1*795d594fSAndroid Build Coastguard Worker /* 2*795d594fSAndroid Build Coastguard Worker * Copyright (C) 2017 The Android Open Source Project 3*795d594fSAndroid Build Coastguard Worker * 4*795d594fSAndroid Build Coastguard Worker * Licensed under the Apache License, Version 2.0 (the "License"); 5*795d594fSAndroid Build Coastguard Worker * you may not use this file except in compliance with the License. 6*795d594fSAndroid Build Coastguard Worker * You may obtain a copy of the License at 7*795d594fSAndroid Build Coastguard Worker * 8*795d594fSAndroid Build Coastguard Worker * http://www.apache.org/licenses/LICENSE-2.0 9*795d594fSAndroid Build Coastguard Worker * 10*795d594fSAndroid Build Coastguard Worker * Unless required by applicable law or agreed to in writing, software 11*795d594fSAndroid Build Coastguard Worker * distributed under the License is distributed on an "AS IS" BASIS, 12*795d594fSAndroid Build Coastguard Worker * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 13*795d594fSAndroid Build Coastguard Worker * See the License for the specific language governing permissions and 14*795d594fSAndroid Build Coastguard Worker * limitations under the License. 15*795d594fSAndroid Build Coastguard Worker */ 16*795d594fSAndroid Build Coastguard Worker 17*795d594fSAndroid Build Coastguard Worker import art.Redefinition; 18*795d594fSAndroid Build Coastguard Worker import java.util.Base64; 19*795d594fSAndroid Build Coastguard Worker 20*795d594fSAndroid Build Coastguard Worker public class DexCacheSmash { 21*795d594fSAndroid Build Coastguard Worker static class Transform { foo()22*795d594fSAndroid Build Coastguard Worker public void foo() {} bar()23*795d594fSAndroid Build Coastguard Worker public void bar() {} getId()24*795d594fSAndroid Build Coastguard Worker public String getId() { 25*795d594fSAndroid Build Coastguard Worker return "TRANSFORM_INITIAL"; 26*795d594fSAndroid Build Coastguard Worker } 27*795d594fSAndroid Build Coastguard Worker } 28*795d594fSAndroid Build Coastguard Worker 29*795d594fSAndroid Build Coastguard Worker static class Transform2 { getId()30*795d594fSAndroid Build Coastguard Worker public String getId() { 31*795d594fSAndroid Build Coastguard Worker return "TRANSFORM2_INITIAL"; 32*795d594fSAndroid Build Coastguard Worker } 33*795d594fSAndroid Build Coastguard Worker } 34*795d594fSAndroid Build Coastguard Worker 35*795d594fSAndroid Build Coastguard Worker /** 36*795d594fSAndroid Build Coastguard Worker * A base64 encoding of the dex/class file of the Transform class above. 