• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (C) 2007 The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *      http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #define TRACE_TAG ADB
18 
19 #include "sysdeps.h"
20 #include "adb.h"
21 
22 #include <ctype.h>
23 #include <errno.h>
24 #include <stdarg.h>
25 #include <stddef.h>
26 #include <stdint.h>
27 #include <stdio.h>
28 #include <stdlib.h>
29 #include <string.h>
30 #include <sys/time.h>
31 #include <time.h>
32 
33 #include <chrono>
34 #include <condition_variable>
35 #include <mutex>
36 #include <string>
37 #include <string_view>
38 #include <thread>
39 #include <vector>
40 
41 #include <android-base/errors.h>
42 #include <android-base/file.h>
43 #include <android-base/logging.h>
44 #include <android-base/macros.h>
45 #include <android-base/parsenetaddress.h>
46 #include <android-base/stringprintf.h>
47 #include <android-base/strings.h>
48 #include <build/version.h>
49 #include <platform_tools_version.h>
50 
51 #include "adb_auth.h"
52 #include "adb_io.h"
53 #include "adb_listeners.h"
54 #include "adb_mdns.h"
55 #include "adb_unique_fd.h"
56 #include "adb_utils.h"
57 #include "sysdeps/chrono.h"
58 #include "transport.h"
59 
60 #if !ADB_HOST
61 #include <sys/capability.h>
62 #include <sys/mount.h>
63 #include <android-base/properties.h>
64 using namespace std::chrono_literals;
65 
66 #include "daemon/logging.h"
67 #endif
68 
69 #if ADB_HOST
70 #include "client/usb.h"
71 #endif
72 
73 #if !ADB_HOST && defined(__ANDROID__)
74 #include "daemon/watchdog.h"
75 
76 static std::atomic<int> active_connections = 0;
77 
IncrementActiveConnections()78 static void IncrementActiveConnections() {
79     if (active_connections++ == 0) {
80         watchdog::Stop();
81     }
82 }
83 
DecrementActiveConnections()84 static void DecrementActiveConnections() {
85     if (--active_connections == 0) {
86         watchdog::Start();
87     }
88 }
89 
90 #endif
91 
adb_version()92 std::string adb_version() {
93     // Don't change the format of this --- it's parsed by ddmlib.
94     return android::base::StringPrintf(
95         "Android Debug Bridge version %d.%d.%d\n"
96         "Version %s-%s\n"
97         "Installed as %s\n",
98         ADB_VERSION_MAJOR, ADB_VERSION_MINOR, ADB_SERVER_VERSION,
99         PLATFORM_TOOLS_VERSION, android::build::GetBuildNumber().c_str(),
100         android::base::GetExecutablePath().c_str());
101 }
102 
calculate_apacket_checksum(const apacket * p)103 uint32_t calculate_apacket_checksum(const apacket* p) {
104     uint32_t sum = 0;
105     for (size_t i = 0; i < p->msg.data_length; ++i) {
106         sum += static_cast<uint8_t>(p->payload[i]);
107     }
108     return sum;
109 }
110 
get_apacket(void)111 apacket* get_apacket(void)
112 {
113     apacket* p = new apacket();
114     if (p == nullptr) {
115         LOG(FATAL) << "failed to allocate an apacket";
116     }
117 
118     memset(&p->msg, 0, sizeof(p->msg));
119     return p;
120 }
121 
put_apacket(apacket * p)122 void put_apacket(apacket *p)
123 {
124     delete p;
125 }
126 
handle_online(atransport * t)127 void handle_online(atransport *t)
128 {
129     D("adb: online");
130     t->online = 1;
131 #if ADB_HOST
132     t->SetConnectionEstablished(true);
133 #elif defined(__ANDROID__)
134     IncrementActiveConnections();
135 #endif
136 }
137 
handle_offline(atransport * t)138 void handle_offline(atransport *t)
139 {
140     if (t->GetConnectionState() == kCsOffline) {
141         LOG(INFO) << t->serial_name() << ": already offline";
142         return;
143     }
144 
145     LOG(INFO) << t->serial_name() << ": offline";
146 
147 #if !ADB_HOST && defined(__ANDROID__)
148     DecrementActiveConnections();
149 #endif
150 
151     t->SetConnectionState(kCsOffline);
152 
153     // Close the associated usb
154     t->online = 0;
155 
156     // This is necessary to avoid a race condition that occurred when a transport closes
157     // while a client socket is still active.
158     close_all_sockets(t);
159 
160     t->RunDisconnects();
161 }
162 
163 #if DEBUG_PACKETS
164 #define DUMPMAX 32
print_packet(const char * label,apacket * p)165 void print_packet(const char *label, apacket *p)
166 {
167     const char* tag;
168     unsigned count;
169 
170     switch(p->msg.command){
171     case A_SYNC: tag = "SYNC"; break;
172     case A_CNXN: tag = "CNXN" ; break;
173     case A_OPEN: tag = "OPEN"; break;
174     case A_OKAY: tag = "OKAY"; break;
175     case A_CLSE: tag = "CLSE"; break;
176     case A_WRTE: tag = "WRTE"; break;
177     case A_AUTH: tag = "AUTH"; break;
178     case A_STLS:
179         tag = "STLS";
180         break;
181     default: tag = "????"; break;
182     }
183 
184     fprintf(stderr, "%s: %s %08x %08x %04x \"",
185             label, tag, p->msg.arg0, p->msg.arg1, p->msg.data_length);
186     count = p->msg.data_length;
187     const char* x = p->payload.data();
188     if (count > DUMPMAX) {
189         count = DUMPMAX;
190         tag = "\n";
191     } else {
192         tag = "\"\n";
193     }
194     while (count-- > 0) {
195         if ((*x >= ' ') && (*x < 127)) {
196             fputc(*x, stderr);
197         } else {
198             fputc('.', stderr);
199         }
200         x++;
201     }
202     fputs(tag, stderr);
203 }
204 #endif
205 
send_ready(unsigned local,unsigned remote,atransport * t)206 static void send_ready(unsigned local, unsigned remote, atransport *t)
207 {
208     D("Calling send_ready");
209     apacket *p = get_apacket();
210     p->msg.command = A_OKAY;
211     p->msg.arg0 = local;
212     p->msg.arg1 = remote;
213     send_packet(p, t);
214 }
215 
send_close(unsigned local,unsigned remote,atransport * t)216 static void send_close(unsigned local, unsigned remote, atransport *t)
217 {
218     D("Calling send_close");
219     apacket *p = get_apacket();
220     p->msg.command = A_CLSE;
221     p->msg.arg0 = local;
222     p->msg.arg1 = remote;
223     send_packet(p, t);
224 }
225 
get_connection_string()226 std::string get_connection_string() {
227     std::vector<std::string> connection_properties;
228 
229 #if !ADB_HOST
230     static const char* cnxn_props[] = {
231         "ro.product.name",
232         "ro.product.model",
233         "ro.product.device",
234     };
235 
236     for (const auto& prop : cnxn_props) {
237         std::string value = std::string(prop) + "=" + android::base::GetProperty(prop, "");
238         connection_properties.push_back(value);
239     }
240 #endif
241 
242     connection_properties.push_back(android::base::StringPrintf(
243         "features=%s", FeatureSetToString(supported_features()).c_str()));
244 
245     return android::base::StringPrintf(
246         "%s::%s", adb_device_banner,
247         android::base::Join(connection_properties, ';').c_str());
248 }
249 
send_tls_request(atransport * t)250 void send_tls_request(atransport* t) {
251     D("Calling send_tls_request");
252     apacket* p = get_apacket();
253     p->msg.command = A_STLS;
254     p->msg.arg0 = A_STLS_VERSION;
255     p->msg.data_length = 0;
256     send_packet(p, t);
257 }
258 
send_connect(atransport * t)259 void send_connect(atransport* t) {
260     D("Calling send_connect");
261     apacket* cp = get_apacket();
262     cp->msg.command = A_CNXN;
263     // Send the max supported version, but because the transport is
264     // initialized to A_VERSION_MIN, this will be compatible with every
265     // device.
