1 //
2 // Copyright (C) 2012 The Android Open Source Project
3 //
4 // Licensed under the Apache License, Version 2.0 (the "License");
5 // you may not use this file except in compliance with the License.
6 // You may obtain a copy of the License at
7 //
8 // http://www.apache.org/licenses/LICENSE-2.0
9 //
10 // Unless required by applicable law or agreed to in writing, software
11 // distributed under the License is distributed on an "AS IS" BASIS,
12 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 // See the License for the specific language governing permissions and
14 // limitations under the License.
15 //
16
17 #include "update_engine/common/utils.h"
18
19 #include <stdint.h>
20
21 #include <dirent.h>
22 #include <elf.h>
23 #include <endian.h>
24 #include <errno.h>
25 #include <fcntl.h>
26 #include <stdio.h>
27 #include <stdlib.h>
28 #include <string.h>
29 #include <sys/mount.h>
30 #include <sys/resource.h>
31 #include <sys/sendfile.h>
32 #include <sys/stat.h>
33 #include <sys/types.h>
34 #include <time.h>
35 #include <unistd.h>
36
37 #include <algorithm>
38 #include <utility>
39 #include <vector>
40
41 #include <android-base/strings.h>
42 #include <base/callback.h>
43 #include <base/files/file_path.h>
44 #include <base/files/file_util.h>
45 #include <base/files/scoped_file.h>
46 #include <base/format_macros.h>
47 #include <base/location.h>
48 #include <base/logging.h>
49 #include <base/posix/eintr_wrapper.h>
50 #include <base/rand_util.h>
51 #include <base/strings/string_number_conversions.h>
52 #include <base/strings/string_split.h>
53 #include <base/strings/string_util.h>
54 #include <base/strings/stringprintf.h>
55 #include <brillo/data_encoding.h>
56
57 #include "update_engine/common/constants.h"
58 #include "update_engine/common/platform_constants.h"
59 #include "update_engine/common/prefs_interface.h"
60 #include "update_engine/common/subprocess.h"
61 #include "update_engine/payload_consumer/file_descriptor.h"
62
63 using base::Time;
64 using base::TimeDelta;
65 using std::min;
66 using std::numeric_limits;
67 using std::string;
68 using std::vector;
69
70 namespace chromeos_update_engine {
71
72 namespace {
73
74 // The following constants control how UnmountFilesystem should retry if
75 // umount() fails with an errno EBUSY, i.e. retry 5 times over the course of
76 // one second.
77 const int kUnmountMaxNumOfRetries = 5;
78 const int kUnmountRetryIntervalInMicroseconds = 200 * 1000; // 200 ms
79
80 // Number of bytes to read from a file to attempt to detect its contents. Used
81 // in GetFileFormat.
82 const int kGetFileFormatMaxHeaderSize = 32;
83
84 // The path to the kernel's boot_id.
85 const char kBootIdPath[] = "/proc/sys/kernel/random/boot_id";
86
87 // If |path| is absolute, or explicit relative to the current working directory,
88 // leaves it as is. Otherwise, uses the system's temp directory, as defined by
89 // base::GetTempDir() and prepends it to |path|. On success stores the full
90 // temporary path in |template_path| and returns true.
GetTempName(const string & path,base::FilePath * template_path)91 bool GetTempName(const string& path, base::FilePath* template_path) {
92 if (path[0] == '/' ||
93 base::StartsWith(path, "./", base::CompareCase::SENSITIVE) ||
94 base::StartsWith(path, "../", base::CompareCase::SENSITIVE)) {
95 *template_path = base::FilePath(path);
96 return true;
97 }
98
99 base::FilePath temp_dir;
100 #ifdef __ANDROID__
101 temp_dir = base::FilePath(constants::kNonVolatileDirectory).Append("tmp");
102 #else
103 TEST_AND_RETURN_FALSE(base::GetTempDir(&temp_dir));
104 #endif // __ANDROID__
105 if (!base::PathExists(temp_dir))
106 TEST_AND_RETURN_FALSE(base::CreateDirectory(temp_dir));
107 *template_path = temp_dir.Append(path);
108 return true;
109 }
110
111 } // namespace
112
113 namespace utils {
114
WriteFile(const char * path,const void * data,size_t data_len)115 bool WriteFile(const char* path, const void* data, size_t data_len) {
116 int fd = HANDLE_EINTR(open(path, O_WRONLY | O_CREAT | O_TRUNC, 0600));
117 TEST_AND_RETURN_FALSE_ERRNO(fd >= 0);
118 ScopedFdCloser fd_closer(&fd);
119 return WriteAll(fd, data, data_len);
120 }
121
ReadAll(int fd,void * buf,size_t count,size_t * out_bytes_read,bool * eof)122 bool ReadAll(
123 int fd, void* buf, size_t count, size_t* out_bytes_read, bool* eof) {
124 char* c_buf = static_cast<char*>(buf);
125 size_t bytes_read = 0;
126 *eof = false;
127 while (bytes_read < count) {
128 ssize_t rc = HANDLE_EINTR(read(fd, c_buf + bytes_read, count - bytes_read));
129 if (rc < 0) {
130 // EAGAIN and EWOULDBLOCK are normal return values when there's no more
131 // input and we are in non-blocking mode.
132 if (errno != EWOULDBLOCK && errno != EAGAIN) {
133 PLOG(ERROR) << "Error reading fd " << fd;
134 *out_bytes_read = bytes_read;
135 return false;
136 }
137 break;
138 } else if (rc == 0) {
139 // A value of 0 means that we reached EOF and there is nothing else to
140 // read from this fd.
