`

Android Permission:Property

阅读更多
property_serice.c


/*
* Copyright (C) 2007 The Android Open Source Project
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
*      http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
#include <string.h>
#include <ctype.h>
#include <fcntl.h>
#include <stdarg.h>
#include <dirent.h>
#include <limits.h>
#include <errno.h>

#include <cutils/misc.h>
#include <cutils/sockets.h>
#include <cutils/ashmem.h>

#define _REALLY_INCLUDE_SYS__SYSTEM_PROPERTIES_H_
#include <sys/_system_properties.h>

#include <sys/socket.h>
#include <sys/un.h>
#include <sys/select.h>
#include <sys/types.h>
#include <netinet/in.h>
#include <sys/mman.h>
#include <sys/atomics.h>
#include <private/android_filesystem_config.h>

#include "property_service.h"
#include "init.h"

#define PERSISTENT_PROPERTY_DIR  "/data/property"

static int persistent_properties_loaded = 0;

/* White list of permissions for setting property services. */
struct {
    const char *prefix;
    unsigned int uid;
} property_perms[] = {
    { "net.rmnet0.",    AID_RADIO },
    { "net.gprs.",      AID_RADIO },
    { "net.ppp0.",      AID_RADIO },
    { "ril.",           AID_RADIO },
    { "gsm.",           AID_RADIO },
    { "net.dns",        AID_RADIO },
    { "net.",           AID_SYSTEM },
    { "dev.",           AID_SYSTEM },
    { "runtime.",       AID_SYSTEM },
    { "hw.",            AID_SYSTEM },
    { "sys.", AID_SYSTEM },
    { "service.", AID_SYSTEM },
    { "wlan.", AID_SYSTEM },
    { "dhcp.", AID_SYSTEM },
    { "dhcp.", AID_DHCP },
    { "vpn.", AID_SYSTEM },
    { "vpn.", AID_VPN },
    { "debug.", AID_SHELL },
    { "log.", AID_SHELL },
    { "service.adb.root", AID_SHELL },
    { "persist.sys.", AID_SYSTEM },
    { "persist.service.",   AID_SYSTEM },
    { "xec.", AID_MEDIA },
    { NULL, 0 }
};

/*
* White list of UID that are allowed to start/stop services.
* Currently there are no user apps that require.
*/
struct {
    const char *service;
    unsigned int uid;
} control_perms[] = {
     {"pppd_gprs", AID_RADIO},
     {NULL, 0 }
};

typedef struct {
    void *data;
    size_t size;
    int fd;
} workspace;

static int init_workspace(workspace *w, size_t size)
{
    void *data;
    int fd;

    fd = ashmem_create_region("system_properties", size);
    if(fd < 0)
        return -1;

    data = mmap(NULL, size, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0);
    if(data == MAP_FAILED)
        goto out;

    /* allow the wolves we share with to do nothing but read */
    ashmem_set_prot_region(fd, PROT_READ);

    w->data = data;
    w->size = size;
    w->fd = fd;

    return 0;

out:
    close(fd);
    return -1;
}

/* (8 header words + 247 toc words) = 1020 bytes */
/* 1024 bytes header and toc + 247 prop_infos @ 128 bytes = 32640 bytes */

#define PA_COUNT_MAX  247
#define PA_INFO_START 1024
#define PA_SIZE       32768

static workspace pa_workspace;
static prop_info *pa_info_array;

extern prop_area *__system_property_area__;

static int init_property_area(void)
{
    prop_area *pa;

    if(pa_info_array)
        return -1;

    if(init_workspace(&pa_workspace, PA_SIZE))
        return -1;

    fcntl(pa_workspace.fd, F_SETFD, FD_CLOEXEC);

    pa_info_array = (void*) (((char*) pa_workspace.data) + PA_INFO_START);

    pa = pa_workspace.data;
    memset(pa, 0, PA_SIZE);
    pa->magic = PROP_AREA_MAGIC;
    pa->version = PROP_AREA_VERSION;

