init.c 12.6 KB
Newer Older
1
/*
M
Mupceet 已提交
2
 * Copyright (c) 2021-2022 Huawei Device Co., Ltd.
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 * http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
#include "init.h"

#include <errno.h>
X
xionglei6 已提交
18
#include <poll.h>
19 20
#include <stdlib.h>
#include <signal.h>
21
#include <time.h>
22 23 24
#include <sys/sysmacros.h>
#include <sys/stat.h>
#include <sys/types.h>
X
xionglei6 已提交
25
#include <sys/socket.h>
4
411148299@qq.com 已提交
26
#include <linux/major.h>
Z
zhr758 已提交
27 28

#include "config_policy_utils.h"
29
#include "device.h"
X
xionglei6 已提交
30
#include "fd_holder_service.h"
X
xionglei6 已提交
31
#include "fs_manager/fs_manager.h"
M
Mupceet 已提交
32
#include "init_control_fd_service.h"
33 34
#include "init_log.h"
#include "init_mount.h"
X
xionglei6 已提交
35
#include "init_group_manager.h"
36
#include "init_param.h"
X
xionglei6 已提交
37 38
#include "init_service.h"
#include "init_service_manager.h"
39 40 41
#include "init_utils.h"
#include "securec.h"
#include "switch_root.h"
X
xionglei6 已提交
42 43
#include "ueventd.h"
#include "ueventd_socket.h"
X
xionglei6 已提交
44
#include "fd_holder_internal.h"
X
xionglei6 已提交
45 46
#include "sandbox.h"
#include "sandbox_namespace.h"
Q
Qin Fandong 已提交
47
#ifdef WITH_SELINUX
X
xionglei6 已提交
48
#include <policycoreutils.h>
R
renwei 已提交
49
#include <selinux/selinux.h>
Q
Qin Fandong 已提交
50
#endif // WITH_SELINUX
51
#include "bootstage.h"
52

X
xionglei6 已提交
53 54
static bool g_enableSandbox;

X
xionglei6 已提交
55 56 57 58
static int FdHolderSockInit(void)
{
    int sock = -1;
    int on = 1;
X
xionglei6 已提交
59 60
    int fdHolderBufferSize = FD_HOLDER_BUFFER_SIZE; // 4KiB
    sock = socket(AF_UNIX, SOCK_DGRAM | SOCK_CLOEXEC | SOCK_NONBLOCK, 0);
X
xionglei6 已提交
61 62 63 64 65 66 67 68 69 70 71 72 73
    if (sock < 0) {
        INIT_LOGE("Failed to create fd holder socket, err = %d", errno);
        return -1;
    }

    setsockopt(sock, SOL_SOCKET, SO_RCVBUFFORCE, &fdHolderBufferSize, sizeof(fdHolderBufferSize));
    setsockopt(sock, SOL_SOCKET, SO_PASSCRED, &on, sizeof(on));

    if (access(INIT_HOLDER_SOCKET_PATH, F_OK) == 0) {
        INIT_LOGI("%s exist, remove it", INIT_HOLDER_SOCKET_PATH);
        unlink(INIT_HOLDER_SOCKET_PATH);
    }
    struct sockaddr_un addr;
X
xionglei6 已提交
74
    addr.sun_family = AF_UNIX;
X
xionglei6 已提交
75 76 77 78 79 80 81 82
    if (strncpy_s(addr.sun_path, sizeof(addr.sun_path),
        INIT_HOLDER_SOCKET_PATH, strlen(INIT_HOLDER_SOCKET_PATH)) != 0) {
        INIT_LOGE("Faild to copy fd hoder socket path");
        close(sock);
        return -1;
    }
    socklen_t len = (socklen_t)(offsetof(struct sockaddr_un, sun_path) + strlen(addr.sun_path) + 1);
    if (bind(sock, (struct sockaddr *)&addr, len) < 0) {
X
xionglei6 已提交
83
        INIT_LOGE("Failed to binder fd folder socket %d", errno);
X
xionglei6 已提交
84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99
        close(sock);
        return -1;
    }

