Parcel.cpp 68 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248
  1. /*
  2. * Copyright (C) 2005 The Android Open Source Project
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the "License");
  5. * you may not use this file except in compliance with the License.
  6. * You may obtain a copy of the License at
  7. *
  8. * http://www.apache.org/licenses/LICENSE-2.0
  9. *
  10. * Unless required by applicable law or agreed to in writing, software
  11. * distributed under the License is distributed on an "AS IS" BASIS,
  12. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  13. * See the License for the specific language governing permissions and
  14. * limitations under the License.
  15. */
  16. #define LOG_TAG "hw-Parcel"
  17. //#define LOG_NDEBUG 0
  18. #include <errno.h>
  19. #include <fcntl.h>
  20. #include <inttypes.h>
  21. #include <pthread.h>
  22. #include <stdint.h>
  23. #include <stdio.h>
  24. #include <stdlib.h>
  25. #include <sys/mman.h>
  26. #include <sys/stat.h>
  27. #include <sys/types.h>
  28. #include <sys/resource.h>
  29. #include <unistd.h>
  30. #include <hwbinder/Binder.h>
  31. #include <hwbinder/BpHwBinder.h>
  32. #include <hwbinder/IPCThreadState.h>
  33. #include <hwbinder/Parcel.h>
  34. #include <hwbinder/ProcessState.h>
  35. #include <hwbinder/TextOutput.h>
  36. #include <hwbinder/binder_kernel.h>
  37. #include <cutils/ashmem.h>
  38. #include <utils/Debug.h>
  39. #include <utils/Log.h>
  40. #include <utils/misc.h>
  41. #include <utils/String8.h>
  42. #include <utils/String16.h>
  43. #include <private/binder/binder_module.h>
  44. #include <hwbinder/Static.h>
  45. #ifndef INT32_MAX
  46. #define INT32_MAX ((int32_t)(2147483647))
  47. #endif
  48. #define LOG_REFS(...)
  49. //#define LOG_REFS(...) ALOG(LOG_DEBUG, LOG_TAG, __VA_ARGS__)
  50. #define LOG_ALLOC(...)
  51. //#define LOG_ALLOC(...) ALOG(LOG_DEBUG, LOG_TAG, __VA_ARGS__)
  52. #define LOG_BUFFER(...)
  53. // #define LOG_BUFFER(...) ALOG(LOG_DEBUG, LOG_TAG, __VA_ARGS__)
  54. // ---------------------------------------------------------------------------
  55. // This macro should never be used at runtime, as a too large value
  56. // of s could cause an integer overflow. Instead, you should always
  57. // use the wrapper function pad_size()
  58. #define PAD_SIZE_UNSAFE(s) (((s)+3)&~3)
  59. static size_t pad_size(size_t s) {
  60. if (s > (SIZE_T_MAX - 3)) {
  61. abort();
  62. }
  63. return PAD_SIZE_UNSAFE(s);
  64. }
  65. // Note: must be kept in sync with android/os/StrictMode.java's PENALTY_GATHER
  66. #define STRICT_MODE_PENALTY_GATHER (0x40 << 16)
  67. namespace android {
  68. namespace hardware {
  69. static pthread_mutex_t gParcelGlobalAllocSizeLock = PTHREAD_MUTEX_INITIALIZER;
  70. static size_t gParcelGlobalAllocSize = 0;
  71. static size_t gParcelGlobalAllocCount = 0;
  72. static size_t gMaxFds = 0;
  73. static const size_t PARCEL_REF_CAP = 1024;
  74. void acquire_binder_object(const sp<ProcessState>& proc,
  75. const flat_binder_object& obj, const void* who)
  76. {
  77. switch (obj.hdr.type) {
  78. case BINDER_TYPE_BINDER:
  79. if (obj.binder) {
  80. LOG_REFS("Parcel %p acquiring reference on local %p", who, obj.cookie);
  81. reinterpret_cast<IBinder*>(obj.cookie)->incStrong(who);
  82. }
  83. return;
  84. case BINDER_TYPE_WEAK_BINDER:
  85. if (obj.binder)
  86. reinterpret_cast<RefBase::weakref_type*>(obj.binder)->incWeak(who);
  87. return;
  88. case BINDER_TYPE_HANDLE: {
  89. const sp<IBinder> b = proc->getStrongProxyForHandle(obj.handle);
  90. if (b != nullptr) {
  91. LOG_REFS("Parcel %p acquiring reference on remote %p", who, b.get());
  92. b->incStrong(who);
  93. }
  94. return;
  95. }
  96. case BINDER_TYPE_WEAK_HANDLE: {
  97. const wp<IBinder> b = proc->getWeakProxyForHandle(obj.handle);
  98. if (b != nullptr) b.get_refs()->incWeak(who);
  99. return;
  100. }
  101. }
  102. ALOGD("Invalid object type 0x%08x", obj.hdr.type);
  103. }
  104. void acquire_object(const sp<ProcessState>& proc, const binder_object_header& obj,
  105. const void *who) {
  106. switch (obj.type) {
  107. case BINDER_TYPE_BINDER:
  108. case BINDER_TYPE_WEAK_BINDER:
  109. case BINDER_TYPE_HANDLE:
  110. case BINDER_TYPE_WEAK_HANDLE: {
  111. const flat_binder_object& fbo = reinterpret_cast<const flat_binder_object&>(obj);
  112. acquire_binder_object(proc, fbo, who);
  113. break;
  114. }
  115. }
  116. }
  117. void release_object(const sp<ProcessState>& proc,
  118. const flat_binder_object& obj, const void* who)
  119. {
  120. switch (obj.hdr.type) {
  121. case BINDER_TYPE_BINDER:
  122. if (obj.binder) {
  123. LOG_REFS("Parcel %p releasing reference on local %p", who, obj.cookie);
  124. reinterpret_cast<IBinder*>(obj.cookie)->decStrong(who);
  125. }
  126. return;
  127. case BINDER_TYPE_WEAK_BINDER:
  128. if (obj.binder)
  129. reinterpret_cast<RefBase::weakref_type*>(obj.binder)->decWeak(who);
  130. return;
  131. case BINDER_TYPE_HANDLE: {
  132. const sp<IBinder> b = proc->getStrongProxyForHandle(obj.handle);
  133. if (b != nullptr) {
  134. LOG_REFS("Parcel %p releasing reference on remote %p", who, b.get());
  135. b->decStrong(who);
  136. }
  137. return;
  138. }
  139. case BINDER_TYPE_WEAK_HANDLE: {
  140. const wp<IBinder> b = proc->getWeakProxyForHandle(obj.handle);
  141. if (b != nullptr) b.get_refs()->decWeak(who);
  142. return;
  143. }
  144. case BINDER_TYPE_FD: {
  145. if (obj.cookie != 0) { // owned
  146. close(obj.handle);
  147. }
  148. return;
  149. }
  150. case BINDER_TYPE_PTR: {
  151. // The relevant buffer is part of the transaction buffer and will be freed that way
  152. return;
  153. }
  154. case BINDER_TYPE_FDA: {
  155. // The enclosed file descriptors are closed in the kernel
  156. return;
  157. }
  158. }
  159. ALOGE("Invalid object type 0x%08x", obj.hdr.type);
  160. }
  161. inline static status_t finish_flatten_binder(
  162. const sp<IBinder>& /*binder*/, const flat_binder_object& flat, Parcel* out)
  163. {
  164. return out->writeObject(flat);
  165. }
  166. status_t flatten_binder(const sp<ProcessState>& /*proc*/,
  167. const sp<IBinder>& binder, Parcel* out)
  168. {
  169. flat_binder_object obj = {};
  170. if (binder != nullptr) {
  171. BHwBinder *local = binder->localBinder();
  172. if (!local) {
  173. BpHwBinder *proxy = binder->remoteBinder();
  174. if (proxy == nullptr) {
  175. ALOGE("null proxy");
  176. }
  177. const int32_t handle = proxy ? proxy->handle() : 0;
  178. obj.hdr.type = BINDER_TYPE_HANDLE;
  179. obj.flags = FLAT_BINDER_FLAG_ACCEPTS_FDS;
  180. obj.binder = 0; /* Don't pass uninitialized stack data to a remote process */
  181. obj.handle = handle;
  182. obj.cookie = 0;
  183. } else {
  184. // Get policy and convert it
  185. int policy = local->getMinSchedulingPolicy();
  186. int priority = local->getMinSchedulingPriority();
  187. obj.flags = priority & FLAT_BINDER_FLAG_PRIORITY_MASK;
  188. obj.flags |= FLAT_BINDER_FLAG_ACCEPTS_FDS | FLAT_BINDER_FLAG_INHERIT_RT;
  189. obj.flags |= (policy & 3) << FLAT_BINDER_FLAG_SCHEDPOLICY_SHIFT;
  190. if (local->isRequestingSid()) {
  191. obj.flags |= FLAT_BINDER_FLAG_TXN_SECURITY_CTX;
  192. }
  193. obj.hdr.type = BINDER_TYPE_BINDER;
  194. obj.binder = reinterpret_cast<uintptr_t>(local->getWeakRefs());
  195. obj.cookie = reinterpret_cast<uintptr_t>(local);
  196. }
  197. } else {
  198. obj.hdr.type = BINDER_TYPE_BINDER;
  199. obj.binder = 0;
  200. obj.cookie = 0;
  201. }
  202. return finish_flatten_binder(binder, obj, out);
  203. }
  204. status_t flatten_binder(const sp<ProcessState>& /*proc*/,
  205. const wp<IBinder>& binder, Parcel* out)
  206. {
  207. flat_binder_object obj = {};
  208. obj.flags = 0x7f | FLAT_BINDER_FLAG_ACCEPTS_FDS;
  209. if (binder != nullptr) {
  210. sp<IBinder> real = binder.promote();
  211. if (real != nullptr) {
  212. IBinder *local = real->localBinder();
  213. if (!local) {
  214. BpHwBinder *proxy = real->remoteBinder();
  215. if (proxy == nullptr) {
  216. ALOGE("null proxy");
  217. }
  218. const int32_t handle = proxy ? proxy->handle() : 0;
  219. obj.hdr.type = BINDER_TYPE_WEAK_HANDLE;
  220. obj.binder = 0; /* Don't pass uninitialized stack data to a remote process */
  221. obj.handle = handle;
  222. obj.cookie = 0;
  223. } else {
  224. obj.hdr.type = BINDER_TYPE_WEAK_BINDER;
  225. obj.binder = reinterpret_cast<uintptr_t>(binder.get_refs());
  226. obj.cookie = reinterpret_cast<uintptr_t>(binder.unsafe_get());
  227. }
  228. return finish_flatten_binder(real, obj, out);
  229. }
  230. // XXX How to deal? In order to flatten the given binder,
  231. // we need to probe it for information, which requires a primary
  232. // reference... but we don't have one.
