Let's reinvent storage, yet again!
Now that we're treating storage as a runtime permission, we need to
grant read/write access without killing the app. This is really
tricky, since we had been using GIDs for access control, and they're
set in stone once Zygote drops privileges.
The only thing left that can change dynamically is the filesystem
itself, so let's do that. This means changing the FUSE daemon to
present itself as three different views:
/mnt/runtime_default/foo - view for apps with no access
/mnt/runtime_read/foo - view for apps with read access
/mnt/runtime_write/foo - view for apps with write access
There is still a single location for all the backing files, and
filesystem permissions are derived the same way for each view, but
the file modes are masked off differently for each mountpoint.
During Zygote fork, it wires up the appropriate storage access into
an isolated mount namespace based on the current app permissions. When
the app is granted permissions dynamically at runtime, the system
asks vold to jump into the existing mount namespace and bind mount
the newly granted access model into place.
Bug: 21858077
Change-Id: Iade538e4bc7af979fe20095f74416e8a0f165a4a
diff --git a/PublicVolume.cpp b/PublicVolume.cpp
index d17853b..e4fdb86 100644
--- a/PublicVolume.cpp
+++ b/PublicVolume.cpp
@@ -111,16 +111,19 @@
}
mRawPath = StringPrintf("/mnt/media_rw/%s", stableName.c_str());
- mFusePath = StringPrintf("/storage/%s", stableName.c_str());
- setInternalPath(mRawPath);
- setPath(mFusePath);
- if (fs_prepare_dir(mRawPath.c_str(), 0700, AID_ROOT, AID_ROOT)) {
- PLOG(ERROR) << getId() << " failed to create mount point " << mRawPath;
- return -errno;
- }
- if (fs_prepare_dir(mFusePath.c_str(), 0700, AID_ROOT, AID_ROOT)) {
- PLOG(ERROR) << getId() << " failed to create mount point " << mFusePath;
+ mFuseDefault = StringPrintf("/mnt/runtime_default/%s", stableName.c_str());
+ mFuseRead = StringPrintf("/mnt/runtime_read/%s", stableName.c_str());
+ mFuseWrite = StringPrintf("/mnt/runtime_write/%s", stableName.c_str());
+
+ setInternalPath(mRawPath);
+ setPath(StringPrintf("/storage/%s", stableName.c_str()));
+
+ if (fs_prepare_dir(mRawPath.c_str(), 0700, AID_ROOT, AID_ROOT) ||
+ fs_prepare_dir(mFuseDefault.c_str(), 0700, AID_ROOT, AID_ROOT) ||
+ fs_prepare_dir(mFuseRead.c_str(), 0700, AID_ROOT, AID_ROOT) ||
+ fs_prepare_dir(mFuseWrite.c_str(), 0700, AID_ROOT, AID_ROOT)) {
+ PLOG(ERROR) << getId() << " failed to create mount points";
return -errno;
}
@@ -134,25 +137,18 @@
initAsecStage();
}
- // TODO: teach FUSE daemon to protect itself with user-specific GID
+ dev_t before = GetDevice(mFuseWrite);
+
if (!(mFusePid = fork())) {
if (!(getMountFlags() & MountFlags::kVisible)) {
- // TODO: mount so that only system apps can access
- if (execl(kFusePath, kFusePath,
- "-u", "1023", // AID_MEDIA_RW
- "-g", "1023", // AID_MEDIA_RW
- mRawPath.c_str(),
- mFusePath.c_str(),
- NULL)) {
- PLOG(ERROR) << "Failed to exec";
- }
+ // TODO: do we need to wrap this device?
} else if (getMountFlags() & MountFlags::kPrimary) {
if (execl(kFusePath, kFusePath,
"-u", "1023", // AID_MEDIA_RW
"-g", "1023", // AID_MEDIA_RW
- "-d",
+ "-w",
mRawPath.c_str(),
- mFusePath.c_str(),
+ stableName.c_str(),
NULL)) {
PLOG(ERROR) << "Failed to exec";
}
@@ -160,10 +156,8 @@
if (execl(kFusePath, kFusePath,
"-u", "1023", // AID_MEDIA_RW
"-g", "1023", // AID_MEDIA_RW
- "-w", "1023", // AID_MEDIA_RW
- "-d",
mRawPath.c_str(),
- mFusePath.c_str(),
+ stableName.c_str(),
NULL)) {
PLOG(ERROR) << "Failed to exec";
}
@@ -178,6 +172,11 @@
return -errno;
}
+ while (before == GetDevice(mFuseWrite)) {
+ LOG(VERBOSE) << "Waiting for FUSE to spin up...";
+ usleep(50000); // 50ms
+ }
+
return OK;
}
@@ -189,17 +188,20 @@
}
ForceUnmount(kAsecPath);
- ForceUnmount(mFusePath);
+
+ ForceUnmount(mFuseDefault);
+ ForceUnmount(mFuseRead);
+ ForceUnmount(mFuseWrite);
ForceUnmount(mRawPath);
- if (TEMP_FAILURE_RETRY(rmdir(mRawPath.c_str()))) {
- PLOG(ERROR) << getId() << " failed to rmdir mount point " << mRawPath;
- }
- if (TEMP_FAILURE_RETRY(rmdir(mFusePath.c_str()))) {
- PLOG(ERROR) << getId() << " failed to rmdir mount point " << mFusePath;
- }
+ rmdir(mFuseDefault.c_str());
+ rmdir(mFuseRead.c_str());
+ rmdir(mFuseWrite.c_str());
+ rmdir(mRawPath.c_str());
- mFusePath.clear();
+ mFuseDefault.clear();
+ mFuseRead.clear();
+ mFuseWrite.clear();
mRawPath.clear();
return OK;