }
H
heyingjiao 已提交
574
    std::string sessionName = CreateSessionName(remoteUid, remotePid);
Z
zgit2021 已提交
575
    if (sessionName.empty()) {
H
heyingjiao 已提交
576
        ZLOGE(LABEL, "pid/uid is invalid, pid = %{public}d, uid = %{public}d", remotePid, remoteUid);
Z
zgit2021 已提交
577 578 579 580 581 582 583 584 585 586
        return IPC_STUB_INVALID_DATA_ERR;
    }
    if (!reply.WriteUint32(IRemoteObject::IF_PROT_DATABUS) || !reply.WriteString(sessionName)) {
        ZLOGE(LABEL, "write to parcel fail");
        return IPC_STUB_INVALID_DATA_ERR;
    }

    return ERR_NONE;
}

H
heyingjiao 已提交
587 588 589 590 591 592 593 594 595 596
int IPCObjectStub::GetPidUid(MessageParcel &data, MessageParcel &reply)
{
    if (!reply.WriteUint32(getpid()) || !reply.WriteUint32(getuid())) {
        ZLOGE(LABEL, "write to parcel fail");
        return IPC_STUB_INVALID_DATA_ERR;
    }
    return ERR_NONE;
}

std::string IPCObjectStub::CreateSessionName(int uid, int pid)
M
mamingshuai 已提交
597 598 599 600 601 602 603 604 605 606 607 608 609 610 611
{
    std::shared_ptr<ISessionService> softbusManager = ISessionService::GetInstance();
    if (softbusManager == nullptr) {
        ZLOGE(LABEL, "fail to get softbus service");
        return "";
    }

    std::string sessionName = "DBinder" + std::to_string(uid) + std::string("_") + std::to_string(pid);
    if (softbusManager->GrantPermission(uid, pid, sessionName) != ERR_NONE) {
        ZLOGE(LABEL, "fail to Grant Permission softbus name");
        return "";
    }

    return sessionName;
}
Y
yangguangzhao 已提交
612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627

bool IPCObjectStub::IsSamgrCall(uint32_t accessToken)
{
    auto tokenType = AccessToken::AccessTokenKit::GetTokenTypeFlag(accessToken);
    if (tokenType != AccessToken::ATokenTypeEnum::TOKEN_NATIVE) {
        ZLOGE(LABEL, "not native call");
        return false;
    }
    AccessToken::NativeTokenInfo nativeTokenInfo;
    int32_t result = AccessToken::AccessTokenKit::GetNativeTokenInfo(accessToken, nativeTokenInfo);
    if (result == ERR_NONE && nativeTokenInfo.processName == SAMGR_PROCESS_NAME) {
        return true;
    }
    ZLOGE(LABEL, "not samgr called, processName:%{private}s", nativeTokenInfo.processName.c_str());
    return false;
}
L
lutao 已提交
628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646

bool IPCObjectStub::HasDumpPermission(uint32_t accessToken) const
{
    int res = AccessToken::AccessTokenKit::VerifyAccessToken(accessToken, "ohos.permission.DUMP");
    if (res == AccessToken::PermissionState::PERMISSION_GRANTED) {
        return true;
    }
    bool ret = false;
    auto tokenType = AccessToken::AccessTokenKit::GetTokenTypeFlag(accessToken);
    if (tokenType == AccessToken::ATokenTypeEnum::TOKEN_NATIVE) {
        AccessToken::NativeTokenInfo nativeTokenInfo;
        int32_t result = AccessToken::AccessTokenKit::GetNativeTokenInfo(accessToken, nativeTokenInfo);
        ret =  (result == ERR_NONE && nativeTokenInfo.apl >= APL_BASIC);
    } else if (tokenType == AccessToken::ATokenTypeEnum::TOKEN_HAP) {
        AccessToken::HapTokenInfo hapTokenInfo;
        int32_t result = AccessToken::AccessTokenKit::GetHapTokenInfo(accessToken, hapTokenInfo);
        ret =  (result == ERR_NONE && hapTokenInfo.apl >= APL_BASIC);
    }
    if (!ret) {
Z
zhangboyuan 已提交
647
        ZLOGD(LABEL, "No dump permission, please check!");
L
lutao 已提交
648 649 650
    }
    return ret;
}
M
mamingshuai 已提交
651 652
#endif
} // namespace OHOS