266     cp->msg.arg0 = A_VERSION;
267     cp->msg.arg1 = t->get_max_payload();
268 
269     std::string connection_str = get_connection_string();
270     // Connect and auth packets are limited to MAX_PAYLOAD_V1 because we don't
271     // yet know how much data the other size is willing to accept.
272     if (connection_str.length() > MAX_PAYLOAD_V1) {
273         LOG(FATAL) << "Connection banner is too long (length = "
274                    << connection_str.length() << ")";
275     }
276 
277     cp->payload.assign(connection_str.begin(), connection_str.end());
278     cp->msg.data_length = cp->payload.size();
279 
280     send_packet(cp, t);
281 }
282 
parse_banner(const std::string & banner,atransport * t)283 void parse_banner(const std::string& banner, atransport* t) {
284     D("parse_banner: %s", banner.c_str());
285 
286     // The format is something like:
287     // "device::ro.product.name=x;ro.product.model=y;ro.product.device=z;".
288     std::vector<std::string> pieces = android::base::Split(banner, ":");
289 
290     // Reset the features list or else if the server sends no features we may
291     // keep the existing feature set (http://b/24405971).
292     t->SetFeatures("");
293 
294     if (pieces.size() > 2) {
295         const std::string& props = pieces[2];
296         for (const auto& prop : android::base::Split(props, ";")) {
297             // The list of properties was traditionally ;-terminated rather than ;-separated.
298             if (prop.empty()) continue;
299 
300             std::vector<std::string> key_value = android::base::Split(prop, "=");
301             if (key_value.size() != 2) continue;
302 
303             const std::string& key = key_value[0];
304             const std::string& value = key_value[1];
305             if (key == "ro.product.name") {
306                 t->product = value;
307             } else if (key == "ro.product.model") {
308                 t->model = value;
309             } else if (key == "ro.product.device") {
310                 t->device = value;
311             } else if (key == "features") {
312                 t->SetFeatures(value);
313             }
314         }
315     }
316 
317     const std::string& type = pieces[0];
318     if (type == "bootloader") {
319         D("setting connection_state to kCsBootloader");
320         t->SetConnectionState(kCsBootloader);
321     } else if (type == "device") {
322         D("setting connection_state to kCsDevice");
323         t->SetConnectionState(kCsDevice);
324     } else if (type == "recovery") {
325         D("setting connection_state to kCsRecovery");
326         t->SetConnectionState(kCsRecovery);
327     } else if (type == "sideload") {
328         D("setting connection_state to kCsSideload");
329         t->SetConnectionState(kCsSideload);
330     } else if (type == "rescue") {
331         D("setting connection_state to kCsRescue");
332         t->SetConnectionState(kCsRescue);
333     } else {
334         D("setting connection_state to kCsHost");
335         t->SetConnectionState(kCsHost);
336     }
337 }
338 
handle_new_connection(atransport * t,apacket * p)339 static void handle_new_connection(atransport* t, apacket* p) {
340     handle_offline(t);
341 
342     t->update_version(p->msg.arg0, p->msg.arg1);
343     std::string banner(p->payload.begin(), p->payload.end());
344     parse_banner(banner, t);
345 
346 #if ADB_HOST
347     handle_online(t);
348 #else
349     ADB_LOG(Connection) << "received CNXN: version=" << p->msg.arg0 << ", maxdata = " << p->msg.arg1
350                         << ", banner = '" << banner << "'";
351 
352     if (t->use_tls) {
353         // We still handshake in TLS mode. If auth_required is disabled,
354         // we'll just not verify the client's certificate. This should be the
355         // first packet the client receives to indicate the new protocol.
356         send_tls_request(t);
357     } else if (!auth_required) {
358         LOG(INFO) << "authentication not required";
359         handle_online(t);
360         send_connect(t);
361     } else {
362         send_auth_request(t);
363     }
364 #endif
365 
366     update_transports();
367 }
368 
handle_packet(apacket * p,atransport * t)369 void handle_packet(apacket *p, atransport *t)
370 {
371     D("handle_packet() %c%c%c%c", ((char*) (&(p->msg.command)))[0],
372             ((char*) (&(p->msg.command)))[1],
373             ((char*) (&(p->msg.command)))[2],
374             ((char*) (&(p->msg.command)))[3]);
375     print_packet("recv", p);
376     CHECK_EQ(p->payload.size(), p->msg.data_length);
377 
378     switch(p->msg.command){
379     case A_CNXN:  // CONNECT(version, maxdata, "system-id-string")
380         handle_new_connection(t, p);
381         break;
382     case A_STLS:  // TLS(version, "")
383         t->use_tls = true;
384 #if ADB_HOST
385         send_tls_request(t);
386         adb_auth_tls_handshake(t);
387 #else
388         adbd_auth_tls_handshake(t);
389 #endif
390         break;
391 
392     case A_AUTH:
393         // All AUTH commands are ignored in TLS mode
394         if (t->use_tls) {
395             break;
396         }
397         switch (p->msg.arg0) {
398 #if ADB_HOST
399             case ADB_AUTH_TOKEN:
400                 if (t->GetConnectionState() != kCsAuthorizing) {
401                     t->SetConnectionState(kCsAuthorizing);
402                 }
403                 send_auth_response(p->payload.data(), p->msg.data_length, t);
404                 break;
405 #else
406             case ADB_AUTH_SIGNATURE: {
407                 // TODO: Switch to string_view.
