1 /*
2  * Copyright (C) 2007 The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *      http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #define TRACE_TAG ADB
18 
19 #include "sysdeps.h"
20 #include "adb.h"
21 
22 #include <ctype.h>
23 #include <errno.h>
24 #include <stdarg.h>
25 #include <stddef.h>
26 #include <stdint.h>
27 #include <stdio.h>
28 #include <stdlib.h>
29 #include <string.h>
30 #include <sys/time.h>
31 #include <time.h>
32 
33 #include <chrono>
34 #include <condition_variable>
35 #include <mutex>
36 #include <string>
37 #include <string_view>
38 #include <thread>
39 #include <vector>
40 
41 #include <android-base/errors.h>
42 #include <android-base/file.h>
43 #include <android-base/logging.h>
44 #include <android-base/macros.h>
45 #include <android-base/parsenetaddress.h>
46 #include <android-base/stringprintf.h>
47 #include <android-base/strings.h>
48 #include <build/version.h>
49 #include <platform_tools_version.h>
50 
51 #include "adb_auth.h"
52 #include "adb_io.h"
53 #include "adb_listeners.h"
54 #include "adb_unique_fd.h"
55 #include "adb_utils.h"
56 #include "adb_wifi.h"
57 #include "sysdeps/chrono.h"
58 #include "transport.h"
59 
60 #if !ADB_HOST
61 #include <sys/capability.h>
62 #include <sys/mount.h>
63 #include <android-base/properties.h>
64 using namespace std::chrono_literals;
65 
66 #include "daemon/logging.h"
67 #endif
68 
69 #if ADB_HOST
70 #include "client/usb.h"
71 #endif
72 
adb_version()73 std::string adb_version() {
74     // Don't change the format of this --- it's parsed by ddmlib.
75     return android::base::StringPrintf(
76         "Android Debug Bridge version %d.%d.%d\n"
77         "Version %s-%s\n"
78         "Installed as %s\n",
79         ADB_VERSION_MAJOR, ADB_VERSION_MINOR, ADB_SERVER_VERSION,
80         PLATFORM_TOOLS_VERSION, android::build::GetBuildNumber().c_str(),
81         android::base::GetExecutablePath().c_str());
82 }
83 
calculate_apacket_checksum(const apacket * p)84 uint32_t calculate_apacket_checksum(const apacket* p) {
85     uint32_t sum = 0;
86     for (size_t i = 0; i < p->msg.data_length; ++i) {
87         sum += static_cast<uint8_t>(p->payload[i]);
88     }
89     return sum;
90 }
91 
get_apacket(void)92 apacket* get_apacket(void)
93 {
94     apacket* p = new apacket();
95     if (p == nullptr) {
96         LOG(FATAL) << "failed to allocate an apacket";
97     }
98 
99     memset(&p->msg, 0, sizeof(p->msg));
100     return p;
101 }
102 
put_apacket(apacket * p)103 void put_apacket(apacket *p)
104 {
105     delete p;
106 }
107 
handle_online(atransport * t)108 void handle_online(atransport *t)
109 {
110     D("adb: online");
111     t->online = 1;
112 #if ADB_HOST
113     t->SetConnectionEstablished(true);
114 #endif
115 }
116 
handle_offline(atransport * t)117 void handle_offline(atransport *t)
118 {
119     if (t->GetConnectionState() == kCsOffline) {
120         LOG(INFO) << t->serial_name() << ": already offline";
121         return;
122     }
123 
124     LOG(INFO) << t->serial_name() << ": offline";
125 
126     t->SetConnectionState(kCsOffline);
127 
128     // Close the associated usb
129     t->online = 0;
130 
131     // This is necessary to avoid a race condition that occurred when a transport closes
132     // while a client socket is still active.
133     close_all_sockets(t);
134 
135     t->RunDisconnects();
136 }
137 
138 #if DEBUG_PACKETS
139 #define DUMPMAX 32
print_packet(const char * label,apacket * p)140 void print_packet(const char *label, apacket *p)
141 {
142     const char* tag;
143     unsigned count;
144 
145     switch(p->msg.command){
146     case A_SYNC: tag = "SYNC"; break;
147     case A_CNXN: tag = "CNXN" ; break;
148     case A_OPEN: tag = "OPEN"; break;
149     case A_OKAY: tag = "OKAY"; break;
150     case A_CLSE: tag = "CLSE"; break;
151     case A_WRTE: tag = "WRTE"; break;
152     case A_AUTH: tag = "AUTH"; break;
153     case A_STLS:
154         tag = "STLS";
155         break;
156     default: tag = "????"; break;
157     }
158 
159     fprintf(stderr, "%s: %s %08x %08x %04x \"",
160             label, tag, p->msg.arg0, p->msg.arg1, p->msg.data_length);
161     count = p->msg.data_length;
162     const char* x = p->payload.data();
163     if (count > DUMPMAX) {
164         count = DUMPMAX;
165         tag = "\n";
166     } else {
167         tag = "\"\n";
168     }
169     while (count-- > 0) {
170         if ((*x >= ' ') && (*x < 127)) {
171             fputc(*x, stderr);
172         } else {
173             fputc('.', stderr);
174         }
175         x++;
176     }
177     fputs(tag, stderr);
178 }
179 #endif
180 
send_ready(unsigned local,unsigned remote,atransport * t)181 static void send_ready(unsigned local, unsigned remote, atransport *t)
182 {
183     D("Calling send_ready");
184     apacket *p = get_apacket();
185     p->msg.command = A_OKAY;
186     p->msg.arg0 = local;
187     p->msg.arg1 = remote;
188     send_packet(p, t);
189 }
190 
send_close(unsigned local,unsigned remote,atransport * t)191 static void send_close(unsigned local, unsigned remote, atransport *t)
192 {
193     D("Calling send_close");
194     apacket *p = get_apacket();
195     p->msg.command = A_CLSE;
196     p->msg.arg0 = local;
197     p->msg.arg1 = remote;
198     send_packet(p, t);
199 }
200 
get_connection_string()201 std::string get_connection_string() {
202     std::vector<std::string> connection_properties;
203 
204 #if !ADB_HOST
205     static const char* cnxn_props[] = {
206         "ro.product.name",
207         "ro.product.model",
208         "ro.product.device",
209     };
210 
211     for (const auto& prop : cnxn_props) {
212         std::string value = std::string(prop) + "=" + android::base::GetProperty(prop, "");
213         connection_properties.push_back(value);
214     }
215 #endif
216 
217     connection_properties.push_back(android::base::StringPrintf(
218         "features=%s", FeatureSetToString(supported_features()).c_str()));
219 
220     return android::base::StringPrintf(
221         "%s::%s", adb_device_banner,
222         android::base::Join(connection_properties, ';').c_str());
223 }
224 
send_tls_request(atransport * t)225 void send_tls_request(atransport* t) {
226     D("Calling send_tls_request");
227     apacket* p = get_apacket();
228     p->msg.command = A_STLS;
229     p->msg.arg0 = A_STLS_VERSION;
230     p->msg.data_length = 0;
231     send_packet(p, t);
232 }
233 
send_connect(atransport * t)234 void send_connect(atransport* t) {
235     D("Calling send_connect");
236     apacket* cp = get_apacket();
237     cp->msg.command = A_CNXN;
238     // Send the max supported version, but because the transport is
239     // initialized to A_VERSION_MIN, this will be compatible with every
240     // device.