37*795d594fSAndroid Build Coastguard Worker */ 38*795d594fSAndroid Build Coastguard Worker static final byte[] TRANSFORM_INITIAL_CLASS_FILE_BYTES = Base64.getDecoder().decode( 39*795d594fSAndroid Build Coastguard Worker "yv66vgAAADQAFwoABAAPCAAQBwASBwAVAQAGPGluaXQ+AQADKClWAQAEQ29kZQEAD0xpbmVOdW1i" + 40*795d594fSAndroid Build Coastguard Worker "ZXJUYWJsZQEAA2ZvbwEAA2JhcgEABWdldElkAQAUKClMamF2YS9sYW5nL1N0cmluZzsBAApTb3Vy" + 41*795d594fSAndroid Build Coastguard Worker "Y2VGaWxlAQASRGV4Q2FjaGVTbWFzaC5qYXZhDAAFAAYBABFUUkFOU0ZPUk1fSU5JVElBTAcAFgEA" + 42*795d594fSAndroid Build Coastguard Worker "F0RleENhY2hlU21hc2gkVHJhbnNmb3JtAQAJVHJhbnNmb3JtAQAMSW5uZXJDbGFzc2VzAQAQamF2" + 43*795d594fSAndroid Build Coastguard Worker "YS9sYW5nL09iamVjdAEADURleENhY2hlU21hc2gAIAADAAQAAAAAAAQAAAAFAAYAAQAHAAAAHQAB" + 44*795d594fSAndroid Build Coastguard Worker "AAEAAAAFKrcAAbEAAAABAAgAAAAGAAEAAAATAAEACQAGAAEABwAAABkAAAABAAAAAbEAAAABAAgA" + 45*795d594fSAndroid Build Coastguard Worker "AAAGAAEAAAAUAAEACgAGAAEABwAAABkAAAABAAAAAbEAAAABAAgAAAAGAAEAAAAVAAEACwAMAAEA" + 46*795d594fSAndroid Build Coastguard Worker "BwAAABsAAQABAAAAAxICsAAAAAEACAAAAAYAAQAAABcAAgANAAAAAgAOABQAAAAKAAEAAwARABMA" + 47*795d594fSAndroid Build Coastguard Worker "CA=="); 48*795d594fSAndroid Build Coastguard Worker static final byte[] TRANSFORM_INITIAL_DEX_FILE_BYTES = Base64.getDecoder().decode( 49*795d594fSAndroid Build Coastguard Worker "ZGV4CjAzNQDhg9CfghG1SRlLClguRuFYsqihr4F7NsGQAwAAcAAAAHhWNBIAAAAAAAAAAOQCAAAS" + 50*795d594fSAndroid Build Coastguard Worker "AAAAcAAAAAcAAAC4AAAAAgAAANQAAAAAAAAAAAAAAAUAAADsAAAAAQAAABQBAABcAgAANAEAAKgB" + 51*795d594fSAndroid Build Coastguard Worker "AACwAQAAxAEAAMcBAADiAQAA8wEAABcCAAA3AgAASwIAAF8CAAByAgAAfQIAAIACAACNAgAAkgIA" + 52*795d594fSAndroid Build Coastguard Worker "AJcCAACeAgAApAIAAAMAAAAEAAAABQAAAAYAAAAHAAAACAAAAAsAAAACAAAABQAAAAAAAAALAAAA" + 53*795d594fSAndroid Build Coastguard Worker "BgAAAAAAAAAAAAEAAAAAAAAAAQANAAAAAAABAA4AAAAAAAAADwAAAAQAAQAAAAAAAAAAAAAAAAAE" + 54*795d594fSAndroid Build Coastguard Worker "AAAAAAAAAAEAAACYAQAAzgIAAAAAAAACAAAAvwIAAMUCAAABAAEAAQAAAKsCAAAEAAAAcBAEAAAA" + 55*795d594fSAndroid Build Coastguard Worker "DgABAAEAAAAAALACAAABAAAADgAAAAEAAQAAAAAAtQIAAAEAAAAOAAAAAgABAAAAAAC6AgAAAwAA" + 56*795d594fSAndroid Build Coastguard Worker "ABoACQARAAAANAEAAAAAAAAAAAAAAAAAAAY8aW5pdD4AEkRleENhY2hlU21hc2guamF2YQABTAAZ" + 57*795d594fSAndroid Build Coastguard Worker "TERleENhY2hlU21hc2gkVHJhbnNmb3JtOwAPTERleENhY2hlU21hc2g7ACJMZGFsdmlrL2Fubm90" + 58*795d594fSAndroid Build Coastguard Worker "YXRpb24vRW5jbG9zaW5nQ2xhc3M7AB5MZGFsdmlrL2Fubm90YXRpb24vSW5uZXJDbGFzczsAEkxq" + 59*795d594fSAndroid Build Coastguard Worker "YXZhL2xhbmcvT2JqZWN0OwASTGphdmEvbGFuZy9TdHJpbmc7ABFUUkFOU0ZPUk1fSU5JVElBTAAJ" + 60*795d594fSAndroid Build Coastguard Worker "VHJhbnNmb3JtAAFWAAthY2Nlc3NGbGFncwADYmFyAANmb28ABWdldElkAARuYW1lAAV2YWx1ZQAT" + 61*795d594fSAndroid Build Coastguard Worker "AAcOABUABw4AFAAHDgAXAAcOAAICAREYAQIDAgwECBAXCgAAAQMAgIAEwAIBAdgCAQHsAgEBgAMO" + 62*795d594fSAndroid Build Coastguard Worker "AAAAAAAAAAEAAAAAAAAAAQAAABIAAABwAAAAAgAAAAcAAAC4AAAAAwAAAAIAAADUAAAABQAAAAUA" + 