141 *eof = true;
142 break;
143 } else {
144 bytes_read += rc;
145 }
146 }
147 *out_bytes_read = bytes_read;
148 return true;
149 }
150
WriteAll(int fd,const void * buf,size_t count)151 bool WriteAll(int fd, const void* buf, size_t count) {
152 const char* c_buf = static_cast<const char*>(buf);
153 ssize_t bytes_written = 0;
154 while (bytes_written < static_cast<ssize_t>(count)) {
155 ssize_t rc = write(fd, c_buf + bytes_written, count - bytes_written);
156 TEST_AND_RETURN_FALSE_ERRNO(rc >= 0);
157 bytes_written += rc;
158 }
159 return true;
160 }
161
PWriteAll(int fd,const void * buf,size_t count,off_t offset)162 bool PWriteAll(int fd, const void* buf, size_t count, off_t offset) {
163 const char* c_buf = static_cast<const char*>(buf);
164 size_t bytes_written = 0;
165 int num_attempts = 0;
166 while (bytes_written < count) {
167 num_attempts++;
168 ssize_t rc = pwrite(fd,
169 c_buf + bytes_written,
170 count - bytes_written,
171 offset + bytes_written);
172 // TODO(garnold) for debugging failure in chromium-os:31077; to be removed.
173 if (rc < 0) {
174 PLOG(ERROR) << "pwrite error; num_attempts=" << num_attempts
175 << " bytes_written=" << bytes_written << " count=" << count
176 << " offset=" << offset;
177 }
178 TEST_AND_RETURN_FALSE_ERRNO(rc >= 0);
179 bytes_written += rc;
180 }
181 return true;
182 }
183
WriteAll(FileDescriptor * fd,const void * buf,size_t count)184 bool WriteAll(FileDescriptor* fd, const void* buf, size_t count) {
185 const char* c_buf = static_cast<const char*>(buf);
186 ssize_t bytes_written = 0;
187 while (bytes_written < static_cast<ssize_t>(count)) {
188 ssize_t rc = fd->Write(c_buf + bytes_written, count - bytes_written);
189 TEST_AND_RETURN_FALSE_ERRNO(rc >= 0);
190 bytes_written += rc;
191 }
192 return true;
193 }
194
WriteAll(const FileDescriptorPtr & fd,const void * buf,size_t count,off_t offset)195 bool WriteAll(const FileDescriptorPtr& fd,
196 const void* buf,
197 size_t count,
198 off_t offset) {
199 TEST_AND_RETURN_FALSE_ERRNO(fd->Seek(offset, SEEK_SET) !=
200 static_cast<off_t>(-1));
201 return WriteAll(fd, buf, count);
202 }
203
PReadAll(int fd,void * buf,size_t count,off_t offset,ssize_t * out_bytes_read)204 bool PReadAll(
205 int fd, void* buf, size_t count, off_t offset, ssize_t* out_bytes_read) {
206 char* c_buf = static_cast<char*>(buf);
207 ssize_t bytes_read = 0;
208 while (bytes_read < static_cast<ssize_t>(count)) {
209 ssize_t rc =
210 pread(fd, c_buf + bytes_read, count - bytes_read, offset + bytes_read);
211 TEST_AND_RETURN_FALSE_ERRNO(rc >= 0);
212 if (rc == 0) {
213 break;
214 }
215 bytes_read += rc;
216 }
217 *out_bytes_read = bytes_read;
218 return true;
219 }
220
ReadAll(FileDescriptor * fd,void * buf,size_t count,off_t offset,ssize_t * out_bytes_read)221 bool ReadAll(FileDescriptor* fd,
222 void* buf,
223 size_t count,
224 off_t offset,
225 ssize_t* out_bytes_read) {
226 TEST_AND_RETURN_FALSE_ERRNO(fd->Seek(offset, SEEK_SET) !=
227 static_cast<off_t>(-1));
228 char* c_buf = static_cast<char*>(buf);
229 ssize_t bytes_read = 0;
230 while (bytes_read < static_cast<ssize_t>(count)) {
231 ssize_t rc = fd->Read(c_buf + bytes_read, count - bytes_read);
232 TEST_AND_RETURN_FALSE_ERRNO(rc >= 0);
233 if (rc == 0) {
234 break;
235 }
236 bytes_read += rc;
237 }
238 *out_bytes_read = bytes_read;
239 return true;
240 }
241
PReadAll(FileDescriptor * fd,void * buf,size_t count,off_t offset,ssize_t * out_bytes_read)242 bool PReadAll(FileDescriptor* fd,
243 void* buf,
244 size_t count,
245 off_t offset,
246 ssize_t* out_bytes_read) {
247 auto old_off = fd->Seek(0, SEEK_CUR);
248 TEST_AND_RETURN_FALSE_ERRNO(old_off >= 0);
249
250 auto success = ReadAll(fd, buf, count, offset, out_bytes_read);
251 TEST_AND_RETURN_FALSE_ERRNO(fd->Seek(old_off, SEEK_SET) == old_off);
252 return success;
253 }
254
PWriteAll(const FileDescriptorPtr & fd,const void * buf,size_t count,off_t offset)255 bool PWriteAll(const FileDescriptorPtr& fd,
256 const void* buf,
257 size_t count,
258 off_t offset) {
259 auto old_off = fd->Seek(0, SEEK_CUR);
260 TEST_AND_RETURN_FALSE_ERRNO(old_off >= 0);
261
262 auto success = WriteAll(fd, buf, count, offset);
263 TEST_AND_RETURN_FALSE_ERRNO(fd->Seek(old_off, SEEK_SET) == old_off);
264 return success;
265 }
266
267 // Append |nbytes| of content from |buf| to the vector pointed to by either
268 // |vec_p| or |str_p|.
AppendBytes(const uint8_t * buf,size_t nbytes,brillo::Blob * vec_p)269 static void AppendBytes(const uint8_t* buf,
270 size_t nbytes,
271 brillo::Blob* vec_p) {
272 CHECK(buf);
273 CHECK(vec_p);
274 vec_p->insert(vec_p->end(), buf, buf + nbytes);
275 }
AppendBytes(const uint8_t * buf,size_t nbytes,string * str_p)276 static void AppendBytes(const uint8_t* buf, size_t nbytes, string* str_p) {
277 CHECK(buf);
278 CHECK(str_p);
279 str_p->append(buf, buf + nbytes);
280 }
281
282 // Reads from an open file |fp|, appending the read content to the container
283 // pointer to by |out_p|. Returns true upon successful reading all of the
284 // file's content, false otherwise. If |size| is not -1, reads up to |size|
285 // bytes.