241     cp->msg.arg0 = A_VERSION;
242     cp->msg.arg1 = t->get_max_payload();
243 
244     std::string connection_str = get_connection_string();
245     // Connect and auth packets are limited to MAX_PAYLOAD_V1 because we don't
246     // yet know how much data the other size is willing to accept.
247     if (connection_str.length() > MAX_PAYLOAD_V1) {
248         LOG(FATAL) << "Connection banner is too long (length = "
249                    << connection_str.length() << ")";
250     }
251 
252     cp->payload.assign(connection_str.begin(), connection_str.end());
253     cp->msg.data_length = cp->payload.size();
254 
255     send_packet(cp, t);
256 }
257 
parse_banner(const std::string & banner,atransport * t)258 void parse_banner(const std::string& banner, atransport* t) {
259     D("parse_banner: %s", banner.c_str());
260 
261     // The format is something like:
262     // "device::ro.product.name=x;ro.product.model=y;ro.product.device=z;".
263     std::vector<std::string> pieces = android::base::Split(banner, ":");
264 
265     // Reset the features list or else if the server sends no features we may
266     // keep the existing feature set (http://b/24405971).
267     t->SetFeatures("");
268 
269     if (pieces.size() > 2) {
270         const std::string& props = pieces[2];
271         for (const auto& prop : android::base::Split(props, ";")) {
272             // The list of properties was traditionally ;-terminated rather than ;-separated.
273             if (prop.empty()) continue;
274 
275             std::vector<std::string> key_value = android::base::Split(prop, "=");
276             if (key_value.size() != 2) continue;
277 
278             const std::string& key = key_value[0];
279             const std::string& value = key_value[1];
280             if (key == "ro.product.name") {
281                 t->product = value;
282             } else if (key == "ro.product.model") {
283                 t->model = value;
284             } else if (key == "ro.product.device") {
285                 t->device = value;
286             } else if (key == "features") {
287                 t->SetFeatures(value);
288             }
289         }
290     }
291 
292     const std::string& type = pieces[0];
293     if (type == "bootloader") {
294         D("setting connection_state to kCsBootloader");
295         t->SetConnectionState(kCsBootloader);
296     } else if (type == "device") {
297         D("setting connection_state to kCsDevice");
298         t->SetConnectionState(kCsDevice);
299     } else if (type == "recovery") {
300         D("setting connection_state to kCsRecovery");
301         t->SetConnectionState(kCsRecovery);
302     } else if (type == "sideload") {
303         D("setting connection_state to kCsSideload");
304         t->SetConnectionState(kCsSideload);
305     } else if (type == "rescue") {
306         D("setting connection_state to kCsRescue");
307         t->SetConnectionState(kCsRescue);
308     } else {
309         D("setting connection_state to kCsHost");
310         t->SetConnectionState(kCsHost);
311     }
312 }
313 
handle_new_connection(atransport * t,apacket * p)314 static void handle_new_connection(atransport* t, apacket* p) {
315     handle_offline(t);
316 
317     t->update_version(p->msg.arg0, p->msg.arg1);
318     std::string banner(p->payload.begin(), p->payload.end());
319     parse_banner(banner, t);
320 
321 #if ADB_HOST
322     handle_online(t);
323 #else
324     ADB_LOG(Connection) << "received CNXN: version=" << p->msg.arg0 << ", maxdata = " << p->msg.arg1
325                         << ", banner = '" << banner << "'";
326 
327     if (t->use_tls) {
328         // We still handshake in TLS mode. If auth_required is disabled,
329         // we'll just not verify the client's certificate. This should be the
330         // first packet the client receives to indicate the new protocol.
331         send_tls_request(t);
332     } else if (!auth_required) {
333         LOG(INFO) << "authentication not required";
334         handle_online(t);
335         send_connect(t);
336     } else {
337         send_auth_request(t);
338     }
339 #endif
340 
341     update_transports();
342 }
343 
handle_packet(apacket * p,atransport * t)344 void handle_packet(apacket *p, atransport *t)
345 {
346     D("handle_packet() %c%c%c%c", ((char*) (&(p->msg.command)))[0],
347             ((char*) (&(p->msg.command)))[1],
348             ((char*) (&(p->msg.command)))[2],
349             ((char*) (&(p->msg.command)))[3]);
350     print_packet("recv", p);
351     CHECK_EQ(p->payload.size(), p->msg.data_length);
352 
353     switch(p->msg.command){
354     case A_CNXN:  // CONNECT(version, maxdata, "system-id-string")
355         handle_new_connection(t, p);
356         break;
357     case A_STLS:  // TLS(version, "")
358         t->use_tls = true;
359 #if ADB_HOST
360         send_tls_request(t);
361         adb_auth_tls_handshake(t);
362 #else
363         adbd_auth_tls_handshake(t);
364 #endif
365         break;
366 
367     case A_AUTH:
368         // All AUTH commands are ignored in TLS mode
369         if (t->use_tls) {
370             break;
371         }
372         switch (p->msg.arg0) {
373 #if ADB_HOST
374             case ADB_AUTH_TOKEN:
375                 if (t->GetConnectionState() != kCsAuthorizing) {
376                     t->SetConnectionState(kCsAuthorizing);
377                 }
378                 send_auth_response(p->payload.data(), p->msg.data_length, t);
379                 break;
380 #else
381             case ADB_AUTH_SIGNATURE: {
382                 // TODO: Switch to string_view.
383                 std::string signature(p->payload.begin(), p->payload.end());
384                 std::string auth_key;
385                 if (adbd_auth_verify(t->token, sizeof(t->token), signature, &auth_key)) {
386                     adbd_auth_verified(t);
387                     t->failed_auth_attempts = 0;
388                     t->auth_key = auth_key;
389                     adbd_notify_framework_connected_key(t);
390                 } else {
391                     if (t->failed_auth_attempts++ > 256) std::this_thread::sleep_for(1s);
392                     send_auth_request(t);
393                 }
394                 break;
395             }
396 
397             case ADB_AUTH_RSAPUBLICKEY:
398                 t->auth_key = std::string(p->payload.data());
399                 adbd_auth_confirm_key(t);
400                 break;
401 #endif
402             default:
403                 t->SetConnectionState(kCsOffline);
404                 handle_offline(t);
405                 break;
406         }
407         break;
408 
409     case A_OPEN: /* OPEN(local-id, 0, "destination") */
410         if (t->online && p->msg.arg0 != 0 && p->msg.arg1 == 0) {
411             std::string_view address(p->payload.begin(), p->payload.size());
412 
413             // Historically, we received service names as a char*, and stopped at the first NUL
414             // byte. The client sent strings with null termination, which post-string_view, start
415             // being interpreted as part of the string, unless we explicitly strip them.