  233. //
  234. // The OpenBinder implementation uses a dynamic_cast<> here,
  235. // but we can't do that with the different reference counting
  236. // implementation we are using.
  237. ALOGE("Unable to unflatten Binder weak reference!");
  238. obj.hdr.type = BINDER_TYPE_BINDER;
  239. obj.binder = 0;
  240. obj.cookie = 0;
  241. return finish_flatten_binder(nullptr, obj, out);
  242. } else {
  243. obj.hdr.type = BINDER_TYPE_BINDER;
  244. obj.binder = 0;
  245. obj.cookie = 0;
  246. return finish_flatten_binder(nullptr, obj, out);
  247. }
  248. }
  249. inline static status_t finish_unflatten_binder(
  250. BpHwBinder* /*proxy*/, const flat_binder_object& /*flat*/,
  251. const Parcel& /*in*/)
  252. {
  253. return NO_ERROR;
  254. }
  255. status_t unflatten_binder(const sp<ProcessState>& proc,
  256. const Parcel& in, sp<IBinder>* out)
  257. {
  258. const flat_binder_object* flat = in.readObject<flat_binder_object>();
  259. if (flat) {
  260. switch (flat->hdr.type) {
  261. case BINDER_TYPE_BINDER:
  262. *out = reinterpret_cast<IBinder*>(flat->cookie);
  263. return finish_unflatten_binder(nullptr, *flat, in);
  264. case BINDER_TYPE_HANDLE:
  265. *out = proc->getStrongProxyForHandle(flat->handle);
  266. return finish_unflatten_binder(
  267. static_cast<BpHwBinder*>(out->get()), *flat, in);
  268. }
  269. }
  270. return BAD_TYPE;
  271. }
  272. status_t unflatten_binder(const sp<ProcessState>& proc,
  273. const Parcel& in, wp<IBinder>* out)
  274. {
  275. const flat_binder_object* flat = in.readObject<flat_binder_object>();
  276. if (flat) {
  277. switch (flat->hdr.type) {
  278. case BINDER_TYPE_BINDER:
  279. *out = reinterpret_cast<IBinder*>(flat->cookie);
  280. return finish_unflatten_binder(nullptr, *flat, in);
  281. case BINDER_TYPE_WEAK_BINDER:
  282. if (flat->binder != 0) {
  283. out->set_object_and_refs(
  284. reinterpret_cast<IBinder*>(flat->cookie),
  285. reinterpret_cast<RefBase::weakref_type*>(flat->binder));
  286. } else {
  287. *out = nullptr;
  288. }
  289. return finish_unflatten_binder(nullptr, *flat, in);
  290. case BINDER_TYPE_HANDLE:
  291. case BINDER_TYPE_WEAK_HANDLE:
  292. *out = proc->getWeakProxyForHandle(flat->handle);
  293. return finish_unflatten_binder(
  294. static_cast<BpHwBinder*>(out->unsafe_get()), *flat, in);
  295. }
  296. }
  297. return BAD_TYPE;
  298. }
  299. /*
  300. * Return true iff:
  301. * 1. obj is indeed a binder_buffer_object (type is BINDER_TYPE_PTR), and
  302. * 2. obj does NOT have the flag BINDER_BUFFER_FLAG_REF (it is not a reference, but
  303. * an actual buffer.)
  304. */
  305. static inline bool isBuffer(const binder_buffer_object& obj) {
  306. return obj.hdr.type == BINDER_TYPE_PTR
  307. && (obj.flags & BINDER_BUFFER_FLAG_REF) == 0;
  308. }
  309. // ---------------------------------------------------------------------------
  310. Parcel::Parcel()
  311. {
  312. LOG_ALLOC("Parcel %p: constructing", this);
  313. initState();
  314. }
  315. Parcel::~Parcel()
  316. {
  317. freeDataNoInit();
  318. LOG_ALLOC("Parcel %p: destroyed", this);
  319. }
  320. size_t Parcel::getGlobalAllocSize() {
  321. pthread_mutex_lock(&gParcelGlobalAllocSizeLock);
  322. size_t size = gParcelGlobalAllocSize;
  323. pthread_mutex_unlock(&gParcelGlobalAllocSizeLock);
  324. return size;
  325. }
  326. size_t Parcel::getGlobalAllocCount() {
  327. pthread_mutex_lock(&gParcelGlobalAllocSizeLock);
  328. size_t count = gParcelGlobalAllocCount;
  329. pthread_mutex_unlock(&gParcelGlobalAllocSizeLock);
  330. return count;
  331. }
  332. const uint8_t* Parcel::data() const
  333. {
  334. return mData;
  335. }
  336. size_t Parcel::dataSize() const
  337. {
  338. return (mDataSize > mDataPos ? mDataSize : mDataPos);
  339. }
  340. size_t Parcel::dataAvail() const
  341. {
  342. size_t result = dataSize() - dataPosition();
  343. if (result > INT32_MAX) {
  344. abort();
  345. }
  346. return result;
  347. }
  348. size_t Parcel::dataPosition() const
  349. {
  350. return mDataPos;
  351. }
  352. size_t Parcel::dataCapacity() const
  353. {
  354. return mDataCapacity;
  355. }
  356. status_t Parcel::setDataSize(size_t size)
  357. {
  358. if (size > INT32_MAX) {
  359. // don't accept size_t values which may have come from an
  360. // inadvertent conversion from a negative int.
  361. return BAD_VALUE;
  362. }
  363. status_t err;
  364. err = continueWrite(size);
  365. if (err == NO_ERROR) {
  366. mDataSize = size;
  367. ALOGV("setDataSize Setting data size of %p to %zu", this, mDataSize);
  368. }
  369. return err;
  370. }
  371. void Parcel::setDataPosition(size_t pos) const
  372. {
  373. if (pos > INT32_MAX) {
  374. // don't accept size_t values which may have come from an
  375. // inadvertent conversion from a negative int.
  376. abort();
  377. }
  378. mDataPos = pos;
  379. mNextObjectHint = 0;
  380. }
  381. status_t Parcel::setDataCapacity(size_t size)
  382. {
  383. if (size > INT32_MAX) {
  384. // don't accept size_t values which may have come from an
  385. // inadvertent conversion from a negative int.
  386. return BAD_VALUE;
  387. }
  388. if (size > mDataCapacity) return continueWrite(size);
  389. return NO_ERROR;
  390. }
  391. status_t Parcel::setData(const uint8_t* buffer, size_t len)
  392. {
  393. if (len > INT32_MAX) {
  394. // don't accept size_t values which may have come from an
  395. // inadvertent conversion from a negative int.
  396. return BAD_VALUE;
  397. }
  398. status_t err = restartWrite(len);
  399. if (err == NO_ERROR) {
  400. memcpy(const_cast<uint8_t*>(data()), buffer, len);
  401. mDataSize = len;
  402. mFdsKnown = false;
  403. }
  404. return err;
  405. }
  406. // Write RPC headers. (previously just the interface token)
  407. status_t Parcel::writeInterfaceToken(const char* interface)
  408. {
  409. // currently the interface identification token is just its name as a string
  410. return writeCString(interface);
  411. }
  412. bool Parcel::enforceInterface(const char* interface) const
  413. {
  414. const char* str = readCString();
  415. if (str != nullptr && strcmp(str, interface) == 0) {
  416. return true;
  417. } else {
  418. ALOGW("**** enforceInterface() expected '%s' but read '%s'",
  419. interface, (str ? str : "<empty string>"));
  420. return false;
  421. }
  422. }
  423. const binder_size_t* Parcel::objects() const
  424. {
  425. return mObjects;
  426. }
  427. size_t Parcel::objectsCount() const
  428. {
  429. return mObjectsSize;
  430. }
  431. status_t Parcel::errorCheck() const
  432. {
  433. return mError;
  434. }
  435. void Parcel::setError(status_t err)
  436. {
  437. mError = err;
  438. }
  439. status_t Parcel::finishWrite(size_t len)
  440. {
  441. if (len > INT32_MAX) {
  442. // don't accept size_t values which may have come from an
  443. // inadvertent conversion from a negative int.
  444. return BAD_VALUE;
  445. }
  446. //printf("Finish write of %d\n", len);
  447. mDataPos += len;
  448. ALOGV("finishWrite Setting data pos of %p to %zu", this, mDataPos);
  449. if (mDataPos > mDataSize) {
  450. mDataSize = mDataPos;
  451. ALOGV("finishWrite Setting data size of %p to %zu", this, mDataSize);
  452. }
  453. //printf("New pos=%d, size=%d\n", mDataPos, mDataSize);
  454. return NO_ERROR;
  455. }
  456. status_t Parcel::writeUnpadded(const void* data, size_t len)
  457. {
  458. if (len > INT32_MAX) {
  459. // don't accept size_t values which may have come from an
  460. // inadvertent conversion from a negative int.
  461. return BAD_VALUE;
  462. }
  463. size_t end = mDataPos + len;
  464. if (end < mDataPos) {
  465. // integer overflow
  466. return BAD_VALUE;
  467. }
  468. if (end <= mDataCapacity) {
  469. restart_write:
  470. memcpy(mData+mDataPos, data, len);
  471. return finishWrite(len);
  472. }
  473. status_t err = growData(len);
  474. if (err == NO_ERROR) goto restart_write;
  475. return err;
  476. }
  477. status_t Parcel::write(const void* data, size_t len)
  478. {
  479. if (len > INT32_MAX) {
  480. // don't accept size_t values which may have come from an
  481. // inadvertent conversion from a negative int.
  482. return BAD_VALUE;
  483. }
  484. void* const d = writeInplace(len);
  485. if (d) {
  486. memcpy(d, data, len);
  487. return NO_ERROR;
  488. }
  489. return mError;
  490. }
  491. void* Parcel::writeInplace(size_t len)
  492. {
  493. if (len > INT32_MAX) {
  494. // don't accept size_t values which may have come from an
  495. // inadvertent conversion from a negative int.
  496. return nullptr;
  497. }
  498. const size_t padded = pad_size(len);
  499. // sanity check for integer overflow
  500. if (mDataPos+padded < mDataPos) {
  501. return nullptr;
  502. }
  503. if ((mDataPos+padded) <= mDataCapacity) {
  504. restart_write:
  505. //printf("Writing %ld bytes, padded to %ld\n", len, padded);
  506. uint8_t* const data = mData+mDataPos;
  507. // Need to pad at end?