286 template <class T>
Read(FILE * fp,off_t size,T * out_p)287 static bool Read(FILE* fp, off_t size, T* out_p) {
288 CHECK(fp);
289 CHECK(size == -1 || size >= 0);
290 uint8_t buf[1024];
291 while (size == -1 || size > 0) {
292 off_t bytes_to_read = sizeof(buf);
293 if (size > 0 && bytes_to_read > size) {
294 bytes_to_read = size;
295 }
296 size_t nbytes = fread(buf, 1, bytes_to_read, fp);
297 if (!nbytes) {
298 break;
299 }
300 AppendBytes(buf, nbytes, out_p);
301 if (size != -1) {
302 CHECK(size >= static_cast<off_t>(nbytes));
303 size -= nbytes;
304 }
305 }
306 if (ferror(fp)) {
307 return false;
308 }
309 return size == 0 || feof(fp);
310 }
311
312 // Opens a file |path| for reading and appends its the contents to a container
313 // |out_p|. Starts reading the file from |offset|. If |offset| is beyond the end
314 // of the file, returns success. If |size| is not -1, reads up to |size| bytes.
315 template <class T>
ReadFileChunkAndAppend(const string & path,off_t offset,off_t size,T * out_p)316 static bool ReadFileChunkAndAppend(const string& path,
317 off_t offset,
318 off_t size,
319 T* out_p) {
320 CHECK_GE(offset, 0);
321 CHECK(size == -1 || size >= 0);
322 base::ScopedFILE fp(fopen(path.c_str(), "r"));
323 if (!fp.get())
324 return false;
325 if (offset) {
326 // Return success without appending any data if a chunk beyond the end of
327 // the file is requested.
328 if (offset >= FileSize(path)) {
329 return true;
330 }
331 TEST_AND_RETURN_FALSE_ERRNO(fseek(fp.get(), offset, SEEK_SET) == 0);
332 }
333 return Read(fp.get(), size, out_p);
334 }
335
336 // TODO(deymo): This is only used in unittest, but requires the private
337 // Read<string>() defined here. Expose Read<string>() or move to base/ version.
ReadPipe(const string & cmd,string * out_p)338 bool ReadPipe(const string& cmd, string* out_p) {
339 FILE* fp = popen(cmd.c_str(), "r");
340 if (!fp)
341 return false;
342 bool success = Read(fp, -1, out_p);
343 return (success && pclose(fp) >= 0);
344 }
345
ReadFile(const string & path,brillo::Blob * out_p)346 bool ReadFile(const string& path, brillo::Blob* out_p) {
347 return ReadFileChunkAndAppend(path, 0, -1, out_p);
348 }
349
ReadFile(const string & path,string * out_p)350 bool ReadFile(const string& path, string* out_p) {
351 return ReadFileChunkAndAppend(path, 0, -1, out_p);
352 }
353
ReadFileChunk(const string & path,off_t offset,off_t size,brillo::Blob * out_p)354 bool ReadFileChunk(const string& path,
355 off_t offset,
356 off_t size,
357 brillo::Blob* out_p) {
358 return ReadFileChunkAndAppend(path, offset, size, out_p);
359 }
360
BlockDevSize(int fd)361 off_t BlockDevSize(int fd) {
362 uint64_t dev_size;
363 int rc = ioctl(fd, BLKGETSIZE64, &dev_size);
364 if (rc == -1) {
365 dev_size = -1;
366 PLOG(ERROR) << "Error running ioctl(BLKGETSIZE64) on " << fd;
367 }
368 return dev_size;
369 }
370
FileSize(int fd)371 off_t FileSize(int fd) {
372 struct stat stbuf;
373 int rc = fstat(fd, &stbuf);
374 CHECK_EQ(rc, 0);
375 if (rc < 0) {
376 PLOG(ERROR) << "Error stat-ing " << fd;
377 return rc;
378 }
379 if (S_ISREG(stbuf.st_mode))
380 return stbuf.st_size;
381 if (S_ISBLK(stbuf.st_mode))
382 return BlockDevSize(fd);
383 LOG(ERROR) << "Couldn't determine the type of " << fd;
384 return -1;
385 }
386
FileSize(const string & path)387 off_t FileSize(const string& path) {
388 int fd = open(path.c_str(), O_RDONLY | O_CLOEXEC);
389 if (fd == -1) {
390 PLOG(ERROR) << "Error opening " << path;
391 return fd;
392 }
393 off_t size = FileSize(fd);
394 if (size == -1)
395 PLOG(ERROR) << "Error getting file size of " << path;
396 close(fd);
397 return size;
398 }
399
SendFile(int out_fd,int in_fd,size_t count)400 bool SendFile(int out_fd, int in_fd, size_t count) {
401 off64_t offset = lseek(in_fd, 0, SEEK_CUR);
402 TEST_AND_RETURN_FALSE_ERRNO(offset >= 0);
403 constexpr size_t BUFFER_SIZE = 4096;
404 while (count > 0) {
405 const auto bytes_written =
406 sendfile(out_fd, in_fd, &offset, std::min(count, BUFFER_SIZE));
407 TEST_AND_RETURN_FALSE_ERRNO(bytes_written > 0);
408 count -= bytes_written;
409 }
410 return true;
411 }
412
HexDumpArray(const uint8_t * const arr,const size_t length)413 void HexDumpArray(const uint8_t* const arr, const size_t length) {
414 LOG(INFO) << "Logging array of length: " << length;
415 const unsigned int bytes_per_line = 16;
416 for (uint32_t i = 0; i < length; i += bytes_per_line) {
417 const unsigned int bytes_remaining = length - i;