416             address = StripTrailingNulls(address);
417 
418             asocket* s = create_local_service_socket(address, t);
419             if (s == nullptr) {
420                 send_close(0, p->msg.arg0, t);
421             } else {
422                 s->peer = create_remote_socket(p->msg.arg0, t);
423                 s->peer->peer = s;
424                 send_ready(s->id, s->peer->id, t);
425                 s->ready(s);
426             }
427         }
428         break;
429 
430     case A_OKAY: /* READY(local-id, remote-id, "") */
431         if (t->online && p->msg.arg0 != 0 && p->msg.arg1 != 0) {
432             asocket* s = find_local_socket(p->msg.arg1, 0);
433             if (s) {
434                 if(s->peer == nullptr) {
435                     /* On first READY message, create the connection. */
436                     s->peer = create_remote_socket(p->msg.arg0, t);
437                     s->peer->peer = s;
438                     s->ready(s);
439                 } else if (s->peer->id == p->msg.arg0) {
440                     /* Other READY messages must use the same local-id */
441                     s->ready(s);
442                 } else {
443                     D("Invalid A_OKAY(%d,%d), expected A_OKAY(%d,%d) on transport %s", p->msg.arg0,
444                       p->msg.arg1, s->peer->id, p->msg.arg1, t->serial.c_str());
445                 }
446             } else {
447                 // When receiving A_OKAY from device for A_OPEN request, the host server may
448                 // have closed the local socket because of client disconnection. Then we need
449                 // to send A_CLSE back to device to close the service on device.
450                 send_close(p->msg.arg1, p->msg.arg0, t);
451             }
452         }
453         break;
454 
455     case A_CLSE: /* CLOSE(local-id, remote-id, "") or CLOSE(0, remote-id, "") */
456         if (t->online && p->msg.arg1 != 0) {
457             asocket* s = find_local_socket(p->msg.arg1, p->msg.arg0);
458             if (s) {
459                 /* According to protocol.txt, p->msg.arg0 might be 0 to indicate
460                  * a failed OPEN only. However, due to a bug in previous ADB
461                  * versions, CLOSE(0, remote-id, "") was also used for normal
462                  * CLOSE() operations.
463                  *
464                  * This is bad because it means a compromised adbd could
465                  * send packets to close connections between the host and
466                  * other devices. To avoid this, only allow this if the local
467                  * socket has a peer on the same transport.
468                  */
469                 if (p->msg.arg0 == 0 && s->peer && s->peer->transport != t) {
470                     D("Invalid A_CLSE(0, %u) from transport %s, expected transport %s", p->msg.arg1,
471                       t->serial.c_str(), s->peer->transport->serial.c_str());
472                 } else {
473                     s->close(s);
474                 }
475             }
476         }
477         break;
478 
479     case A_WRTE: /* WRITE(local-id, remote-id, <data>) */
480         if (t->online && p->msg.arg0 != 0 && p->msg.arg1 != 0) {
481             asocket* s = find_local_socket(p->msg.arg1, p->msg.arg0);
482             if (s) {
483                 unsigned rid = p->msg.arg0;
484                 if (s->enqueue(s, std::move(p->payload)) == 0) {
485                     D("Enqueue the socket");
486                     send_ready(s->id, rid, t);
487                 }
488             }
489         }
490         break;
491 
492     default:
493         printf("handle_packet: what is %08x?!\n", p->msg.command);
494     }
495 
496     put_apacket(p);
497 }
498 
499 #if ADB_HOST
500 
501 #ifdef _WIN32
502 
503 // Try to make a handle non-inheritable and if there is an error, don't output
504 // any error info, but leave GetLastError() for the caller to read. This is
505 // convenient if the caller is expecting that this may fail and they'd like to
506 // ignore such a failure.
_try_make_handle_noninheritable(HANDLE h)507 static bool _try_make_handle_noninheritable(HANDLE h) {
508     if (h != INVALID_HANDLE_VALUE && h != NULL) {
509         return SetHandleInformation(h, HANDLE_FLAG_INHERIT, 0) ? true : false;
510     }
511 
512     return true;
513 }
514 
515 // Try to make a handle non-inheritable with the expectation that this should
516 // succeed, so if this fails, output error info.
_make_handle_noninheritable(HANDLE h)517 static bool _make_handle_noninheritable(HANDLE h) {
518     if (!_try_make_handle_noninheritable(h)) {
519         // Show the handle value to give us a clue in case we have problems
520         // with pseudo-handle values.
521         fprintf(stderr, "adb: cannot make handle 0x%p non-inheritable: %s\n", h,
522                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
523         return false;
524     }
525 
526     return true;
527 }
528 
529 // Create anonymous pipe, preventing inheritance of the read pipe and setting
530 // security of the write pipe to sa.
_create_anonymous_pipe(unique_handle * pipe_read_out,unique_handle * pipe_write_out,SECURITY_ATTRIBUTES * sa)531 static bool _create_anonymous_pipe(unique_handle* pipe_read_out,
532                                    unique_handle* pipe_write_out,
533                                    SECURITY_ATTRIBUTES* sa) {
534     HANDLE pipe_read_raw = NULL;
535     HANDLE pipe_write_raw = NULL;
536     if (!CreatePipe(&pipe_read_raw, &pipe_write_raw, sa, 0)) {
537         fprintf(stderr, "adb: CreatePipe failed: %s\n",
538                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
539         return false;
540     }
541 
542     unique_handle pipe_read(pipe_read_raw);
543     pipe_read_raw = NULL;
544     unique_handle pipe_write(pipe_write_raw);
545     pipe_write_raw = NULL;
546 
547     if (!_make_handle_noninheritable(pipe_read.get())) {
548         return false;
549     }
550 
551     *pipe_read_out = std::move(pipe_read);
552     *pipe_write_out = std::move(pipe_write);
553 
554     return true;
555 }
556 
557 // Read from a pipe (that we take ownership of) and write the result to stdout/stderr. Return on
558 // error or when the pipe is closed. Internally makes inheritable handles, so this should not be
559 // called if subprocesses may be started concurrently.
_redirect_pipe_thread(HANDLE h,DWORD nStdHandle)560 static unsigned _redirect_pipe_thread(HANDLE h, DWORD nStdHandle) {
561     // Take ownership of the HANDLE and close when we're done.