408                 std::string signature(p->payload.begin(), p->payload.end());
409                 std::string auth_key;
410                 if (adbd_auth_verify(t->token, sizeof(t->token), signature, &auth_key)) {
411                     adbd_auth_verified(t);
412                     t->failed_auth_attempts = 0;
413                     t->auth_key = auth_key;
414                     adbd_notify_framework_connected_key(t);
415                 } else {
416                     if (t->failed_auth_attempts++ > 256) std::this_thread::sleep_for(1s);
417                     send_auth_request(t);
418                 }
419                 break;
420             }
421 
422             case ADB_AUTH_RSAPUBLICKEY:
423                 t->auth_key = std::string(p->payload.data());
424                 adbd_auth_confirm_key(t);
425                 break;
426 #endif
427             default:
428                 t->SetConnectionState(kCsOffline);
429                 handle_offline(t);
430                 break;
431         }
432         break;
433 
434     case A_OPEN: /* OPEN(local-id, 0, "destination") */
435         if (t->online && p->msg.arg0 != 0 && p->msg.arg1 == 0) {
436             std::string_view address(p->payload.begin(), p->payload.size());
437 
438             // Historically, we received service names as a char*, and stopped at the first NUL
439             // byte. The client sent strings with null termination, which post-string_view, start
440             // being interpreted as part of the string, unless we explicitly strip them.
441             address = StripTrailingNulls(address);
442 
443             asocket* s = create_local_service_socket(address, t);
444             if (s == nullptr) {
445                 send_close(0, p->msg.arg0, t);
446             } else {
447                 s->peer = create_remote_socket(p->msg.arg0, t);
448                 s->peer->peer = s;
449                 send_ready(s->id, s->peer->id, t);
450                 s->ready(s);
451             }
452         }
453         break;
454 
455     case A_OKAY: /* READY(local-id, remote-id, "") */
456         if (t->online && p->msg.arg0 != 0 && p->msg.arg1 != 0) {
457             asocket* s = find_local_socket(p->msg.arg1, 0);
458             if (s) {
459                 if(s->peer == nullptr) {
460                     /* On first READY message, create the connection. */
461                     s->peer = create_remote_socket(p->msg.arg0, t);
462                     s->peer->peer = s;
463                     s->ready(s);
464                 } else if (s->peer->id == p->msg.arg0) {
465                     /* Other READY messages must use the same local-id */
466                     s->ready(s);
467                 } else {
468                     D("Invalid A_OKAY(%d,%d), expected A_OKAY(%d,%d) on transport %s", p->msg.arg0,
469                       p->msg.arg1, s->peer->id, p->msg.arg1, t->serial.c_str());
470                 }
471             } else {
472                 // When receiving A_OKAY from device for A_OPEN request, the host server may
473                 // have closed the local socket because of client disconnection. Then we need
474                 // to send A_CLSE back to device to close the service on device.
475                 send_close(p->msg.arg1, p->msg.arg0, t);
476             }
477         }
478         break;
479 
480     case A_CLSE: /* CLOSE(local-id, remote-id, "") or CLOSE(0, remote-id, "") */
481         if (t->online && p->msg.arg1 != 0) {
482             asocket* s = find_local_socket(p->msg.arg1, p->msg.arg0);
483             if (s) {
484                 /* According to protocol.txt, p->msg.arg0 might be 0 to indicate
485                  * a failed OPEN only. However, due to a bug in previous ADB
486                  * versions, CLOSE(0, remote-id, "") was also used for normal
487                  * CLOSE() operations.
488                  *
489                  * This is bad because it means a compromised adbd could
490                  * send packets to close connections between the host and
491                  * other devices. To avoid this, only allow this if the local
492                  * socket has a peer on the same transport.
493                  */
494                 if (p->msg.arg0 == 0 && s->peer && s->peer->transport != t) {
495                     D("Invalid A_CLSE(0, %u) from transport %s, expected transport %s", p->msg.arg1,
496                       t->serial.c_str(), s->peer->transport->serial.c_str());
497                 } else {
498                     s->close(s);
499                 }
500             }
501         }
502         break;
503 
504     case A_WRTE: /* WRITE(local-id, remote-id, <data>) */
505         if (t->online && p->msg.arg0 != 0 && p->msg.arg1 != 0) {
506             asocket* s = find_local_socket(p->msg.arg1, p->msg.arg0);
507             if (s) {
508                 unsigned rid = p->msg.arg0;
509                 if (s->enqueue(s, std::move(p->payload)) == 0) {
510                     D("Enqueue the socket");
511                     send_ready(s->id, rid, t);
512                 }
513             }
514         }
515         break;
516 
517     default:
518         printf("handle_packet: what is %08x?!\n", p->msg.command);
519     }
520 
521     put_apacket(p);
522 }
523 
524 #if ADB_HOST
525 
526 #ifdef _WIN32
527 
528 // Try to make a handle non-inheritable and if there is an error, don't output
529 // any error info, but leave GetLastError() for the caller to read. This is
530 // convenient if the caller is expecting that this may fail and they'd like to
531 // ignore such a failure.
_try_make_handle_noninheritable(HANDLE h)532 static bool _try_make_handle_noninheritable(HANDLE h) {
533     if (h != INVALID_HANDLE_VALUE && h != NULL) {
534         return SetHandleInformation(h, HANDLE_FLAG_INHERIT, 0) ? true : false;
535     }
536 
537     return true;
538 }
539 
540 // Try to make a handle non-inheritable with the expectation that this should
541 // succeed, so if this fails, output error info.
_make_handle_noninheritable(HANDLE h)542 static bool _make_handle_noninheritable(HANDLE h) {
543     if (!_try_make_handle_noninheritable(h)) {
544         // Show the handle value to give us a clue in case we have problems
545         // with pseudo-handle values.
546         fprintf(stderr, "adb: cannot make handle 0x%p non-inheritable: %s\n", h,
547                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
548         return false;
549     }
550 
551     return true;
552 }
553 
554 // Create anonymous pipe, preventing inheritance of the read pipe and setting
555 // security of the write pipe to sa.
_create_anonymous_pipe(unique_handle * pipe_read_out,unique_handle * pipe_write_out,SECURITY_ATTRIBUTES * sa)556 static bool _create_anonymous_pipe(unique_handle* pipe_read_out,
557                                    unique_handle* pipe_write_out,
558                                    SECURITY_ATTRIBUTES* sa) {
559     HANDLE pipe_read_raw = NULL;
560     HANDLE pipe_write_raw = NULL;
561     if (!CreatePipe(&pipe_read_raw, &pipe_write_raw, sa, 0)) {
562         fprintf(stderr, "adb: CreatePipe failed: %s\n",
563                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
564         return false;
565     }
566 
567     unique_handle pipe_read(pipe_read_raw);
568     pipe_read_raw = NULL;
569     unique_handle pipe_write(pipe_write_raw);
570     pipe_write_raw = NULL;
571 
572     if (!_make_handle_noninheritable(pipe_read.get())) {
573         return false;
574     }
575 
576     *pipe_read_out = std::move(pipe_read);
577     *pipe_write_out = std::move(pipe_write);
578 
579     return true;
580 }
581 
582 // Read from a pipe (that we take ownership of) and write the result to stdout/stderr. Return on
583 // error or when the pipe is closed. Internally makes inheritable handles, so this should not be
584 // called if subprocesses may be started concurrently.
_redirect_pipe_thread(HANDLE h,DWORD nStdHandle)585 static unsigned _redirect_pipe_thread(HANDLE h, DWORD nStdHandle) {
586     // Take ownership of the HANDLE and close when we're done.