  508. if (padded != len) {
  509. #if BYTE_ORDER == BIG_ENDIAN
  510. static const uint32_t mask[4] = {
  511. 0x00000000, 0xffffff00, 0xffff0000, 0xff000000
  512. };
  513. #endif
  514. #if BYTE_ORDER == LITTLE_ENDIAN
  515. static const uint32_t mask[4] = {
  516. 0x00000000, 0x00ffffff, 0x0000ffff, 0x000000ff
  517. };
  518. #endif
  519. //printf("Applying pad mask: %p to %p\n", (void*)mask[padded-len],
  520. // *reinterpret_cast<void**>(data+padded-4));
  521. *reinterpret_cast<uint32_t*>(data+padded-4) &= mask[padded-len];
  522. }
  523. finishWrite(padded);
  524. return data;
  525. }
  526. status_t err = growData(padded);
  527. if (err == NO_ERROR) goto restart_write;
  528. return nullptr;
  529. }
  530. status_t Parcel::writeInt8(int8_t val)
  531. {
  532. return write(&val, sizeof(val));
  533. }
  534. status_t Parcel::writeUint8(uint8_t val)
  535. {
  536. return write(&val, sizeof(val));
  537. }
  538. status_t Parcel::writeInt16(int16_t val)
  539. {
  540. return write(&val, sizeof(val));
  541. }
  542. status_t Parcel::writeUint16(uint16_t val)
  543. {
  544. return write(&val, sizeof(val));
  545. }
  546. status_t Parcel::writeInt32(int32_t val)
  547. {
  548. return writeAligned(val);
  549. }
  550. status_t Parcel::writeUint32(uint32_t val)
  551. {
  552. return writeAligned(val);
  553. }
  554. status_t Parcel::writeBool(bool val)
  555. {
  556. return writeInt8(int8_t(val));
  557. }
  558. status_t Parcel::writeInt64(int64_t val)
  559. {
  560. return writeAligned(val);
  561. }
  562. status_t Parcel::writeUint64(uint64_t val)
  563. {
  564. return writeAligned(val);
  565. }
  566. status_t Parcel::writePointer(uintptr_t val)
  567. {
  568. return writeAligned<binder_uintptr_t>(val);
  569. }
  570. status_t Parcel::writeFloat(float val)
  571. {
  572. return writeAligned(val);
  573. }
  574. #if defined(__mips__) && defined(__mips_hard_float)
  575. status_t Parcel::writeDouble(double val)
  576. {
  577. union {
  578. double d;
  579. unsigned long long ll;
  580. } u;
  581. u.d = val;
  582. return writeAligned(u.ll);
  583. }
  584. #else
  585. status_t Parcel::writeDouble(double val)
  586. {
  587. return writeAligned(val);
  588. }
  589. #endif
  590. status_t Parcel::writeCString(const char* str)
  591. {
  592. return write(str, strlen(str)+1);
  593. }
  594. status_t Parcel::writeString16(const std::unique_ptr<String16>& str)
  595. {
  596. if (!str) {
  597. return writeInt32(-1);
  598. }
  599. return writeString16(*str);
  600. }
  601. status_t Parcel::writeString16(const String16& str)
  602. {
  603. return writeString16(str.string(), str.size());
  604. }
  605. status_t Parcel::writeString16(const char16_t* str, size_t len)
  606. {
  607. if (str == nullptr) return writeInt32(-1);
  608. status_t err = writeInt32(len);
  609. if (err == NO_ERROR) {
  610. len *= sizeof(char16_t);
  611. uint8_t* data = (uint8_t*)writeInplace(len+sizeof(char16_t));
  612. if (data) {
  613. memcpy(data, str, len);
  614. *reinterpret_cast<char16_t*>(data+len) = 0;
  615. return NO_ERROR;
  616. }
  617. err = mError;
  618. }
  619. return err;
  620. }
  621. status_t Parcel::writeStrongBinder(const sp<IBinder>& val)
  622. {
  623. return flatten_binder(ProcessState::self(), val, this);
  624. }
  625. status_t Parcel::writeWeakBinder(const wp<IBinder>& val)
  626. {
  627. return flatten_binder(ProcessState::self(), val, this);
  628. }
  629. template <typename T>
  630. status_t Parcel::writeObject(const T& val)
  631. {
  632. const bool enoughData = (mDataPos+sizeof(val)) <= mDataCapacity;
  633. const bool enoughObjects = mObjectsSize < mObjectsCapacity;
  634. if (enoughData && enoughObjects) {
  635. restart_write:
  636. *reinterpret_cast<T*>(mData+mDataPos) = val;
  637. const binder_object_header* hdr = reinterpret_cast<binder_object_header*>(mData+mDataPos);
  638. switch (hdr->type) {
  639. case BINDER_TYPE_BINDER:
  640. case BINDER_TYPE_WEAK_BINDER:
  641. case BINDER_TYPE_HANDLE:
  642. case BINDER_TYPE_WEAK_HANDLE: {
  643. const flat_binder_object *fbo = reinterpret_cast<const flat_binder_object*>(hdr);
  644. if (fbo->binder != 0) {
  645. mObjects[mObjectsSize++] = mDataPos;
  646. acquire_binder_object(ProcessState::self(), *fbo, this);
  647. }
  648. break;
  649. }
  650. case BINDER_TYPE_FD: {
  651. // remember if it's a file descriptor
  652. if (!mAllowFds) {
  653. // fail before modifying our object index
  654. return FDS_NOT_ALLOWED;
  655. }
  656. mHasFds = mFdsKnown = true;
  657. mObjects[mObjectsSize++] = mDataPos;
  658. break;
  659. }
  660. case BINDER_TYPE_FDA:
  661. mObjects[mObjectsSize++] = mDataPos;
  662. break;
  663. case BINDER_TYPE_PTR: {
  664. const binder_buffer_object *buffer_obj = reinterpret_cast<
  665. const binder_buffer_object*>(hdr);
  666. if ((void *)buffer_obj->buffer != nullptr) {
  667. mObjects[mObjectsSize++] = mDataPos;
  668. }
  669. break;
  670. }
  671. default: {
  672. ALOGE("writeObject: unknown type %d", hdr->type);
  673. break;
  674. }
  675. }
  676. return finishWrite(sizeof(val));
  677. }
  678. if (!enoughData) {
  679. const status_t err = growData(sizeof(val));
  680. if (err != NO_ERROR) return err;
  681. }
  682. if (!enoughObjects) {
  683. size_t newSize = ((mObjectsSize+2)*3)/2;
  684. if (newSize * sizeof(binder_size_t) < mObjectsSize) return NO_MEMORY; // overflow
  685. binder_size_t* objects = (binder_size_t*)realloc(mObjects, newSize*sizeof(binder_size_t));
  686. if (objects == nullptr) return NO_MEMORY;
  687. mObjects = objects;
  688. mObjectsCapacity = newSize;
  689. }
  690. goto restart_write;
  691. }
  692. template status_t Parcel::writeObject<flat_binder_object>(const flat_binder_object& val);
  693. template status_t Parcel::writeObject<binder_fd_object>(const binder_fd_object& val);
  694. template status_t Parcel::writeObject<binder_buffer_object>(const binder_buffer_object& val);
  695. template status_t Parcel::writeObject<binder_fd_array_object>(const binder_fd_array_object& val);
  696. // TODO merge duplicated code in writeEmbeddedBuffer, writeEmbeddedReference, and writeEmbeddedNullReference
  697. // TODO merge duplicated code in writeBuffer, writeReference, and writeNullReference
  698. bool Parcel::validateBufferChild(size_t child_buffer_handle,
  699. size_t child_offset) const {
  700. if (child_buffer_handle >= mObjectsSize)
  701. return false;
  702. binder_buffer_object *child = reinterpret_cast<binder_buffer_object*>
  703. (mData + mObjects[child_buffer_handle]);
  704. if (!isBuffer(*child) || child_offset > child->length) {
  705. // Parent object not a buffer, or not large enough
  706. LOG_BUFFER("writeEmbeddedReference found wierd child. "
  707. "child_offset = %zu, child->length = %zu",
  708. child_offset, (size_t)child->length);
  709. return false;
  710. }
  711. return true;
  712. }
  713. bool Parcel::validateBufferParent(size_t parent_buffer_handle,
  714. size_t parent_offset) const {
  715. if (parent_buffer_handle >= mObjectsSize)
  716. return false;
  717. binder_buffer_object *parent = reinterpret_cast<binder_buffer_object*>
  718. (mData + mObjects[parent_buffer_handle]);
  719. if (!isBuffer(*parent) ||
  720. sizeof(binder_uintptr_t) > parent->length ||
  721. parent_offset > parent->length - sizeof(binder_uintptr_t)) {
  722. // Parent object not a buffer, or not large enough
  723. return false;
  724. }
  725. return true;
  726. }
  727. status_t Parcel::writeEmbeddedBuffer(
  728. const void *buffer, size_t length, size_t *handle,
  729. size_t parent_buffer_handle, size_t parent_offset) {
  730. LOG_BUFFER("writeEmbeddedBuffer(%p, %zu, parent = (%zu, %zu)) -> %zu",
  731. buffer, length, parent_buffer_handle,
  732. parent_offset, mObjectsSize);
  733. if(!validateBufferParent(parent_buffer_handle, parent_offset))
  734. return BAD_VALUE;
  735. binder_buffer_object obj = {
  736. .hdr = { .type = BINDER_TYPE_PTR },
  737. .buffer = reinterpret_cast<binder_uintptr_t>(buffer),
  738. .length = length,
  739. .flags = BINDER_BUFFER_FLAG_HAS_PARENT,
  740. .parent = parent_buffer_handle,
  741. .parent_offset = parent_offset,
  742. };
  743. if (handle != nullptr) {
  744. // We use an index into mObjects as a handle
  745. *handle = mObjectsSize;
  746. }
  747. return writeObject(obj);
  748. }
  749. status_t Parcel::writeBuffer(const void *buffer, size_t length, size_t *handle)
  750. {
  751. LOG_BUFFER("writeBuffer(%p, %zu) -> %zu",
  752. buffer, length, mObjectsSize);
  753. binder_buffer_object obj {
  754. .hdr = { .type = BINDER_TYPE_PTR },
  755. .buffer = reinterpret_cast<binder_uintptr_t>(buffer),
  756. .length = length,
  757. .flags = 0,
  758. };
  759. if (handle != nullptr) {
  760. // We use an index into mObjects as a handle
  761. *handle = mObjectsSize;
  762. }
  763. return writeObject(obj);
  764. }
  765. status_t Parcel::incrementNumReferences() {
  766. ++mNumRef;
  767. LOG_BUFFER("incrementNumReferences: %zu", mNumRef);
  768. return mNumRef <= PARCEL_REF_CAP ? OK : NO_MEMORY;
  769. }
  770. status_t Parcel::writeReference(size_t *handle,
  771. size_t child_buffer_handle, size_t child_offset) {
  772. LOG_BUFFER("writeReference(child = (%zu, %zu)) -> %zu",
  773. child_buffer_handle, child_offset,
  774. mObjectsSize);
  775. status_t status = incrementNumReferences();
  776. if (status != OK)
  777. return status;
  778. if (!validateBufferChild(child_buffer_handle, child_offset))
  779. return BAD_VALUE;
  780. binder_buffer_object obj {
  781. .hdr = { .type = BINDER_TYPE_PTR },
  782. .flags = BINDER_BUFFER_FLAG_REF,
  783. // The current binder.h does not have child and child_offset names yet.