63*795d594fSAndroid Build Coastguard Worker "AADsAAAABgAAAAEAAAAUAQAAAxAAAAEAAAA0AQAAASAAAAQAAABAAQAABiAAAAEAAACYAQAAAiAA" + 64*795d594fSAndroid Build Coastguard Worker "ABIAAACoAQAAAyAAAAQAAACrAgAABCAAAAIAAAC/AgAAACAAAAEAAADOAgAAABAAAAEAAADkAgAA"); 65*795d594fSAndroid Build Coastguard Worker static final Redefinition.CommonClassDefinition TRANSFORM_INITIAL = 66*795d594fSAndroid Build Coastguard Worker new Redefinition.CommonClassDefinition(Transform.class, 67*795d594fSAndroid Build Coastguard Worker TRANSFORM_INITIAL_CLASS_FILE_BYTES, TRANSFORM_INITIAL_DEX_FILE_BYTES); 68*795d594fSAndroid Build Coastguard Worker 69*795d594fSAndroid Build Coastguard Worker /** 70*795d594fSAndroid Build Coastguard Worker * A base64 encoding of the following (invalid) class. 71*795d594fSAndroid Build Coastguard Worker * 72*795d594fSAndroid Build Coastguard Worker * .class LDexCacheSmash$Transform2; 73*795d594fSAndroid Build Coastguard Worker * .super Ljava/lang/Object; 74*795d594fSAndroid Build Coastguard Worker * .source "DexCacheSmash.java" 75*795d594fSAndroid Build Coastguard Worker * 76*795d594fSAndroid Build Coastguard Worker * # annotations 77*795d594fSAndroid Build Coastguard Worker * .annotation system Ldalvik/annotation/EnclosingClass; 78*795d594fSAndroid Build Coastguard Worker * value = LDexCacheSmash; 79*795d594fSAndroid Build Coastguard Worker * .end annotation 80*795d594fSAndroid Build Coastguard Worker * 81*795d594fSAndroid Build Coastguard Worker * .annotation system Ldalvik/annotation/InnerClass; 82*795d594fSAndroid Build Coastguard Worker * accessFlags = 0x8 83*795d594fSAndroid Build Coastguard Worker * name = "Transform2" 84*795d594fSAndroid Build Coastguard Worker * .end annotation 85*795d594fSAndroid Build Coastguard Worker * 86*795d594fSAndroid Build Coastguard Worker * 87*795d594fSAndroid Build Coastguard Worker * # direct methods 88*795d594fSAndroid Build Coastguard Worker * .method constructor <init>()V 89*795d594fSAndroid Build Coastguard Worker * .registers 1 90*795d594fSAndroid Build Coastguard Worker * 91*795d594fSAndroid Build Coastguard Worker * .prologue 92*795d594fSAndroid Build Coastguard Worker * .line 26 93*795d594fSAndroid Build Coastguard Worker * invoke-direct {p0}, Ljava/lang/Object;-><init>()V 94*795d594fSAndroid Build Coastguard Worker * 95*795d594fSAndroid Build Coastguard Worker * return-void 96*795d594fSAndroid Build Coastguard Worker * .end method 97*795d594fSAndroid Build Coastguard Worker * 98*795d594fSAndroid Build Coastguard Worker * 99*795d594fSAndroid Build Coastguard Worker * # virtual methods 100*795d594fSAndroid Build Coastguard Worker * .method public getId()Ljava/lang/String; 101*795d594fSAndroid Build Coastguard Worker * .registers 2 102*795d594fSAndroid Build Coastguard Worker * 103*795d594fSAndroid Build Coastguard Worker * .prologue 104*795d594fSAndroid Build Coastguard Worker * .line 28 105*795d594fSAndroid Build Coastguard Worker * # NB Fails verification due to this function not returning a String. 