Supervised user whitelists: Cleanup
[chromium-blink-merge.git] / content / browser / utility_process_host_impl.cc
blobf6b43bec6aadfa9eb37838196a9c5808b8a6492e
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file.
5 #include "content/browser/utility_process_host_impl.h"
7 #include "base/base_switches.h"
8 #include "base/bind.h"
9 #include "base/bind_helpers.h"
10 #include "base/command_line.h"
11 #include "base/lazy_instance.h"
12 #include "base/message_loop/message_loop.h"
13 #include "base/process/process_handle.h"
14 #include "base/run_loop.h"
15 #include "base/sequenced_task_runner.h"
16 #include "base/strings/utf_string_conversions.h"
17 #include "base/synchronization/lock.h"
18 #include "base/synchronization/waitable_event.h"
19 #include "content/browser/browser_child_process_host_impl.h"
20 #include "content/browser/mojo/mojo_application_host.h"
21 #include "content/browser/renderer_host/render_process_host_impl.h"
22 #include "content/common/child_process_host_impl.h"
23 #include "content/common/in_process_child_thread_params.h"
24 #include "content/common/utility_messages.h"
25 #include "content/public/browser/browser_thread.h"
26 #include "content/public/browser/content_browser_client.h"
27 #include "content/public/browser/utility_process_host_client.h"
28 #include "content/public/common/content_switches.h"
29 #include "content/public/common/process_type.h"
30 #include "content/public/common/sandboxed_process_launcher_delegate.h"
31 #include "ipc/ipc_switches.h"
32 #include "ui/base/ui_base_switches.h"
34 namespace content {
36 // NOTE: changes to this class need to be reviewed by the security team.
37 class UtilitySandboxedProcessLauncherDelegate
38 : public SandboxedProcessLauncherDelegate {
39 public:
40 UtilitySandboxedProcessLauncherDelegate(const base::FilePath& exposed_dir,
41 bool launch_elevated,
42 bool no_sandbox,
43 const base::EnvironmentMap& env,
44 ChildProcessHost* host)
45 : exposed_dir_(exposed_dir),
46 #if defined(OS_WIN)
47 launch_elevated_(launch_elevated)
48 #elif defined(OS_POSIX)
49 env_(env),
50 no_sandbox_(no_sandbox),
51 ipc_fd_(host->TakeClientFileDescriptor())
52 #endif // OS_WIN
55 ~UtilitySandboxedProcessLauncherDelegate() override {}
57 #if defined(OS_WIN)
58 bool ShouldLaunchElevated() override { return launch_elevated_; }
59 void PreSandbox(bool* disable_default_policy,
60 base::FilePath* exposed_dir) override {
61 *exposed_dir = exposed_dir_;
63 #elif defined(OS_POSIX)
65 bool ShouldUseZygote() override {
66 return !no_sandbox_ && exposed_dir_.empty();
68 base::EnvironmentMap GetEnvironment() override { return env_; }
69 base::ScopedFD TakeIpcFd() override { return ipc_fd_.Pass(); }
70 #endif // OS_WIN
72 private:
73 base::FilePath exposed_dir_;
75 #if defined(OS_WIN)
76 bool launch_elevated_;
77 #elif defined(OS_POSIX)
78 base::EnvironmentMap env_;
79 bool no_sandbox_;
80 base::ScopedFD ipc_fd_;
81 #endif // OS_WIN
84 UtilityMainThreadFactoryFunction g_utility_main_thread_factory = NULL;
86 UtilityProcessHost* UtilityProcessHost::Create(
87 const scoped_refptr<UtilityProcessHostClient>& client,
88 const scoped_refptr<base::SequencedTaskRunner>& client_task_runner) {