562     unique_handle   read_pipe(h);
563     const char*     output_name = nStdHandle == STD_OUTPUT_HANDLE ? "stdout" : "stderr";
564     const int       original_fd = fileno(nStdHandle == STD_OUTPUT_HANDLE ? stdout : stderr);
565     std::unique_ptr<FILE, decltype(&fclose)> stream(nullptr, fclose);
566 
567     if (original_fd == -1) {
568         fprintf(stderr, "adb: failed to get file descriptor for %s: %s\n", output_name,
569                 strerror(errno));
570         return EXIT_FAILURE;
571     }
572 
573     // If fileno() is -2, stdout/stderr is not associated with an output stream, so we should read,
574     // but don't write. Otherwise, make a FILE* identical to stdout/stderr except that it is in
575     // binary mode with no CR/LR translation since we're reading raw.
576     if (original_fd >= 0) {
577         // This internally makes a duplicate file handle that is inheritable, so callers should not
578         // call this function if subprocesses may be started concurrently.
579         const int fd = dup(original_fd);
580         if (fd == -1) {
581             fprintf(stderr, "adb: failed to duplicate file descriptor for %s: %s\n", output_name,
582                     strerror(errno));
583             return EXIT_FAILURE;
584         }
585 
586         // Note that although we call fdopen() below with a binary flag, it may not adhere to that
587         // flag, so we have to set the mode manually.
588         if (_setmode(fd, _O_BINARY) == -1) {
589             fprintf(stderr, "adb: failed to set binary mode for duplicate of %s: %s\n", output_name,
590                     strerror(errno));
591             unix_close(fd);
592             return EXIT_FAILURE;
593         }
594 
595         stream.reset(fdopen(fd, "wb"));
596         if (stream.get() == nullptr) {
597             fprintf(stderr, "adb: failed to open duplicate stream for %s: %s\n", output_name,
598                     strerror(errno));
599             unix_close(fd);
600             return EXIT_FAILURE;
601         }
602 
603         // Unbuffer the stream because it will be buffered by default and we want subprocess output
604         // to be shown immediately.
605         if (setvbuf(stream.get(), NULL, _IONBF, 0) == -1) {
606             fprintf(stderr, "adb: failed to unbuffer %s: %s\n", output_name, strerror(errno));
607             return EXIT_FAILURE;
608         }
609 
610         // fd will be closed when stream is closed.
611     }
612 
613     while (true) {
614         char    buf[64 * 1024];
615         DWORD   bytes_read = 0;
616         if (!ReadFile(read_pipe.get(), buf, sizeof(buf), &bytes_read, NULL)) {
617             const DWORD err = GetLastError();
618             // ERROR_BROKEN_PIPE is expected when the subprocess closes
619             // the other end of the pipe.
620             if (err == ERROR_BROKEN_PIPE) {
621                 return EXIT_SUCCESS;
622             } else {
623                 fprintf(stderr, "adb: failed to read from %s: %s\n", output_name,
624                         android::base::SystemErrorCodeToString(err).c_str());
625                 return EXIT_FAILURE;
626             }
627         }
628 
629         // Don't try to write if our stdout/stderr was not setup by the parent process.
630         if (stream) {
631             // fwrite() actually calls adb_fwrite() which can write UTF-8 to the console.
632             const size_t bytes_written = fwrite(buf, 1, bytes_read, stream.get());
633             if (bytes_written != bytes_read) {
634                 fprintf(stderr, "adb: error: only wrote %zu of %lu bytes to %s\n", bytes_written,
635                         bytes_read, output_name);
636                 return EXIT_FAILURE;
637             }
638         }
639     }
640 }
641 
_redirect_stdout_thread(HANDLE h)642 static unsigned __stdcall _redirect_stdout_thread(HANDLE h) {
643     adb_thread_setname("stdout redirect");
644     return _redirect_pipe_thread(h, STD_OUTPUT_HANDLE);
645 }
646 
_redirect_stderr_thread(HANDLE h)647 static unsigned __stdcall _redirect_stderr_thread(HANDLE h) {
648     adb_thread_setname("stderr redirect");
649     return _redirect_pipe_thread(h, STD_ERROR_HANDLE);
650 }
651 
652 #endif
653 
ReportServerStartupFailure(pid_t pid)654 static void ReportServerStartupFailure(pid_t pid) {
655     fprintf(stderr, "ADB server didn't ACK\n");
656     fprintf(stderr, "Full server startup log: %s\n", GetLogFilePath().c_str());
657     fprintf(stderr, "Server had pid: %d\n", pid);
658 
659     android::base::unique_fd fd(unix_open(GetLogFilePath(), O_RDONLY));
660     if (fd == -1) return;
661 
662     // Let's not show more than 128KiB of log...
663     unix_lseek(fd, -128 * 1024, SEEK_END);
664     std::string content;
665     if (!android::base::ReadFdToString(fd, &content)) return;
666 
667     std::string header = android::base::StringPrintf("--- adb starting (pid %d) ---", pid);
668     std::vector<std::string> lines = android::base::Split(content, "\n");
669     int i = lines.size() - 1;
670     while (i >= 0 && lines[i] != header) --i;
671     while (static_cast<size_t>(i) < lines.size()) fprintf(stderr, "%s\n", lines[i++].c_str());
672 }
673 
launch_server(const std::string & socket_spec)674 int launch_server(const std::string& socket_spec) {
675 #if defined(_WIN32)
676     /* we need to start the server in the background                    */
677     /* we create a PIPE that will be used to wait for the server's "OK" */
678     /* message since the pipe handles must be inheritable, we use a     */
679     /* security attribute                                               */
680     SECURITY_ATTRIBUTES   sa;
681     sa.nLength = sizeof(sa);
682     sa.lpSecurityDescriptor = NULL;
683     sa.bInheritHandle = TRUE;
684 
685     // Redirect stdin to Windows /dev/null. If we instead pass an original
686     // stdin/stdout/stderr handle and it is a console handle, when the adb
687     // server starts up, the C Runtime will see a console handle for a process
688     // that isn't connected to a console and it will configure
689     // stdin/stdout/stderr to be closed. At that point, freopen() could be used
690     // to reopen stderr/out, but it would take more massaging to fixup the file
691     // descriptor number that freopen() uses. It's simplest to avoid all of this
692     // complexity by just redirecting stdin to `nul' and then the C Runtime acts
693     // as expected.
694     unique_handle   nul_read(CreateFileW(L"nul", GENERIC_READ,
695             FILE_SHARE_READ | FILE_SHARE_WRITE, &sa, OPEN_EXISTING,
696             FILE_ATTRIBUTE_NORMAL, NULL));
697     if (nul_read.get() == INVALID_HANDLE_VALUE) {
698         fprintf(stderr, "adb: CreateFileW 'nul' failed: %s\n",
699                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
700         return -1;
701     }
702 
703     // Create pipes with non-inheritable read handle, inheritable write handle. We need to connect
704     // the subprocess to pipes instead of just letting the subprocess inherit our existing
705     // stdout/stderr handles because a DETACHED_PROCESS cannot write to a console that it is not
706     // attached to.
