2021-01-07 06:21:17 +00:00
|
|
|
#include <libgen.h>
|
|
|
|
#include <dlfcn.h>
|
|
|
|
#include <sys/mount.h>
|
|
|
|
#include <sys/sendfile.h>
|
2021-01-07 07:41:37 +00:00
|
|
|
#include <sys/prctl.h>
|
2021-08-21 10:52:59 +00:00
|
|
|
#include <android/log.h>
|
2021-01-07 06:21:17 +00:00
|
|
|
|
|
|
|
#include <utils.hpp>
|
2021-08-18 10:44:32 +00:00
|
|
|
#include <daemon.hpp>
|
|
|
|
#include <magisk.hpp>
|
2021-01-07 06:21:17 +00:00
|
|
|
|
|
|
|
#include "inject.hpp"
|
2021-08-19 11:55:17 +00:00
|
|
|
#include "../magiskhide/magiskhide.hpp"
|
2021-01-07 06:21:17 +00:00
|
|
|
|
|
|
|
using namespace std;
|
|
|
|
|
|
|
|
static void *self_handle = nullptr;
|
|
|
|
static atomic<int> active_threads = -1;
|
|
|
|
|
2021-08-21 10:52:59 +00:00
|
|
|
static int zygisk_log(int prio, const char *fmt, va_list ap);
|
|
|
|
|
|
|
|
#define zlog(prio) [](auto fmt, auto ap){ return zygisk_log(ANDROID_LOG_##prio, fmt, ap); }
|
|
|
|
static void zygisk_logging() {
|
|
|
|
log_cb.d = zlog(DEBUG);
|
|
|
|
log_cb.i = zlog(INFO);
|
|
|
|
log_cb.w = zlog(WARN);
|
|
|
|
log_cb.e = zlog(ERROR);
|
|
|
|
log_cb.ex = nop_ex;
|
|
|
|
}
|
|
|
|
|
2021-01-08 08:53:24 +00:00
|
|
|
void self_unload() {
|
2021-08-19 08:54:12 +00:00
|
|
|
LOGD("zygisk: Request to self unload\n");
|
|
|
|
// If deny failed, do not unload or else it will cause SIGSEGV
|
2021-01-08 08:53:24 +00:00
|
|
|
if (!unhook_functions())
|
|
|
|
return;
|
2021-08-01 21:35:16 +00:00
|
|
|
new_daemon_thread(reinterpret_cast<thread_entry>(&dlclose), self_handle);
|
2021-01-07 06:21:17 +00:00
|
|
|
active_threads--;
|
|
|
|
}
|
|
|
|
|
2021-08-18 10:44:32 +00:00
|
|
|
static void *unload_first_stage(void *v) {
|
2021-01-07 06:21:17 +00:00
|
|
|
// Setup 1ms
|
|
|
|
timespec ts = { .tv_sec = 0, .tv_nsec = 1000000L };
|
|
|
|
|
2021-01-07 07:59:05 +00:00
|
|
|
while (getenv(INJECT_ENV_1))
|
2021-01-07 06:21:17 +00:00
|
|
|
nanosleep(&ts, nullptr);
|
|
|
|
|
|
|
|
// Wait another 1ms to make sure all threads left our code
|
|
|
|
nanosleep(&ts, nullptr);
|
|
|
|
|
2021-08-18 10:44:32 +00:00
|
|
|
char *path = static_cast<char *>(v);
|
|
|
|
unmap_all(path);
|
2021-01-07 06:21:17 +00:00
|
|
|
active_threads--;
|
|
|
|
return nullptr;
|
|
|
|
}
|
|
|
|
|
2021-01-07 07:41:37 +00:00
|
|
|
// Make sure /proc/self/environ does not reveal our secrets
|
|
|
|
// Copy all env to a contiguous memory and set the memory region as MM_ENV
|
|
|
|
static void sanitize_environ() {
|
|
|
|
static string env;
|
|
|
|
|
|
|
|
for (int i = 0; environ[i]; ++i) {
|
2021-01-07 07:59:05 +00:00
|
|
|
if (str_starts(environ[i], INJECT_ENV_1 "="))
|
|
|
|
continue;
|
2021-01-07 07:41:37 +00:00
|
|
|
env += environ[i];
|
|
|
|
env += '\0';
|
|
|
|
}
|
|
|
|
|
|
|
|
for (int i = 0; i < 2; ++i) {
|
|
|
|
bool success = true;
|
|
|
|