  784. // Use the buffer and length parameters.
  785. .buffer = child_buffer_handle,
  786. .length = child_offset,
  787. };
  788. if (handle != nullptr)
  789. // We use an index into mObjects as a handle
  790. *handle = mObjectsSize;
  791. return writeObject(obj);
  792. }
  793. /* Write an object that describes a pointer from parent to child.
  794. * Output the handle of that object in the size_t *handle variable. */
  795. status_t Parcel::writeEmbeddedReference(size_t *handle,
  796. size_t child_buffer_handle, size_t child_offset,
  797. size_t parent_buffer_handle, size_t parent_offset) {
  798. LOG_BUFFER("writeEmbeddedReference(child = (%zu, %zu), parent = (%zu, %zu)) -> %zu",
  799. child_buffer_handle, child_offset,
  800. parent_buffer_handle, parent_offset,
  801. mObjectsSize);
  802. status_t status = incrementNumReferences();
  803. if (status != OK)
  804. return status;
  805. // The current binder.h does not have child and child_offset names yet.
  806. // Use the buffer and length parameters.
  807. if (!validateBufferChild(child_buffer_handle, child_offset))
  808. return BAD_VALUE;
  809. if(!validateBufferParent(parent_buffer_handle, parent_offset))
  810. return BAD_VALUE;
  811. binder_buffer_object obj {
  812. .hdr = { .type = BINDER_TYPE_PTR },
  813. .flags = BINDER_BUFFER_FLAG_REF | BINDER_BUFFER_FLAG_HAS_PARENT,
  814. .buffer = child_buffer_handle,
  815. .length = child_offset,
  816. .parent = parent_buffer_handle,
  817. .parent_offset = parent_offset,
  818. };
  819. if (handle != nullptr) {
  820. // We use an index into mObjects as a handle
  821. *handle = mObjectsSize;
  822. }
  823. return writeObject(obj);
  824. }
  825. status_t Parcel::writeNullReference(size_t * handle) {
  826. LOG_BUFFER("writeNullReference -> %zu", mObjectsSize);
  827. status_t status = incrementNumReferences();
  828. if (status != OK)
  829. return status;
  830. binder_buffer_object obj {
  831. .hdr = { .type = BINDER_TYPE_PTR },
  832. .flags = BINDER_BUFFER_FLAG_REF,
  833. };
  834. if (handle != nullptr)
  835. // We use an index into mObjects as a handle
  836. *handle = mObjectsSize;
  837. return writeObject(obj);
  838. }
  839. status_t Parcel::writeEmbeddedNullReference(size_t * handle,
  840. size_t parent_buffer_handle, size_t parent_offset) {
  841. LOG_BUFFER("writeEmbeddedNullReference(parent = (%zu, %zu)) -> %zu",
  842. parent_buffer_handle,
  843. parent_offset,
  844. mObjectsSize);
  845. status_t status = incrementNumReferences();
  846. if (status != OK)
  847. return status;
  848. if(!validateBufferParent(parent_buffer_handle, parent_offset))
  849. return BAD_VALUE;
  850. binder_buffer_object obj {
  851. .hdr = { .type = BINDER_TYPE_PTR, },
  852. .flags = BINDER_BUFFER_FLAG_REF | BINDER_BUFFER_FLAG_HAS_PARENT,
  853. .parent = parent_buffer_handle,
  854. .parent_offset = parent_offset,
  855. };
  856. if (handle != nullptr) {
  857. // We use an index into mObjects as a handle
  858. *handle = mObjectsSize;
  859. }
  860. return writeObject(obj);
  861. }
  862. void Parcel::clearCache() const {
  863. LOG_BUFFER("clearing cache.");
  864. mBufCachePos = 0;
  865. mBufCache.clear();
  866. }
  867. void Parcel::updateCache() const {
  868. if(mBufCachePos == mObjectsSize)
  869. return;
  870. LOG_BUFFER("updating cache from %zu to %zu", mBufCachePos, mObjectsSize);
  871. for(size_t i = mBufCachePos; i < mObjectsSize; i++) {
  872. binder_size_t dataPos = mObjects[i];
  873. binder_buffer_object *obj =
  874. reinterpret_cast<binder_buffer_object*>(mData+dataPos);
  875. if(!isBuffer(*obj))
  876. continue;
  877. BufferInfo ifo;
  878. ifo.index = i;
  879. ifo.buffer = obj->buffer;
  880. ifo.bufend = obj->buffer + obj->length;
  881. mBufCache.push_back(ifo);
  882. }
  883. mBufCachePos = mObjectsSize;
  884. }
  885. /* O(n) (n=#buffers) to find a buffer that contains the given addr */
  886. status_t Parcel::findBuffer(const void *ptr, size_t length, bool *found,
  887. size_t *handle, size_t *offset) const {
  888. if(found == nullptr)
  889. return UNKNOWN_ERROR;
  890. updateCache();
  891. binder_uintptr_t ptrVal = reinterpret_cast<binder_uintptr_t>(ptr);
  892. // true if the pointer is in some buffer, but the length is too big
  893. // so that ptr + length doesn't fit into the buffer.
  894. bool suspectRejectBadPointer = false;
  895. LOG_BUFFER("findBuffer examining %zu objects.", mObjectsSize);
  896. for(auto entry = mBufCache.rbegin(); entry != mBufCache.rend(); ++entry ) {
  897. if(entry->buffer <= ptrVal && ptrVal < entry->bufend) {
  898. // might have found it.
  899. if(ptrVal + length <= entry->bufend) {
  900. *found = true;
  901. if(handle != nullptr) *handle = entry->index;
  902. if(offset != nullptr) *offset = ptrVal - entry->buffer;
  903. LOG_BUFFER(" findBuffer has a match at %zu!", entry->index);
  904. return OK;
  905. } else {
  906. suspectRejectBadPointer = true;
  907. }
  908. }
  909. }
  910. LOG_BUFFER("findBuffer did not find for ptr = %p.", ptr);
  911. *found = false;
  912. return suspectRejectBadPointer ? BAD_VALUE : OK;
  913. }
  914. /* findBuffer with the assumption that ptr = .buffer (so it points to top
  915. * of the buffer, aka offset 0).
  916. * */
  917. status_t Parcel::quickFindBuffer(const void *ptr, size_t *handle) const {
  918. updateCache();
  919. binder_uintptr_t ptrVal = reinterpret_cast<binder_uintptr_t>(ptr);
  920. LOG_BUFFER("quickFindBuffer examining %zu objects.", mObjectsSize);
  921. for(auto entry = mBufCache.rbegin(); entry != mBufCache.rend(); ++entry ) {
  922. if(entry->buffer == ptrVal) {
  923. if(handle != nullptr) *handle = entry->index;
  924. return OK;
  925. }
  926. }
  927. LOG_BUFFER("quickFindBuffer did not find for ptr = %p.", ptr);
  928. return NO_INIT;
  929. }
  930. status_t Parcel::writeNativeHandleNoDup(const native_handle_t *handle,
  931. bool embedded,
  932. size_t parent_buffer_handle,
  933. size_t parent_offset)
  934. {
  935. size_t buffer_handle;
  936. status_t status = OK;
  937. if (handle == nullptr) {
  938. status = writeUint64(0);
  939. return status;
  940. }
  941. size_t native_handle_size = sizeof(native_handle_t)
  942. + handle->numFds * sizeof(int) + handle->numInts * sizeof(int);
  943. writeUint64(native_handle_size);
  944. if (embedded) {
  945. status = writeEmbeddedBuffer((void*) handle,
  946. native_handle_size, &buffer_handle,
  947. parent_buffer_handle, parent_offset);
  948. } else {
  949. status = writeBuffer((void*) handle, native_handle_size, &buffer_handle);
  950. }
  951. if (status != OK) {
  952. return status;
  953. }
  954. struct binder_fd_array_object fd_array {
  955. .hdr = { .type = BINDER_TYPE_FDA },
  956. .num_fds = static_cast<binder_size_t>(handle->numFds),
  957. .parent = buffer_handle,
  958. .parent_offset = offsetof(native_handle_t, data),
  959. };
  960. return writeObject(fd_array);
  961. }
  962. status_t Parcel::writeNativeHandleNoDup(const native_handle_t *handle)
  963. {
  964. return writeNativeHandleNoDup(handle, false /* embedded */);
  965. }
  966. status_t Parcel::writeEmbeddedNativeHandle(const native_handle_t *handle,
  967. size_t parent_buffer_handle,
  968. size_t parent_offset)
  969. {
  970. return writeNativeHandleNoDup(handle, true /* embedded */,
  971. parent_buffer_handle, parent_offset);
  972. }
  973. void Parcel::remove(size_t /*start*/, size_t /*amt*/)
  974. {
  975. LOG_ALWAYS_FATAL("Parcel::remove() not yet implemented!");
  976. }
  977. status_t Parcel::read(void* outData, size_t len) const
  978. {
  979. if (len > INT32_MAX) {
  980. // don't accept size_t values which may have come from an
  981. // inadvertent conversion from a negative int.
  982. return BAD_VALUE;
  983. }
  984. if ((mDataPos+pad_size(len)) >= mDataPos && (mDataPos+pad_size(len)) <= mDataSize
  985. && len <= pad_size(len)) {
  986. memcpy(outData, mData+mDataPos, len);
  987. mDataPos += pad_size(len);
  988. ALOGV("read Setting data pos of %p to %zu", this, mDataPos);
  989. return NO_ERROR;
  990. }
  991. return NOT_ENOUGH_DATA;
  992. }
  993. const void* Parcel::readInplace(size_t len) const
  994. {
  995. if (len > INT32_MAX) {
  996. // don't accept size_t values which may have come from an
  997. // inadvertent conversion from a negative int.