    // Owned by root
    if (lchown(addr.sun_path, 0, 0)) {
        INIT_LOGW("Failed to change owner of fd holder socket, err = %d", errno);
    }
    mode_t mode = S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP | S_IROTH | S_IWOTH;
    if (fchmodat(AT_FDCWD, addr.sun_path, mode, AT_SYMLINK_NOFOLLOW)) {
        INIT_LOGW("Failed to change mode of fd holder socket, err = %d", errno);
    }
    INIT_LOGI("Init fd holder socket done");
    return sock;
}

100 101 102
void SystemInit(void)
{
    SignalInit();
X
xionglei6 已提交
103 104
    // umask call always succeeds and return the previous mask value which is not needed here
    (void)umask(DEFAULT_UMASK_INIT);
105
    MakeDirRecursive("/dev/unix/socket", S_IRWXU | S_IRGRP | S_IXGRP | S_IROTH | S_IXOTH);
X
xionglei6 已提交
106 107 108 109
    int sock = FdHolderSockInit();
    if (sock >= 0) {
        RegisterFdHoldWatcher(sock);
    }
M
Mupceet 已提交
110
    InitControlFd();
X
xionglei6 已提交
111 112 113 114 115
}

static void EnableDevKmsg(void)
{
    /* printk_devkmsg default value is ratelimit, We need to set "on" and remove the restrictions */
X
xionglei6 已提交
116
    int fd = open("/proc/sys/kernel/printk_devkmsg", O_WRONLY | O_CLOEXEC, S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP);
X
xionglei6 已提交
117 118 119 120 121 122 123 124
    if (fd < 0) {
        return;
    }
    char *kmsgStatus = "on";
    write(fd, kmsgStatus, strlen(kmsgStatus) + 1);
    close(fd);
    fd = -1;
    return;
125 126 127 128 129 130 131 132 133 134 135 136
}

void LogInit(void)
{
    CloseStdio();
    int ret = mknod("/dev/kmsg", S_IFCHR | S_IWUSR | S_IRUSR,
        makedev(MEM_MAJOR, DEV_KMSG_MINOR));
    if (ret == 0) {
        OpenLogDevice();
    }
}

X
xionglei6 已提交
137
static char **GetRequiredDevices(Fstab fstab, int *requiredNum)
138
{
X
xionglei6 已提交
139 140 141 142 143 144 145
    int num = 0;
    FstabItem *item = fstab.head;
    while (item != NULL) {
        if (FM_MANAGER_REQUIRED_ENABLED(item->fsManagerFlags)) {
            num++;
        }
        item = item->next;
146
    }
X
xionglei6 已提交
147 148 149 150 151 152 153 154 155 156 157
    char **devices = (char **)calloc(num, sizeof(char *));
    INIT_ERROR_CHECK(devices != NULL, return NULL, "Failed calloc err=%d", errno);

    int i = 0;
    item = fstab.head;
    while (item != NULL) {
        if (FM_MANAGER_REQUIRED_ENABLED(item->fsManagerFlags)) {
            devices[i] = strdup(item->deviceName);
            INIT_ERROR_CHECK(devices[i] != NULL, FreeStringVector(devices, num); return NULL,
                "Failed strdup err=%d", errno);
            i++;
158
        }
X
xionglei6 已提交
159
        item = item->next;
160
    }
X
xionglei6 已提交
161 162
    *requiredNum = num;
    return devices;
163 164
}

