2 // Open Service Platform
3 // Copyright (c) 2012 Samsung Electronics Co., Ltd.
5 // Licensed under the Apache License, Version 2.0 (the License);
6 // you may not use this file except in compliance with the License.
7 // You may obtain a copy of the License at
9 // http://www.apache.org/licenses/LICENSE-2.0
11 // Unless required by applicable law or agreed to in writing, software
12 // distributed under the License is distributed on an "AS IS" BASIS,
13 // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 // See the License for the specific language governing permissions and
15 // limitations under the License.
26 #include <sys/mount.h>
29 #include <sys/types.h>
31 #include <sys/prctl.h>
39 #define LOG_TAG "ENV_CONFIG"
41 #define _MAX_PACKAGEID_LENGTH 10
42 #define _MAX_APIVERSION_LENGTH 3
45 #define _SECURE_LOGI LOGI
46 #define _SECURE_LOGE LOGE
48 #define _SECURE_LOGI(...)
49 #define _SECURE_LOGE(...)
52 static const char* _OSP_COMPAT_SHARED_PATH = "/opt/usr/share/.osp-compat/\0";
53 static const char* _EXT_OSP_HOME_PATH = "/opt/storage/sdcard/osp/\0";
57 char src_path[PATH_MAX];
58 char dest_path[PATH_MAX];
65 char app_privilege; // 0: root privilege
69 * XXX: The returned app_roodir must be freed in caller.
72 get_app_rootpath_from_path(const char* bin_path)
74 char* app_rootpath = NULL;
75 char* delimiter = NULL;
77 /* e.g., The specified bin_path is "/opt/apps/com.samsung.basicapp/bin/basicapp" */
79 length = strlen(bin_path);
80 app_rootpath = (char *)malloc(length + 1);
81 if(app_rootpath == NULL)
84 memset(app_rootpath, '\0', length + 1);
85 strncpy(app_rootpath, bin_path, length);
87 _SECURE_LOGI("input bin_path: %s", app_rootpath);
89 delimiter = strrchr(app_rootpath, '/');
92 delimiter = strrchr(app_rootpath, '/');
99 get_package_id_from_app_rootpath(const char* app_rootpath, char* package_id)
101 const char* p = NULL;
102 if (strncmp(app_rootpath, "/opt/apps/org.tizen.", 19) == 0)
104 p = strrchr(app_rootpath, '.') + 1;
108 p = strrchr(app_rootpath, '/') + 1;
110 strncpy(package_id, p, _MAX_PACKAGEID_LENGTH);
111 package_id[_MAX_PACKAGEID_LENGTH] = '\0';
112 _SECURE_LOGI("package id: %s", package_id);
117 get_package_id_from_package_name(const char* package_name, char* package_id)
121 if (strncmp(package_name, "com", 3) == 0)
122 { // in case of com.samsung.#osp#[package_id]#[serviceid]
123 tmpbuf = strstr(package_name, "#osp#");
126 strncpy(package_id, tmpbuf + 5, _MAX_PACKAGEID_LENGTH);
129 else if (strncmp(package_name, "osp", 3) == 0)
130 { // in case of osp.[package_id].#osp#[serviceid]
131 tmpbuf = strstr(package_name, "osp.");
134 strncpy(package_id, tmpbuf + 4, _MAX_PACKAGEID_LENGTH);
137 else if (strncmp(package_name, "org.tizen", 9) == 0)
139 // in case of org.tizen.[package_id]#[serviceid]
140 tmpbuf = strstr(package_name, "org.tizen.");
143 strncpy(package_id, tmpbuf + 10, _MAX_PACKAGEID_LENGTH);
146 else if (strlen(package_name) == 10)
148 strncpy(package_id, package_name, _MAX_PACKAGEID_LENGTH);
152 LOGE("package name is invalid (%s)", package_name);