success &= (0 <= prctl(PR_SET_MM, PR_SET_MM_ENV_START, env.data(), 0, 0));
|
|
|
|
success &= (0 <= prctl(PR_SET_MM, PR_SET_MM_ENV_END, env.data() + env.size(), 0, 0));
|
|
|
|
if (success)
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-08-01 21:35:16 +00:00
|
|
|
__attribute__((destructor))
|
|
|
|
static void inject_cleanup_wait() {
|
|
|
|
if (active_threads < 0)
|
|
|
|
return;
|
|
|
|
|
|
|
|
// Setup 1ms
|
|
|
|
timespec ts = { .tv_sec = 0, .tv_nsec = 1000000L };
|
|
|
|
|
|
|
|
// Check flag in busy loop
|
|
|
|
while (active_threads)
|
|
|
|
nanosleep(&ts, nullptr);
|
|
|
|
|
|
|
|
// Wait another 1ms to make sure all threads left our code
|
|
|
|
nanosleep(&ts, nullptr);
|
|
|
|
}
|
|
|
|
|
2021-01-07 06:21:17 +00:00
|
|
|
__attribute__((constructor))
|
|
|
|
static void inject_init() {
|
2021-08-18 10:44:32 +00:00
|
|
|
if (char *env = getenv(INJECT_ENV_2)) {
|
2021-08-21 10:52:59 +00:00
|
|
|
zygisk_logging();
|
2021-08-19 08:54:12 +00:00
|
|
|
LOGD("zygisk: inject 2nd stage\n");
|
2021-01-07 06:21:17 +00:00
|
|
|
active_threads = 1;
|
2021-01-07 07:59:05 +00:00
|
|
|
unsetenv(INJECT_ENV_2);
|
2021-01-07 06:21:17 +00:00
|
|
|
|
|
|
|
// Get our own handle
|
2021-08-18 10:44:32 +00:00
|
|
|
self_handle = dlopen(env, RTLD_LAZY);
|
2021-01-07 06:21:17 +00:00
|
|
|
dlclose(self_handle);
|
|
|
|
|
2021-01-08 08:53:24 +00:00
|
|
|
hook_functions();
|
2021-01-07 06:21:17 +00:00
|
|
|
|
2021-08-18 10:44:32 +00:00
|
|
|
// Update path to 1st stage lib
|
|
|
|
*(strrchr(env, '.') - 1) = '1';
|
|
|
|
|
2021-01-07 07:59:05 +00:00
|
|
|
// Some cleanup
|
2021-01-07 07:41:37 +00:00
|
|
|
sanitize_environ();
|
2021-01-07 07:59:05 +00:00
|
|
|
active_threads++;
|
2021-08-18 10:44:32 +00:00
|
|
|
new_daemon_thread(&unload_first_stage, env);
|
|
|
|
} else if (getenv(INJECT_ENV_1)) {
|
2021-08-21 10:52:59 +00:00
|
|
|
android_logging();
|
2021-08-19 08:54:12 +00:00
|
|
|
LOGD("zygisk: inject 1st stage\n");
|
2021-01-07 07:59:05 +00:00
|
|
|
|
2021-08-18 10:44:32 +00:00
|
|
|
char *ld = getenv("LD_PRELOAD");
|
|
|
|
char *path;
|
|
|
|
if (char *c = strrchr(ld, ':')) {
|
|
|
|
*c = '\0';
|
|
|
|
setenv("LD_PRELOAD", ld, 1); // Restore original LD_PRELOAD
|
|
|
|
path = c + 1;
|
|
|
|
} else {
|
2021-01-07 07:59:05 +00:00
|
|
|
unsetenv("LD_PRELOAD");
|
2021-08-18 10:44:32 +00:00
|
|
|
path = ld;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Update path to 2nd stage lib
|
|
|
|
*(strrchr(path, '.') - 1) = '2';
|
2021-01-07 07:59:05 +00:00
|
|
|
|
|
|
|
// Setup second stage
|
2021-08-18 10:44:32 +00:00
|
|
|
setenv(INJECT_ENV_2, path, 1);
|
|
|
|
dlopen(path, RTLD_LAZY);
|
2021-01-07 07:59:05 +00:00
|
|
|
|
|
|
|
unsetenv(INJECT_ENV_1);
|
2021-01-07 06:21:17 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-08-19 11:55:17 +00:00
|
|
|
// Start code for magiskd IPC
|