        /* plug into the lib property services */
    __system_property_area__ = pa;

    return 0;
}

static void update_prop_info(prop_info *pi, const char *value, unsigned len)
{
    pi->serial = pi->serial | 1;
    memcpy(pi->value, value, len + 1);
    pi->serial = (len << 24) | ((pi->serial + 1) & 0xffffff);
    __futex_wake(&pi->serial, INT32_MAX);
}

static int property_write(prop_info *pi, const char *value)
{
    int valuelen = strlen(value);
    if(valuelen >= PROP_VALUE_MAX) return -1;
    update_prop_info(pi, value, valuelen);
    return 0;
}


/*
* Checks permissions for starting/stoping system services.
* AID_SYSTEM and AID_ROOT are always allowed.
*
* Returns 1 if uid allowed, 0 otherwise.
*/
static int check_control_perms(const char *name, int uid) {
    int i;
    if (uid == AID_SYSTEM || uid == AID_ROOT)
        return 1;

    /* Search the ACL */
    for (i = 0; control_perms[i].service; i++) {
        if (strcmp(control_perms[i].service, name) == 0) {
            if (control_perms[i].uid == uid)
                return 1;
        }
    }
    return 0;
}

/*
* Checks permissions for setting system properties.
* Returns 1 if uid allowed, 0 otherwise.
*/
static int check_perms(const char *name, unsigned int uid)
{
    int i;
    if (uid == 0)
        return 1;

    if(!strncmp(name, "ro.", 3))
        name +=3;

    for (i = 0; property_perms[i].prefix; i++) {
        int tmp;
        if (strncmp(property_perms[i].prefix, name,
                    strlen(property_perms[i].prefix)) == 0) {
            if (property_perms[i].uid == uid) {
                return 1;
            }
        }
    }

    return 0;
}

const char* property_get(const char *name)
{
    prop_info *pi;

    if(strlen(name) >= PROP_NAME_MAX) return 0;

    pi = (prop_info*) __system_property_find(name);

    if(pi != 0) {
        return pi->value;
    } else {
        return 0;
    }
}

static void write_peristent_property(const char *name, const char *value)
{
    const char *tempPath = PERSISTENT_PROPERTY_DIR "/.temp";
    char path[PATH_MAX];
    int fd, length;

    snprintf(path, sizeof(path), "%s/%s", PERSISTENT_PROPERTY_DIR, name);

    fd = open(tempPath, O_WRONLY|O_CREAT|O_TRUNC, 0600);
    if (fd < 0) {
        ERROR("Unable to write persistent property to temp file %s errno: %d\n", tempPath, errno);
        return;  
    }
    write(fd, value, strlen(value));
    close(fd);

    if (rename(tempPath, path)) {
        unlink(tempPath);
        ERROR("Unable to rename persistent property file %s to %s\n", tempPath, path);
    }
}

int property_set(const char *name, const char *value)
{
    prop_area *pa;
    prop_info *pi;

    int namelen = strlen(name);
    int valuelen = strlen(value);

    if(namelen >= PROP_NAME_MAX) return -1;
    if(valuelen >= PROP_VALUE_MAX) return -1;
    if(namelen < 1) return -1;

    pi = (prop_info*) __system_property_find(name);

    if(pi != 0) {
        /* ro.* properties may NEVER be modified once set */
        if(!strncmp(name, "ro.", 3)) return -1;

        pa = __system_property_area__;
        update_prop_info(pi, value, valuelen);
        pa->serial++;
        __futex_wake(&pa->serial, INT32_MAX);
    } else {
        pa = __system_property_area__;
        if(pa->count == PA_COUNT_MAX) return -1;

        pi = pa_info_array + pa->count;
        pi->serial = (valuelen << 24);
        memcpy(pi->name, name, namelen + 1);
        memcpy(pi->value, value, valuelen + 1);

        pa->toc[pa->count] =
            (namelen << 24) | (((unsigned) pi) - ((unsigned) pa));