X
xionglei6 已提交
165
static int StartUeventd(char **requiredDevices, int num)
166
{
X
xionglei6 已提交
167 168 169 170 171
    INIT_ERROR_CHECK(requiredDevices != NULL && num > 0, return -1, "Failed parameters");
    int ueventSockFd = UeventdSocketInit();
    if (ueventSockFd < 0) {
        INIT_LOGE("Failed to create uevent socket");
        return -1;
172
    }
X
xionglei6 已提交
173
    RetriggerUevent(ueventSockFd, requiredDevices, num);
X
xionglei6 已提交
174
    close(ueventSockFd);
X
xionglei6 已提交
175 176 177 178 179 180
    return 0;
}

static void StartInitSecondStage(void)
{
    int requiredNum = 0;
M
Mupceet 已提交
181 182
    Fstab* fstab = LoadRequiredFstab();
    INIT_ERROR_CHECK(fstab != NULL, abort(), "Failed to load required fstab");
X
xionglei6 已提交
183 184 185 186 187 188 189 190 191 192 193 194 195 196
    char **devices = GetRequiredDevices(*fstab, &requiredNum);
    if (devices != NULL && requiredNum > 0) {
        int ret = StartUeventd(devices, requiredNum);
        if (ret == 0) {
            ret = MountRequriedPartitions(fstab);
        }
        FreeStringVector(devices, requiredNum);
        devices = NULL;
        ReleaseFstab(fstab);
        fstab = NULL;
        if (ret < 0) {
            // If mount required partitions failure.
            // There is no necessary to continue.
            // Just abort
X
xionglei6 已提交
197 198 199
            INIT_LOGE("Mount requried partitions failed; please check fstab file");
            // Execute sh for debugging
            execv("/bin/sh", NULL);
X
xionglei6 已提交
200 201
            abort();
        }
202
    }
X
xionglei6 已提交
203
#ifndef DISABLE_INIT_TWO_STAGES
204 205
    SwitchRoot("/usr");
    // Execute init second stage
X
xionglei6 已提交
206
    char * const args[] = {
207 208
        "/bin/init",
        "--second-stage",
S
sun_fan 已提交
209
        NULL,
210 211 212 213 214
    };
    if (execv("/bin/init", args) != 0) {
        INIT_LOGE("Failed to exec \"/bin/init\", err = %d", errno);
        exit(-1);
    }
S
sun_fan 已提交
215
#endif
X
xionglei6 已提交
216
}
217 218 219 220

void SystemPrepare(void)
{
    MountBasicFs();
221
    CreateDeviceNode();
X
xionglei6 已提交
222
    LogInit();
223 224 225 226 227
    // Make sure init log always output to /dev/kmsg.
    EnableDevKmsg();
    // Only ohos normal system support
    // two stages of init.
    // If we are in updater mode, only one stage of init,
S
sun_fan 已提交
228
    INIT_LOGI("DISABLE_INIT_TWO_STAGES not defined");
229 230 231 232 233
    if (InUpdaterMode() == 0) {
        StartInitSecondStage();
    }
}

Q
Qin Fandong 已提交
234 235 236 237
void SystemLoadSelinux(void)
{
#ifdef WITH_SELINUX
    // load selinux policy and context
R
renwei 已提交
238
    if (LoadPolicy() < 0) {
Q
Qin Fandong 已提交
239 240 241 242
        INIT_LOGE("main, load_policy failed.");
    } else {
        INIT_LOGI("main, load_policy success.");
    }
R
renwei 已提交
243 244

    setcon("u:r:init:s0");
R
renwei 已提交
245
    (void)RestoreconRecurse("/dev");
Q
Qin Fandong 已提交
246 247 248
#endif // WITH_SELINUX
}

X
xionglei6 已提交
249 250 251 252
static void BootStateChange(const char *content)
{
    INIT_LOGI("boot start %s finish.", content);
    if (strcmp("init", content) == 0) {
X
xionglei6 已提交
253
        StartAllServices(START_MODE_BOOT);
X
xionglei6 已提交
254 255 256 257
        return;
    }
    if (strcmp("post-init", content) == 0) {
        StartAllServices(START_MODE_NARMAL);
M
Mupceet 已提交
258 259
        // Destroy all hooks
        HookMgrDestroy(NULL);
X
xionglei6 已提交
260 261 262 263 264
        return;
    }
}