|
|
|
|
2021-01-07 06:21:17 +00:00
|
|
|
int app_process_main(int argc, char *argv[]) {
|
2021-08-21 10:52:59 +00:00
|
|
|
android_logging();
|
2021-08-18 10:44:32 +00:00
|
|
|
|
|
|
|
if (int fd = connect_daemon(); fd >= 0) {
|
|
|
|
write_int(fd, ZYGISK_REQUEST);
|
|
|
|
write_int(fd, ZYGISK_SETUP);
|
|
|
|
|
|
|
|
if (read_int(fd) == 0) {
|
|
|
|
string path = read_string(fd);
|
|
|
|
string lib = path + ".1.so";
|
|
|
|
if (char *ld = getenv("LD_PRELOAD")) {
|
|
|
|
char env[256];
|
|
|
|
sprintf(env, "%s:%s", ld, lib.data());
|
|
|
|
setenv("LD_PRELOAD", env, 1);
|
|
|
|
} else {
|
|
|
|
setenv("LD_PRELOAD", lib.data(), 1);
|
|
|
|
}
|
|
|
|
setenv(INJECT_ENV_1, "1", 1);
|
|
|
|
}
|
|
|
|
close(fd);
|
2021-01-07 06:21:17 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Execute real app_process
|
2021-08-18 10:44:32 +00:00
|
|
|
char buf[256];
|
|
|
|
xreadlink("/proc/self/exe", buf, sizeof(buf));
|
|
|
|
xumount2("/proc/self/exe", MNT_DETACH);
|
2021-01-07 06:21:17 +00:00
|
|
|
execve(buf, argv, environ);
|
2021-01-07 07:41:37 +00:00
|
|
|
return 1;
|
2021-01-07 06:21:17 +00:00
|
|
|
}
|
2021-08-18 10:44:32 +00:00
|
|
|
|
2021-08-21 10:52:59 +00:00
|
|
|
static int zygisk_log(int prio, const char *fmt, va_list ap) {
|
|
|
|
// If we don't have log pipe set, ask magiskd for it
|
|
|
|
// This could happen multiple times in zygote because it was closed to prevent crashing
|
|
|
|
if (logd_fd < 0) {
|
|
|
|
// Change logging temporarily to prevent infinite recursion and stack overflow
|
|
|
|
android_logging();
|
|
|
|
if (int fd = connect_daemon(); fd >= 0) {
|
|
|
|
write_int(fd, ZYGISK_REQUEST);
|
|
|
|
write_int(fd, ZYGISK_GET_LOG_PIPE);
|
|
|
|
if (read_int(fd) == 0) {
|
|
|
|
logd_fd = recv_fd(fd);
|
|
|
|
}
|
|
|
|
close(fd);
|
|
|
|
}
|
|
|
|
zygisk_logging();
|
|
|
|
}
|
|
|
|
|
|
|
|
sigset_t mask;
|
|
|
|
sigset_t orig_mask;
|
|
|
|
bool sig = false;
|
|
|
|
// Make sure SIGPIPE won't crash zygote
|
|
|
|
if (logd_fd >= 0) {
|
|
|
|
sig = true;
|
|
|
|
sigemptyset(&mask);
|
|
|
|
sigaddset(&mask, SIGPIPE);
|
|
|
|
pthread_sigmask(SIG_BLOCK, &mask, &orig_mask);
|
|
|
|
}
|
|
|
|
int ret = magisk_log(prio, fmt, ap);
|
|
|
|
if (sig) {
|
|
|
|
timespec ts{};
|
|
|
|
sigtimedwait(&mask, nullptr, &ts);
|
|
|
|
pthread_sigmask(SIG_SETMASK, &orig_mask, nullptr);
|
|
|
|
}
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
|
2021-08-19 11:55:17 +00:00
|
|
|
bool remote_check_denylist(int uid, const char *process) {
|
|
|
|
if (int fd = connect_daemon(); fd >= 0) {
|
|
|
|
write_int(fd, ZYGISK_REQUEST);
|
|
|
|
write_int(fd, ZYGISK_CHECK_DENYLIST);
|
|
|
|
|
|
|
|
int ret = -1;
|
|
|
|
if (read_int(fd) == 0) {
|
|
|
|
write_int(fd, uid);
|
|
|
|
write_string(fd, process);
|
|
|
|
ret = read_int(fd);
|
|
|
|
}
|
|
|
|
close(fd);
|
|
|
|
return ret >= 0 && ret;