418 const unsigned int bytes_per_this_line =
419 min(bytes_per_line, bytes_remaining);
420 char header[100];
421 int r = snprintf(header, sizeof(header), "0x%08x : ", i);
422 TEST_AND_RETURN(r == 13);
423 string line = header;
424 for (unsigned int j = 0; j < bytes_per_this_line; j++) {
425 char buf[20];
426 uint8_t c = arr[i + j];
427 r = snprintf(buf, sizeof(buf), "%02x ", static_cast<unsigned int>(c));
428 TEST_AND_RETURN(r == 3);
429 line += buf;
430 }
431 LOG(INFO) << line;
432 }
433 }
434
SplitPartitionName(const string & partition_name,string * out_disk_name,int * out_partition_num)435 bool SplitPartitionName(const string& partition_name,
436 string* out_disk_name,
437 int* out_partition_num) {
438 if (!base::StartsWith(
439 partition_name, "/dev/", base::CompareCase::SENSITIVE)) {
440 LOG(ERROR) << "Invalid partition device name: " << partition_name;
441 return false;
442 }
443
444 size_t last_nondigit_pos = partition_name.find_last_not_of("0123456789");
445 if (last_nondigit_pos == string::npos ||
446 (last_nondigit_pos + 1) == partition_name.size()) {
447 LOG(ERROR) << "Unable to parse partition device name: " << partition_name;
448 return false;
449 }
450
451 if (out_disk_name) {
452 // Special case for MMC devices which have the following naming scheme:
453 // mmcblk0p2
454 size_t disk_name_len = last_nondigit_pos;
455 if (partition_name[last_nondigit_pos] != 'p' || last_nondigit_pos == 0 ||
456 !isdigit(partition_name[last_nondigit_pos - 1])) {
457 disk_name_len++;
458 }
459 *out_disk_name = partition_name.substr(0, disk_name_len);
460 }
461
462 if (out_partition_num) {
463 string partition_str = partition_name.substr(last_nondigit_pos + 1);
464 *out_partition_num = atoi(partition_str.c_str());
465 }
466 return true;
467 }
468
MakePartitionName(const string & disk_name,int partition_num)469 string MakePartitionName(const string& disk_name, int partition_num) {
470 if (partition_num < 1) {
471 LOG(ERROR) << "Invalid partition number: " << partition_num;
472 return string();
473 }
474
475 if (!base::StartsWith(disk_name, "/dev/", base::CompareCase::SENSITIVE)) {
476 LOG(ERROR) << "Invalid disk name: " << disk_name;
477 return string();
478 }
479
480 string partition_name = disk_name;
481 if (isdigit(partition_name.back())) {
482 // Special case for devices with names ending with a digit.
483 // Add "p" to separate the disk name from partition number,
484 // e.g. "/dev/loop0p2"
485 partition_name += 'p';
486 }
487
488 partition_name += std::to_string(partition_num);
489
490 return partition_name;
491 }
492
FileExists(const char * path)493 bool FileExists(const char* path) {
494 struct stat stbuf;
495 return 0 == lstat(path, &stbuf);
496 }
497
IsSymlink(const char * path)498 bool IsSymlink(const char* path) {
499 struct stat stbuf;
500 return lstat(path, &stbuf) == 0 && S_ISLNK(stbuf.st_mode) != 0;
501 }
502
IsRegFile(const char * path)503 bool IsRegFile(const char* path) {
504 struct stat stbuf;
505 return lstat(path, &stbuf) == 0 && S_ISREG(stbuf.st_mode) != 0;
506 }
507
MakeTempFile(const string & base_filename_template,string * filename,int * fd)508 bool MakeTempFile(const string& base_filename_template,
509 string* filename,
510 int* fd) {
511 base::FilePath filename_template;
512 TEST_AND_RETURN_FALSE(
513 GetTempName(base_filename_template, &filename_template));
514 DCHECK(filename || fd);
515 vector<char> buf(filename_template.value().size() + 1);
516 memcpy(buf.data(),
517 filename_template.value().data(),
518 filename_template.value().size());
519 buf[filename_template.value().size()] = '\0';
520
521 int mkstemp_fd = mkstemp(buf.data());
522 TEST_AND_RETURN_FALSE_ERRNO(mkstemp_fd >= 0);
523 if (filename) {
524 *filename = buf.data();
525 }
526 if (fd) {
527 *fd = mkstemp_fd;
528 } else {
529 close(mkstemp_fd);
530 }
531 return true;
532 }
533
SetBlockDeviceReadOnly(const string & device,bool read_only)534 bool SetBlockDeviceReadOnly(const string& device, bool read_only) {
535 int fd = HANDLE_EINTR(open(device.c_str(), O_RDONLY | O_CLOEXEC));
536 if (fd < 0) {
537 PLOG(ERROR) << "Opening block device " << device;
538 return false;
539 }
540 ScopedFdCloser fd_closer(&fd);
541 // We take no action if not needed.
542 int read_only_flag;
543 int expected_flag = read_only ? 1 : 0;
544 int rc = ioctl(fd, BLKROGET, &read_only_flag);
545 // In case of failure reading the setting we will try to set it anyway.