707     unique_handle   ack_read, ack_write;
708     if (!_create_anonymous_pipe(&ack_read, &ack_write, &sa)) {
709         return -1;
710     }
711     unique_handle   stdout_read, stdout_write;
712     if (!_create_anonymous_pipe(&stdout_read, &stdout_write, &sa)) {
713         return -1;
714     }
715     unique_handle   stderr_read, stderr_write;
716     if (!_create_anonymous_pipe(&stderr_read, &stderr_write, &sa)) {
717         return -1;
718     }
719 
720     /* Some programs want to launch an adb command and collect its output by
721      * calling CreateProcess with inheritable stdout/stderr handles, then
722      * using read() to get its output. When this happens, the stdout/stderr
723      * handles passed to the adb client process will also be inheritable.
724      * When starting the adb server here, care must be taken to reset them
725      * to non-inheritable.
726      * Otherwise, something bad happens: even if the adb command completes,
727      * the calling process is stuck while read()-ing from the stdout/stderr
728      * descriptors, because they're connected to corresponding handles in the
729      * adb server process (even if the latter never uses/writes to them).
730      * Note that even if we don't pass these handles in the STARTUPINFO struct,
731      * if they're marked inheritable, they're still inherited, requiring us to
732      * deal with this.
733      *
734      * If we're still having problems with inheriting random handles in the
735      * future, consider using PROC_THREAD_ATTRIBUTE_HANDLE_LIST to explicitly
736      * specify which handles should be inherited: http://blogs.msdn.com/b/oldnewthing/archive/2011/12/16/10248328.aspx
737      *
738      * Older versions of Windows return console pseudo-handles that cannot be
739      * made non-inheritable, so ignore those failures.
740      */
741     _try_make_handle_noninheritable(GetStdHandle(STD_INPUT_HANDLE));
742     _try_make_handle_noninheritable(GetStdHandle(STD_OUTPUT_HANDLE));
743     _try_make_handle_noninheritable(GetStdHandle(STD_ERROR_HANDLE));
744 
745     STARTUPINFOW    startup;
746     ZeroMemory( &startup, sizeof(startup) );
747     startup.cb = sizeof(startup);
748     startup.hStdInput  = nul_read.get();
749     startup.hStdOutput = stdout_write.get();
750     startup.hStdError  = stderr_write.get();
751     startup.dwFlags    = STARTF_USESTDHANDLES;
752 
753     // Verify that the pipe_write handle value can be passed on the command line
754     // as %d and that the rest of adb code can pass it around in an int.
755     const int ack_write_as_int = cast_handle_to_int(ack_write.get());
756     if (cast_int_to_handle(ack_write_as_int) != ack_write.get()) {
757         // If this fires, either handle values are larger than 32-bits or else
758         // there is a bug in our casting.
759         // https://msdn.microsoft.com/en-us/library/windows/desktop/aa384203%28v=vs.85%29.aspx
760         fprintf(stderr, "adb: cannot fit pipe handle value into 32-bits: 0x%p\n", ack_write.get());
761         return -1;
762     }
763 
764     // get path of current program
765     WCHAR       program_path[MAX_PATH];
766     const DWORD module_result = GetModuleFileNameW(NULL, program_path,
767                                                    arraysize(program_path));
768     if ((module_result >= arraysize(program_path)) || (module_result == 0)) {
769         // String truncation or some other error.
770         fprintf(stderr, "adb: cannot get executable path: %s\n",
771                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
772         return -1;
773     }
774 
775     WCHAR   args[64];
776     snwprintf(args, arraysize(args), L"adb -L %s fork-server server --reply-fd %d",
777               socket_spec.c_str(), ack_write_as_int);
778 
779     PROCESS_INFORMATION   pinfo;
780     ZeroMemory(&pinfo, sizeof(pinfo));
781 
782     if (!CreateProcessW(
783             program_path,                              /* program path  */
784             args,
785                                     /* the fork-server argument will set the
786                                        debug = 2 in the child           */
787             NULL,                   /* process handle is not inheritable */
788             NULL,                    /* thread handle is not inheritable */
789             TRUE,                          /* yes, inherit some handles */
790             DETACHED_PROCESS, /* the new process doesn't have a console */
791             NULL,                     /* use parent's environment block */
792             NULL,                    /* use parent's starting directory */
793             &startup,                 /* startup info, i.e. std handles */
794             &pinfo )) {
795         fprintf(stderr, "adb: CreateProcessW failed: %s\n",
796                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
797         return -1;
798     }
799 
800     unique_handle   process_handle(pinfo.hProcess);
801     pinfo.hProcess = NULL;
802 
803     // Close handles that we no longer need to complete the rest.
804     CloseHandle(pinfo.hThread);
805     pinfo.hThread = NULL;
806 
807     nul_read.reset();
808     ack_write.reset();
809     stdout_write.reset();
810     stderr_write.reset();
811 
812     // Start threads to read from subprocess stdout/stderr and write to ours to make subprocess
813     // errors easier to diagnose. Note that the threads internally create inheritable handles, but
814     // that is ok because we've already spawned the subprocess.
815 
816     // In the past, reading from a pipe before the child process's C Runtime
817     // started up and called GetFileType() caused a hang: http://blogs.msdn.com/b/oldnewthing/archive/2011/12/02/10243553.aspx#10244216
818     // This is reportedly fixed in Windows Vista: https://support.microsoft.com/en-us/kb/2009703
819     // I was unable to reproduce the problem on Windows XP. It sounds like a
820     // Windows Update may have fixed this: https://www.duckware.com/tech/peeknamedpipe.html
821     unique_handle   stdout_thread(reinterpret_cast<HANDLE>(
822             _beginthreadex(NULL, 0, _redirect_stdout_thread, stdout_read.get(),
823                            0, NULL)));
824     if (stdout_thread.get() == nullptr) {
825         fprintf(stderr, "adb: cannot create thread: %s\n", strerror(errno));
826         return -1;
827     }
828     stdout_read.release();  // Transfer ownership to new thread
829 
830     unique_handle   stderr_thread(reinterpret_cast<HANDLE>(
831             _beginthreadex(NULL, 0, _redirect_stderr_thread, stderr_read.get(),
832                            0, NULL)));
833     if (stderr_thread.get() == nullptr) {
834         fprintf(stderr, "adb: cannot create thread: %s\n", strerror(errno));
835         return -1;
836     }
837     stderr_read.release();  // Transfer ownership to new thread
838 
839     bool    got_ack = false;
840 
841     // Wait for the "OK\n" message, for the pipe to be closed, or other error.
842     {
843         char    temp[3];
844         DWORD   count = 0;
845 
846         if (ReadFile(ack_read.get(), temp, sizeof(temp), &count, NULL)) {
847             const CHAR  expected[] = "OK\n";
848             const DWORD expected_length = arraysize(expected) - 1;
849             if (count == expected_length &&
850                 memcmp(temp, expected, expected_length) == 0) {
851                 got_ack = true;
852             } else {
853                 ReportServerStartupFailure(pinfo.dwProcessId);
854                 return -1;
855             }
856         } else {
857             const DWORD err = GetLastError();
858             // If the ACK was not written and the process exited, GetLastError()
859             // is probably ERROR_BROKEN_PIPE, in which case that info is not
860             // useful to the user.