587     unique_handle   read_pipe(h);
588     const char*     output_name = nStdHandle == STD_OUTPUT_HANDLE ? "stdout" : "stderr";
589     const int       original_fd = fileno(nStdHandle == STD_OUTPUT_HANDLE ? stdout : stderr);
590     std::unique_ptr<FILE, decltype(&fclose)> stream(nullptr, fclose);
591 
592     if (original_fd == -1) {
593         fprintf(stderr, "adb: failed to get file descriptor for %s: %s\n", output_name,
594                 strerror(errno));
595         return EXIT_FAILURE;
596     }
597 
598     // If fileno() is -2, stdout/stderr is not associated with an output stream, so we should read,
599     // but don't write. Otherwise, make a FILE* identical to stdout/stderr except that it is in
600     // binary mode with no CR/LR translation since we're reading raw.
601     if (original_fd >= 0) {
602         // This internally makes a duplicate file handle that is inheritable, so callers should not
603         // call this function if subprocesses may be started concurrently.
604         const int fd = dup(original_fd);
605         if (fd == -1) {
606             fprintf(stderr, "adb: failed to duplicate file descriptor for %s: %s\n", output_name,
607                     strerror(errno));
608             return EXIT_FAILURE;
609         }
610 
611         // Note that although we call fdopen() below with a binary flag, it may not adhere to that
612         // flag, so we have to set the mode manually.
613         if (_setmode(fd, _O_BINARY) == -1) {
614             fprintf(stderr, "adb: failed to set binary mode for duplicate of %s: %s\n", output_name,
615                     strerror(errno));
616             unix_close(fd);
617             return EXIT_FAILURE;
618         }
619 
620         stream.reset(fdopen(fd, "wb"));
621         if (stream.get() == nullptr) {
622             fprintf(stderr, "adb: failed to open duplicate stream for %s: %s\n", output_name,
623                     strerror(errno));
624             unix_close(fd);
625             return EXIT_FAILURE;
626         }
627 
628         // Unbuffer the stream because it will be buffered by default and we want subprocess output
629         // to be shown immediately.
630         if (setvbuf(stream.get(), NULL, _IONBF, 0) == -1) {
631             fprintf(stderr, "adb: failed to unbuffer %s: %s\n", output_name, strerror(errno));
632             return EXIT_FAILURE;
633         }
634 
635         // fd will be closed when stream is closed.
636     }
637 
638     while (true) {
639         char    buf[64 * 1024];
640         DWORD   bytes_read = 0;
641         if (!ReadFile(read_pipe.get(), buf, sizeof(buf), &bytes_read, NULL)) {
642             const DWORD err = GetLastError();
643             // ERROR_BROKEN_PIPE is expected when the subprocess closes
644             // the other end of the pipe.
645             if (err == ERROR_BROKEN_PIPE) {
646                 return EXIT_SUCCESS;
647             } else {
648                 fprintf(stderr, "adb: failed to read from %s: %s\n", output_name,
649                         android::base::SystemErrorCodeToString(err).c_str());
650                 return EXIT_FAILURE;
651             }
652         }
653 
654         // Don't try to write if our stdout/stderr was not setup by the parent process.
655         if (stream) {
656             // fwrite() actually calls adb_fwrite() which can write UTF-8 to the console.
657             const size_t bytes_written = fwrite(buf, 1, bytes_read, stream.get());
658             if (bytes_written != bytes_read) {
659                 fprintf(stderr, "adb: error: only wrote %zu of %lu bytes to %s\n", bytes_written,
660                         bytes_read, output_name);
661                 return EXIT_FAILURE;
662             }
663         }
664     }
665 }
666 
_redirect_stdout_thread(HANDLE h)667 static unsigned __stdcall _redirect_stdout_thread(HANDLE h) {
668     adb_thread_setname("stdout redirect");
669     return _redirect_pipe_thread(h, STD_OUTPUT_HANDLE);
670 }
671 
_redirect_stderr_thread(HANDLE h)672 static unsigned __stdcall _redirect_stderr_thread(HANDLE h) {
673     adb_thread_setname("stderr redirect");
674     return _redirect_pipe_thread(h, STD_ERROR_HANDLE);
675 }
676 
677 #endif
678 
ReportServerStartupFailure(pid_t pid)679 static void ReportServerStartupFailure(pid_t pid) {
680     fprintf(stderr, "ADB server didn't ACK\n");
681     fprintf(stderr, "Full server startup log: %s\n", GetLogFilePath().c_str());
682     fprintf(stderr, "Server had pid: %d\n", pid);
683 
684     android::base::unique_fd fd(unix_open(GetLogFilePath(), O_RDONLY));
685     if (fd == -1) return;
686 
687     // Let's not show more than 128KiB of log...
688     unix_lseek(fd, -128 * 1024, SEEK_END);
689     std::string content;
690     if (!android::base::ReadFdToString(fd, &content)) return;
691 
692     std::string header = android::base::StringPrintf("--- adb starting (pid %d) ---", pid);
693     std::vector<std::string> lines = android::base::Split(content, "\n");
694     int i = lines.size() - 1;
695     while (i >= 0 && lines[i] != header) --i;
696     while (static_cast<size_t>(i) < lines.size()) fprintf(stderr, "%s\n", lines[i++].c_str());
697 }
698 
launch_server(const std::string & socket_spec)699 int launch_server(const std::string& socket_spec) {
700 #if defined(_WIN32)
701     /* we need to start the server in the background                    */
702     /* we create a PIPE that will be used to wait for the server's "OK" */
703     /* message since the pipe handles must be inheritable, we use a     */
704     /* security attribute                                               */
705     SECURITY_ATTRIBUTES   sa;
706     sa.nLength = sizeof(sa);
707     sa.lpSecurityDescriptor = NULL;
708     sa.bInheritHandle = TRUE;
709 
710     // Redirect stdin to Windows /dev/null. If we instead pass an original
711     // stdin/stdout/stderr handle and it is a console handle, when the adb
712     // server starts up, the C Runtime will see a console handle for a process
713     // that isn't connected to a console and it will configure
714     // stdin/stdout/stderr to be closed. At that point, freopen() could be used
715     // to reopen stderr/out, but it would take more massaging to fixup the file
716     // descriptor number that freopen() uses. It's simplest to avoid all of this
717     // complexity by just redirecting stdin to `nul' and then the C Runtime acts
718     // as expected.
719     unique_handle   nul_read(CreateFileW(L"nul", GENERIC_READ,
720             FILE_SHARE_READ | FILE_SHARE_WRITE, &sa, OPEN_EXISTING,
721             FILE_ATTRIBUTE_NORMAL, NULL));
722     if (nul_read.get() == INVALID_HANDLE_VALUE) {
723         fprintf(stderr, "adb: CreateFileW 'nul' failed: %s\n",
724                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
725         return -1;
726     }
727 
728     // Create pipes with non-inheritable read handle, inheritable write handle. We need to connect
729     // the subprocess to pipes instead of just letting the subprocess inherit our existing
730     // stdout/stderr handles because a DETACHED_PROCESS cannot write to a console that it is not
731     // attached to.