        pa->count++;
        pa->serial++;
        __futex_wake(&pa->serial, INT32_MAX);
    }
    /* If name starts with "net." treat as a DNS property. */
    if (strncmp("net.", name, strlen("net.")) == 0)  {
        if (strcmp("net.change", name) == 0) {
            return 0;
        }
       /*
        * The 'net.change' property is a special property used track when any
        * 'net.*' property name is updated. It is _ONLY_ updated here. Its value
        * contains the last updated 'net.*' property.
        */
        property_set("net.change", name);
    } else if (persistent_properties_loaded &&
            strncmp("persist.", name, strlen("persist.")) == 0) {
        /*
         * Don't write properties to disk until after we have read all default properties
         * to prevent them from being overwritten by default values.
         */
        write_peristent_property(name, value);
    }
    property_changed(name, value);
    return 0;
}

static int property_list(void (*propfn)(const char *key, const char *value, void *cookie),
                  void *cookie)
{
    char name[PROP_NAME_MAX];
    char value[PROP_VALUE_MAX];
    const prop_info *pi;
    unsigned n;

    for(n = 0; (pi = __system_property_find_nth(n)); n++) {
        __system_property_read(pi, name, value);
        propfn(name, value, cookie);
    }
    return 0;
}

void handle_property_set_fd(int fd)
{
    prop_msg msg;
    int s;
    int r;
    int res;
    struct ucred cr;
    struct sockaddr_un addr;
    socklen_t addr_size = sizeof(addr);
    socklen_t cr_size = sizeof(cr);

    if ((s = accept(fd, (struct sockaddr *) &addr, &addr_size)) < 0) {
        return;
    }

    /* Check socket options here */
    if (getsockopt(s, SOL_SOCKET, SO_PEERCRED, &cr, &cr_size) < 0) {
        close(s);
        ERROR("Unable to recieve socket options\n");
        return;
    }

    r = recv(s, &msg, sizeof(msg), 0);
    close(s);
    if(r != sizeof(prop_msg)) {
        ERROR("sys_prop: mis-match msg size recieved: %d expected: %d\n",
              r, sizeof(prop_msg));
        return;
    }

    switch(msg.cmd) {
    case PROP_MSG_SETPROP:
        msg.name[PROP_NAME_MAX-1] = 0;
        msg.value[PROP_VALUE_MAX-1] = 0;

        if(memcmp(msg.name,"ctl.",4) == 0) {
            if (check_control_perms(msg.value, cr.uid)) {
                handle_control_message((char*) msg.name + 4, (char*) msg.value);
            } else {
                ERROR("sys_prop: Unable to %s service ctl [%s] uid: %d pid:%d\n",
                        msg.name + 4, msg.value, cr.uid, cr.pid);
            }
        } else {
            if (check_perms(msg.name, cr.uid)) {
                property_set((char*) msg.name, (char*) msg.value);
            } else {
                ERROR("sys_prop: permission denied uid:%d  name:%s\n",
                      cr.uid, msg.name);
            }
        }
        break;

    default:
        break;
    }
}

void get_property_workspace(int *fd, int *sz)
{
    *fd = pa_workspace.fd;
    *sz = pa_workspace.size;
}

static void load_properties(char *data)
{
    char *key, *value, *eol, *sol, *tmp;

    sol = data;
    while((eol = strchr(sol, '\n'))) {
        key = sol;
        *eol++ = 0;
        sol = eol;

        value = strchr(key, '=');
        if(value == 0) continue;
        *value++ = 0;

        while(isspace(*key)) key++;
        if(*key == '#') continue;
        tmp = value - 2;
        while((tmp > key) && isspace(*tmp)) *tmp-- = 0;

        while(isspace(*value)) value++;
        tmp = eol - 2;
        while((tmp > value) && isspace(*tmp)) *tmp-- = 0;

        property_set(key, value);
    }
}

static void load_properties_from_file(const char *fn)
{
    char *data;
    unsigned sz;

    data = read_file(fn, &sz);

