Magisk/native/jni/magiskhide/proc_monitor.c

207 lines
4.8 KiB
C
Raw Normal View History

2017-07-10 17:39:33 +02:00
/* proc_monitor.c - Monitor am_proc_start events and unmount
2017-08-01 09:34:16 +02:00
*
2017-07-10 17:39:33 +02:00
* We monitor the logcat am_proc_start events. When a target starts up,
* we pause it ASAP, and fork a new process to join its mount namespace
* and do all the unmounting/mocking
2017-04-06 00:12:29 +02:00
*/
#include <stdlib.h>
#include <stdio.h>
#include <string.h>
#include <unistd.h>
2018-07-13 16:14:32 +02:00
#include <fcntl.h>
2017-04-06 00:12:29 +02:00
#include <signal.h>
#include <pthread.h>
#include <sys/types.h>
#include <sys/wait.h>
2017-07-10 17:39:33 +02:00
#include <sys/mount.h>
2017-04-06 00:12:29 +02:00
#include "magisk.h"
2018-07-02 16:11:28 +02:00
#include "daemon.h"
2017-04-06 00:12:29 +02:00
#include "utils.h"
2016-12-30 19:44:24 +01:00
#include "magiskhide.h"
2018-07-02 16:11:28 +02:00
static int sockfd = -1;
2017-04-07 01:50:02 +02:00
2017-04-06 00:12:29 +02:00
// Workaround for the lack of pthread_cancel
static void term_thread(int sig) {
LOGD("proc_monitor: running cleanup\n");
2017-04-20 16:45:56 +02:00
destroy_list();
hideEnabled = 0;
2018-07-02 16:11:28 +02:00
close(sockfd);
sockfd = -1;
2017-04-21 18:54:08 +02:00
pthread_mutex_destroy(&hide_lock);
2017-05-07 21:11:14 +02:00
pthread_mutex_destroy(&file_lock);
LOGD("proc_monitor: terminating...\n");
pthread_exit(NULL);
2017-04-06 00:12:29 +02:00
}
2017-01-01 11:54:13 +01:00
2018-07-11 17:41:38 +02:00
static int read_ns(const int pid, struct stat *st) {
2017-07-02 19:02:11 +02:00
char path[32];
sprintf(path, "/proc/%d/ns/mnt", pid);
2018-07-11 17:41:38 +02:00
return stat(path, st);
2017-07-02 19:02:11 +02:00
}
2017-07-10 17:39:33 +02:00
static void lazy_unmount(const char* mountpoint) {
2018-01-11 17:23:38 +01:00
if (umount2(mountpoint, MNT_DETACH) != -1)
2017-07-10 17:39:33 +02:00
LOGD("hide_daemon: Unmounted (%s)\n", mountpoint);
}
static int parse_ppid(int pid) {
char stat[512], path[32];
int fd, ppid;
sprintf(path, "/proc/%d/stat", pid);
fd = xopen(path, O_RDONLY);
xread(fd, stat, sizeof(stat));
close(fd);
/* PID COMM STATE PPID ..... */
sscanf(stat, "%*d %*s %*c %d", &ppid);
return ppid;
}
static void hide_daemon(int pid) {
2017-07-10 17:39:33 +02:00
LOGD("hide_daemon: start unmount for pid=[%d]\n", pid);
char *line, buffer[PATH_MAX];
2017-07-10 17:39:33 +02:00
struct vector mount_list;
manage_selinux();
2017-07-18 06:26:23 +02:00
clean_magisk_props();
2017-07-10 17:39:33 +02:00
if (switch_mnt_ns(pid))
goto exit;
2017-07-10 17:39:33 +02:00
snprintf(buffer, sizeof(buffer), "/proc/%d/mounts", pid);
2017-07-10 17:39:33 +02:00
vec_init(&mount_list);
file_to_vector(buffer, &mount_list);
2018-06-16 23:16:52 +02:00
// Unmount dummy skeletons and /sbin links
2017-07-10 17:39:33 +02:00
vec_for_each(&mount_list, line) {
2018-06-16 23:16:52 +02:00
if (strstr(line, "tmpfs /system/") || strstr(line, "tmpfs /vendor/") || strstr(line, "tmpfs /sbin")) {
2017-07-10 17:39:33 +02:00
sscanf(line, "%*s %4096s", buffer);
lazy_unmount(buffer);
}