732     unique_handle   ack_read, ack_write;
733     if (!_create_anonymous_pipe(&ack_read, &ack_write, &sa)) {
734         return -1;
735     }
736     unique_handle   stdout_read, stdout_write;
737     if (!_create_anonymous_pipe(&stdout_read, &stdout_write, &sa)) {
738         return -1;
739     }
740     unique_handle   stderr_read, stderr_write;
741     if (!_create_anonymous_pipe(&stderr_read, &stderr_write, &sa)) {
742         return -1;
743     }
744 
745     /* Some programs want to launch an adb command and collect its output by
746      * calling CreateProcess with inheritable stdout/stderr handles, then
747      * using read() to get its output. When this happens, the stdout/stderr
748      * handles passed to the adb client process will also be inheritable.
749      * When starting the adb server here, care must be taken to reset them
750      * to non-inheritable.
751      * Otherwise, something bad happens: even if the adb command completes,
752      * the calling process is stuck while read()-ing from the stdout/stderr
753      * descriptors, because they're connected to corresponding handles in the
754      * adb server process (even if the latter never uses/writes to them).
755      * Note that even if we don't pass these handles in the STARTUPINFO struct,
756      * if they're marked inheritable, they're still inherited, requiring us to
757      * deal with this.
758      *
759      * If we're still having problems with inheriting random handles in the
760      * future, consider using PROC_THREAD_ATTRIBUTE_HANDLE_LIST to explicitly
761      * specify which handles should be inherited: http://blogs.msdn.com/b/oldnewthing/archive/2011/12/16/10248328.aspx
762      *
763      * Older versions of Windows return console pseudo-handles that cannot be
764      * made non-inheritable, so ignore those failures.
765      */
766     _try_make_handle_noninheritable(GetStdHandle(STD_INPUT_HANDLE));
767     _try_make_handle_noninheritable(GetStdHandle(STD_OUTPUT_HANDLE));
768     _try_make_handle_noninheritable(GetStdHandle(STD_ERROR_HANDLE));
769 
770     STARTUPINFOW    startup;
771     ZeroMemory( &startup, sizeof(startup) );
772     startup.cb = sizeof(startup);
773     startup.hStdInput  = nul_read.get();
774     startup.hStdOutput = stdout_write.get();
775     startup.hStdError  = stderr_write.get();
776     startup.dwFlags    = STARTF_USESTDHANDLES;
777 
778     // Verify that the pipe_write handle value can be passed on the command line
779     // as %d and that the rest of adb code can pass it around in an int.
780     const int ack_write_as_int = cast_handle_to_int(ack_write.get());
781     if (cast_int_to_handle(ack_write_as_int) != ack_write.get()) {
782         // If this fires, either handle values are larger than 32-bits or else
783         // there is a bug in our casting.
784         // https://msdn.microsoft.com/en-us/library/windows/desktop/aa384203%28v=vs.85%29.aspx
785         fprintf(stderr, "adb: cannot fit pipe handle value into 32-bits: 0x%p\n", ack_write.get());
786         return -1;
787     }
788 
789     // get path of current program
790     WCHAR       program_path[MAX_PATH];
791     const DWORD module_result = GetModuleFileNameW(NULL, program_path,
792                                                    arraysize(program_path));
793     if ((module_result >= arraysize(program_path)) || (module_result == 0)) {
794         // String truncation or some other error.
795         fprintf(stderr, "adb: cannot get executable path: %s\n",
796                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
797         return -1;
798     }
799 
800     WCHAR   args[64];
801     snwprintf(args, arraysize(args), L"adb -L %s fork-server server --reply-fd %d",
802               socket_spec.c_str(), ack_write_as_int);
803 
804     PROCESS_INFORMATION   pinfo;
805     ZeroMemory(&pinfo, sizeof(pinfo));
806 
807     if (!CreateProcessW(
808             program_path,                              /* program path  */
809             args,
810                                     /* the fork-server argument will set the
811                                        debug = 2 in the child           */
812             NULL,                   /* process handle is not inheritable */
813             NULL,                    /* thread handle is not inheritable */
814             TRUE,                          /* yes, inherit some handles */
815             DETACHED_PROCESS, /* the new process doesn't have a console */
816             NULL,                     /* use parent's environment block */
817             NULL,                    /* use parent's starting directory */
818             &startup,                 /* startup info, i.e. std handles */
819             &pinfo )) {
820         fprintf(stderr, "adb: CreateProcessW failed: %s\n",
821                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
822         return -1;
823     }
824 
825     unique_handle   process_handle(pinfo.hProcess);
826     pinfo.hProcess = NULL;
827 
828     // Close handles that we no longer need to complete the rest.
829     CloseHandle(pinfo.hThread);
830     pinfo.hThread = NULL;
831 
832     nul_read.reset();
833     ack_write.reset();
834     stdout_write.reset();
835     stderr_write.reset();
836 
837     // Start threads to read from subprocess stdout/stderr and write to ours to make subprocess
838     // errors easier to diagnose. Note that the threads internally create inheritable handles, but
839     // that is ok because we've already spawned the subprocess.
840 
841     // In the past, reading from a pipe before the child process's C Runtime
842     // started up and called GetFileType() caused a hang: http://blogs.msdn.com/b/oldnewthing/archive/2011/12/02/10243553.aspx#10244216
843     // This is reportedly fixed in Windows Vista: https://support.microsoft.com/en-us/kb/2009703
844     // I was unable to reproduce the problem on Windows XP. It sounds like a
845     // Windows Update may have fixed this: https://www.duckware.com/tech/peeknamedpipe.html
846     unique_handle   stdout_thread(reinterpret_cast<HANDLE>(
847             _beginthreadex(NULL, 0, _redirect_stdout_thread, stdout_read.get(),
848                            0, NULL)));
849     if (stdout_thread.get() == nullptr) {
850         fprintf(stderr, "adb: cannot create thread: %s\n", strerror(errno));
851         return -1;
852     }
853     stdout_read.release();  // Transfer ownership to new thread
854 
855     unique_handle   stderr_thread(reinterpret_cast<HANDLE>(
856             _beginthreadex(NULL, 0, _redirect_stderr_thread, stderr_read.get(),
857                            0, NULL)));
858     if (stderr_thread.get() == nullptr) {
859         fprintf(stderr, "adb: cannot create thread: %s\n", strerror(errno));
860         return -1;
861     }
862     stderr_read.release();  // Transfer ownership to new thread
863 
864     bool    got_ack = false;
865 
866     // Wait for the "OK\n" message, for the pipe to be closed, or other error.
867     {
868         char    temp[3];
869         DWORD   count = 0;
870 
871         if (ReadFile(ack_read.get(), temp, sizeof(temp), &count, NULL)) {
872             const CHAR  expected[] = "OK\n";
873             const DWORD expected_length = arraysize(expected) - 1;
874             if (count == expected_length &&
875                 memcmp(temp, expected, expected_length) == 0) {
876                 got_ack = true;
877             } else {
878                 ReportServerStartupFailure(pinfo.dwProcessId);
879                 return -1;
880             }
881         } else {
882             const DWORD err = GetLastError();
883             // If the ACK was not written and the process exited, GetLastError()
884             // is probably ERROR_BROKEN_PIPE, in which case that info is not
885             // useful to the user.