861             fprintf(stderr, "could not read ok from ADB Server%s\n",
862                     err == ERROR_BROKEN_PIPE ? "" :
863                     android::base::StringPrintf(": %s",
864                             android::base::SystemErrorCodeToString(err).c_str()).c_str());
865         }
866     }
867 
868     // Always try to wait a bit for threads reading stdout/stderr to finish.
869     // If the process started ok, it should close the pipes causing the threads
870     // to finish. If the process had an error, it should exit, also causing
871     // the pipes to be closed. In that case we want to read all of the output
872     // and write it out so that the user can diagnose failures.
873     const DWORD     thread_timeout_ms = 15 * 1000;
874     const HANDLE    threads[] = { stdout_thread.get(), stderr_thread.get() };
875     const DWORD     wait_result = WaitForMultipleObjects(arraysize(threads),
876             threads, TRUE, thread_timeout_ms);
877     if (wait_result == WAIT_TIMEOUT) {
878         // Threads did not finish after waiting a little while. Perhaps the
879         // server didn't close pipes, or it is hung.
880         fprintf(stderr, "adb: timed out waiting for threads to finish reading from ADB server\n");
881         // Process handles are signaled when the process exits, so if we wait
882         // on the handle for 0 seconds and it returns 'timeout', that means that
883         // the process is still running.
884         if (WaitForSingleObject(process_handle.get(), 0) == WAIT_TIMEOUT) {
885             // We could TerminateProcess(), but that seems somewhat presumptive.
886             fprintf(stderr, "adb: server is running with process id %lu\n", pinfo.dwProcessId);
887         }
888         return -1;
889     }
890 
891     if (wait_result != WAIT_OBJECT_0) {
892         fprintf(stderr, "adb: unexpected result waiting for threads: %lu: %s\n", wait_result,
893                 android::base::SystemErrorCodeToString(GetLastError()).c_str());
894         return -1;
895     }
896 
897     // For now ignore the thread exit codes and assume they worked properly.
898 
899     if (!got_ack) {
900         return -1;
901     }
902 #else /* !defined(_WIN32) */
903     // set up a pipe so the child can tell us when it is ready.
904     unique_fd pipe_read, pipe_write;
905     if (!Pipe(&pipe_read, &pipe_write)) {
906         fprintf(stderr, "pipe failed in launch_server, errno: %d\n", errno);
907         return -1;
908     }
909 
910     std::string path = android::base::GetExecutablePath();
911 
912     pid_t pid = fork();
913     if (pid < 0) return -1;
914 
915     if (pid == 0) {
916         // child side of the fork
917         pipe_read.reset();
918 
919         // android::base::Pipe unconditionally opens the pipe with O_CLOEXEC.
920         // Undo this manually.
921         fcntl(pipe_write.get(), F_SETFD, 0);
922 
923         char reply_fd[30];
924         snprintf(reply_fd, sizeof(reply_fd), "%d", pipe_write.get());
925         // child process
926         int result = execl(path.c_str(), "adb", "-L", socket_spec.c_str(), "fork-server", "server",
927                            "--reply-fd", reply_fd, NULL);
928         // this should not return
929         fprintf(stderr, "adb: execl returned %d: %s\n", result, strerror(errno));
930     } else {
931         // parent side of the fork
932         char temp[3] = {};
933         // wait for the "OK\n" message
934         pipe_write.reset();
935         int ret = adb_read(pipe_read.get(), temp, 3);
936         int saved_errno = errno;
937         pipe_read.reset();
938         if (ret < 0) {
939             fprintf(stderr, "could not read ok from ADB Server, errno = %d\n", saved_errno);
940             return -1;
941         }
942         if (ret != 3 || temp[0] != 'O' || temp[1] != 'K' || temp[2] != '\n') {
943             ReportServerStartupFailure(pid);
944             return -1;
945         }
946     }
947 #endif /* !defined(_WIN32) */
948     return 0;
949 }
950 #endif /* ADB_HOST */
951 
handle_forward_request(const char * service,atransport * transport,int reply_fd)952 bool handle_forward_request(const char* service, atransport* transport, int reply_fd) {
953     return handle_forward_request(service, [transport](std::string*) { return transport; },
954                                   reply_fd);
955 }
956 
957 // Try to handle a network forwarding request.
handle_forward_request(const char * service,std::function<atransport * (std::string * error)> transport_acquirer,int reply_fd)958 bool handle_forward_request(const char* service,
959                             std::function<atransport*(std::string* error)> transport_acquirer,
960                             int reply_fd) {
961     if (!strcmp(service, "list-forward")) {
962         // Create the list of forward redirections.
963         std::string listeners = format_listeners();
964 #if ADB_HOST
965         SendOkay(reply_fd);
966 #endif
967         SendProtocolString(reply_fd, listeners);
968         return true;
969     }
970 
971     if (!strcmp(service, "killforward-all")) {
972         remove_all_listeners();
973 #if ADB_HOST
974         /* On the host: 1st OKAY is connect, 2nd OKAY is status */
975         SendOkay(reply_fd);
976 #endif
977         SendOkay(reply_fd);
978         return true;
979     }
980 
981     if (!strncmp(service, "forward:", 8) || !strncmp(service, "killforward:", 12)) {
982         // killforward:local
983         // forward:(norebind:)?local;remote
984         std::string error;
985         atransport* transport = transport_acquirer(&error);
986         if (!transport) {
987             SendFail(reply_fd, error);
988             return true;
989         }
990 
991         bool kill_forward = false;
992         bool no_rebind = false;
993         if (android::base::StartsWith(service, "killforward:")) {
994             kill_forward = true;
995             service += 12;
996         } else {
997             service += 8;   // skip past "forward:"
998             if (android::base::StartsWith(service, "norebind:")) {
999                 no_rebind = true;
1000                 service += 9;
1001             }
1002         }
1003 
1004         std::vector<std::string> pieces = android::base::Split(service, ";");
1005 
1006         if (kill_forward) {
1007             // Check killforward: parameter format: '<local>'
1008             if (pieces.size() != 1 || pieces[0].empty()) {
1009                 SendFail(reply_fd, android::base::StringPrintf("bad killforward: %s", service));
1010                 return true;
1011             }
1012         } else {
1013             // Check forward: parameter format: '<local>;<remote>'
1014             if (pieces.size() != 2 || pieces[0].empty() || pieces[1].empty() || pieces[1][0] == '*') {
1015                 SendFail(reply_fd, android::base::StringPrintf("bad forward: %s", service));
1016                 return true;
1017             }
1018         }
1019 
1020         InstallStatus r;
1021         int resolved_tcp_port = 0;
1022         if (kill_forward) {
1023             r = remove_listener(pieces[0].c_str(), transport);
1024         } else {
1025             int flags = 0;
1026             if (no_rebind) {
1027                 flags |= INSTALL_LISTENER_NO_REBIND;
1028             }
1029             r = install_listener(pieces[0], pieces[1].c_str(), transport, flags, &resolved_tcp_port,
1030                                  &error);
1031         }
1032         if (r == INSTALL_STATUS_OK) {
1033 #if ADB_HOST
1034             // On the host: 1st OKAY is connect, 2nd OKAY is status.