  998. return nullptr;
  999. }
  1000. if ((mDataPos+pad_size(len)) >= mDataPos && (mDataPos+pad_size(len)) <= mDataSize
  1001. && len <= pad_size(len)) {
  1002. const void* data = mData+mDataPos;
  1003. mDataPos += pad_size(len);
  1004. ALOGV("readInplace Setting data pos of %p to %zu", this, mDataPos);
  1005. return data;
  1006. }
  1007. return nullptr;
  1008. }
  1009. template<class T>
  1010. status_t Parcel::readAligned(T *pArg) const {
  1011. COMPILE_TIME_ASSERT_FUNCTION_SCOPE(PAD_SIZE_UNSAFE(sizeof(T)) == sizeof(T));
  1012. if ((mDataPos+sizeof(T)) <= mDataSize) {
  1013. const void* data = mData+mDataPos;
  1014. mDataPos += sizeof(T);
  1015. *pArg = *reinterpret_cast<const T*>(data);
  1016. return NO_ERROR;
  1017. } else {
  1018. return NOT_ENOUGH_DATA;
  1019. }
  1020. }
  1021. template<class T>
  1022. T Parcel::readAligned() const {
  1023. T result;
  1024. if (readAligned(&result) != NO_ERROR) {
  1025. result = 0;
  1026. }
  1027. return result;
  1028. }
  1029. template<class T>
  1030. status_t Parcel::writeAligned(T val) {
  1031. COMPILE_TIME_ASSERT_FUNCTION_SCOPE(PAD_SIZE_UNSAFE(sizeof(T)) == sizeof(T));
  1032. if ((mDataPos+sizeof(val)) <= mDataCapacity) {
  1033. restart_write:
  1034. *reinterpret_cast<T*>(mData+mDataPos) = val;
  1035. return finishWrite(sizeof(val));
  1036. }
  1037. status_t err = growData(sizeof(val));
  1038. if (err == NO_ERROR) goto restart_write;
  1039. return err;
  1040. }
  1041. status_t Parcel::readInt8(int8_t *pArg) const
  1042. {
  1043. return read(pArg, sizeof(*pArg));
  1044. }
  1045. status_t Parcel::readUint8(uint8_t *pArg) const
  1046. {
  1047. return read(pArg, sizeof(*pArg));
  1048. }
  1049. status_t Parcel::readInt16(int16_t *pArg) const
  1050. {
  1051. return read(pArg, sizeof(*pArg));
  1052. }
  1053. status_t Parcel::readUint16(uint16_t *pArg) const
  1054. {
  1055. return read(pArg, sizeof(*pArg));
  1056. }
  1057. status_t Parcel::readInt32(int32_t *pArg) const
  1058. {
  1059. return readAligned(pArg);
  1060. }
  1061. int32_t Parcel::readInt32() const
  1062. {
  1063. return readAligned<int32_t>();
  1064. }
  1065. status_t Parcel::readUint32(uint32_t *pArg) const
  1066. {
  1067. return readAligned(pArg);
  1068. }
  1069. uint32_t Parcel::readUint32() const
  1070. {
  1071. return readAligned<uint32_t>();
  1072. }
  1073. status_t Parcel::readInt64(int64_t *pArg) const
  1074. {
  1075. return readAligned(pArg);
  1076. }
  1077. int64_t Parcel::readInt64() const
  1078. {
  1079. return readAligned<int64_t>();
  1080. }
  1081. status_t Parcel::readUint64(uint64_t *pArg) const
  1082. {
  1083. return readAligned(pArg);
  1084. }
  1085. uint64_t Parcel::readUint64() const
  1086. {
  1087. return readAligned<uint64_t>();
  1088. }
  1089. status_t Parcel::readPointer(uintptr_t *pArg) const
  1090. {
  1091. status_t ret;
  1092. binder_uintptr_t ptr;
  1093. ret = readAligned(&ptr);
  1094. if (!ret)
  1095. *pArg = ptr;
  1096. return ret;
  1097. }
  1098. uintptr_t Parcel::readPointer() const
  1099. {
  1100. return readAligned<binder_uintptr_t>();
  1101. }
  1102. status_t Parcel::readFloat(float *pArg) const
  1103. {
  1104. return readAligned(pArg);
  1105. }
  1106. float Parcel::readFloat() const
  1107. {
  1108. return readAligned<float>();
  1109. }
  1110. #if defined(__mips__) && defined(__mips_hard_float)
  1111. status_t Parcel::readDouble(double *pArg) const
  1112. {
  1113. union {
  1114. double d;
  1115. unsigned long long ll;
  1116. } u;
  1117. u.d = 0;
  1118. status_t status;
  1119. status = readAligned(&u.ll);
  1120. *pArg = u.d;
  1121. return status;
  1122. }
  1123. double Parcel::readDouble() const
  1124. {
  1125. union {
  1126. double d;
  1127. unsigned long long ll;
  1128. } u;
  1129. u.ll = readAligned<unsigned long long>();
  1130. return u.d;
  1131. }
  1132. #else
  1133. status_t Parcel::readDouble(double *pArg) const
  1134. {
  1135. return readAligned(pArg);
  1136. }
  1137. double Parcel::readDouble() const
  1138. {
  1139. return readAligned<double>();
  1140. }
  1141. #endif
  1142. status_t Parcel::readBool(bool *pArg) const
  1143. {
  1144. int8_t tmp;
  1145. status_t ret = readInt8(&tmp);
  1146. *pArg = (tmp != 0);
  1147. return ret;
  1148. }
  1149. bool Parcel::readBool() const
  1150. {
  1151. int8_t tmp;
  1152. status_t err = readInt8(&tmp);
  1153. if (err != OK) {
  1154. return 0;
  1155. }
  1156. return tmp != 0;
  1157. }
  1158. const char* Parcel::readCString() const
  1159. {
  1160. if (mDataPos < mDataSize) {
  1161. const size_t avail = mDataSize-mDataPos;
  1162. const char* str = reinterpret_cast<const char*>(mData+mDataPos);
  1163. // is the string's trailing NUL within the parcel's valid bounds?
  1164. const char* eos = reinterpret_cast<const char*>(memchr(str, 0, avail));
  1165. if (eos) {
  1166. const size_t len = eos - str;
  1167. mDataPos += pad_size(len+1);
  1168. ALOGV("readCString Setting data pos of %p to %zu", this, mDataPos);
  1169. return str;
  1170. }
  1171. }
  1172. return nullptr;
  1173. }
  1174. String16 Parcel::readString16() const
  1175. {
  1176. size_t len;
  1177. const char16_t* str = readString16Inplace(&len);
  1178. if (str) return String16(str, len);
  1179. ALOGE("Reading a NULL string not supported here.");
  1180. return String16();
  1181. }
  1182. status_t Parcel::readString16(std::unique_ptr<String16>* pArg) const
  1183. {
  1184. const int32_t start = dataPosition();
  1185. int32_t size;
  1186. status_t status = readInt32(&size);
  1187. pArg->reset();
  1188. if (status != OK || size < 0) {
  1189. return status;
  1190. }
  1191. setDataPosition(start);
  1192. pArg->reset(new (std::nothrow) String16());
  1193. status = readString16(pArg->get());
  1194. if (status != OK) {
  1195. pArg->reset();
  1196. }
  1197. return status;
  1198. }
  1199. status_t Parcel::readString16(String16* pArg) const
  1200. {
  1201. size_t len;
  1202. const char16_t* str = readString16Inplace(&len);
  1203. if (str) {
  1204. pArg->setTo(str, len);
  1205. return 0;
  1206. } else {
  1207. *pArg = String16();
  1208. return UNEXPECTED_NULL;
  1209. }
  1210. }
  1211. const char16_t* Parcel::readString16Inplace(size_t* outLen) const
  1212. {
  1213. int32_t size = readInt32();
  1214. // watch for potential int overflow from size+1
  1215. if (size >= 0 && size < INT32_MAX) {
  1216. *outLen = size;
  1217. const char16_t* str = (const char16_t*)readInplace((size+1)*sizeof(char16_t));
  1218. if (str != nullptr) {
  1219. return str;
  1220. }
  1221. }
  1222. *outLen = 0;
  1223. return nullptr;
  1224. }
  1225. status_t Parcel::readStrongBinder(sp<IBinder>* val) const
  1226. {
  1227. status_t status = readNullableStrongBinder(val);
  1228. if (status == OK && !val->get()) {
  1229. status = UNEXPECTED_NULL;
  1230. }
  1231. return status;
  1232. }
  1233. status_t Parcel::readNullableStrongBinder(sp<IBinder>* val) const
  1234. {
  1235. return unflatten_binder(ProcessState::self(), *this, val);
  1236. }
  1237. sp<IBinder> Parcel::readStrongBinder() const
  1238. {
  1239. sp<IBinder> val;
  1240. // Note that a lot of code in Android reads binders by hand with this
  1241. // method, and that code has historically been ok with getting nullptr
  1242. // back (while ignoring error codes).
  1243. readNullableStrongBinder(&val);
  1244. return val;
  1245. }
  1246. wp<IBinder> Parcel::readWeakBinder() const
  1247. {
  1248. wp<IBinder> val;
  1249. unflatten_binder(ProcessState::self(), *this, &val);
  1250. return val;
  1251. }
  1252. template<typename T>
  1253. const T* Parcel::readObject(size_t *objects_offset) const
  1254. {
  1255. const size_t DPOS = mDataPos;
  1256. if (objects_offset != nullptr) {
  1257. *objects_offset = 0;
  1258. }
  1259. if ((DPOS+sizeof(T)) <= mDataSize) {
  1260. const T* obj = reinterpret_cast<const T*>(mData+DPOS);
  1261. mDataPos = DPOS + sizeof(T);
  1262. const binder_object_header *hdr = reinterpret_cast<const binder_object_header*>(obj);
  1263. switch (hdr->type) {
  1264. case BINDER_TYPE_BINDER:
  1265. case BINDER_TYPE_WEAK_BINDER:
  1266. case BINDER_TYPE_HANDLE:
  1267. case BINDER_TYPE_WEAK_HANDLE: {
  1268. const flat_binder_object *flat_obj =
  1269. reinterpret_cast<const flat_binder_object*>(hdr);
  1270. if (flat_obj->cookie == 0 && flat_obj->binder == 0) {
  1271. // When transferring a NULL binder object, we don't write it into
  1272. // the object list, so we don't want to check for it when
  1273. // reading.
  1274. ALOGV("readObject Setting data pos of %p to %zu", this, mDataPos);
  1275. return obj;
  1276. }
  1277. break;
  1278. }
  1279. case BINDER_TYPE_FD:
  1280. case BINDER_TYPE_FDA:
  1281. // fd (-arrays) must always appear in the meta-data list (eg touched by the kernel)
  1282. break;
  1283. case BINDER_TYPE_PTR: {
  1284. const binder_buffer_object *buffer_obj =
  1285. reinterpret_cast<const binder_buffer_object*>(hdr);
  1286. if ((void *)buffer_obj->buffer == nullptr) {
  1287. // null pointers can be returned directly - they're not written in the
  1288. // object list. All non-null buffers must appear in the objects list.