    if(data != 0) {
        load_properties(data);
        free(data);
    }
}

static void load_persistent_properties()
{
    DIR* dir = opendir(PERSISTENT_PROPERTY_DIR);
    struct dirent*  entry;
    char path[PATH_MAX];
    char value[PROP_VALUE_MAX];
    int fd, length;

    if (dir) {
        while ((entry = readdir(dir)) != NULL) {
            if (strncmp("persist.", entry->d_name, strlen("persist.")))
                continue;
#if HAVE_DIRENT_D_TYPE
            if (entry->d_type != DT_REG)
                continue;
#endif
            /* open the file and read the property value */
            snprintf(path, sizeof(path), "%s/%s", PERSISTENT_PROPERTY_DIR, entry->d_name);
            fd = open(path, O_RDONLY);
            if (fd >= 0) {
                length = read(fd, value, sizeof(value) - 1);
                if (length >= 0) {
                    value[length] = 0;
                    property_set(entry->d_name, value);
                } else {
                    ERROR("Unable to read persistent property file %s errno: %d\n", path, errno);
                }
                close(fd);
            } else {
                ERROR("Unable to open persistent property file %s errno: %d\n", path, errno);
            }
        }
        closedir(dir);
    } else {
        ERROR("Unable to open persistent property directory %s errno: %d\n", PERSISTENT_PROPERTY_DIR, errno);
    }
   
    persistent_properties_loaded = 1;
}

void property_init(void)
{
    init_property_area();
    load_properties_from_file(PROP_PATH_RAMDISK_DEFAULT);
}

int start_property_service(void)
{
    int fd;

    load_properties_from_file(PROP_PATH_SYSTEM_BUILD);
    load_properties_from_file(PROP_PATH_SYSTEM_DEFAULT);
    load_properties_from_file(PROP_PATH_LOCAL_OVERRIDE);
    /* Read persistent properties after all default values have been loaded. */
    load_persistent_properties();

    fd = create_socket(PROP_SERVICE_NAME, SOCK_STREAM, 0666, 0, 0);
    if(fd < 0) return -1;
    fcntl(fd, F_SETFD, FD_CLOEXEC);
    fcntl(fd, F_SETFL, O_NONBLOCK);

    listen(fd,;
    return fd;
}
分享到:
评论

相关推荐

    一个简单的开源Android工具类库

    &lt;uses-permission android:name="android.permission.WRITE_EXTERNAL_STORAGE" /&gt; &lt;uses-permission android:name="android.permission.READ_EXTERNAL_STORAGE" /&gt; &lt;uses-permission android:name="android....

    android将域名转成Ip的demo

    &lt;uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" /&gt; &lt;uses-permission android:name="android.permission.INTERNET" /&gt; ``` 总的来说,Android将域名转成IP的Demo是实现网络通信中的一个...

    android调用webservice 的对象序列化代码

    &lt;uses-permission android:name="android.permission.INTERNET" /&gt; ``` 以上就是一个基本的Android调用WebService并进行对象序列化的示例。在实际开发中,你可能需要处理更多复杂情况,如处理异常、优化性能、支持...

    android_power_code.zip_android_电量显示

    &lt;uses-permission android:name="android.permission.BATTERY_STATS" /&gt; ``` 此外,优化电量显示的性能也非常重要。频繁更新UI会消耗资源,因此建议根据实际情况调整更新频率,比如使用Handler或...

    Android :okhttp+Springmvc文件解析器实现android向服务器上传照片

    &lt;uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" /&gt; &lt;uses-permission android:name="android.permission.WRITE_EXTERNAL_STORAGE" /&gt; &lt;uses-permission android:name="android....

    基于安卓Android的电池监控源码.zip

    7. **权限声明**: 在AndroidManifest.xml中,需要添加 `&lt;uses-permission android:name="android.permission.BROADCAST_BOOT_COMPLETED" /&gt;` 和 `&lt;uses-permission android:name="android.permission.BATTERY_STATS...

    Android 节日短信回复助手源码.rar

    5. **权限管理**:由于涉及到读取和发送短信,应用需要在AndroidManifest.xml中声明相应的权限,如 `&lt;uses-permission android:name="android.permission.READ_SMS" /&gt;` 和 `&lt;uses-permission android:name="android...