886             fprintf(stderr, "could not read ok from ADB Server%s\n",
887                     err == ERROR_BROKEN_PIPE ? "" :
888                     android::base::StringPrintf(": %s",
889                             android::base::SystemErrorCodeToString(err).c_str()).c_str());
890         }
891     }
892 
893     // Always try to wait a bit for threads reading stdout/stderr to finish.
894     // If the process started ok, it should close the pipes causing the threads
895     // to finish. If the process had an error, it should exit, also causing
896     // the pipes to be closed. In that case we want to read all of the output
897     // and write it out so that the user can diagnose failures.
898     const DWORD     thread_timeout_ms = 15 * 1000;
899     const HANDLE    threads[] = { stdout_thread.get(), stderr_thread.get() };
900     const DWORD     wait_result = WaitForMultipleObjects(arraysize(threads),
901             threads, TRUE, thread_timeout_ms);
902     if (wait_result == WAIT_TIMEOUT) {
903         // Threads did not finish after waiting a little while. Perhaps the
904         // server didn't close pipes, or it is hung.
905         fprintf(stderr, "adb: timed out waiting for threads to finish reading from ADB server\n");
906         // Process handles are signaled when the process exits, so if we wait
907         // on the handle for 0 seconds and it returns 'timeout', that means that
908         // the process is still running.
909         if (WaitForSingleObject(process_handle.get(), 0) == WAIT_TIMEOUT) {
910             // We could TerminateProcess(), but that seems somewhat presumptive.
911             fprintf(stderr, "adb: server is running with process id %lu\n", pinfo.dwProcessId);
912         }
913         return -1;
914     }
915 
916     if (wait_result != WAIT_OBJECT_0) {
917         fprintf(stderr, "adb: unexpected result waiting for threads: %lu: %s\n", wait_result,
918                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
919         return -1;
920     }
921 
922     // For now ignore the thread exit codes and assume they worked properly.
923 
924     if (!got_ack) {
925         return -1;
926     }
927 #else /* !defined(_WIN32) */
928     // set up a pipe so the child can tell us when it is ready.
929     unique_fd pipe_read, pipe_write;
930     if (!Pipe(&pipe_read, &pipe_write)) {
931         fprintf(stderr, "pipe failed in launch_server, errno: %d\n", errno);
932         return -1;
933     }
934 
935     std::string path = android::base::GetExecutablePath();
936 
937     pid_t pid = fork();
938     if (pid < 0) return -1;
939 
940     if (pid == 0) {
941         // child side of the fork
942         pipe_read.reset();
943 
944         // android::base::Pipe unconditionally opens the pipe with O_CLOEXEC.
945         // Undo this manually.
946         fcntl(pipe_write.get(), F_SETFD, 0);
947 
948         char reply_fd[30];
949         snprintf(reply_fd, sizeof(reply_fd), "%d", pipe_write.get());
950         // child process
951         int result = execl(path.c_str(), "adb", "-L", socket_spec.c_str(), "fork-server", "server",
952                            "--reply-fd", reply_fd, NULL);
953         // this should not return
954         fprintf(stderr, "adb: execl returned %d: %s\n", result, strerror(errno));
955     } else {
956         // parent side of the fork
957         char temp[3] = {};
958         // wait for the "OK\n" message
959         pipe_write.reset();
960         int ret = adb_read(pipe_read.get(), temp, 3);
961         int saved_errno = errno;
962         pipe_read.reset();
963         if (ret < 0) {
964             fprintf(stderr, "could not read ok from ADB Server, errno = %d\n", saved_errno);
965             return -1;
966         }
967         if (ret != 3 || temp[0] != 'O' || temp[1] != 'K' || temp[2] != '\n') {
968             ReportServerStartupFailure(pid);
969             return -1;
970         }
971     }
972 #endif /* !defined(_WIN32) */
973     return 0;
974 }
975 #endif /* ADB_HOST */
976 
handle_forward_request(const char * service,atransport * transport,int reply_fd)977 bool handle_forward_request(const char* service, atransport* transport, int reply_fd) {
978     return handle_forward_request(service, [transport](std::string*) { return transport; },
979                                   reply_fd);
980 }
981 
982 // Try to handle a network forwarding request.
handle_forward_request(const char * service,std::function<atransport * (std::string * error)> transport_acquirer,int reply_fd)983 bool handle_forward_request(const char* service,
984                             std::function<atransport*(std::string* error)> transport_acquirer,
985                             int reply_fd) {
986     if (!strcmp(service, "list-forward")) {
987         // Create the list of forward redirections.
988         std::string listeners = format_listeners();
989 #if ADB_HOST
990         SendOkay(reply_fd);
991 #endif
992         SendProtocolString(reply_fd, listeners);
993         return true;
994     }
995 
996     if (!strcmp(service, "killforward-all")) {
997         remove_all_listeners();
998 #if ADB_HOST
999         /* On the host: 1st OKAY is connect, 2nd OKAY is status */
1000         SendOkay(reply_fd);
1001 #endif
1002         SendOkay(reply_fd);
1003         return true;
1004     }
1005 
1006     if (!strncmp(service, "forward:", 8) || !strncmp(service, "killforward:", 12)) {
1007         // killforward:local
1008         // forward:(norebind:)?local;remote
1009         std::string error;
1010         atransport* transport = transport_acquirer(&error);
1011         if (!transport) {
1012             SendFail(reply_fd, error);
1013             return true;
1014         }
1015 
1016         bool kill_forward = false;
1017         bool no_rebind = false;
1018         if (android::base::StartsWith(service, "killforward:")) {
1019             kill_forward = true;
1020             service += 12;
1021         } else {
1022             service += 8;   // skip past "forward:"
1023             if (android::base::StartsWith(service, "norebind:")) {
1024                 no_rebind = true;
1025                 service += 9;
1026             }
1027         }
1028 
1029         std::vector<std::string> pieces = android::base::Split(service, ";");
1030 
1031         if (kill_forward) {
1032             // Check killforward: parameter format: '<local>'
1033             if (pieces.size() != 1 || pieces[0].empty()) {
1034                 SendFail(reply_fd, android::base::StringPrintf("bad killforward: %s", service));
1035                 return true;
1036             }
1037         } else {
1038             // Check forward: parameter format: '<local>;<remote>'
1039             if (pieces.size() != 2 || pieces[0].empty() || pieces[1].empty() || pieces[1][0] == '*') {
1040                 SendFail(reply_fd, android::base::StringPrintf("bad forward: %s", service));
1041                 return true;
1042             }
1043         }
1044 
1045         InstallStatus r;
1046         int resolved_tcp_port = 0;
1047         if (kill_forward) {
1048             r = remove_listener(pieces[0].c_str(), transport);
1049         } else {
1050             int flags = 0;
1051             if (no_rebind) {
1052                 flags |= INSTALL_LISTENER_NO_REBIND;
1053             }
1054             r = install_listener(pieces[0], pieces[1].c_str(), transport, flags, &resolved_tcp_port,
1055                                  &error);
1056         }
1057         if (r == INSTALL_STATUS_OK) {
1058 #if ADB_HOST
1059             // On the host: 1st OKAY is connect, 2nd OKAY is status.