free(line);
}
vec_destroy(&mount_list);
// Re-read mount infos
snprintf(buffer, sizeof(buffer), "/proc/%d/mounts", pid);
2017-07-10 17:39:33 +02:00
vec_init(&mount_list);
file_to_vector(buffer, &mount_list);
2018-06-16 23:16:52 +02:00
// Unmount everything under /system, /vendor, and loop mounts
2017-07-10 17:39:33 +02:00
vec_for_each(&mount_list, line) {
2018-06-16 23:16:52 +02:00
if (strstr(line, "/dev/block/loop") || strstr(line, " /system/") || strstr(line, " /vendor/")) {
2017-07-10 17:39:33 +02:00
sscanf(line, "%*s %4096s", buffer);
lazy_unmount(buffer);
}
free(line);
}
2018-06-16 23:16:52 +02:00
vec_destroy(&mount_list);
2017-07-10 17:39:33 +02:00
exit:
// Send resume signal
kill(pid, SIGCONT);
_exit(0);
2017-07-10 17:39:33 +02:00
}
2017-04-21 18:54:08 +02:00
void proc_monitor() {
// Unblock user signals
sigset_t block_set;
sigemptyset(&block_set);
sigaddset(&block_set, TERM_THREAD);
pthread_sigmask(SIG_UNBLOCK, &block_set, NULL);
2017-04-06 00:12:29 +02:00
// Register the cancel signal
2017-05-07 21:11:14 +02:00
struct sigaction act;
memset(&act, 0, sizeof(act));
act.sa_handler = term_thread;
sigaction(TERM_THREAD, &act, NULL);
2017-05-07 21:11:14 +02:00
if (access("/proc/1/ns/mnt", F_OK) != 0) {
2017-07-10 17:39:33 +02:00
LOGE("proc_monitor: Your kernel doesn't support mount namespace :(\n");
term_thread(TERM_THREAD);
2017-07-10 17:39:33 +02:00
}
while(1) {
// Connect to the log daemon
connect_daemon2(LOG_DAEMON, &sockfd);
write_int(sockfd, HIDE_CONNECT);
FILE *log_in = fdopen(sockfd, "r");
char buf[4096];
while (fgets(buf, sizeof(buf), log_in)) {
char *ss = strchr(buf, '[');
int pid, ppid, num = 0;
2018-07-11 17:41:38 +02:00
char *pos = ss, proc[256];
struct stat ns, pns;
while(1) {
pos = strchr(pos, ',');
if(pos == NULL)
break;
pos[0] = ' ';
++num;
}
if(sscanf(ss, num == 6 ? "[%*d %d %*d %*d %256s" : "[%*d %d %*d %256s", &pid, proc) != 2)
continue;
// Make sure our target is alive
if (kill(pid, 0))
continue;
// Allow hiding sub-services of applications
char *colon = strchr(proc, ':');
if (colon)
*colon = '\0';
int hide = 0;
pthread_mutex_lock(&hide_lock);
char *line;
vec_for_each(hide_list, line) {
if (strcmp(proc, line) == 0) {
hide = 1;
break;
}
}
pthread_mutex_unlock(&hide_lock);
if (!hide)
continue;
ppid = parse_ppid(pid);
2018-07-11 17:41:38 +02:00
read_ns(ppid, &pns);
do {
2018-07-11 17:41:38 +02:00
read_ns(pid, &ns);
if (ns.st_dev == pns.st_dev && ns.st_ino == pns.st_ino)
usleep(50);
else
break;
} while (1);
// Send pause signal ASAP
if (kill(pid, SIGSTOP) == -1)
continue;
// Restore the colon so we can log the actual process name
if (colon)
*colon = ':';
#ifdef MAGISK_DEBUG
2018-07-11 17:41:38 +02:00
LOGI("proc_monitor: %s (PID=[%d] ns=%llu)(PPID=[%d] ns=%llu)\n",
proc, pid, ns.st_ino, ppid, pns.st_ino);
#else
LOGI("proc_monitor: %s\n", proc);
#endif
2017-07-10 17:39:33 +02:00
/*
* The setns system call do not support multithread processes
* We have to fork a new process, setns, then do the unmounts
*/
if (fork_dont_care() == 0)
hide_daemon(pid);
}
// The other end EOF, restart the connection
2017-06-02 22:31:01 +02:00
}
}