#if defined(OHOS_SERVICE_DUMP)
X
xionglei6 已提交
265
static int SystemDump(int id, const char *name, int argc, const char **argv)
X
xionglei6 已提交
266
{
X
xionglei6 已提交
267
    INIT_ERROR_CHECK(argv != NULL && argc >= 1, return 0, "Invalid install parameter");
X
xionglei6 已提交
268 269
    INIT_LOGI("Dump system info %s", argv[0]);
    DumpAllServices();
M
Mupceet 已提交
270 271
    SystemDumpParameters(1);
    SystemDumpTriggers(1);
X
xionglei6 已提交
272
    return 0;
X
xionglei6 已提交
273 274 275
}
#endif

X
xionglei6 已提交
276 277 278 279 280 281 282 283 284 285
static void IsEnableSandbox(void)
{
    const char *name = "const.sandbox";
    char value[MAX_BUFFER_LEN] = {0};
    unsigned int len = MAX_BUFFER_LEN;
    if (SystemReadParam(name, value, &len) != 0) {
        INIT_LOGE("Failed read param.");
        g_enableSandbox = false;
    }
    if (strcmp(value, "enable") == 0) {
X
xionglei6 已提交
286
        INIT_LOGI("Enable sandbox.");
X
xionglei6 已提交
287 288
        g_enableSandbox = true;
    } else {
X
xionglei6 已提交
289
        INIT_LOGI("Disable sandbox.");
X
xionglei6 已提交
290 291 292 293
        g_enableSandbox = false;
    }
}

Z
zhr758 已提交
294 295 296 297 298 299 300 301 302 303 304 305 306
static void InitLoadParamFiles(void)
{
    // Load const params, these can't be override!
    LoadDefaultParams("/system/etc/param/ohos_const", LOAD_PARAM_NORMAL);
    CfgFiles *files = GetCfgFiles("etc/param");
    for (int i = MAX_CFG_POLICY_DIRS_CNT - 1; files && i >= 0; i--) {
        if (files->paths[i]) {
            LoadDefaultParams(files->paths[i], LOAD_PARAM_ONLY_ADD);
        }
    }
    FreeCfgFiles(files);
}

307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330
typedef struct HOOK_TIMING_STAT {
    struct timespec startTime;
    struct timespec endTime;
} HOOK_TIMING_STAT;

static void InitPreHook(const HOOK_INFO *hookInfo)
{
    HOOK_TIMING_STAT *stat = (HOOK_TIMING_STAT *)hookInfo->cookie;
    clock_gettime(CLOCK_MONOTONIC, &(stat->startTime));
}

static void InitPostHook(const HOOK_INFO *hookInfo)
{
    long long diff;
    HOOK_TIMING_STAT *stat = (HOOK_TIMING_STAT *)hookInfo->cookie;
    clock_gettime(CLOCK_MONOTONIC, &(stat->endTime));

    diff = (long long)((stat->endTime.tv_sec - stat->startTime.tv_sec) / 1000);
    if (stat->endTime.tv_nsec > stat->startTime.tv_nsec) {
        diff += (stat->endTime.tv_nsec - stat->startTime.tv_nsec) * 1000;
    } else {
        diff -= (stat->endTime.tv_nsec - stat->startTime.tv_nsec) * 1000;
    }

M
Mupceet 已提交
331
    INIT_LOGV("Executing hook [%d:%d:%p] cost [%lld]ms, return %d.",
332 333 334
                hookInfo->stage, hookInfo->prio, hookInfo->hook, diff, hookInfo->retVal);
}

335 336
void SystemConfig(void)
{
337 338 339 340 341 342 343 344 345
    HOOK_TIMING_STAT timingStat;
    HOOK_EXEC_ARGS args;

    args.flags = 0;
    args.cookie = (void *)&timingStat;
    args.preHook = InitPreHook;
    args.postHook = InitPostHook;