155 package_id[_MAX_PACKAGEID_LENGTH] = '\0';
156 _SECURE_LOGI("package_id: %s", package_id);
161 internal_is_mounted(const char* pkgid)
163 char mount_flag[64] = { 0, };
164 static const char dir[][64] =
166 { "/tmp/osp-compat" },
167 { "/tmp/osp-compat/mount" },
168 { "/tmp/osp-compat/mount/internal" }
171 sprintf(mount_flag, "/tmp/osp-compat/mount/internal/%s", pkgid);
172 int res = access(mount_flag, F_OK);
175 LOGI("Intenal path is already mounted.");
178 else if (res == -1 && errno == ENOENT)
181 for (i = 0; i < sizeof(dir)/64; ++i)
183 int res = mkdir(dir[i], 0755);
184 if (res == -1 && errno != EEXIST)
186 LOGE("Failed to create directory (%s), errno: %d (%s)", dir[i], errno, strerror(errno));
191 int fd = creat(mount_flag, 0644);
194 LOGE("Failed to create mount flag (%s), errno: %d (%s)", mount_flag, errno, strerror(errno));
201 LOGE("Failed to access mount flag (%s), errno: %d (%s)", mount_flag, errno, strerror(errno));
205 LOGI("Intenal path mount succeeded.");
210 external_is_mounted(const char* pkgid)
212 char mount_flag[64] = { 0, };
213 static const char dir[][64] =
215 { "/tmp/osp-compat" },
216 { "/tmp/osp-compat/mount" },
217 { "/tmp/osp-compat/mount/external" }
220 sprintf(mount_flag, "/tmp/osp-compat/mount/external/%s", pkgid);
221 int res = access(mount_flag, F_OK);
224 LOGI("Extenal path is already mounted.");
227 else if (res == -1 && errno == ENOENT)
230 for (i = 0; i < sizeof(dir)/64; ++i)
232 int res = mkdir(dir[i], 0755);
233 if (res == -1 && errno != EEXIST)
235 LOGE("Failed to create directory (%s), errno: %d (%s)", dir[i], errno, strerror(errno));
240 int fd = creat(mount_flag, 0644);
243 LOGE("Failed to create mount flag (%s), errno: %d (%s)", mount_flag, errno, strerror(errno));
250 LOGE("Failed to access mount flag (%s), errno: %d (%s)", mount_flag, errno, strerror(errno));
254 LOGI("Extenal path mount succeeded.");
259 mount_native_paths(const char* app_rootpath)
262 static const struct _path_info mount_info[] =
264 //{ "/bin", "./bin" },
267 { "/dev/pts", "./dev/pts" },
268 { "/dev/shm", "./dev/shm" },
272 { "/proc", "./proc" },
273 { "/sbin", "./sbin" },
274 { "/smack", "./smack" },
277 { "/sys/kernel/debug", "./sys/kernel/debug" },
281 { "/var/run", "./var/run" },
283 { "/opt/usr", "./opt/usr" },
284 { "/opt/var/kdb/db", "./opt/var/kdb/db" },
285 //{ "/opt/storage/sdcard","./opt/storage/sdcard" }
288 if (chdir(app_rootpath) != 0)
290 LOGE("chdir() failed path: %s, errno: %d (%s)", app_rootpath, errno, strerror(errno));
294 for (i = 0; i < sizeof(mount_info)/sizeof(struct _path_info); ++i)
296 if (mount(mount_info[i].src_path, mount_info[i].dest_path, NULL, MS_BIND, NULL) != 0)
298 LOGE("mount() failed, src path: %s, dest path: %s, errno: %d (%s)",
299 mount_info[i].src_path, mount_info[i].dest_path, errno, strerror(errno));
302 for (j = i; j > 0; --j)
304 umount2(mount_info[j-1].dest_path, MNT_DETACH);
314 mount_osp_internal_paths(const char* app_rootpath, const char* pkgid)
317 char osp_share_pkgid_path[PATH_MAX] = {0, };