1035             SendOkay(reply_fd);
1036 #endif
1037             SendOkay(reply_fd);
1038 
1039             // If a TCP port was resolved, send the actual port number back.
1040             if (resolved_tcp_port != 0) {
1041                 SendProtocolString(reply_fd, android::base::StringPrintf("%d", resolved_tcp_port));
1042             }
1043 
1044             return true;
1045         }
1046 
1047         std::string message;
1048         switch (r) {
1049           case INSTALL_STATUS_OK: message = "success (!)"; break;
1050           case INSTALL_STATUS_INTERNAL_ERROR: message = "internal error"; break;
1051           case INSTALL_STATUS_CANNOT_BIND:
1052             message = android::base::StringPrintf("cannot bind listener: %s",
1053                                                   error.c_str());
1054             break;
1055           case INSTALL_STATUS_CANNOT_REBIND:
1056             message = android::base::StringPrintf("cannot rebind existing socket");
1057             break;
1058           case INSTALL_STATUS_LISTENER_NOT_FOUND:
1059             message = android::base::StringPrintf("listener '%s' not found", service);
1060             break;
1061         }
1062         SendFail(reply_fd, message);
1063         return true;
1064     }
1065 
1066     return false;
1067 }
1068 
1069 #if ADB_HOST
SendOkay(int fd,const std::string & s)1070 static int SendOkay(int fd, const std::string& s) {
1071     SendOkay(fd);
1072     SendProtocolString(fd, s);
1073     return 0;
1074 }
1075 
1076 static bool g_reject_kill_server = false;
adb_set_reject_kill_server(bool value)1077 void adb_set_reject_kill_server(bool value) {
1078     g_reject_kill_server = value;
1079 }
1080 
handle_mdns_request(std::string_view service,int reply_fd)1081 static bool handle_mdns_request(std::string_view service, int reply_fd) {
1082     if (!android::base::ConsumePrefix(&service, "mdns:")) {
1083         return false;
1084     }
1085 
1086     if (service == "check") {
1087         std::string check = mdns_check();
1088         SendOkay(reply_fd, check);
1089         return true;
1090     }
1091     if (service == "services") {
1092         std::string services_list = mdns_list_discovered_services();
1093         SendOkay(reply_fd, services_list);
1094         return true;
1095     }
1096 
1097     return false;
1098 }
1099 
handle_host_request(std::string_view service,TransportType type,const char * serial,TransportId transport_id,int reply_fd,asocket * s)1100 HostRequestResult handle_host_request(std::string_view service, TransportType type,
1101                                       const char* serial, TransportId transport_id, int reply_fd,
1102                                       asocket* s) {
1103     if (service == "kill") {
1104         if (g_reject_kill_server) {
1105             LOG(WARNING) << "adb server ignoring kill-server";
1106             SendFail(reply_fd, "kill-server rejected by remote server");
1107         } else {
1108             fprintf(stderr, "adb server killed by remote request\n");
1109             SendOkay(reply_fd);
1110 
1111             // Rely on process exit to close the socket for us.
1112             exit(0);
1113         }
1114     }
1115 
1116     LOG(DEBUG) << "handle_host_request(" << service << ")";
1117 
1118     // Transport selection:
1119     if (service.starts_with("transport") || service.starts_with("tport:")) {
1120         TransportType type = kTransportAny;
1121 
1122         std::string serial_storage;
1123         bool legacy = true;
1124 
1125         // New transport selection protocol:
1126         // This is essentially identical to the previous version, except it returns the selected
1127         // transport id to the caller as well.
1128         if (android::base::ConsumePrefix(&service, "tport:")) {
1129             legacy = false;
1130             if (android::base::ConsumePrefix(&service, "serial:")) {
1131                 serial_storage = service;
1132                 serial = serial_storage.c_str();
1133             } else if (service == "usb") {
1134                 type = kTransportUsb;
1135             } else if (service == "local") {
1136                 type = kTransportLocal;
1137             } else if (service == "any") {
1138                 type = kTransportAny;
1139             }
1140 
1141             // Selection by id is unimplemented, since you obviously already know the transport id
1142             // you're connecting to.
1143         } else {
1144             if (android::base::ConsumePrefix(&service, "transport-id:")) {
1145                 if (!ParseUint(&transport_id, service)) {
1146                     SendFail(reply_fd, "invalid transport id");
1147                     return HostRequestResult::Handled;
1148                 }
1149             } else if (service == "transport-usb") {
1150                 type = kTransportUsb;
1151             } else if (service == "transport-local") {
1152                 type = kTransportLocal;
1153             } else if (service == "transport-any") {
1154                 type = kTransportAny;
1155             } else if (android::base::ConsumePrefix(&service, "transport:")) {
1156                 serial_storage = service;
1157                 serial = serial_storage.c_str();
1158             }
1159         }
1160 
1161         std::string error;
1162         atransport* t = acquire_one_transport(type, serial, transport_id, nullptr, &error);
1163         if (t != nullptr) {
1164             s->transport = t;
1165             SendOkay(reply_fd);
1166 
1167             if (!legacy) {
1168                 // Nothing we can do if this fails.
1169                 WriteFdExactly(reply_fd, &t->id, sizeof(t->id));
1170             }
1171 
1172             return HostRequestResult::SwitchedTransport;
1173         } else {
1174             SendFail(reply_fd, error);
1175             return HostRequestResult::Handled;
1176         }
1177     }
1178 
1179     // return a list of all connected devices
1180     if (service == "devices" || service == "devices-l") {
1181         bool long_listing = service == "devices-l";
1182         D("Getting device list...");
1183         std::string device_list = list_transports(long_listing);
1184         D("Sending device list...");
1185         SendOkay(reply_fd, device_list);
1186         return HostRequestResult::Handled;
1187     }
1188 
1189     if (service == "reconnect-offline") {
1190         std::string response;
1191         close_usb_devices([&response](const atransport* transport) {
1192             if (!ConnectionStateIsOnline(transport->GetConnectionState())) {
1193                 response += "reconnecting " + transport->serial_name() + "\n";
1194                 return true;
1195             }
1196             return false;
1197         }, true);
1198         if (!response.empty()) {
1199             response.resize(response.size() - 1);
1200         }
1201         SendOkay(reply_fd, response);
1202         return HostRequestResult::Handled;
1203     }
1204 
1205     if (service == "features") {
1206         std::string error;
1207         atransport* t =
1208                 s->transport ? s->transport
1209                              : acquire_one_transport(type, serial, transport_id, nullptr, &error);
1210         if (t != nullptr) {
1211             SendOkay(reply_fd, FeatureSetToString(t->features()));
1212         } else {
1213             SendFail(reply_fd, error);
1214         }
1215         return HostRequestResult::Handled;
1216     }
1217 
1218     if (service == "host-features") {
1219         FeatureSet features = supported_features();
1220         // Abuse features to report libusb status.