546 if (rc == 0 && read_only_flag == expected_flag)
547 return true;
548
549 rc = ioctl(fd, BLKROSET, &expected_flag);
550 if (rc != 0) {
551 PLOG(ERROR) << "Marking block device " << device
552 << " as read_only=" << expected_flag;
553 return false;
554 }
555 return true;
556 }
557
MountFilesystem(const string & device,const string & mountpoint,unsigned long mountflags,const string & type,const string & fs_mount_options)558 bool MountFilesystem(const string& device,
559 const string& mountpoint,
560 unsigned long mountflags, // NOLINT(runtime/int)
561 const string& type,
562 const string& fs_mount_options) {
563 vector<const char*> fstypes;
564 if (type.empty()) {
565 fstypes = {"ext2", "ext3", "ext4", "squashfs", "erofs"};
566 } else {
567 fstypes = {type.c_str()};
568 }
569 for (const char* fstype : fstypes) {
570 int rc = mount(device.c_str(),
571 mountpoint.c_str(),
572 fstype,
573 mountflags,
574 fs_mount_options.c_str());
575 if (rc == 0)
576 return true;
577
578 PLOG(WARNING) << "Unable to mount destination device " << device << " on "
579 << mountpoint << " as " << fstype;
580 }
581 if (!type.empty()) {
582 LOG(ERROR) << "Unable to mount " << device << " with any supported type";
583 }
584 return false;
585 }
586
UnmountFilesystem(const string & mountpoint)587 bool UnmountFilesystem(const string& mountpoint) {
588 int num_retries = 1;
589 for (;; ++num_retries) {
590 if (umount(mountpoint.c_str()) == 0)
591 return true;
592 if (errno != EBUSY || num_retries >= kUnmountMaxNumOfRetries)
593 break;
594 usleep(kUnmountRetryIntervalInMicroseconds);
595 }
596 if (errno == EINVAL) {
597 LOG(INFO) << "Not a mountpoint: " << mountpoint;
598 return false;
599 }
600 PLOG(WARNING) << "Error unmounting " << mountpoint << " after " << num_retries
601 << " attempts. Lazy unmounting instead, error was";
602 if (umount2(mountpoint.c_str(), MNT_DETACH) != 0) {
603 PLOG(ERROR) << "Lazy unmount failed";
604 return false;
605 }
606 return true;
607 }
608
IsMountpoint(const std::string & mountpoint)609 bool IsMountpoint(const std::string& mountpoint) {
610 struct stat stdir, stparent;
611
612 // Check whether the passed mountpoint is a directory and the /.. is in the
613 // same device or not. If mountpoint/.. is in a different device it means that
614 // there is a filesystem mounted there. If it is not, but they both point to
615 // the same inode it basically is the special case of /.. pointing to /. This
616 // test doesn't play well with bind mount but that's out of the scope of what
617 // we want to detect here.
618 if (lstat(mountpoint.c_str(), &stdir) != 0) {
619 PLOG(ERROR) << "Error stat'ing " << mountpoint;
620 return false;
621 }
622 if (!S_ISDIR(stdir.st_mode))
623 return false;
624
625 base::FilePath parent(mountpoint);
626 parent = parent.Append("..");
627 if (lstat(parent.value().c_str(), &stparent) != 0) {
628 PLOG(ERROR) << "Error stat'ing " << parent.value();
629 return false;
630 }
631 return S_ISDIR(stparent.st_mode) &&
632 (stparent.st_dev != stdir.st_dev || stparent.st_ino == stdir.st_ino);
633 }
634
635 // Tries to parse the header of an ELF file to obtain a human-readable
636 // description of it on the |output| string.
GetFileFormatELF(const uint8_t * buffer,size_t size,string * output)637 static bool GetFileFormatELF(const uint8_t* buffer,
638 size_t size,
639 string* output) {
640 // 0x00: EI_MAG - ELF magic header, 4 bytes.
641 if (size < SELFMAG || memcmp(buffer, ELFMAG, SELFMAG) != 0)
642 return false;
643 *output = "ELF";
644
645 // 0x04: EI_CLASS, 1 byte.
646 if (size < EI_CLASS + 1)
647 return true;
648 switch (buffer[EI_CLASS]) {
649 case ELFCLASS32:
650 *output += " 32-bit";
651 break;
652 case ELFCLASS64:
653 *output += " 64-bit";
654 break;
655 default:
656 *output += " ?-bit";
657 }
658
659 // 0x05: EI_DATA, endianness, 1 byte.
660 if (size < EI_DATA + 1)
661 return true;
662 uint8_t ei_data = buffer[EI_DATA];
663 switch (ei_data) {
664 case ELFDATA2LSB:
665 *output += " little-endian";
666 break;
667 case ELFDATA2MSB:
668 *output += " big-endian";
669 break;
670 default:
671 *output += " ?-endian";
672 // Don't parse anything after the 0x10 offset if endianness is unknown.
673 return true;
674 }
675
676 const Elf32_Ehdr* hdr = reinterpret_cast<const Elf32_Ehdr*>(buffer);
677 // 0x12: e_machine, 2 byte endianness based on ei_data. The position (0x12)
678 // and size is the same for both 32 and 64 bits.
679 if (size < offsetof(Elf32_Ehdr, e_machine) + sizeof(hdr->e_machine))
680 return true;
681 uint16_t e_machine;
682 // Fix endianness regardless of the host endianness.
683 if (ei_data == ELFDATA2LSB)
684 e_machine = le16toh(hdr->e_machine);
685 else
686 e_machine = be16toh(hdr->e_machine);
687
688 switch (e_machine) {
689 case EM_386:
690 *output += " x86";
691 break;
692 case EM_MIPS:
693 *output += " mips";
694 break;
695 case EM_ARM:
696 *output += " arm";
697 break;
698 case EM_X86_64:
699 *output += " x86-64";
700 break;
701 default:
702 *output += " unknown-arch";
703 }
704 return true;
705 }
706
GetFileFormat(const string & path)707 string GetFileFormat(const string& path) {
708 brillo::Blob buffer;
709 if (!ReadFileChunkAndAppend(path, 0, kGetFileFormatMaxHeaderSize, &buffer))
710 return "File not found.";
711
712 string result;
713 if (GetFileFormatELF(buffer.data(), buffer.size(), &result))
714 return result;
715
716 return "data";
717 }
718
FuzzInt(int value,unsigned int range)719 int FuzzInt(int value, unsigned int range) {
720 int min = value - range / 2;
721 int max = value + range - range / 2;
722 return base::RandInt(min, max);
723 }
724
FormatSecs(unsigned secs)725 string FormatSecs(unsigned secs) {
726 return FormatTimeDelta(TimeDelta::FromSeconds(secs));
727 }
728
FormatTimeDelta(TimeDelta delta)729 string FormatTimeDelta(TimeDelta delta) {
730 string str;
731
732 // Handle negative durations by prefixing with a minus.