318 char osp_share2_pkgid_path[PATH_MAX] = {0, };
319 struct _path_info mount_info[] =
321 { "\0", "./data/Share" },
322 { "\0", "./data/Share2" },
323 { "/opt/usr/share/.osp-compat/share", "./Share" },
324 { "/opt/usr/share/.osp-compat/share2", "./Share2" },
325 { "/opt/usr/media", "./Media" }
328 strncpy(osp_share_pkgid_path, _OSP_COMPAT_SHARED_PATH, strlen(_OSP_COMPAT_SHARED_PATH));
329 strncat(osp_share_pkgid_path, "share/", 6);
330 strncat(osp_share_pkgid_path, pkgid, strlen(pkgid));
332 strncpy(osp_share2_pkgid_path, _OSP_COMPAT_SHARED_PATH, strlen(_OSP_COMPAT_SHARED_PATH));
333 strncat(osp_share2_pkgid_path, "share2/", 7);
334 strncat(osp_share2_pkgid_path, pkgid, strlen(pkgid));
336 strncpy(mount_info[0].src_path, osp_share_pkgid_path, strlen(osp_share_pkgid_path));
337 strncpy(mount_info[1].src_path, osp_share2_pkgid_path, strlen(osp_share2_pkgid_path));
339 if (chdir(app_rootpath) != 0)
341 LOGE("chdir() failed, path: %s, errno: %d (%s)", app_rootpath, errno, strerror(errno));
345 for (i = 0; i < sizeof(mount_info)/sizeof(struct _path_info); ++i)
347 if (mount(mount_info[i].src_path, mount_info[i].dest_path, NULL, MS_BIND, NULL) != 0)
349 LOGE("mount() failed, src path: %s, dest path: %s, errno: %d (%s)",
350 mount_info[i].src_path, mount_info[i].dest_path, errno, strerror(errno));
353 for (j = i; j > 0; --j)
355 umount2(mount_info[j-1].dest_path, MNT_DETACH);
365 mount_linux_paths(const char* app_rootpath)
368 static const struct _path_info mount_info[] =
371 { "/cache", "./cache" },
373 { "/data", "./data" },
375 { "/dev/pts", "./dev/pts" },
376 { "/dev/shm", "./dev/shm" },
379 { "/lib/modules", "./lib/modules" },
380 { "/media", "./media" },
382 { "/proc", "./proc" },
384 { "/sbin", "./sbin" },
385 { "/smack", "./smack" },
388 { "/sys/fs/cgroup", "./sys/fs/cgroup" },
389 { "/sys/fs/cgroup/systemd", "./sys/fs/cgroup/systemd" },
390 { "/system", "./system" },
394 { "/var/run", "./var/run" },
396 { "/opt/usr", "./opt/usr" },
397 //{ "/opt/var/run", "./opt/var/run" },
398 { "/opt/storage/sdcard","./opt/storage/sdcard" },
401 if (chdir(app_rootpath) != 0)
403 LOGE("chdir() failed path: %s, errno: %d (%s)", app_rootpath, errno, strerror(errno));
407 for (i = 0; i < sizeof(mount_info)/sizeof(struct _path_info); ++i)
409 if (i == 27) // /opt/storage/sdcard
412 int ret = vconf_get_int(VCONFKEY_SYSMAN_MMC_STATUS, &mmc_mounted);
415 LOGE("vconf_get_int(VCONFKEY_SYSMAN_MMC_STATUS) failed.");
417 if (mmc_mounted == 0)
423 LOGI("src path: %s, dest path: %s", mount_info[i].src_path, mount_info[i].dest_path);
424 if (mount(mount_info[i].src_path, mount_info[i].dest_path, NULL, MS_BIND, NULL) != 0)
426 LOGE("mount() failed, src path: %s, dest path: %s, errno: %d (%s)",
427 mount_info[i].src_path, mount_info[i].dest_path, errno, strerror(errno));
430 for (j = i; j > 0; --j)
432 umount2(mount_info[j-1].dest_path, MNT_DETACH);
442 create_osp_external_paths(const char* app_rootpath, const char* pkgid)
444 char osp_ext_apps_pkgid_path[PATH_MAX] = {0, };