106*795d594fSAndroid Build Coastguard Worker * return-void 107*795d594fSAndroid Build Coastguard Worker * .end method 108*795d594fSAndroid Build Coastguard Worker */ 109*795d594fSAndroid Build Coastguard Worker static final byte[] TRANSFORM2_INVALID_CLASS_FILE_BYTES = Base64.getDecoder().decode( 110*795d594fSAndroid Build Coastguard Worker "yv66vgAAADQAEwcAEgcAEQEABjxpbml0PgEAAygpVgEABENvZGUKAAIAEAEAD0xpbmVOdW1iZXJU" + 111*795d594fSAndroid Build Coastguard Worker "YWJsZQEABWdldElkAQAUKClMamF2YS9sYW5nL1N0cmluZzsBAApTb3VyY2VGaWxlAQASRGV4Q2Fj" + 112*795d594fSAndroid Build Coastguard Worker "aGVTbWFzaC5qYXZhAQAMSW5uZXJDbGFzc2VzBwAPAQAKVHJhbnNmb3JtMgEADURleENhY2hlU21h" + 113*795d594fSAndroid Build Coastguard Worker "c2gMAAMABAEAEGphdmEvbGFuZy9PYmplY3QBABhEZXhDYWNoZVNtYXNoJFRyYW5zZm9ybTIAIAAB" + 114*795d594fSAndroid Build Coastguard Worker "AAIAAAAAAAIAAAADAAQAAQAFAAAAHQABAAEAAAAFKrcABrEAAAABAAcAAAAGAAEAAAAaAAEACAAJ" + 115*795d594fSAndroid Build Coastguard Worker "AAEABQAAABkAAQABAAAAAbEAAAABAAcAAAAGAAEAAAAcAAIACgAAAAIACwAMAAAACgABAAEADQAO" + 116*795d594fSAndroid Build Coastguard Worker "AAg="); 117*795d594fSAndroid Build Coastguard Worker static final byte[] TRANSFORM2_INVALID_DEX_FILE_BYTES = Base64.getDecoder().decode( 118*795d594fSAndroid Build Coastguard Worker "ZGV4CjAzNQCFcegr6Ns+I7iEF4uLRkUX4yGrLhP6soEgAwAAcAAAAHhWNBIAAAAAAAAAAHQCAAAP" + 119*795d594fSAndroid Build Coastguard Worker "AAAAcAAAAAcAAACsAAAAAgAAAMgAAAAAAAAAAAAAAAMAAADgAAAAAQAAAPgAAAAIAgAAGAEAABgB" + 120*795d594fSAndroid Build Coastguard Worker "AAAgAQAANAEAADcBAABTAQAAZAEAAIgBAACoAQAAvAEAANABAADcAQAA3wEAAOwBAADzAQAA+QEA" + 121*795d594fSAndroid Build Coastguard Worker "AAMAAAAEAAAABQAAAAYAAAAHAAAACAAAAAoAAAACAAAABQAAAAAAAAAKAAAABgAAAAAAAAAAAAEA" + 122*795d594fSAndroid Build Coastguard Worker "AAAAAAAAAAAMAAAABAABAAAAAAAAAAAAAAAAAAQAAAAAAAAAAQAAACACAABmAgAAAAAAAAY8aW5p" + 123*795d594fSAndroid Build Coastguard Worker "dD4AEkRleENhY2hlU21hc2guamF2YQABTAAaTERleENhY2hlU21hc2gkVHJhbnNmb3JtMjsAD0xE" + 124*795d594fSAndroid Build Coastguard Worker "ZXhDYWNoZVNtYXNoOwAiTGRhbHZpay9hbm5vdGF0aW9uL0VuY2xvc2luZ0NsYXNzOwAeTGRhbHZp" + 125*795d594fSAndroid Build Coastguard Worker "ay9hbm5vdGF0aW9uL0lubmVyQ2xhc3M7ABJMamF2YS9sYW5nL09iamVjdDsAEkxqYXZhL2xhbmcv" + 126*795d594fSAndroid Build Coastguard Worker "U3RyaW5nOwAKVHJhbnNmb3JtMgABVgALYWNjZXNzRmxhZ3MABWdldElkAARuYW1lAAV2YWx1ZQAC" + 127*795d594fSAndroid Build Coastguard Worker "AwILBAgNFwkCAgEOGAEAAAAAAAIAAAAJAgAAAAIAABQCAAAAAAAAAAAAAAAAAAAaAAcOABwABw4A" + 128*795d594fSAndroid Build Coastguard Worker "AAABAAEAAQAAADACAAAEAAAAcBACAAAADgACAAEAAAAAADUCAAABAAAADgAAAAEBAICABLwEAQHU" + 