1060             SendOkay(reply_fd);
1061 #endif
1062             SendOkay(reply_fd);
1063 
1064             // If a TCP port was resolved, send the actual port number back.
1065             if (resolved_tcp_port != 0) {
1066                 SendProtocolString(reply_fd, android::base::StringPrintf("%d", resolved_tcp_port));
1067             }
1068 
1069             return true;
1070         }
1071 
1072         std::string message;
1073         switch (r) {
1074           case INSTALL_STATUS_OK: message = "success (!)"; break;
1075           case INSTALL_STATUS_INTERNAL_ERROR: message = "internal error"; break;
1076           case INSTALL_STATUS_CANNOT_BIND:
1077             message = android::base::StringPrintf("cannot bind listener: %s",
1078                                                   error.c_str());
1079             break;
1080           case INSTALL_STATUS_CANNOT_REBIND:
1081             message = android::base::StringPrintf("cannot rebind existing socket");
1082             break;
1083           case INSTALL_STATUS_LISTENER_NOT_FOUND:
1084             message = android::base::StringPrintf("listener '%s' not found", service);
1085             break;
1086         }
1087         SendFail(reply_fd, message);
1088         return true;
1089     }
1090 
1091     return false;
1092 }
1093 
1094 #if ADB_HOST
SendOkay(int fd,const std::string & s)1095 static int SendOkay(int fd, const std::string& s) {
1096     SendOkay(fd);
1097     SendProtocolString(fd, s);
1098     return 0;
1099 }
1100 
1101 static bool g_reject_kill_server = false;
adb_set_reject_kill_server(bool value)1102 void adb_set_reject_kill_server(bool value) {
1103     g_reject_kill_server = value;
1104 }
1105 
handle_mdns_request(std::string_view service,int reply_fd)1106 static bool handle_mdns_request(std::string_view service, int reply_fd) {
1107     if (!android::base::ConsumePrefix(&service, "mdns:")) {
1108         return false;
1109     }
1110 
1111     if (service == "check") {
1112         std::string check = mdns_check();
1113         SendOkay(reply_fd, check);
1114         return true;
1115     }
1116     if (service == "services") {
1117         std::string services_list = mdns_list_discovered_services();
1118         SendOkay(reply_fd, services_list);
1119         return true;
1120     }
1121 
1122     return false;
1123 }
1124 
handle_host_request(std::string_view service,TransportType type,const char * serial,TransportId transport_id,int reply_fd,asocket * s)1125 HostRequestResult handle_host_request(std::string_view service, TransportType type,
1126                                       const char* serial, TransportId transport_id, int reply_fd,
1127                                       asocket* s) {
1128     if (service == "kill") {
1129         if (g_reject_kill_server) {
1130             LOG(WARNING) << "adb server ignoring kill-server";
1131             SendFail(reply_fd, "kill-server rejected by remote server");
1132         } else {
1133             fprintf(stderr, "adb server killed by remote request\n");
1134             SendOkay(reply_fd);
1135 
1136             // Rely on process exit to close the socket for us.
1137             exit(0);
1138         }
1139     }
1140 
1141     LOG(DEBUG) << "handle_host_request(" << service << ")";
1142 
1143     // Transport selection:
1144     if (service.starts_with("transport") || service.starts_with("tport:")) {
1145         TransportType type = kTransportAny;
1146 
1147         std::string serial_storage;
1148         bool legacy = true;
1149 
1150         // New transport selection protocol:
1151         // This is essentially identical to the previous version, except it returns the selected
1152         // transport id to the caller as well.
1153         if (android::base::ConsumePrefix(&service, "tport:")) {
1154             legacy = false;
1155             if (android::base::ConsumePrefix(&service, "serial:")) {
1156                 serial_storage = service;
1157                 serial = serial_storage.c_str();
1158             } else if (service == "usb") {
1159                 type = kTransportUsb;
1160             } else if (service == "local") {
1161                 type = kTransportLocal;
1162             } else if (service == "any") {
1163                 type = kTransportAny;
1164             }
1165 
1166             // Selection by id is unimplemented, since you obviously already know the transport id
1167             // you're connecting to.
1168         } else {
1169             if (android::base::ConsumePrefix(&service, "transport-id:")) {
1170                 if (!ParseUint(&transport_id, service)) {
1171                     SendFail(reply_fd, "invalid transport id");
1172                     return HostRequestResult::Handled;
1173                 }
1174             } else if (service == "transport-usb") {
1175                 type = kTransportUsb;
1176             } else if (service == "transport-local") {
1177                 type = kTransportLocal;
1178             } else if (service == "transport-any") {
1179                 type = kTransportAny;
1180             } else if (android::base::ConsumePrefix(&service, "transport:")) {
1181                 serial_storage = service;
1182                 serial = serial_storage.c_str();
1183             }
1184         }
1185 
1186         std::string error;
1187         atransport* t = acquire_one_transport(type, serial, transport_id, nullptr, &error);
1188         if (t != nullptr) {
1189             s->transport = t;
1190             SendOkay(reply_fd);
1191 
1192             if (!legacy) {
1193                 // Nothing we can do if this fails.
1194                 WriteFdExactly(reply_fd, &t->id, sizeof(t->id));
1195             }
1196 
1197             return HostRequestResult::SwitchedTransport;
1198         } else {
1199             SendFail(reply_fd, error);
1200             return HostRequestResult::Handled;
1201         }
1202     }
1203 
1204     // return a list of all connected devices
1205     if (service == "devices" || service == "devices-l") {
1206         bool long_listing = service == "devices-l";
1207         D("Getting device list...");
1208         std::string device_list = list_transports(long_listing);
1209         D("Sending device list...");
1210         SendOkay(reply_fd, device_list);
1211         return HostRequestResult::Handled;
1212     }
1213 
1214     if (service == "reconnect-offline") {
1215         std::string response;
1216         close_usb_devices([&response](const atransport* transport) {
1217             if (!ConnectionStateIsOnline(transport->GetConnectionState())) {
1218                 response += "reconnecting " + transport->serial_name() + "\n";
1219                 return true;
1220             }
1221             return false;
1222         }, true);
1223         if (!response.empty()) {
1224             response.resize(response.size() - 1);
1225         }
1226         SendOkay(reply_fd, response);
1227         return HostRequestResult::Handled;
1228     }
1229 
1230     if (service == "features") {
1231         std::string error;
1232         atransport* t =
1233                 s->transport ? s->transport
1234                              : acquire_one_transport(type, serial, transport_id, nullptr, &error);
1235         if (t != nullptr) {
1236             SendOkay(reply_fd, FeatureSetToString(t->features()));
1237         } else {
1238             SendFail(reply_fd, error);
1239         }
1240         return HostRequestResult::Handled;
1241     }
1242 
1243     if (service == "host-features") {
1244         FeatureSet features = supported_features();
1245         // Abuse features to report libusb status.