445 char osp_ext_apps_pkgid_share_path[PATH_MAX] = {0, };
446 char osp_ext_apps_pkgid_share2_path[PATH_MAX] = {0, };
447 char osp_ext_share_pkgid_path[PATH_MAX] = {0, };
448 char osp_ext_share2_pkgid_path[PATH_MAX] = {0, };
449 struct _dir_info external_dirs[] =
451 { "./HomeExt", 0000, 0 },
452 { "./ShareExt", 0000, 0 },
453 { "./Share2Ext", 0000, 0 },
454 { "/opt/storage/sdcard/osp", 0777, 0 },
455 { "/opt/storage/sdcard/osp/apps", 0777, 0 },
456 { "/opt/storage/sdcard/osp/share", 0777, 0 },
457 { "/opt/storage/sdcard/osp/share2", 0777, 0 },
463 { "/opt/storage/sdcard/Images", 0777, 0 },
464 { "/opt/storage/sdcard/Sounds", 0777, 0 },
465 { "/opt/storage/sdcard/Videos", 0777, 0 },
466 { "/opt/storage/sdcard/Others", 0777, 0 }
470 strncpy(osp_ext_apps_pkgid_path, _EXT_OSP_HOME_PATH, strlen(_EXT_OSP_HOME_PATH));
471 strncat(osp_ext_apps_pkgid_path, "apps/", 5);
472 strncat(osp_ext_apps_pkgid_path, pkgid, strlen(pkgid));
474 strncpy(osp_ext_apps_pkgid_share_path, osp_ext_apps_pkgid_path, strlen(osp_ext_apps_pkgid_path));
475 strncat(osp_ext_apps_pkgid_share_path, "/Share", 6);
477 strncpy(osp_ext_apps_pkgid_share2_path, osp_ext_apps_pkgid_path, strlen(osp_ext_apps_pkgid_path));
478 strncat(osp_ext_apps_pkgid_share2_path, "/Share2", 7);
480 strncpy(osp_ext_share_pkgid_path, _EXT_OSP_HOME_PATH, strlen(_EXT_OSP_HOME_PATH));
481 strncat(osp_ext_share_pkgid_path, "share/", 6);
482 strncat(osp_ext_share_pkgid_path, pkgid, strlen(pkgid));
484 strncpy(osp_ext_share2_pkgid_path, _EXT_OSP_HOME_PATH, strlen(_EXT_OSP_HOME_PATH));
485 strncat(osp_ext_share2_pkgid_path, "share2/", 7);
486 strncat(osp_ext_share2_pkgid_path, pkgid, strlen(pkgid));
488 strncpy(external_dirs[7].path, osp_ext_apps_pkgid_path, strlen(osp_ext_apps_pkgid_path));
489 strncpy(external_dirs[8].path, osp_ext_apps_pkgid_share_path, strlen(osp_ext_apps_pkgid_share_path));
490 strncpy(external_dirs[9].path, osp_ext_apps_pkgid_share2_path, strlen(osp_ext_apps_pkgid_share2_path));
491 strncpy(external_dirs[10].path, osp_ext_share_pkgid_path, strlen(osp_ext_share_pkgid_path));
492 strncpy(external_dirs[11].path, osp_ext_share2_pkgid_path, strlen(osp_ext_share2_pkgid_path));
494 if (chdir(app_rootpath) != 0)
496 LOGE("chdir() failed (%s), path: %s", strerror(errno), app_rootpath);
500 for (i = 0; i < sizeof(external_dirs)/sizeof(struct _dir_info); i++)
502 int ret = mkdir(external_dirs[i].path, external_dirs[i].mode);
503 if (ret == -1 && errno != 17) // EEXIST
505 LOGE("mkdir() failed, path: %s, errno: %d (%s)", external_dirs[i].path, errno, strerror(errno));
514 mount_osp_external_paths(const char* app_rootpath, const char* pkgid)
516 char osp_ext_apps_pkgid_path[PATH_MAX] = {0, };
517 char osp_ext_share_pkgid_path[PATH_MAX] = {0, };
518 char osp_ext_share2_pkgid_path[PATH_MAX] = {0, };
519 struct _path_info mount_info[] =
521 { "/opt/storage/sdcard", "./Storagecard/Media" },
522 { "/opt/storage/sdcard/osp/share", "./ShareExt" },
523 { "/opt/storage/sdcard/osp/share2", "./Share2Ext" },
524 { "\0", "./HomeExt" },