  1289. return obj;
  1290. }
  1291. break;
  1292. }
  1293. }
  1294. // Ensure that this object is valid...
  1295. binder_size_t* const OBJS = mObjects;
  1296. const size_t N = mObjectsSize;
  1297. size_t opos = mNextObjectHint;
  1298. if (N > 0) {
  1299. ALOGV("Parcel %p looking for obj at %zu, hint=%zu",
  1300. this, DPOS, opos);
  1301. // Start at the current hint position, looking for an object at
  1302. // the current data position.
  1303. if (opos < N) {
  1304. while (opos < (N-1) && OBJS[opos] < DPOS) {
  1305. opos++;
  1306. }
  1307. } else {
  1308. opos = N-1;
  1309. }
  1310. if (OBJS[opos] == DPOS) {
  1311. // Found it!
  1312. ALOGV("Parcel %p found obj %zu at index %zu with forward search",
  1313. this, DPOS, opos);
  1314. mNextObjectHint = opos+1;
  1315. ALOGV("readObject Setting data pos of %p to %zu", this, mDataPos);
  1316. if (objects_offset != nullptr) {
  1317. *objects_offset = opos;
  1318. }
  1319. return obj;
  1320. }
  1321. // Look backwards for it...
  1322. while (opos > 0 && OBJS[opos] > DPOS) {
  1323. opos--;
  1324. }
  1325. if (OBJS[opos] == DPOS) {
  1326. // Found it!
  1327. ALOGV("Parcel %p found obj %zu at index %zu with backward search",
  1328. this, DPOS, opos);
  1329. mNextObjectHint = opos+1;
  1330. ALOGV("readObject Setting data pos of %p to %zu", this, mDataPos);
  1331. if (objects_offset != nullptr) {
  1332. *objects_offset = opos;
  1333. }
  1334. return obj;
  1335. }
  1336. }
  1337. ALOGW("Attempt to read object from Parcel %p at offset %zu that is not in the object list",
  1338. this, DPOS);
  1339. }
  1340. return nullptr;
  1341. }
  1342. template const flat_binder_object* Parcel::readObject<flat_binder_object>(size_t *objects_offset) const;
  1343. template const binder_fd_object* Parcel::readObject<binder_fd_object>(size_t *objects_offset) const;
  1344. template const binder_buffer_object* Parcel::readObject<binder_buffer_object>(size_t *objects_offset) const;
  1345. template const binder_fd_array_object* Parcel::readObject<binder_fd_array_object>(size_t *objects_offset) const;
  1346. bool Parcel::verifyBufferObject(const binder_buffer_object *buffer_obj,
  1347. size_t size, uint32_t flags, size_t parent,
  1348. size_t parentOffset) const {
  1349. if (buffer_obj->length != size) {
  1350. ALOGE("Buffer length %" PRIu64 " does not match expected size %zu.",
  1351. static_cast<uint64_t>(buffer_obj->length), size);
  1352. return false;
  1353. }
  1354. if (buffer_obj->flags != flags) {
  1355. ALOGE("Buffer flags 0x%02X do not match expected flags 0x%02X.", buffer_obj->flags, flags);
  1356. return false;
  1357. }
  1358. if (flags & BINDER_BUFFER_FLAG_HAS_PARENT) {
  1359. if (buffer_obj->parent != parent) {
  1360. ALOGE("Buffer parent %" PRIu64 " does not match expected parent %zu.",
  1361. static_cast<uint64_t>(buffer_obj->parent), parent);
  1362. return false;
  1363. }
  1364. if (buffer_obj->parent_offset != parentOffset) {
  1365. ALOGE("Buffer parent offset %" PRIu64 " does not match expected offset %zu.",
  1366. static_cast<uint64_t>(buffer_obj->parent_offset), parentOffset);
  1367. return false;
  1368. }
  1369. }
  1370. return true;
  1371. }
  1372. status_t Parcel::readBuffer(size_t buffer_size, size_t *buffer_handle,
  1373. uint32_t flags, size_t parent, size_t parentOffset,
  1374. const void **buffer_out) const {
  1375. const binder_buffer_object* buffer_obj = readObject<binder_buffer_object>(buffer_handle);
  1376. if (buffer_obj == nullptr || !isBuffer(*buffer_obj)) {
  1377. return BAD_VALUE;
  1378. }
  1379. if (!verifyBufferObject(buffer_obj, buffer_size, flags, parent, parentOffset)) {
  1380. return BAD_VALUE;
  1381. }
  1382. // in read side, always use .buffer and .length.
  1383. *buffer_out = reinterpret_cast<void*>(buffer_obj->buffer);
  1384. return OK;
  1385. }
  1386. status_t Parcel::readNullableBuffer(size_t buffer_size, size_t *buffer_handle,
  1387. const void **buffer_out) const
  1388. {
  1389. return readBuffer(buffer_size, buffer_handle,
  1390. 0 /* flags */, 0 /* parent */, 0 /* parentOffset */,
  1391. buffer_out);
  1392. }
  1393. status_t Parcel::readBuffer(size_t buffer_size, size_t *buffer_handle,
  1394. const void **buffer_out) const
  1395. {
  1396. status_t status = readNullableBuffer(buffer_size, buffer_handle, buffer_out);
  1397. if (status == OK && *buffer_out == nullptr) {
  1398. return UNEXPECTED_NULL;
  1399. }
  1400. return status;
  1401. }
  1402. status_t Parcel::readEmbeddedBuffer(size_t buffer_size,
  1403. size_t *buffer_handle,
  1404. size_t parent_buffer_handle,
  1405. size_t parent_offset,
  1406. const void **buffer_out) const
  1407. {
  1408. status_t status = readNullableEmbeddedBuffer(buffer_size, buffer_handle,
  1409. parent_buffer_handle,
  1410. parent_offset, buffer_out);
  1411. if (status == OK && *buffer_out == nullptr) {
  1412. return UNEXPECTED_NULL;
  1413. }
  1414. return status;
  1415. }
  1416. status_t Parcel::readNullableEmbeddedBuffer(size_t buffer_size,
  1417. size_t *buffer_handle,
  1418. size_t parent_buffer_handle,
  1419. size_t parent_offset,
  1420. const void **buffer_out) const
  1421. {
  1422. return readBuffer(buffer_size, buffer_handle, BINDER_BUFFER_FLAG_HAS_PARENT,
  1423. parent_buffer_handle, parent_offset, buffer_out);
  1424. }
  1425. // isRef if corresponds to a writeReference call, else corresponds to a writeBuffer call.
  1426. // see ::android::hardware::writeReferenceToParcel for details.
  1427. status_t Parcel::readReference(void const* *bufptr,
  1428. size_t *buffer_handle, bool *isRef) const
  1429. {
  1430. LOG_BUFFER("readReference");
  1431. const binder_buffer_object* buffer_obj = readObject<binder_buffer_object>();
  1432. LOG_BUFFER(" readReference: buf = %p, len = %zu, flags = %x",
  1433. (void*)buffer_obj->buffer, (size_t)buffer_obj->length,
  1434. (int)buffer_obj->flags);
  1435. // TODO need verification here
  1436. if (buffer_obj && buffer_obj->hdr.type == BINDER_TYPE_PTR) {
  1437. if (buffer_handle != nullptr) {
  1438. *buffer_handle = 0; // TODO fix this, as readBuffer would do
  1439. }
  1440. if(isRef != nullptr) {
  1441. *isRef = (buffer_obj->flags & BINDER_BUFFER_FLAG_REF) != 0;
  1442. LOG_BUFFER(" readReference: isRef = %d", *isRef);
  1443. }
  1444. // in read side, always use .buffer and .length.
  1445. if(bufptr != nullptr) {
  1446. *bufptr = (void*)buffer_obj->buffer;
  1447. }
  1448. return OK;
  1449. }
  1450. return BAD_VALUE;
  1451. }
  1452. // isRef if corresponds to a writeEmbeddedReference call, else corresponds to a writeEmbeddedBuffer call.
  1453. // see ::android::hardware::writeEmbeddedReferenceToParcel for details.