1221         if (should_use_libusb()) {
1222             features.emplace_back(kFeatureLibusb);
1223         }
1224         features.emplace_back(kFeaturePushSync);
1225         SendOkay(reply_fd, FeatureSetToString(features));
1226         return HostRequestResult::Handled;
1227     }
1228 
1229     // remove TCP transport
1230     if (service.starts_with("disconnect:")) {
1231         std::string address(service.substr(11));
1232         if (address.empty()) {
1233             kick_all_tcp_devices();
1234             SendOkay(reply_fd, "disconnected everything");
1235             return HostRequestResult::Handled;
1236         }
1237 
1238         std::string serial;
1239         std::string host;
1240         int port = DEFAULT_ADB_LOCAL_TRANSPORT_PORT;
1241         std::string error;
1242         if (address.starts_with("vsock:") || address.starts_with("localfilesystem:")) {
1243             serial = address;
1244         } else if (!android::base::ParseNetAddress(address, &host, &port, &serial, &error)) {
1245             SendFail(reply_fd, android::base::StringPrintf("couldn't parse '%s': %s",
1246                                                            address.c_str(), error.c_str()));
1247             return HostRequestResult::Handled;
1248         }
1249         atransport* t = find_transport(serial.c_str());
1250         if (t == nullptr) {
1251             SendFail(reply_fd, android::base::StringPrintf("no such device '%s'", serial.c_str()));
1252             return HostRequestResult::Handled;
1253         }
1254         kick_transport(t);
1255         SendOkay(reply_fd, android::base::StringPrintf("disconnected %s", address.c_str()));
1256         return HostRequestResult::Handled;
1257     }
1258 
1259     // Returns our value for ADB_SERVER_VERSION.
1260     if (service == "version") {
1261         SendOkay(reply_fd, android::base::StringPrintf("%04x", ADB_SERVER_VERSION));
1262         return HostRequestResult::Handled;
1263     }
1264 
1265     // These always report "unknown" rather than the actual error, for scripts.
1266     if (service == "get-serialno") {
1267         std::string error;
1268         atransport* t =
1269                 s->transport ? s->transport
1270                              : acquire_one_transport(type, serial, transport_id, nullptr, &error);
1271         if (t) {
1272             SendOkay(reply_fd, !t->serial.empty() ? t->serial : "unknown");
1273         } else {
1274             SendFail(reply_fd, error);
1275         }
1276         return HostRequestResult::Handled;
1277     }
1278     if (service == "get-devpath") {
1279         std::string error;
1280         atransport* t =
1281                 s->transport ? s->transport
1282                              : acquire_one_transport(type, serial, transport_id, nullptr, &error);
1283         if (t) {
1284             SendOkay(reply_fd, !t->devpath.empty() ? t->devpath : "unknown");
1285         } else {
1286             SendFail(reply_fd, error);
1287         }
1288         return HostRequestResult::Handled;
1289     }
1290     if (service == "get-state") {
1291         std::string error;
1292         atransport* t =
1293                 s->transport ? s->transport
1294                              : acquire_one_transport(type, serial, transport_id, nullptr, &error);
1295         if (t) {
1296             SendOkay(reply_fd, t->connection_state_name());
1297         } else {
1298             SendFail(reply_fd, error);
1299         }
1300         return HostRequestResult::Handled;
1301     }
1302 
1303     // Indicates a new emulator instance has started.
1304     if (android::base::ConsumePrefix(&service, "emulator:")) {
1305         unsigned int port;
1306         if (!ParseUint(&port, service)) {
1307           LOG(ERROR) << "received invalid port for emulator: " << service;
1308         } else {
1309           local_connect(port);
1310         }
1311 
1312         /* we don't even need to send a reply */
1313         return HostRequestResult::Handled;
1314     }
1315 
1316     if (service == "reconnect") {
1317         std::string response;
1318         atransport* t = s->transport ? s->transport
1319                                      : acquire_one_transport(type, serial, transport_id, nullptr,
1320                                                              &response, true);
1321         if (t != nullptr) {
1322             kick_transport(t, true);
1323             response =
1324                     "reconnecting " + t->serial_name() + " [" + t->connection_state_name() + "]\n";
1325         }
1326         SendOkay(reply_fd, response);
1327         return HostRequestResult::Handled;
1328     }
1329 
1330     // TODO: Switch handle_forward_request to string_view.
1331     std::string service_str(service);
1332     auto transport_acquirer = [=](std::string* error) {
1333         if (s->transport) {
1334             return s->transport;
1335         } else {
1336             std::string error;
1337             return acquire_one_transport(type, serial, transport_id, nullptr, &error);
1338         }
1339     };
1340     if (handle_forward_request(service_str.c_str(), transport_acquirer, reply_fd)) {
1341         return HostRequestResult::Handled;
1342     }
1343 
1344     if (handle_mdns_request(service, reply_fd)) {
1345         return HostRequestResult::Handled;
1346     }
1347 
1348     return HostRequestResult::Unhandled;
1349 }
1350 
1351 static auto& init_mutex = *new std::mutex();
1352 static auto& init_cv = *new std::condition_variable();
1353 static bool device_scan_complete = false;
1354 static bool transports_ready = false;
1355 
update_transport_status()1356 void update_transport_status() {
1357     bool result = iterate_transports([](const atransport* t) {
1358         if (t->type == kTransportUsb && t->online != 1) {
1359             return false;
1360         }
1361         return true;
1362     });
1363 
1364     bool ready;
1365     {
1366         std::lock_guard<std::mutex> lock(init_mutex);
1367         transports_ready = result;
1368         ready = transports_ready && device_scan_complete;
1369     }
1370 
1371     if (ready) {
1372         init_cv.notify_all();
1373     }
1374 }
1375 
adb_notify_device_scan_complete()1376 void adb_notify_device_scan_complete() {
1377     {
1378         std::lock_guard<std::mutex> lock(init_mutex);
1379         if (device_scan_complete) {
1380             return;
1381         }
1382 
1383         device_scan_complete = true;
1384     }
1385 
1386     update_transport_status();
1387 }
1388 
adb_wait_for_device_initialization()1389 void adb_wait_for_device_initialization() {
1390     std::unique_lock<std::mutex> lock(init_mutex);
1391     init_cv.wait_for(lock, 3s, []() { return device_scan_complete && transports_ready; });
1392 }
1393 
1394 #endif  // ADB_HOST
1395