525 { "\0", "./HomeExt/Share" },
526 { "\0", "./HomeExt/Share2" }
530 strncpy(osp_ext_apps_pkgid_path, _EXT_OSP_HOME_PATH, strlen(_EXT_OSP_HOME_PATH));
531 strncat(osp_ext_apps_pkgid_path, "apps/", 5);
532 strncat(osp_ext_apps_pkgid_path, pkgid, strlen(pkgid));
534 strncpy(osp_ext_share_pkgid_path, _EXT_OSP_HOME_PATH, strlen(_EXT_OSP_HOME_PATH));
535 strncat(osp_ext_share_pkgid_path, "share/", 6);
536 strncat(osp_ext_share_pkgid_path, pkgid, strlen(pkgid));
538 strncpy(osp_ext_share2_pkgid_path, _EXT_OSP_HOME_PATH, strlen(_EXT_OSP_HOME_PATH));
539 strncat(osp_ext_share2_pkgid_path, "share2/", 7);
540 strncat(osp_ext_share2_pkgid_path, pkgid, strlen(pkgid));
542 strncpy(mount_info[3].src_path, osp_ext_apps_pkgid_path, strlen(osp_ext_apps_pkgid_path));
543 strncpy(mount_info[4].src_path, osp_ext_share_pkgid_path, strlen(osp_ext_share_pkgid_path));
544 strncpy(mount_info[5].src_path, osp_ext_share2_pkgid_path, strlen(osp_ext_share2_pkgid_path));
546 if (chdir(app_rootpath) != 0)
548 LOGE("chdir() failed, path: %s, errno: %d (%s)", app_rootpath, errno, strerror(errno));
551 LOGI("app_rootpath: %s", app_rootpath);
553 for (i = 0; i < sizeof(mount_info)/sizeof(struct _path_info); i++)
555 if (mount(mount_info[i].src_path, mount_info[i].dest_path, NULL, MS_BIND, NULL) != 0)
557 LOGE("mount() failed, src path: %s, dest path: %s, errno: %d (%s)",
558 mount_info[i].src_path, mount_info[i].dest_path, errno, strerror(errno));
561 for (j = i; j > 0; --j)
563 umount2(mount_info[j-1].dest_path, MNT_DETACH);
573 do_pre_exe(const char* package_name, const char* bin_path, const char* package_id)
575 char* app_rootpath = NULL;
578 /* e.g., app_rootdir is "/opt/usr/apps/[pkgId] */
579 app_rootpath = get_app_rootpath_from_path(bin_path);
581 _SECURE_LOGI("[data_caging] do_pre_exe() was called, package name: %s, package id: %s, binary: %s, app root: %s",
582 package_name, package_id, bin_path, app_rootpath);
586 if (!internal_is_mounted(package_id))
588 if (mount_native_paths(app_rootpath) != 0)
592 if (mount_osp_internal_paths(app_rootpath, package_id) != 0)
598 int ret = vconf_get_int(VCONFKEY_SYSMAN_MMC_STATUS, &mmc_mounted);
601 LOGE("vconf_get_int(VCONFKEY_SYSMAN_MMC_STATUS) failed.");
603 if (mmc_mounted == 1)
605 LOGI("MMC is mounted.");
606 if (create_osp_external_paths(app_rootpath, package_id) != 0)
611 if (!external_is_mounted(package_id))
613 if (mount_osp_external_paths(app_rootpath, package_id) != 0)
619 LOGI("mount() succeeded.");
621 if (chroot(app_rootpath) != 0)
623 LOGE("chroot() failed, path: %s, errno: %d (%s)", app_rootpath, errno, strerror(errno));
628 LOGE("chdir() failed, path: /, errno: %d (%s)", errno, strerror(errno));
631 LOGI("chroot() succeeded.");
633 if (chdir("/data") != 0)
635 LOGE("chdir() failed, path: /data, errno: %d (%s)", errno, strerror(errno));
642 LOGI("[data_caging] do_pre_exec() succeeded.");
649 LOGI("[data_caging] do_pre_exec() failed.");
654 do_virtual_root(const char* virtual_root_path, const char* package_id)
