1*d57664e9SAndroid Build Coastguard Worker /*
2*d57664e9SAndroid Build Coastguard Worker * Copyright (C) 2022 The Android Open Source Project
3*d57664e9SAndroid Build Coastguard Worker *
4*d57664e9SAndroid Build Coastguard Worker * Licensed under the Apache License, Version 2.0 (the "License");
5*d57664e9SAndroid Build Coastguard Worker * you may not use this file except in compliance with the License.
6*d57664e9SAndroid Build Coastguard Worker * You may obtain a copy of the License at
7*d57664e9SAndroid Build Coastguard Worker *
8*d57664e9SAndroid Build Coastguard Worker * http://www.apache.org/licenses/LICENSE-2.0
9*d57664e9SAndroid Build Coastguard Worker *
10*d57664e9SAndroid Build Coastguard Worker * Unless required by applicable law or agreed to in writing, software
11*d57664e9SAndroid Build Coastguard Worker * distributed under the License is distributed on an "AS IS" BASIS,
12*d57664e9SAndroid Build Coastguard Worker * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13*d57664e9SAndroid Build Coastguard Worker * See the License for the specific language governing permissions and
14*d57664e9SAndroid Build Coastguard Worker * limitations under the License.
15*d57664e9SAndroid Build Coastguard Worker */
16*d57664e9SAndroid Build Coastguard Worker
17*d57664e9SAndroid Build Coastguard Worker #include "androidfw/ApkParsing.h"
18*d57664e9SAndroid Build Coastguard Worker #include <algorithm>
19*d57664e9SAndroid Build Coastguard Worker #include <array>
20*d57664e9SAndroid Build Coastguard Worker #include <stdlib.h>
21*d57664e9SAndroid Build Coastguard Worker #include <string_view>
22*d57664e9SAndroid Build Coastguard Worker #include <sys/types.h>
23*d57664e9SAndroid Build Coastguard Worker
24*d57664e9SAndroid Build Coastguard Worker const std::string_view APK_LIB = "lib/";
25*d57664e9SAndroid Build Coastguard Worker const size_t APK_LIB_LEN = APK_LIB.size();
26*d57664e9SAndroid Build Coastguard Worker
27*d57664e9SAndroid Build Coastguard Worker const std::string_view LIB_PREFIX = "/lib";
28*d57664e9SAndroid Build Coastguard Worker const size_t LIB_PREFIX_LEN = LIB_PREFIX.size();
29*d57664e9SAndroid Build Coastguard Worker
30*d57664e9SAndroid Build Coastguard Worker const std::string_view LIB_SUFFIX = ".so";
31*d57664e9SAndroid Build Coastguard Worker const size_t LIB_SUFFIX_LEN = LIB_SUFFIX.size();
32*d57664e9SAndroid Build Coastguard Worker
33*d57664e9SAndroid Build Coastguard Worker static const std::array<std::string_view, 2> abis = {"arm64-v8a", "x86_64"};
34*d57664e9SAndroid Build Coastguard Worker
35*d57664e9SAndroid Build Coastguard Worker namespace android::util {
ValidLibraryPathLastSlash(const char * fileName,bool suppress64Bit,bool debuggable)36*d57664e9SAndroid Build Coastguard Worker const char* ValidLibraryPathLastSlash(const char* fileName, bool suppress64Bit, bool debuggable) {
37*d57664e9SAndroid Build Coastguard Worker // Make sure the filename is at least to the minimum library name size.
38*d57664e9SAndroid Build Coastguard Worker const size_t fileNameLen = strlen(fileName);
39*d57664e9SAndroid Build Coastguard Worker static const size_t minLength = APK_LIB_LEN + 2 + LIB_PREFIX_LEN + 1 + LIB_SUFFIX_LEN;
40*d57664e9SAndroid Build Coastguard Worker if (fileNameLen < minLength) {
41*d57664e9SAndroid Build Coastguard Worker return nullptr;
42*d57664e9SAndroid Build Coastguard Worker }
43*d57664e9SAndroid Build Coastguard Worker
44*d57664e9SAndroid Build Coastguard Worker const char* lastSlash = strrchr(fileName, '/');
45*d57664e9SAndroid Build Coastguard Worker if (!lastSlash) {
46*d57664e9SAndroid Build Coastguard Worker return nullptr;
47*d57664e9SAndroid Build Coastguard Worker }
48*d57664e9SAndroid Build Coastguard Worker
49*d57664e9SAndroid Build Coastguard Worker // Skip directories.
50*d57664e9SAndroid Build Coastguard Worker if (*(lastSlash + 1) == 0) {
51*d57664e9SAndroid Build Coastguard Worker return nullptr;
52*d57664e9SAndroid Build Coastguard Worker }
53*d57664e9SAndroid Build Coastguard Worker
54*d57664e9SAndroid Build Coastguard Worker // Make sure the filename is safe.