  1454. status_t Parcel::readEmbeddedReference(void const* *bufptr,
  1455. size_t *buffer_handle,
  1456. size_t /* parent_buffer_handle */,
  1457. size_t /* parent_offset */,
  1458. bool *isRef) const
  1459. {
  1460. // TODO verify parent and offset
  1461. LOG_BUFFER("readEmbeddedReference");
  1462. return (readReference(bufptr, buffer_handle, isRef));
  1463. }
  1464. status_t Parcel::readEmbeddedNativeHandle(size_t parent_buffer_handle,
  1465. size_t parent_offset,
  1466. const native_handle_t **handle) const
  1467. {
  1468. status_t status = readNullableEmbeddedNativeHandle(parent_buffer_handle, parent_offset, handle);
  1469. if (status == OK && *handle == nullptr) {
  1470. return UNEXPECTED_NULL;
  1471. }
  1472. return status;
  1473. }
  1474. status_t Parcel::readNullableNativeHandleNoDup(const native_handle_t **handle,
  1475. bool embedded,
  1476. size_t parent_buffer_handle,
  1477. size_t parent_offset) const
  1478. {
  1479. status_t status;
  1480. uint64_t nativeHandleSize;
  1481. size_t fdaParent;
  1482. status = readUint64(&nativeHandleSize);
  1483. if (status != OK || nativeHandleSize == 0) {
  1484. *handle = nullptr;
  1485. return status;
  1486. }
  1487. if (nativeHandleSize < sizeof(native_handle_t)) {
  1488. ALOGE("Received a native_handle_t size that was too small.");
  1489. return BAD_VALUE;
  1490. }
  1491. if (embedded) {
  1492. status = readNullableEmbeddedBuffer(nativeHandleSize, &fdaParent,
  1493. parent_buffer_handle, parent_offset,
  1494. reinterpret_cast<const void**>(handle));
  1495. } else {
  1496. status = readNullableBuffer(nativeHandleSize, &fdaParent,
  1497. reinterpret_cast<const void**>(handle));
  1498. }
  1499. if (status != OK) {
  1500. return status;
  1501. }
  1502. int numFds = (*handle)->numFds;
  1503. int numInts = (*handle)->numInts;
  1504. if (numFds < 0 || numFds > NATIVE_HANDLE_MAX_FDS) {
  1505. ALOGE("Received native_handle with invalid number of fds.");
  1506. return BAD_VALUE;
  1507. }
  1508. if (numInts < 0 || numInts > NATIVE_HANDLE_MAX_INTS) {
  1509. ALOGE("Received native_handle with invalid number of ints.");
  1510. return BAD_VALUE;
  1511. }
  1512. if (nativeHandleSize != (sizeof(native_handle_t) + ((numFds + numInts) * sizeof(int)))) {
  1513. ALOGE("Size of native_handle doesn't match.");
  1514. return BAD_VALUE;
  1515. }
  1516. const binder_fd_array_object* fd_array_obj = readObject<binder_fd_array_object>();
  1517. if (fd_array_obj == nullptr || fd_array_obj->hdr.type != BINDER_TYPE_FDA) {
  1518. ALOGE("Can't find file-descriptor array object.");
  1519. return BAD_VALUE;
  1520. }
  1521. if (static_cast<int>(fd_array_obj->num_fds) != numFds) {
  1522. ALOGE("Number of native handles does not match.");
  1523. return BAD_VALUE;
  1524. }
  1525. if (fd_array_obj->parent != fdaParent) {
  1526. ALOGE("Parent handle of file-descriptor array not correct.");
  1527. return BAD_VALUE;
  1528. }
  1529. if (fd_array_obj->parent_offset != offsetof(native_handle_t, data)) {
  1530. ALOGE("FD array object not properly offset in parent.");
  1531. return BAD_VALUE;
  1532. }
  1533. return OK;
  1534. }
  1535. status_t Parcel::readNullableEmbeddedNativeHandle(size_t parent_buffer_handle,
  1536. size_t parent_offset,
  1537. const native_handle_t **handle) const
  1538. {
  1539. return readNullableNativeHandleNoDup(handle, true /* embedded */, parent_buffer_handle,
  1540. parent_offset);
  1541. }
  1542. status_t Parcel::readNativeHandleNoDup(const native_handle_t **handle) const
  1543. {
  1544. status_t status = readNullableNativeHandleNoDup(handle);
  1545. if (status == OK && *handle == nullptr) {
  1546. return UNEXPECTED_NULL;
  1547. }
  1548. return status;
  1549. }
  1550. status_t Parcel::readNullableNativeHandleNoDup(const native_handle_t **handle) const
  1551. {
  1552. return readNullableNativeHandleNoDup(handle, false /* embedded */);
  1553. }
  1554. void Parcel::closeFileDescriptors()
  1555. {
  1556. size_t i = mObjectsSize;
  1557. if (i > 0) {
  1558. //ALOGI("Closing file descriptors for %zu objects...", i);
  1559. }
  1560. while (i > 0) {
  1561. i--;
  1562. const flat_binder_object* flat
  1563. = reinterpret_cast<flat_binder_object*>(mData+mObjects[i]);
  1564. if (flat->hdr.type == BINDER_TYPE_FD) {
  1565. //ALOGI("Closing fd: %ld", flat->handle);
  1566. close(flat->handle);
  1567. }
  1568. }
  1569. }
  1570. uintptr_t Parcel::ipcData() const
  1571. {
  1572. return reinterpret_cast<uintptr_t>(mData);
  1573. }
  1574. size_t Parcel::ipcDataSize() const
  1575. {
  1576. return mDataSize > mDataPos ? mDataSize : mDataPos;
  1577. }
  1578. uintptr_t Parcel::ipcObjects() const
  1579. {
  1580. return reinterpret_cast<uintptr_t>(mObjects);
  1581. }
  1582. size_t Parcel::ipcObjectsCount() const
  1583. {
  1584. return mObjectsSize;
  1585. }
  1586. #define BUFFER_ALIGNMENT_BYTES 8
  1587. size_t Parcel::ipcBufferSize() const
  1588. {
  1589. size_t totalBuffersSize = 0;
  1590. // Add size for BINDER_TYPE_PTR
  1591. size_t i = mObjectsSize;
  1592. while (i > 0) {
  1593. i--;
  1594. const binder_buffer_object* buffer
  1595. = reinterpret_cast<binder_buffer_object*>(mData+mObjects[i]);
  1596. if (isBuffer(*buffer)) {
  1597. /* The binder kernel driver requires each buffer to be 8-byte
  1598. * aligned */
  1599. size_t alignedSize = (buffer->length + (BUFFER_ALIGNMENT_BYTES - 1))
  1600. & ~(BUFFER_ALIGNMENT_BYTES - 1);
  1601. if (alignedSize > SIZE_MAX - totalBuffersSize) {
  1602. ALOGE("ipcBuffersSize(): invalid buffer sizes.");
  1603. return 0;
  1604. }
  1605. totalBuffersSize += alignedSize;
  1606. }
  1607. }
  1608. return totalBuffersSize;
  1609. }
  1610. void Parcel::ipcSetDataReference(const uint8_t* data, size_t dataSize,
  1611. const binder_size_t* objects, size_t objectsCount, release_func relFunc, void* relCookie)
  1612. {
  1613. binder_size_t minOffset = 0;
  1614. freeDataNoInit();
  1615. mError = NO_ERROR;
  1616. mData = const_cast<uint8_t*>(data);
  1617. mDataSize = mDataCapacity = dataSize;
  1618. //ALOGI("setDataReference Setting data size of %p to %lu (pid=%d)", this, mDataSize, getpid());
  1619. mDataPos = 0;
  1620. ALOGV("setDataReference Setting data pos of %p to %zu", this, mDataPos);
  1621. mObjects = const_cast<binder_size_t*>(objects);
  1622. mObjectsSize = mObjectsCapacity = objectsCount;
  1623. mNextObjectHint = 0;
  1624. clearCache();
  1625. mNumRef = 0;
  1626. mOwner = relFunc;
  1627. mOwnerCookie = relCookie;
  1628. for (size_t i = 0; i < mObjectsSize; i++) {
  1629. binder_size_t offset = mObjects[i];
  1630. if (offset < minOffset) {
  1631. ALOGE("%s: bad object offset %" PRIu64 " < %" PRIu64 "\n",
  1632. __func__, (uint64_t)offset, (uint64_t)minOffset);
  1633. mObjectsSize = 0;
  1634. break;
  1635. }
  1636. minOffset = offset + sizeof(flat_binder_object);
  1637. }
  1638. scanForFds();
  1639. }
  1640. void Parcel::print(TextOutput& to, uint32_t /*flags*/) const
  1641. {
  1642. to << "Parcel(";
  1643. if (errorCheck() != NO_ERROR) {
  1644. const status_t err = errorCheck();
  1645. to << "Error: " << (void*)(intptr_t)err << " \"" << strerror(-err) << "\"";
  1646. } else if (dataSize() > 0) {
  1647. const uint8_t* DATA = data();
  1648. to << indent << HexDump(DATA, dataSize()) << dedent;
  1649. const binder_size_t* OBJS = objects();
  1650. const size_t N = objectsCount();
  1651. for (size_t i=0; i<N; i++) {
  1652. const flat_binder_object* flat
  1653. = reinterpret_cast<const flat_binder_object*>(DATA+OBJS[i]);
  1654. if (flat->hdr.type == BINDER_TYPE_PTR) {
  1655. const binder_buffer_object* buffer
  1656. = reinterpret_cast<const binder_buffer_object*>(DATA+OBJS[i]);
  1657. if(isBuffer(*buffer)) {
  1658. HexDump bufferDump((const uint8_t*)buffer->buffer, (size_t)buffer->length);
  1659. bufferDump.setSingleLineCutoff(0);
  1660. to << endl << "Object #" << i << " @ " << (void*)OBJS[i] << " (buffer size " << buffer->length << "):";
  1661. to << indent << bufferDump << dedent;
  1662. } else {
  1663. to << endl << "Object #" << i << " @ " << (void*)OBJS[i];
  1664. }
  1665. } else {
  1666. to << endl << "Object #" << i << " @ " << (void*)OBJS[i] << ": "
  1667. << TypeCode(flat->hdr.type & 0x7f7f7f00)
  1668. << " = " << flat->binder;
  1669. }
  1670. }
  1671. } else {
  1672. to << "NULL";
  1673. }
  1674. to << ")";
  1675. }
  1676. void Parcel::releaseObjects()
  1677. {
  1678. const sp<ProcessState> proc(ProcessState::self());
  1679. size_t i = mObjectsSize;
  1680. uint8_t* const data = mData;
  1681. binder_size_t* const objects = mObjects;
  1682. while (i > 0) {
  1683. i--;
  1684. const flat_binder_object* flat
  1685. = reinterpret_cast<flat_binder_object*>(data+objects[i]);
  1686. release_object(proc, *flat, this);
  1687. }
  1688. }
  1689. void Parcel::acquireObjects()
  1690. {
  1691. const sp<ProcessState> proc(ProcessState::self());
  1692. size_t i = mObjectsSize;
  1693. uint8_t* const data = mData;
  1694. binder_size_t* const objects = mObjects;
  1695. while (i > 0) {
  1696. i--;
  1697. const binder_object_header* flat
  1698. = reinterpret_cast<binder_object_header*>(data+objects[i]);
  1699. acquire_object(proc, *flat, this);
  1700. }
  1701. }
  1702. void Parcel::freeData()
  1703. {
  1704. freeDataNoInit();
  1705. initState();
  1706. }
  1707. void Parcel::freeDataNoInit()
  1708. {
  1709. if (mOwner) {
  1710. LOG_ALLOC("Parcel %p: freeing other owner data", this);
  1711. //ALOGI("Freeing data ref of %p (pid=%d)", this, getpid());
  1712. mOwner(this, mData, mDataSize, mObjects, mObjectsSize, mOwnerCookie);
  1713. } else {
  1714. LOG_ALLOC("Parcel %p: freeing allocated data", this);
  1715. releaseObjects();
  1716. if (mData) {
  1717. LOG_ALLOC("Parcel %p: freeing with %zu capacity", this, mDataCapacity);
  1718. pthread_mutex_lock(&gParcelGlobalAllocSizeLock);
  1719. if (mDataCapacity <= gParcelGlobalAllocSize) {
  1720. gParcelGlobalAllocSize = gParcelGlobalAllocSize - mDataCapacity;
  1721. } else {
  1722. gParcelGlobalAllocSize = 0;
  1723. }
  1724. if (gParcelGlobalAllocCount > 0) {
  1725. gParcelGlobalAllocCount--;
  1726. }
  1727. pthread_mutex_unlock(&gParcelGlobalAllocSizeLock);
  1728. free(mData);
  1729. }
  1730. if (mObjects) free(mObjects);
  1731. }
  1732. }
  1733. status_t Parcel::growData(size_t len)
  1734. {
  1735. if (len > INT32_MAX) {
  1736. // don't accept size_t values which may have come from an
  1737. // inadvertent conversion from a negative int.