733 if (delta.ToInternalValue() < 0) {
734 delta *= -1;
735 str = "-";
736 }
737
738 // Canonicalize into days, hours, minutes, seconds and microseconds.
739 unsigned days = delta.InDays();
740 delta -= TimeDelta::FromDays(days);
741 unsigned hours = delta.InHours();
742 delta -= TimeDelta::FromHours(hours);
743 unsigned mins = delta.InMinutes();
744 delta -= TimeDelta::FromMinutes(mins);
745 unsigned secs = delta.InSeconds();
746 delta -= TimeDelta::FromSeconds(secs);
747 unsigned usecs = delta.InMicroseconds();
748
749 if (days)
750 base::StringAppendF(&str, "%ud", days);
751 if (days || hours)
752 base::StringAppendF(&str, "%uh", hours);
753 if (days || hours || mins)
754 base::StringAppendF(&str, "%um", mins);
755 base::StringAppendF(&str, "%u", secs);
756 if (usecs) {
757 int width = 6;
758 while ((usecs / 10) * 10 == usecs) {
759 usecs /= 10;
760 width--;
761 }
762 base::StringAppendF(&str, ".%0*u", width, usecs);
763 }
764 base::StringAppendF(&str, "s");
765 return str;
766 }
767
ToString(const Time utc_time)768 string ToString(const Time utc_time) {
769 Time::Exploded exp_time;
770 utc_time.UTCExplode(&exp_time);
771 return base::StringPrintf("%d/%d/%d %d:%02d:%02d GMT",
772 exp_time.month,
773 exp_time.day_of_month,
774 exp_time.year,
775 exp_time.hour,
776 exp_time.minute,
777 exp_time.second);
778 }
779
ToString(bool b)780 string ToString(bool b) {
781 return (b ? "true" : "false");
782 }
783
ToString(DownloadSource source)784 string ToString(DownloadSource source) {
785 switch (source) {
786 case kDownloadSourceHttpsServer:
787 return "HttpsServer";
788 case kDownloadSourceHttpServer:
789 return "HttpServer";
790 case kDownloadSourceHttpPeer:
791 return "HttpPeer";
792 case kNumDownloadSources:
793 return "Unknown";
794 // Don't add a default case to let the compiler warn about newly added
795 // download sources which should be added here.
796 }
797
798 return "Unknown";
799 }
800
ToString(PayloadType payload_type)801 string ToString(PayloadType payload_type) {
802 switch (payload_type) {
803 case kPayloadTypeDelta:
804 return "Delta";
805 case kPayloadTypeFull:
806 return "Full";
807 case kPayloadTypeForcedFull:
808 return "ForcedFull";
809 case kNumPayloadTypes:
810 return "Unknown";
811 // Don't add a default case to let the compiler warn about newly added
812 // payload types which should be added here.
813 }
814
815 return "Unknown";
816 }
817
GetBaseErrorCode(ErrorCode code)818 ErrorCode GetBaseErrorCode(ErrorCode code) {
819 // Ignore the higher order bits in the code by applying the mask as
820 // we want the enumerations to be in the small contiguous range
821 // with values less than ErrorCode::kUmaReportedMax.
822 ErrorCode base_code = static_cast<ErrorCode>(
823 static_cast<int>(code) & ~static_cast<int>(ErrorCode::kSpecialFlags));
824
825 // Make additional adjustments required for UMA and error classification.
826 // TODO(jaysri): Move this logic to UeErrorCode.cc when we fix
827 // chromium-os:34369.
828 if (base_code >= ErrorCode::kOmahaRequestHTTPResponseBase) {
829 // Since we want to keep the enums to a small value, aggregate all HTTP
830 // errors into this one bucket for UMA and error classification purposes.
831 LOG(INFO) << "Converting error code " << base_code
832 << " to ErrorCode::kOmahaErrorInHTTPResponse";
833 base_code = ErrorCode::kOmahaErrorInHTTPResponse;
834 }
835
836 return base_code;
837 }
838
StringVectorToString(const vector<string> & vec_str)839 string StringVectorToString(const vector<string>& vec_str) {
840 string str = "[";
841 for (vector<string>::const_iterator i = vec_str.begin(); i != vec_str.end();
842 ++i) {
843 if (i != vec_str.begin())
844 str += ", ";
845 str += '"';
846 str += *i;
847 str += '"';
848 }
849 str += "]";
850 return str;
851 }
852
853 // The P2P file id should be the same for devices running new version and old
854 // version so that they can share it with each other. The hash in the response
855 // was base64 encoded, but now that we switched to use "hash_sha256" field which
856 // is hex encoded, we have to convert them back to base64 for P2P. However, the
857 // base64 encoded hash was base64 encoded here again historically for some
858 // reason, so we keep the same behavior here.
CalculateP2PFileId(const brillo::Blob & payload_hash,size_t payload_size)859 string CalculateP2PFileId(const brillo::Blob& payload_hash,
860 size_t payload_size) {
861 string encoded_hash = brillo::data_encoding::Base64Encode(
862 brillo::data_encoding::Base64Encode(payload_hash));
863 return base::StringPrintf("cros_update_size_%" PRIuS "_hash_%s",
864 payload_size,
865 encoded_hash.c_str());
866 }
867
ConvertToOmahaInstallDate(Time time,int * out_num_days)868 bool ConvertToOmahaInstallDate(Time time, int* out_num_days) {
869 time_t unix_time = time.ToTimeT();
870 // Output of: date +"%s" --date="Jan 1, 2007 0:00 PST".