55*d57664e9SAndroid Build Coastguard Worker if (!isFilenameSafe(lastSlash + 1)) {
56*d57664e9SAndroid Build Coastguard Worker return nullptr;
57*d57664e9SAndroid Build Coastguard Worker }
58*d57664e9SAndroid Build Coastguard Worker
59*d57664e9SAndroid Build Coastguard Worker // Make sure file starts with 'lib/' prefix.
60*d57664e9SAndroid Build Coastguard Worker if (strncmp(fileName, APK_LIB.data(), APK_LIB_LEN) != 0) {
61*d57664e9SAndroid Build Coastguard Worker return nullptr;
62*d57664e9SAndroid Build Coastguard Worker }
63*d57664e9SAndroid Build Coastguard Worker
64*d57664e9SAndroid Build Coastguard Worker // Make sure there aren't subdirectories by checking if the next / after lib/ is the last slash
65*d57664e9SAndroid Build Coastguard Worker if (memchr(fileName + APK_LIB_LEN, '/', fileNameLen - APK_LIB_LEN) != lastSlash) {
66*d57664e9SAndroid Build Coastguard Worker return nullptr;
67*d57664e9SAndroid Build Coastguard Worker }
68*d57664e9SAndroid Build Coastguard Worker
69*d57664e9SAndroid Build Coastguard Worker if (!debuggable) {
70*d57664e9SAndroid Build Coastguard Worker // Make sure the filename starts with lib and ends with ".so".
71*d57664e9SAndroid Build Coastguard Worker if (strncmp(fileName + fileNameLen - LIB_SUFFIX_LEN, LIB_SUFFIX.data(), LIB_SUFFIX_LEN) != 0
72*d57664e9SAndroid Build Coastguard Worker || strncmp(lastSlash, LIB_PREFIX.data(), LIB_PREFIX_LEN) != 0) {
73*d57664e9SAndroid Build Coastguard Worker return nullptr;
74*d57664e9SAndroid Build Coastguard Worker }
75*d57664e9SAndroid Build Coastguard Worker }
76*d57664e9SAndroid Build Coastguard Worker
77*d57664e9SAndroid Build Coastguard Worker // Don't include 64 bit versions if they are suppressed
78*d57664e9SAndroid Build Coastguard Worker if (suppress64Bit && std::find(abis.begin(), abis.end(), std::string_view(
79*d57664e9SAndroid Build Coastguard Worker fileName + APK_LIB_LEN, lastSlash - fileName - APK_LIB_LEN)) != abis.end()) {
80*d57664e9SAndroid Build Coastguard Worker return nullptr;
81*d57664e9SAndroid Build Coastguard Worker }
82*d57664e9SAndroid Build Coastguard Worker
83*d57664e9SAndroid Build Coastguard Worker return lastSlash;
84*d57664e9SAndroid Build Coastguard Worker }
85*d57664e9SAndroid Build Coastguard Worker
isFilenameSafe(const char * filename)86*d57664e9SAndroid Build Coastguard Worker bool isFilenameSafe(const char* filename) {
87*d57664e9SAndroid Build Coastguard Worker off_t offset = 0;
88*d57664e9SAndroid Build Coastguard Worker for (;;) {
89*d57664e9SAndroid Build Coastguard Worker switch (*(filename + offset)) {
90*d57664e9SAndroid Build Coastguard Worker case 0:
91*d57664e9SAndroid Build Coastguard Worker // Null.
92*d57664e9SAndroid Build Coastguard Worker // If we've reached the end, all the other characters are good.
93*d57664e9SAndroid Build Coastguard Worker return true;
94*d57664e9SAndroid Build Coastguard Worker
95*d57664e9SAndroid Build Coastguard Worker case 'A' ... 'Z':
96*d57664e9SAndroid Build Coastguard Worker case 'a' ... 'z':
97*d57664e9SAndroid Build Coastguard Worker case '0' ... '9':
98*d57664e9SAndroid Build Coastguard Worker case '+':
99*d57664e9SAndroid Build Coastguard Worker case ',':
100*d57664e9SAndroid Build Coastguard Worker case '-':
101*d57664e9SAndroid Build Coastguard Worker case '.':
102*d57664e9SAndroid Build Coastguard Worker case '/':
103*d57664e9SAndroid Build Coastguard Worker case '=':
104*d57664e9SAndroid Build Coastguard Worker case '_':
105*d57664e9SAndroid Build Coastguard Worker offset++;
106*d57664e9SAndroid Build Coastguard Worker break;
107*d57664e9SAndroid Build Coastguard Worker
108*d57664e9SAndroid Build Coastguard Worker default:
109*d57664e9SAndroid Build Coastguard Worker // We found something that is not good.
110*d57664e9SAndroid Build Coastguard Worker return false;
111*d57664e9SAndroid Build Coastguard Worker }
112*d57664e9SAndroid Build Coastguard Worker }
113*d57664e9SAndroid Build Coastguard Worker // Should not reach here.
114*d57664e9SAndroid Build Coastguard Worker }
115*d57664e9SAndroid Build Coastguard Worker }