    HookMgrExecute(NULL, INIT_GLOBAL_INIT, (void *)&args);
X
xionglei6 已提交
346
    InitServiceSpace();
347 348

    HookMgrExecute(NULL, INIT_PRE_PARAM_SERVICE, (void *)&args);
Z
zhr758 已提交
349
    InitParamService();
X
xionglei6 已提交
350 351 352
    InitParseGroupCfg();
    RegisterBootStateChange(BootStateChange);

R
renwei 已提交
353 354 355
    // load SELinux context and policy
    // Do not move position!
    SystemLoadSelinux();
356
    // parse parameters
357
    HookMgrExecute(NULL, INIT_PRE_PARAM_LOAD, (void *)&args);
Z
zhr758 已提交
358
    InitLoadParamFiles();
359
    // read config
360
    HookMgrExecute(NULL, INIT_PRE_CFG_LOAD, (void *)&args);
361 362
    ReadConfig();
    INIT_LOGI("Parse init config file done.");
363 364
    HookMgrExecute(NULL, INIT_POST_CFG_LOAD, (void *)&args);

365
    // dump config
X
xionglei6 已提交
366 367 368
#if defined(OHOS_SERVICE_DUMP)
    AddCmdExecutor("display", SystemDump);
    (void)AddCompleteJob("param:ohos.servicectrl.display", "ohos.servicectrl.display=*", "display system");
369
#endif
X
xionglei6 已提交
370
    IsEnableSandbox();
371 372 373 374 375 376 377 378 379 380
    // execute init
    PostTrigger(EVENT_TRIGGER_BOOT, "pre-init", strlen("pre-init"));
    PostTrigger(EVENT_TRIGGER_BOOT, "init", strlen("init"));
    PostTrigger(EVENT_TRIGGER_BOOT, "post-init", strlen("post-init"));
}

void SystemRun(void)
{
    StartParamService();
}
X
xionglei6 已提交
381

X
xionglei6 已提交
382
void SetServiceEnterSandbox(const char *execPath, unsigned int attribute)
X
xionglei6 已提交
383 384
{
    if (g_enableSandbox == false) {
X
xionglei6 已提交
385
        return;
X
xionglei6 已提交
386
    }
X
xionglei6 已提交
387 388 389 390 391 392 393 394 395
    if ((attribute & SERVICE_ATTR_SANDBOX) != SERVICE_ATTR_SANDBOX) {
        return;
    }
    INIT_ERROR_CHECK(execPath != NULL, return, "Service path is null.");
    if (strncmp(execPath, "/system/bin/", strlen("/system/bin/")) == 0) {
        if (strcmp(execPath, "/system/bin/appspawn") == 0) {
            INIT_LOGI("Appspawn skip enter sandbox.");
        } else if (strcmp(execPath, "/system/bin/hilogd") == 0) {
            INIT_LOGI("Hilogd skip enter sandbox.");
X
xionglei6 已提交
396
        } else {
M
Mupceet 已提交
397 398
            INIT_INFO_CHECK(EnterSandbox("system") == 0, return,
                "Service %s skip enter sandbox system.", execPath);
X
xionglei6 已提交
399
        }
X
xionglei6 已提交
400 401
    } else if (strncmp(execPath, "/vendor/bin/", strlen("/vendor/bin/")) == 0) {
        // chipset sandbox will be implemented later.
M
Mupceet 已提交
402 403
        INIT_INFO_CHECK(EnterSandbox("system") == 0, return,
            "Service %s skip enter sandbox system.", execPath);
X
xionglei6 已提交
404
    } else {
M
Mupceet 已提交
405
        INIT_LOGI("Service %s does not enter sandbox", execPath);
X
xionglei6 已提交
406
    }
X
xionglei6 已提交
407
    return;
X
xionglei6 已提交
408
}