  1738. return BAD_VALUE;
  1739. }
  1740. size_t newSize = ((mDataSize+len)*3)/2;
  1741. return (newSize <= mDataSize)
  1742. ? (status_t) NO_MEMORY
  1743. : continueWrite(newSize);
  1744. }
  1745. status_t Parcel::restartWrite(size_t desired)
  1746. {
  1747. if (desired > INT32_MAX) {
  1748. // don't accept size_t values which may have come from an
  1749. // inadvertent conversion from a negative int.
  1750. return BAD_VALUE;
  1751. }
  1752. if (mOwner) {
  1753. freeData();
  1754. return continueWrite(desired);
  1755. }
  1756. uint8_t* data = (uint8_t*)realloc(mData, desired);
  1757. if (!data && desired > mDataCapacity) {
  1758. mError = NO_MEMORY;
  1759. return NO_MEMORY;
  1760. }
  1761. releaseObjects();
  1762. if (data) {
  1763. LOG_ALLOC("Parcel %p: restart from %zu to %zu capacity", this, mDataCapacity, desired);
  1764. pthread_mutex_lock(&gParcelGlobalAllocSizeLock);
  1765. gParcelGlobalAllocSize += desired;
  1766. gParcelGlobalAllocSize -= mDataCapacity;
  1767. if (!mData) {
  1768. gParcelGlobalAllocCount++;
  1769. }
  1770. pthread_mutex_unlock(&gParcelGlobalAllocSizeLock);
  1771. mData = data;
  1772. mDataCapacity = desired;
  1773. }
  1774. mDataSize = mDataPos = 0;
  1775. ALOGV("restartWrite Setting data size of %p to %zu", this, mDataSize);
  1776. ALOGV("restartWrite Setting data pos of %p to %zu", this, mDataPos);
  1777. free(mObjects);
  1778. mObjects = nullptr;
  1779. mObjectsSize = mObjectsCapacity = 0;
  1780. mNextObjectHint = 0;
  1781. mHasFds = false;
  1782. clearCache();
  1783. mNumRef = 0;
  1784. mFdsKnown = true;
  1785. mAllowFds = true;
  1786. return NO_ERROR;
  1787. }
  1788. status_t Parcel::continueWrite(size_t desired)
  1789. {
  1790. if (desired > INT32_MAX) {
  1791. // don't accept size_t values which may have come from an
  1792. // inadvertent conversion from a negative int.
  1793. return BAD_VALUE;
  1794. }
  1795. // If shrinking, first adjust for any objects that appear
  1796. // after the new data size.
  1797. size_t objectsSize = mObjectsSize;
  1798. if (desired < mDataSize) {
  1799. if (desired == 0) {
  1800. objectsSize = 0;
  1801. } else {
  1802. while (objectsSize > 0) {
  1803. if (mObjects[objectsSize-1] < desired)
  1804. break;
  1805. objectsSize--;
  1806. }
  1807. }
  1808. }
  1809. if (mOwner) {
  1810. // If the size is going to zero, just release the owner's data.
  1811. if (desired == 0) {
  1812. freeData();
  1813. return NO_ERROR;
  1814. }
  1815. // If there is a different owner, we need to take
  1816. // posession.
  1817. uint8_t* data = (uint8_t*)malloc(desired);
  1818. if (!data) {
  1819. mError = NO_MEMORY;
  1820. return NO_MEMORY;
  1821. }
  1822. binder_size_t* objects = nullptr;
  1823. if (objectsSize) {
  1824. objects = (binder_size_t*)calloc(objectsSize, sizeof(binder_size_t));
  1825. if (!objects) {
  1826. free(data);
  1827. mError = NO_MEMORY;
  1828. return NO_MEMORY;
  1829. }
  1830. // Little hack to only acquire references on objects
  1831. // we will be keeping.
  1832. size_t oldObjectsSize = mObjectsSize;
  1833. mObjectsSize = objectsSize;
  1834. acquireObjects();
  1835. mObjectsSize = oldObjectsSize;
  1836. }
  1837. if (mData) {
  1838. memcpy(data, mData, mDataSize < desired ? mDataSize : desired);
  1839. }
  1840. if (objects && mObjects) {
  1841. memcpy(objects, mObjects, objectsSize*sizeof(binder_size_t));
  1842. }
  1843. //ALOGI("Freeing data ref of %p (pid=%d)", this, getpid());
  1844. mOwner(this, mData, mDataSize, mObjects, mObjectsSize, mOwnerCookie);
  1845. mOwner = nullptr;
  1846. LOG_ALLOC("Parcel %p: taking ownership of %zu capacity", this, desired);
  1847. pthread_mutex_lock(&gParcelGlobalAllocSizeLock);
  1848. gParcelGlobalAllocSize += desired;
  1849. gParcelGlobalAllocCount++;
  1850. pthread_mutex_unlock(&gParcelGlobalAllocSizeLock);
  1851. mData = data;
  1852. mObjects = objects;
  1853. mDataSize = (mDataSize < desired) ? mDataSize : desired;
  1854. ALOGV("continueWrite Setting data size of %p to %zu", this, mDataSize);
  1855. mDataCapacity = desired;
  1856. mObjectsSize = mObjectsCapacity = objectsSize;
  1857. mNextObjectHint = 0;
  1858. clearCache();
  1859. } else if (mData) {
  1860. if (objectsSize < mObjectsSize) {
  1861. // Need to release refs on any objects we are dropping.
  1862. const sp<ProcessState> proc(ProcessState::self());
  1863. for (size_t i=objectsSize; i<mObjectsSize; i++) {
  1864. const flat_binder_object* flat
  1865. = reinterpret_cast<flat_binder_object*>(mData+mObjects[i]);
  1866. if (flat->hdr.type == BINDER_TYPE_FD) {
  1867. // will need to rescan because we may have lopped off the only FDs
  1868. mFdsKnown = false;
  1869. }
  1870. release_object(proc, *flat, this);
  1871. }
  1872. binder_size_t* objects =
  1873. (binder_size_t*)realloc(mObjects, objectsSize*sizeof(binder_size_t));
  1874. if (objects) {
  1875. mObjects = objects;
  1876. }
  1877. mObjectsSize = objectsSize;
  1878. mNextObjectHint = 0;
  1879. clearCache();
  1880. }
  1881. // We own the data, so we can just do a realloc().
  1882. if (desired > mDataCapacity) {
  1883. uint8_t* data = (uint8_t*)realloc(mData, desired);
  1884. if (data) {
  1885. LOG_ALLOC("Parcel %p: continue from %zu to %zu capacity", this, mDataCapacity,
  1886. desired);
  1887. pthread_mutex_lock(&gParcelGlobalAllocSizeLock);
  1888. gParcelGlobalAllocSize += desired;
  1889. gParcelGlobalAllocSize -= mDataCapacity;
  1890. pthread_mutex_unlock(&gParcelGlobalAllocSizeLock);
  1891. mData = data;
  1892. mDataCapacity = desired;
  1893. } else {
  1894. mError = NO_MEMORY;
  1895. return NO_MEMORY;
  1896. }
  1897. } else {
  1898. if (mDataSize > desired) {
  1899. mDataSize = desired;
  1900. ALOGV("continueWrite Setting data size of %p to %zu", this, mDataSize);
  1901. }
  1902. if (mDataPos > desired) {
  1903. mDataPos = desired;
  1904. ALOGV("continueWrite Setting data pos of %p to %zu", this, mDataPos);
  1905. }
  1906. }
  1907. } else {
  1908. // This is the first data. Easy!
  1909. uint8_t* data = (uint8_t*)malloc(desired);
  1910. if (!data) {
  1911. mError = NO_MEMORY;
  1912. return NO_MEMORY;
  1913. }
  1914. if(!(mDataCapacity == 0 && mObjects == nullptr
  1915. && mObjectsCapacity == 0)) {
  1916. ALOGE("continueWrite: %zu/%p/%zu/%zu", mDataCapacity, mObjects, mObjectsCapacity, desired);
  1917. }
  1918. LOG_ALLOC("Parcel %p: allocating with %zu capacity", this, desired);
  1919. pthread_mutex_lock(&gParcelGlobalAllocSizeLock);
  1920. gParcelGlobalAllocSize += desired;
  1921. gParcelGlobalAllocCount++;
  1922. pthread_mutex_unlock(&gParcelGlobalAllocSizeLock);
  1923. mData = data;
  1924. mDataSize = mDataPos = 0;
  1925. ALOGV("continueWrite Setting data size of %p to %zu", this, mDataSize);
  1926. ALOGV("continueWrite Setting data pos of %p to %zu", this, mDataPos);
  1927. mDataCapacity = desired;
  1928. }
  1929. return NO_ERROR;
  1930. }
  1931. void Parcel::initState()
  1932. {
  1933. LOG_ALLOC("Parcel %p: initState", this);
  1934. mError = NO_ERROR;
  1935. mData = nullptr;
  1936. mDataSize = 0;
  1937. mDataCapacity = 0;
  1938. mDataPos = 0;
  1939. ALOGV("initState Setting data size of %p to %zu", this, mDataSize);
  1940. ALOGV("initState Setting data pos of %p to %zu", this, mDataPos);
  1941. mObjects = nullptr;
  1942. mObjectsSize = 0;
  1943. mObjectsCapacity = 0;
  1944. mNextObjectHint = 0;
  1945. mHasFds = false;
  1946. mFdsKnown = true;
  1947. mAllowFds = true;
  1948. mOwner = nullptr;
  1949. clearCache();
  1950. mNumRef = 0;
  1951. // racing multiple init leads only to multiple identical write
  1952. if (gMaxFds == 0) {
  1953. struct rlimit result;
  1954. if (!getrlimit(RLIMIT_NOFILE, &result)) {
  1955. gMaxFds = (size_t)result.rlim_cur;
  1956. //ALOGI("parcel fd limit set to %zu", gMaxFds);
  1957. } else {
  1958. ALOGW("Unable to getrlimit: %s", strerror(errno));
  1959. gMaxFds = 1024;
  1960. }
  1961. }
  1962. }
  1963. void Parcel::scanForFds() const
  1964. {
  1965. bool hasFds = false;
  1966. for (size_t i=0; i<mObjectsSize; i++) {
  1967. const flat_binder_object* flat
  1968. = reinterpret_cast<const flat_binder_object*>(mData + mObjects[i]);
  1969. if (flat->hdr.type == BINDER_TYPE_FD) {
  1970. hasFds = true;
  1971. break;
  1972. }
  1973. }
  1974. mHasFds = hasFds;
  1975. mFdsKnown = true;
  1976. }
  1977. }; // namespace hardware
  1978. }; // namespace android