656 _SECURE_LOGI("[virtual_root] do_virtual_root() was called, virtual root path: %s, package id: %s",
657 virtual_root_path, package_id);
661 if (!internal_is_mounted(package_id))
663 if (mount_linux_paths(virtual_root_path) != 0)
668 LOGI("mount() succeeded.");
670 if (chroot(virtual_root_path) != 0)
672 LOGE("chroot() failed. path: %s, errno: %d (%s)", virtual_root_path, errno, strerror(errno));
677 LOGE("chdir() failed. path: /data, errno: %d (%s)", errno, strerror(errno));
680 LOGI("chroot() succeeded.");
684 LOGI("[virtual_root] do_virtual_root() succeeded.");
690 LOGI("[virtual_root] do_virtual_root() failed.");
695 do_pre_exec(const char* package_name, const char* bin_path)
697 char* app_rootpath = NULL;
698 char app_compat_path[PATH_MAX] = { 0, };
699 const char app_compat_file[] = "/info/compat.info\0";
700 char package_id[_MAX_PACKAGEID_LENGTH + 1] = { 0, };
701 char osp_app_data_path[PATH_MAX] = { 0, };
704 _SECURE_LOGI("do_pre_exec() is called, package name: %s, binary path: %s", package_name, bin_path);
706 app_rootpath = get_app_rootpath_from_path(bin_path);
708 strncpy(app_compat_path, app_rootpath, strlen(app_rootpath));
709 strncat(app_compat_path, app_compat_file, strlen(app_compat_file));
710 if (access(app_compat_path, F_OK) == 0)
716 //if (package_name == NULL)
718 //LOGI("The package name is empty.");
719 get_package_id_from_app_rootpath(app_rootpath, package_id);
724 get_package_id_from_package_name(package_name, package_id);
729 _SECURE_LOGI("package: %s (%s), binary: %s, OSP compat: %d", package_name, package_id, bin_path, osp_compat);
731 // FIXME: Temporary code with security risk
732 prctl(PR_SET_KEEPCAPS, 1);
737 //unshare(CLONE_NEWNS);
738 return do_pre_exe(package_name, bin_path, package_id);
741 char virtual_root_file[PATH_MAX] = { 0, };
742 const char virtual_root_info[] = "/info/virtualroot.info";
743 strncpy(virtual_root_file, app_rootpath, strlen(app_rootpath));
744 strncat(virtual_root_file, virtual_root_info, strlen(virtual_root_info));
745 if (access(virtual_root_file, F_OK) == 0)
747 LOGI("This is virtual root application.");
748 int fd = open(virtual_root_file, O_RDONLY);
751 LOGE("failed to open %s, errno: %d (%s)", virtual_root_file, errno, strerror(errno));
755 char user_path[PATH_MAX] = { 0, };
756 int read_bytes = read(fd, user_path, PATH_MAX);
759 LOGE("failed to read %s, errno: %d (%s)", virtual_root_file, errno, strerror(errno));
765 char virtual_root_path[PATH_MAX] = { 0, };
766 sprintf(virtual_root_path, "%s/data/%s", app_rootpath, user_path);
768 int res = do_virtual_root(virtual_root_path, package_id);
773 // API version is equal to or greater than Tizen 2.0
774 // Set current working dir to "/opt/apps/{pkgId}/data"
775 strncpy(osp_app_data_path, app_rootpath, strlen(app_rootpath));
776 strncat(osp_app_data_path, "/data", strlen("/data"));
778 if (chdir(osp_app_data_path) != 0)
780 LOGE("chdir() failed, path: %s, errno: %d (%s)", osp_app_data_path, errno, strerror(errno));
784 LOGI("[data_caging] do_pre_exec() succeeded.");