871 const time_t kOmahaEpoch = 1167638400;
872 const int64_t kNumSecondsPerWeek = 7 * 24 * 3600;
873 const int64_t kNumDaysPerWeek = 7;
874
875 time_t omaha_time = unix_time - kOmahaEpoch;
876
877 if (omaha_time < 0)
878 return false;
879
880 // Note, as per the comment in utils.h we are deliberately not
881 // handling DST correctly.
882
883 int64_t num_weeks_since_omaha_epoch = omaha_time / kNumSecondsPerWeek;
884 *out_num_days = num_weeks_since_omaha_epoch * kNumDaysPerWeek;
885
886 return true;
887 }
888
GetMinorVersion(const brillo::KeyValueStore & store,uint32_t * minor_version)889 bool GetMinorVersion(const brillo::KeyValueStore& store,
890 uint32_t* minor_version) {
891 string result;
892 if (store.GetString("PAYLOAD_MINOR_VERSION", &result)) {
893 if (!base::StringToUint(result, minor_version)) {
894 LOG(ERROR) << "StringToUint failed when parsing delta minor version.";
895 return false;
896 }
897 return true;
898 }
899 return false;
900 }
901
ReadExtents(const std::string & path,const google::protobuf::RepeatedPtrField<Extent> & extents,brillo::Blob * out_data,size_t block_size)902 bool ReadExtents(const std::string& path,
903 const google::protobuf::RepeatedPtrField<Extent>& extents,
904 brillo::Blob* out_data,
905 size_t block_size) {
906 return ReadExtents(path,
907 {extents.begin(), extents.end()},
908 out_data,
909 utils::BlocksInExtents(extents) * block_size,
910 block_size);
911 }
912
WriteExtents(const std::string & path,const google::protobuf::RepeatedPtrField<Extent> & extents,const brillo::Blob & data,size_t block_size)913 bool WriteExtents(const std::string& path,
914 const google::protobuf::RepeatedPtrField<Extent>& extents,
915 const brillo::Blob& data,
916 size_t block_size) {
917 EintrSafeFileDescriptor fd;
918 TEST_AND_RETURN_FALSE(fd.Open(path.c_str(), O_RDWR));
919 size_t bytes_written = 0;
920 for (const auto& ext : extents) {
921 TEST_AND_RETURN_FALSE_ERRNO(
922 fd.Seek(ext.start_block() * block_size, SEEK_SET));
923 TEST_AND_RETURN_FALSE_ERRNO(
924 fd.Write(data.data() + bytes_written, ext.num_blocks() * block_size));
925 bytes_written += ext.num_blocks() * block_size;
926 }
927 return true;
928 }
ReadExtents(const std::string & path,const vector<Extent> & extents,brillo::Blob * out_data,ssize_t out_data_size,size_t block_size)929 bool ReadExtents(const std::string& path,
930 const vector<Extent>& extents,
931 brillo::Blob* out_data,
932 ssize_t out_data_size,
933 size_t block_size) {
934 FileDescriptorPtr fd = std::make_shared<EintrSafeFileDescriptor>();
935 fd->Open(path.c_str(), O_RDONLY);
936 return ReadExtents(fd, extents, out_data, out_data_size, block_size);
937 }
938
ReadExtents(FileDescriptorPtr fd,const google::protobuf::RepeatedPtrField<Extent> & extents,brillo::Blob * out_data,size_t block_size)939 bool ReadExtents(FileDescriptorPtr fd,
940 const google::protobuf::RepeatedPtrField<Extent>& extents,
941 brillo::Blob* out_data,
942 size_t block_size) {
943 return ReadExtents(fd,
944 {extents.begin(), extents.end()},
945 out_data,
946 utils::BlocksInExtents(extents) * block_size,
947 block_size);
948 }
949
ReadExtents(FileDescriptorPtr fd,const vector<Extent> & extents,brillo::Blob * out_data,ssize_t out_data_size,size_t block_size)950 bool ReadExtents(FileDescriptorPtr fd,
951 const vector<Extent>& extents,
952 brillo::Blob* out_data,
953 ssize_t out_data_size,
954 size_t block_size) {
955 brillo::Blob data(out_data_size);
956 ssize_t bytes_read = 0;
957
958 for (const Extent& extent : extents) {
959 ssize_t bytes_read_this_iteration = 0;
960 ssize_t bytes = extent.num_blocks() * block_size;
961 TEST_LE(bytes_read + bytes, out_data_size);
962 TEST_AND_RETURN_FALSE(utils::PReadAll(fd,
963 &data[bytes_read],
964 bytes,
965 extent.start_block() * block_size,
966 &bytes_read_this_iteration));
967 TEST_AND_RETURN_FALSE(bytes_read_this_iteration == bytes);
968 bytes_read += bytes_read_this_iteration;
969 }
970 TEST_AND_RETURN_FALSE(out_data_size == bytes_read);
971 *out_data = data;
972 return true;
973 }
974
GetVpdValue(string key,string * result)975 bool GetVpdValue(string key, string* result) {
976 int exit_code = 0;
977 string value, error;
978 vector<string> cmd = {"vpd_get_value", key};
979 if (!chromeos_update_engine::Subprocess::SynchronousExec(
980 cmd, &exit_code, &value, &error) ||
981 exit_code) {
982 LOG(ERROR) << "Failed to get vpd key for " << value
983 << " with exit code: " << exit_code << " and error: " << error;
984 return false;
985 } else if (!error.empty()) {
986 LOG(INFO) << "vpd_get_value succeeded but with following errors: " << error;
987 }
988
989 base::TrimWhitespaceASCII(value, base::TRIM_ALL, &value);
990 *result = value;
991 return true;
992 }
993
GetBootId(string * boot_id)994 bool GetBootId(string* boot_id) {
995 TEST_AND_RETURN_FALSE(
996 base::ReadFileToString(base::FilePath(kBootIdPath), boot_id));
997 base::TrimWhitespaceASCII(*boot_id, base::TRIM_TRAILING, boot_id);
998 return true;
999 }
1000
VersionPrefix(const std::string & version)1001 int VersionPrefix(const std::string& version) {
1002 if (version.empty()) {
1003 return 0;
1004 }
1005 vector<string> tokens = base::SplitString(
1006 version, ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL);
1007 int value;
1008 if (tokens.empty() || !base::StringToInt(tokens[0], &value))
1009 return -1; // Target version is invalid.