1246         if (should_use_libusb()) {
1247             features.emplace_back(kFeatureLibusb);
1248         }
1249         features.emplace_back(kFeaturePushSync);
1250         SendOkay(reply_fd, FeatureSetToString(features));
1251         return HostRequestResult::Handled;
1252     }
1253 
1254     // remove TCP transport
1255     if (service.starts_with("disconnect:")) {
1256         std::string address(service.substr(11));
1257         if (address.empty()) {
1258             kick_all_tcp_devices();
1259             SendOkay(reply_fd, "disconnected everything");
1260             return HostRequestResult::Handled;
1261         }
1262 
1263         // Mdns instance named device
1264         atransport* t = find_transport(address.c_str());
1265         if (t != nullptr) {
1266             kick_transport(t);
1267             SendOkay(reply_fd, android::base::StringPrintf("disconnected %s", address.c_str()));
1268             return HostRequestResult::Handled;
1269         }
1270 
1271         std::string serial;
1272         std::string host;
1273         int port = DEFAULT_ADB_LOCAL_TRANSPORT_PORT;
1274         std::string error;
1275         if (address.starts_with("vsock:") || address.starts_with("localfilesystem:")) {
1276             serial = address;
1277         } else if (!android::base::ParseNetAddress(address, &host, &port, &serial, &error)) {
1278             SendFail(reply_fd, android::base::StringPrintf("couldn't parse '%s': %s",
1279                                                            address.c_str(), error.c_str()));
1280             return HostRequestResult::Handled;
1281         }
1282         t = find_transport(serial.c_str());
1283         if (t == nullptr) {
1284             SendFail(reply_fd, android::base::StringPrintf("no such device '%s'", serial.c_str()));
1285             return HostRequestResult::Handled;
1286         }
1287         kick_transport(t);
1288         SendOkay(reply_fd, android::base::StringPrintf("disconnected %s", address.c_str()));
1289         return HostRequestResult::Handled;
1290     }
1291 
1292     // Returns our value for ADB_SERVER_VERSION.
1293     if (service == "version") {
1294         SendOkay(reply_fd, android::base::StringPrintf("%04x", ADB_SERVER_VERSION));
1295         return HostRequestResult::Handled;
1296     }
1297 
1298     // These always report "unknown" rather than the actual error, for scripts.
1299     if (service == "get-serialno") {
1300         std::string error;
1301         atransport* t =
1302                 s->transport ? s->transport
1303                              : acquire_one_transport(type, serial, transport_id, nullptr, &error);
1304         if (t) {
1305             SendOkay(reply_fd, !t->serial.empty() ? t->serial : "unknown");
1306         } else {
1307             SendFail(reply_fd, error);
1308         }
1309         return HostRequestResult::Handled;
1310     }
1311     if (service == "get-devpath") {
1312         std::string error;
1313         atransport* t =
1314                 s->transport ? s->transport
1315                              : acquire_one_transport(type, serial, transport_id, nullptr, &error);
1316         if (t) {
1317             SendOkay(reply_fd, !t->devpath.empty() ? t->devpath : "unknown");
1318         } else {
1319             SendFail(reply_fd, error);
1320         }
1321         return HostRequestResult::Handled;
1322     }
1323     if (service == "get-state") {
1324         std::string error;
1325         atransport* t =
1326                 s->transport ? s->transport
1327                              : acquire_one_transport(type, serial, transport_id, nullptr, &error);
1328         if (t) {
1329             SendOkay(reply_fd, t->connection_state_name());
1330         } else {
1331             SendFail(reply_fd, error);
1332         }
1333         return HostRequestResult::Handled;
1334     }
1335 
1336     // Indicates a new emulator instance has started.
1337     if (android::base::ConsumePrefix(&service, "emulator:")) {
1338         unsigned int port;
1339         if (!ParseUint(&port, service)) {
1340           LOG(ERROR) << "received invalid port for emulator: " << service;
1341         } else {
1342           local_connect(port);
1343         }
1344 
1345         /* we don't even need to send a reply */
1346         return HostRequestResult::Handled;
1347     }
1348 
1349     if (service == "reconnect") {
1350         std::string response;
1351         atransport* t = s->transport ? s->transport
1352                                      : acquire_one_transport(type, serial, transport_id, nullptr,
1353                                                              &response, true);
1354         if (t != nullptr) {
1355             kick_transport(t, true);
1356             response =
1357                     "reconnecting " + t->serial_name() + " [" + t->connection_state_name() + "]\n";
1358         }
1359         SendOkay(reply_fd, response);
1360         return HostRequestResult::Handled;
1361     }
1362 
1363     // TODO: Switch handle_forward_request to string_view.
1364     std::string service_str(service);
1365     auto transport_acquirer = [=](std::string* error) {
1366         if (s->transport) {
1367             return s->transport;
1368         } else {
1369             std::string error;
1370             return acquire_one_transport(type, serial, transport_id, nullptr, &error);
1371         }
1372     };
1373     if (handle_forward_request(service_str.c_str(), transport_acquirer, reply_fd)) {
1374         return HostRequestResult::Handled;
1375     }
1376 
1377     if (handle_mdns_request(service, reply_fd)) {
1378         return HostRequestResult::Handled;
1379     }
1380 
1381     return HostRequestResult::Unhandled;
1382 }
1383 
1384 static auto& init_mutex = *new std::mutex();
1385 static auto& init_cv = *new std::condition_variable();
1386 static bool device_scan_complete = false;
1387 static bool transports_ready = false;
1388 
update_transport_status()1389 void update_transport_status() {
1390     bool result = iterate_transports([](const atransport* t) {
1391         if (t->type == kTransportUsb && t->online != 1) {
1392             return false;
1393         }
1394         return true;
1395     });
1396 
1397     bool ready;
1398     {
1399         std::lock_guard<std::mutex> lock(init_mutex);
1400         transports_ready = result;
1401         ready = transports_ready && device_scan_complete;
1402     }
1403 
1404     if (ready) {
1405         init_cv.notify_all();
1406     }
1407 }
1408 
adb_notify_device_scan_complete()1409 void adb_notify_device_scan_complete() {
1410     {
1411         std::lock_guard<std::mutex> lock(init_mutex);
1412         if (device_scan_complete) {
1413             return;
1414         }
1415 
1416         device_scan_complete = true;
1417     }
1418 
1419     update_transport_status();
1420 }
1421 
adb_wait_for_device_initialization()1422 void adb_wait_for_device_initialization() {
1423     std::unique_lock<std::mutex> lock(init_mutex);
1424     init_cv.wait_for(lock, 3s, []() { return device_scan_complete && transports_ready; });
1425 }
1426 
1427 #endif  // ADB_HOST
1428