    安卓读写GPIO,用于对硬件IO口进行读写

    &lt;uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" /&gt; &lt;uses-feature android:name="android.hardware.gpio" android:required="true" /&gt; ``` 2. **GPIO API使用**:Android提供了一个名为`...

    Android BLE实现对蓝牙的读写

    &lt;uses-permission android:name="android.permission.BLUETOOTH" /&gt; &lt;uses-permission android:name="android.permission.BLUETOOTH_ADMIN" /&gt; ``` 接下来,你需要使用`BluetoothManager`来获取`BluetoothAdapter`,...

    android 显示当前电量

    &lt;uses-permission android:name="android.permission.ACCESS_COARSE_LOCATION" /&gt; ``` 8. **释放BroadcastReceiver**: 当不再需要电池状态更新时,记得在Activity的onPause()或onDestroy()方法中注销...

    Android的ksoap调用实例

    &lt;uses-permission android:name="android.permission.INTERNET" /&gt; ``` 6. **HelloAndroidSoap项目**:根据提供的文件名"HelloAndroidSoap",这可能是一个简单的Android项目示例,包含了一个展示如何在Android应用...

    Android源码数字液晶时钟Demo

    4. **权限申请**:在Android系统中,访问系统时间可能需要申请相应的权限,如`&lt;uses-permission android:name="android.permission.ACCESS_FINE_LOCATION" /&gt;`,因为精确的时间信息可能来源于GPS或其他位置服务。...

    Android 小钢琴源码.zip

    7. **权限管理**:在AndroidManifest.xml中,可能包含了对录音和播放音频所需的权限声明,如`&lt;uses-permission android:name="android.permission.RECORD_AUDIO" /&gt;`。 8. **版本适配**:由于Android系统的碎片化,...

    android利用SOAP实现天气预报

    &lt;uses-permission android:name="android.permission.INTERNET" /&gt; ``` 2. 异步处理:由于网络操作可能会阻塞主线程,建议在AsyncTask或其他异步任务中执行SOAP请求。 3. 错误处理:要处理可能出现的网络错误、解析...

    android 调用 Webservice源码

    - 确保AndroidManifest.xml文件中添加了Internet权限:`&lt;uses-permission android:name="android.permission.INTERNET" /&gt;` - 针对不同环境,可能需要处理SSL证书问题,尤其是使用自签名证书的服务器。 - Web服务...

    android广告栏循环轮播图

    在AndroidManifest.xml中,需要声明`&lt;uses-permission android:name="android.permission.INTERNET" /&gt;`,否则应用将无法进行网络访问。 8. **适配器模式**: 为了方便管理和更新数据集,适配器模式可能被用来连接...

    Android代码-吹一吹效果源码.zip

    6. **权限管理**:由于涉及到麦克风使用,应用需要在AndroidManifest.xml中声明`&lt;uses-permission android:name="android.permission.RECORD_AUDIO" /&gt;`权限。 7. **UI设计**:吹一吹效果可能伴随着特定的UI动画,...

    android ksoap调用天气预报

    &lt;uses-permission android:name="android.permission.INTERNET" /&gt; ``` 此外,由于Android网络访问规则的变化,对于Android 9.0及以上版本,还需要在应用级别设置网络安全配置,或者在请求时开启网络权限: ```...

    在Android中调用C#写的WebService(附源代码).rar

    &lt;uses-permission android:name="android.permission.INTERNET" /&gt; ``` 在提供的压缩包中,`testWebServiceCall.rar`可能是示例代码,而`在Android中调用C#写的WebService(附源代码).txt`可能包含更详细的步骤或...

    android soap开发

    - 网络权限:确保AndroidManifest.xml文件中添加了`&lt;uses-permission android:name="android.permission.INTERNET" /&gt;`,以允许应用访问网络。 - 异步调用:由于网络操作可能会阻塞主线程,建议在AsyncTask或其他...

Global site tag (gtag.js) - Google Analytics