129*795d594fSAndroid Build Coastguard Worker "BA4AAAAAAAAAAQAAAAAAAAABAAAADwAAAHAAAAACAAAABwAAAKwAAAADAAAAAgAAAMgAAAAFAAAA" + 130*795d594fSAndroid Build Coastguard Worker "AwAAAOAAAAAGAAAAAQAAAPgAAAACIAAADwAAABgBAAAEIAAAAgAAAAACAAADEAAAAgAAABACAAAG" + 131*795d594fSAndroid Build Coastguard Worker "IAAAAQAAACACAAADIAAAAgAAADACAAABIAAAAgAAADwCAAAAIAAAAQAAAGYCAAAAEAAAAQAAAHQC" + 132*795d594fSAndroid Build Coastguard Worker "AAA="); 133*795d594fSAndroid Build Coastguard Worker static final Redefinition.CommonClassDefinition TRANSFORM2_INVALID = 134*795d594fSAndroid Build Coastguard Worker new Redefinition.CommonClassDefinition(Transform2.class, 135*795d594fSAndroid Build Coastguard Worker TRANSFORM2_INVALID_CLASS_FILE_BYTES, TRANSFORM2_INVALID_DEX_FILE_BYTES); 136*795d594fSAndroid Build Coastguard Worker run()137*795d594fSAndroid Build Coastguard Worker public static void run() throws Exception { 138*795d594fSAndroid Build Coastguard Worker try { 139*795d594fSAndroid Build Coastguard Worker Redefinition.doMultiClassRedefinition(TRANSFORM2_INVALID); 140*795d594fSAndroid Build Coastguard Worker } catch (Exception e) { 141*795d594fSAndroid Build Coastguard Worker if (!e.getMessage().contains("JVMTI_ERROR_FAILS_VERIFICATION")) { 142*795d594fSAndroid Build Coastguard Worker throw new Error( 143*795d594fSAndroid Build Coastguard Worker "Unexpected error: Expected failure due to JVMTI_ERROR_FAILS_VERIFICATION", 144*795d594fSAndroid Build Coastguard Worker e); 145*795d594fSAndroid Build Coastguard Worker } 146*795d594fSAndroid Build Coastguard Worker } 147*795d594fSAndroid Build Coastguard Worker // Doing this redefinition after a redefinition that failed due to FAILS_VERIFICATION could 148*795d594fSAndroid Build Coastguard Worker // cause a use-after-free of the Transform2's DexCache by the redefinition code if it 149*795d594fSAndroid Build Coastguard Worker // happens that the native pointer of the art::DexFile created for the Transform 150*795d594fSAndroid Build Coastguard Worker // redefinition aliases the one created for Transform2's failed redefinition. 151*795d594fSAndroid Build Coastguard Worker // 152*795d594fSAndroid Build Coastguard Worker // Due to the order of checks performed by the redefinition code FAILS_VERIFICATION is the 153*795d594fSAndroid Build Coastguard Worker // only failure mode that can cause Use-after-frees in this way. 154*795d594fSAndroid Build Coastguard Worker // 155*795d594fSAndroid Build Coastguard Worker // This should never throw any exceptions (except perhaps OOME in very strange 156*795d594fSAndroid Build Coastguard Worker // circumstances). 157*795d594fSAndroid Build Coastguard Worker Redefinition.doMultiClassRedefinition(TRANSFORM_INITIAL); 158*795d594fSAndroid Build Coastguard Worker } 159*795d594fSAndroid Build Coastguard Worker } 160