1 /*
2  * Copyright (C) 2024 The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *      http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #ifndef NATIVE_BRIDGE_SUPPORT_GUEST_STATE_DLEXT_NAMESPACES_H_
18 #define NATIVE_BRIDGE_SUPPORT_GUEST_STATE_DLEXT_NAMESPACES_H_
19 
20 #include <android/dlext.h>
21 #include <stdbool.h>
22 #include <sys/cdefs.h>
23 
24 __BEGIN_DECLS
25 
26 enum {
27   /* A regular namespace is the namespace with a custom search path that does
28    * not impose any restrictions on the location of native libraries.
29    */
30   ANDROID_NAMESPACE_TYPE_REGULAR = 0,
31 
32   /* An isolated namespace requires all the libraries to be on the search path
33    * or under permitted_when_isolated_path. The search path is the union of
34    * ld_library_path and default_library_path.
35    */
36   ANDROID_NAMESPACE_TYPE_ISOLATED = 1,
37 
38   /* The shared namespace clones the list of libraries of the caller namespace upon creation
39    * which means that they are shared between namespaces - the caller namespace and the new one
40    * will use the same copy of a library if it was loaded prior to android_create_namespace call.
41    *
42    * Note that libraries loaded after the namespace is created will not be shared.
43    *
44    * Shared namespaces can be isolated or regular. Note that they do not inherit the search path nor
45    * permitted_path from the caller's namespace.
46    */
47   ANDROID_NAMESPACE_TYPE_SHARED = 2,
48 
49   /* This flag instructs linker to enable exempt-list workaround for the namespace.
50    * See http://b/26394120 for details.
51    */
52   ANDROID_NAMESPACE_TYPE_EXEMPT_LIST_ENABLED = 0x08000000,
53 
54   /* This flag instructs linker to use this namespace as the anonymous
55    * namespace. The anonymous namespace is used in the case when linker cannot
56    * identify the caller of dlopen/dlsym. This happens for the code not loaded
57    * by dynamic linker; for example calls from the mono-compiled code. There can
58    * be only one anonymous namespace in a process. If there already is an
59    * anonymous namespace in the process, using this flag when creating a new
60    * namespace causes an error.
61    */
62   ANDROID_NAMESPACE_TYPE_ALSO_USED_AS_ANONYMOUS = 0x10000000,
63 
64   ANDROID_NAMESPACE_TYPE_SHARED_ISOLATED =
65       ANDROID_NAMESPACE_TYPE_SHARED | ANDROID_NAMESPACE_TYPE_ISOLATED,
66 };
67 
68 /*
69  * Creates new linker namespace.
70  * ld_library_path and default_library_path represent the search path
71  * for the libraries in the namespace.
72  *
73  * The libraries in the namespace are searched by following order:
74  * 1. ld_library_path (Think of this as namespace-local LD_LIBRARY_PATH)
75  * 2. In directories specified by DT_RUNPATH of the "needed by" binary.
76  * 3. default_library_path (This of this as namespace-local default library path)
77  *
78  * When type is ANDROID_NAMESPACE_TYPE_ISOLATED the resulting namespace requires all of
79  * the libraries to be on the search path or under the permitted_when_isolated_path;
80  * the search_path is ld_library_path:default_library_path. Note that the
81  * permitted_when_isolated_path path is not part of the search_path and
82  * does not affect the search order. It is a way to allow loading libraries from specific
83  * locations when using absolute path.
84  * If a library or any of its dependencies are outside of the permitted_when_isolated_path
85  * and search_path, and it is not part of the public namespace dlopen will fail.
86  */
87 extern struct android_namespace_t* android_create_namespace(
88     const char* name, const char* ld_library_path, const char* default_library_path, uint64_t type,
89     const char* permitted_when_isolated_path, struct android_namespace_t* parent);
90 
91 /*
92  * Creates a link between namespaces. Every link has list of sonames of
93  * shared libraries. These are the libraries which are accessible from
94  * namespace 'from' but loaded within namespace 'to' context.
95  * When to namespace is nullptr this function establishes a link between
96  * 'from' namespace and the default namespace.
97  *
98  * The lookup order of the libraries in namespaces with links is following:
99  * 1. Look inside current namespace using 'this' namespace search path.
100  * 2. Look in linked namespaces
101  * 2.1. Perform soname check - if library soname is not in the list of shared
102  *      libraries sonames skip this link, otherwise
103  * 2.2. Search library using linked namespace search path. Note that this
104  *      step will not go deeper into linked namespaces for this library but
105  *      will do so for DT_NEEDED libraries.
106  */
107 extern bool android_link_namespaces(struct android_namespace_t* from,
108                                     struct android_namespace_t* to,
109                                     const char* shared_libs_sonames);
110 
111 extern struct android_namespace_t* android_get_exported_namespace(const char* name);
112 
113 __END_DECLS
114 
115 #endif  // NATIVE_BRIDGE_SUPPORT_GUEST_STATE_DLEXT_NAMESPACES_H_