|
|
|
|
}
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
int remote_request_unmount() {
|
|
|
|
if (int fd = connect_daemon(); fd >= 0) {
|
|
|
|
write_int(fd, ZYGISK_REQUEST);
|
|
|
|
write_int(fd, ZYGISK_UNMOUNT);
|
|
|
|
int ret = read_int(fd);
|
|
|
|
close(fd);
|
|
|
|
return ret;
|
|
|
|
}
|
|
|
|
return DAEMON_ERROR;
|
|
|
|
}
|
|
|
|
|
2021-08-18 10:44:32 +00:00
|
|
|
// The following code runs in magiskd
|
|
|
|
|
|
|
|
static void setup_files(int client, ucred *cred) {
|
2021-08-22 09:11:48 +00:00
|
|
|
LOGD("zygisk: setup files for pid=[%d]\n", cred->pid);
|
2021-08-18 10:44:32 +00:00
|
|
|
|
2021-08-22 09:11:48 +00:00
|
|
|
char buf[256];
|
|
|
|
snprintf(buf, sizeof(buf), "/proc/%d/exe", cred->pid);
|
|
|
|
if (xreadlink(buf, buf, sizeof(buf)) < 0) {
|
2021-08-18 10:44:32 +00:00
|
|
|
write_int(client, 1);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
write_int(client, 0);
|
|
|
|
|
|
|
|
string path = MAGISKTMP + "/zygisk." + basename(buf);
|
|
|
|
cp_afc(buf, (path + ".1.so").data());
|
|
|
|
cp_afc(buf, (path + ".2.so").data());
|
|
|
|
|
|
|
|
write_string(client, path);
|
|
|
|
}
|
|
|
|
|
2021-08-19 11:55:17 +00:00
|
|
|
static void check_denylist(int client) {
|
|
|
|
if (!hide_enabled()) {
|
|
|
|
write_int(client, HIDE_NOT_ENABLED);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
write_int(client, 0);
|
|
|
|
int uid = read_int(client);
|
|
|
|
string process = read_string(client);
|
|
|
|
write_int(client, is_hide_target(uid, process));
|
|
|
|
}
|
|
|
|
|
|
|
|
static void do_unmount(int client, ucred *cred) {
|
|
|
|
LOGD("zygisk: cleanup mount namespace for pid=[%d]\n", cred->pid);
|
|
|
|
if (hide_enabled()) {
|
|
|
|
hide_daemon(cred->pid, client);
|
|
|
|
} else {
|
|
|
|
write_int(client, HIDE_NOT_ENABLED);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-08-21 10:52:59 +00:00
|
|
|
static void send_log_pipe(int fd) {
|
|
|
|
// There is race condition here, but we can't really do much about it...
|
2021-08-22 09:11:48 +00:00
|
|
|
if (logd_fd >= 0) {
|
2021-08-21 10:52:59 +00:00
|
|
|
write_int(fd, 0);
|
|
|
|
send_fd(fd, logd_fd);
|
|
|
|
} else {
|
|
|
|
write_int(fd, 1);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-08-18 10:44:32 +00:00
|
|
|
void zygisk_handler(int client, ucred *cred) {
|
|
|
|
int code = read_int(client);
|
|
|
|
switch (code) {
|
|
|
|
case ZYGISK_SETUP:
|
|
|
|
setup_files(client, cred);
|
|
|
|
break;
|
2021-08-19 11:55:17 +00:00
|
|
|
case ZYGISK_CHECK_DENYLIST:
|
|
|
|
check_denylist(client);
|
|
|
|
break;
|
|
|
|
case ZYGISK_UNMOUNT:
|
|
|
|
do_unmount(client, cred);
|
|
|
|
break;
|
2021-08-21 10:52:59 +00:00
|
|
|
case ZYGISK_GET_LOG_PIPE:
|
|
|
|
send_log_pipe(client);
|
|
|
|
break;
|
2021-08-18 10:44:32 +00:00
|
|
|
}
|
|
|
|
close(client);
|
|
|
|
}
|