89 return new UtilityProcessHostImpl(client, client_task_runner);
92 void UtilityProcessHostImpl::RegisterUtilityMainThreadFactory(
93 UtilityMainThreadFactoryFunction create) {
94 g_utility_main_thread_factory = create;
97 UtilityProcessHostImpl::UtilityProcessHostImpl(
98 const scoped_refptr<UtilityProcessHostClient>& client,
99 const scoped_refptr<base::SequencedTaskRunner>& client_task_runner)
100 : client_(client),
101 client_task_runner_(client_task_runner),
102 is_batch_mode_(false),
103 is_mdns_enabled_(false),
104 no_sandbox_(false),
105 run_elevated_(false),
106 #if defined(OS_LINUX)
107 child_flags_(ChildProcessHost::CHILD_ALLOW_SELF),
108 #else
109 child_flags_(ChildProcessHost::CHILD_NORMAL),
110 #endif
111 started_(false),
112 name_(base::ASCIIToUTF16("utility process")) {
115 UtilityProcessHostImpl::~UtilityProcessHostImpl() {
116 DCHECK_CURRENTLY_ON(BrowserThread::IO);
117 if (is_batch_mode_)
118 EndBatchMode();
120 // We could be destroyed as a result of Chrome shutdown. When that happens,
121 // the Mojo channel doesn't get the opportunity to shut down cleanly because
122 // it posts to the IO thread (the current thread) which is being destroyed.
123 // To guarantee proper shutdown of the Mojo channel, do it explicitly here.
124 if (mojo_application_host_)
125 mojo_application_host_->ShutdownOnIOThread();
128 bool UtilityProcessHostImpl::Send(IPC::Message* message) {
129 if (!StartProcess())
130 return false;
132 return process_->Send(message);
135 bool UtilityProcessHostImpl::StartBatchMode() {
136 CHECK(!is_batch_mode_);
137 is_batch_mode_ = StartProcess();
138 Send(new UtilityMsg_BatchMode_Started());
139 return is_batch_mode_;
142 void UtilityProcessHostImpl::EndBatchMode() {
143 CHECK(is_batch_mode_);
144 is_batch_mode_ = false;
145 Send(new UtilityMsg_BatchMode_Finished());
148 void UtilityProcessHostImpl::SetExposedDir(const base::FilePath& dir) {
149 exposed_dir_ = dir;
152 void UtilityProcessHostImpl::EnableMDns() {
153 is_mdns_enabled_ = true;
156 void UtilityProcessHostImpl::DisableSandbox() {
157 no_sandbox_ = true;
160 #if defined(OS_WIN)
161 void UtilityProcessHostImpl::ElevatePrivileges() {
162 no_sandbox_ = true;
163 run_elevated_ = true;
165 #endif
167 const ChildProcessData& UtilityProcessHostImpl::GetData() {
168 return process_->GetData();
171 #if defined(OS_POSIX)
173 void UtilityProcessHostImpl::SetEnv(const base::EnvironmentMap& env) {
174 env_ = env;
177 #endif // OS_POSIX
179 bool UtilityProcessHostImpl::StartMojoMode() {
180 CHECK(!mojo_application_host_);
181 mojo_application_host_.reset(new MojoApplicationHost);
183 bool mojo_result = mojo_application_host_->Init();
184 if (!mojo_result)
185 return false;
187 return StartProcess();
190 ServiceRegistry* UtilityProcessHostImpl::GetServiceRegistry() {
191 DCHECK(mojo_application_host_);
192 return mojo_application_host_->service_registry();
195 void UtilityProcessHostImpl::SetName(const base::string16& name) {
196 name_ = name;
199 bool UtilityProcessHostImpl::StartProcess() {
200 if (started_)
201 return true;
202 started_ = true;
204 if (is_batch_mode_)
205 return true;
207 // Name must be set or metrics_service will crash in any test which
208 // launches a UtilityProcessHost.