1010 return value;
1011 }
1012
ParseRollbackKeyVersion(const string & raw_version,uint16_t * high_version,uint16_t * low_version)1013 void ParseRollbackKeyVersion(const string& raw_version,
1014 uint16_t* high_version,
1015 uint16_t* low_version) {
1016 DCHECK(high_version);
1017 DCHECK(low_version);
1018 *high_version = numeric_limits<uint16_t>::max();
1019 *low_version = numeric_limits<uint16_t>::max();
1020
1021 vector<string> parts = base::SplitString(
1022 raw_version, ".", base::TRIM_WHITESPACE, base::SPLIT_WANT_ALL);
1023 if (parts.size() != 2) {
1024 // The version string must have exactly one period.
1025 return;
1026 }
1027
1028 int high;
1029 int low;
1030 if (!(base::StringToInt(parts[0], &high) &&
1031 base::StringToInt(parts[1], &low))) {
1032 // Both parts of the version could not be parsed correctly.
1033 return;
1034 }
1035
1036 if (high >= 0 && high < numeric_limits<uint16_t>::max() && low >= 0 &&
1037 low < numeric_limits<uint16_t>::max()) {
1038 *high_version = static_cast<uint16_t>(high);
1039 *low_version = static_cast<uint16_t>(low);
1040 }
1041 }
1042
GetFilePath(int fd)1043 string GetFilePath(int fd) {
1044 base::FilePath proc("/proc/self/fd/" + std::to_string(fd));
1045 base::FilePath file_name;
1046
1047 if (!base::ReadSymbolicLink(proc, &file_name)) {
1048 return "not found";
1049 }
1050 return file_name.value();
1051 }
1052
GetTimeAsString(time_t utime)1053 string GetTimeAsString(time_t utime) {
1054 struct tm tm;
1055 CHECK_EQ(localtime_r(&utime, &tm), &tm);
1056 char str[16];
1057 CHECK_EQ(strftime(str, sizeof(str), "%Y%m%d-%H%M%S", &tm), 15u);
1058 return str;
1059 }
1060
GetExclusionName(const string & str_to_convert)1061 string GetExclusionName(const string& str_to_convert) {
1062 return base::NumberToString(base::StringPieceHash()(str_to_convert));
1063 }
1064
ParseTimestamp(std::string_view str,int64_t * out)1065 static bool ParseTimestamp(std::string_view str, int64_t* out) {
1066 if (!base::StringToInt64(base::StringPiece(str.data(), str.size()), out)) {
1067 LOG(WARNING) << "Invalid timestamp: " << str;
1068 return false;
1069 }
1070 return true;
1071 }
1072
IsTimestampNewer(const std::string_view old_version,const std::string_view new_version)1073 ErrorCode IsTimestampNewer(const std::string_view old_version,
1074 const std::string_view new_version) {
1075 if (old_version.empty() || new_version.empty()) {
1076 LOG(WARNING)
1077 << "One of old/new timestamp is empty, permit update anyway. Old: "
1078 << old_version << " New: " << new_version;
1079 return ErrorCode::kSuccess;
1080 }
1081 int64_t old_ver = 0;
1082 if (!ParseTimestamp(old_version, &old_ver)) {
1083 return ErrorCode::kError;
1084 }
1085 int64_t new_ver = 0;
1086 if (!ParseTimestamp(new_version, &new_ver)) {
1087 return ErrorCode::kDownloadManifestParseError;
1088 }
1089 if (old_ver > new_ver) {
1090 return ErrorCode::kPayloadTimestampError;
1091 }
1092 return ErrorCode::kSuccess;
1093 }
1094
GetReadonlyZeroBlock(size_t size)1095 std::unique_ptr<android::base::MappedFile> GetReadonlyZeroBlock(size_t size) {
1096 android::base::unique_fd fd{HANDLE_EINTR(open("/dev/zero", O_RDONLY))};
1097 return android::base::MappedFile::FromFd(fd, 0, size, PROT_READ);
1098 }
1099
GetReadonlyZeroString(size_t size)1100 std::string_view GetReadonlyZeroString(size_t size) {
1101 // Reserve 512MB of Virtual Address Space. No actual memory will be used.
1102 static auto zero_block = GetReadonlyZeroBlock(1024 * 1024 * 512);
1103 if (size > zero_block->size()) {
1104 auto larger_block = GetReadonlyZeroBlock(size);
1105 zero_block = std::move(larger_block);
1106 }
1107 return {zero_block->data(), size};
1108 }
1109
1110 } // namespace utils
1111
HexEncode(const brillo::Blob & blob)1112 std::string HexEncode(const brillo::Blob& blob) noexcept {
1113 return base::HexEncode(blob.data(), blob.size());
1114 }
1115
HexEncode(const std::string_view blob)1116 std::string HexEncode(const std::string_view blob) noexcept {
1117 return base::HexEncode(blob.data(), blob.size());
1118 }
1119
ToStringView(const std::vector<unsigned char> & blob)1120 [[nodiscard]] std::string_view ToStringView(
1121 const std::vector<unsigned char>& blob) noexcept {
1122 return std::string_view{reinterpret_cast<const char*>(blob.data()),
1123 blob.size()};
1124 }
1125
ToStringView(const void * data,size_t size)1126 [[nodiscard]] std::string_view ToStringView(const void* data,
1127 size_t size) noexcept {
1128 return std::string_view(reinterpret_cast<const char*>(data), size);
1129 }
1130
1131 } // namespace chromeos_update_engine
1132