209 process_.reset(new BrowserChildProcessHostImpl(PROCESS_TYPE_UTILITY, this));
210 process_->SetName(name_);
212 std::string channel_id = process_->GetHost()->CreateChannel();
213 if (channel_id.empty())
214 return false;
216 if (RenderProcessHost::run_renderer_in_process()) {
217 DCHECK(g_utility_main_thread_factory);
218 // See comment in RenderProcessHostImpl::Init() for the background on why we
219 // support single process mode this way.
220 in_process_thread_.reset(
221 g_utility_main_thread_factory(InProcessChildThreadParams(
222 channel_id, BrowserThread::UnsafeGetMessageLoopForThread(
223 BrowserThread::IO)->task_runner())));
224 in_process_thread_->Start();
225 } else {
226 const base::CommandLine& browser_command_line =
227 *base::CommandLine::ForCurrentProcess();
228 int child_flags = child_flags_;
230 bool has_cmd_prefix = browser_command_line.HasSwitch(
231 switches::kUtilityCmdPrefix);
233 // When running under gdb, forking /proc/self/exe ends up forking the gdb
234 // executable instead of Chromium. It is almost safe to assume that no
235 // updates will happen while a developer is running with
236 // |switches::kUtilityCmdPrefix|. See ChildProcessHost::GetChildPath() for
237 // a similar case with Valgrind.
238 if (has_cmd_prefix)
239 child_flags = ChildProcessHost::CHILD_NORMAL;
241 base::FilePath exe_path = ChildProcessHost::GetChildPath(child_flags);
242 if (exe_path.empty()) {
243 NOTREACHED() << "Unable to get utility process binary name.";
244 return false;
247 base::CommandLine* cmd_line = new base::CommandLine(exe_path);
248 cmd_line->AppendSwitchASCII(switches::kProcessType,
249 switches::kUtilityProcess);
250 cmd_line->AppendSwitchASCII(switches::kProcessChannelID, channel_id);
251 std::string locale = GetContentClient()->browser()->GetApplicationLocale();
252 cmd_line->AppendSwitchASCII(switches::kLang, locale);
254 if (no_sandbox_)
255 cmd_line->AppendSwitch(switches::kNoSandbox);
257 // Browser command-line switches to propagate to the utility process.
258 static const char* const kSwitchNames[] = {
259 switches::kDebugPluginLoading,
260 switches::kNoSandbox,
261 switches::kProfilerTiming,
262 #if defined(OS_MACOSX)
263 switches::kEnableSandboxLogging,
264 #endif
266 cmd_line->CopySwitchesFrom(browser_command_line, kSwitchNames,
267 arraysize(kSwitchNames));
269 if (has_cmd_prefix) {
270 // Launch the utility child process with some prefix
271 // (usually "xterm -e gdb --args").
272 cmd_line->PrependWrapper(browser_command_line.GetSwitchValueNative(
273 switches::kUtilityCmdPrefix));
276 if (!exposed_dir_.empty()) {
277 cmd_line->AppendSwitchPath(switches::kUtilityProcessAllowedDir,
278 exposed_dir_);
281 if (is_mdns_enabled_)
282 cmd_line->AppendSwitch(switches::kUtilityProcessEnableMDns);
284 #if defined(OS_WIN)
285 // Let the utility process know if it is intended to be elevated.
286 if (run_elevated_)
287 cmd_line->AppendSwitch(switches::kUtilityProcessRunningElevated);
288 #endif
290 process_->Launch(
291 new UtilitySandboxedProcessLauncherDelegate(exposed_dir_,
292 run_elevated_,
293 no_sandbox_, env_,
294 process_->GetHost()),
295 cmd_line,
296 true);
299 return true;
302 bool UtilityProcessHostImpl::OnMessageReceived(const IPC::Message& message) {
303 if (!client_.get())
304 return true;
306 client_task_runner_->PostTask(
307 FROM_HERE,
308 base::Bind(
309 base::IgnoreResult(&UtilityProcessHostClient::OnMessageReceived),
310 client_.get(),
311 message));
313 return true;
316 void UtilityProcessHostImpl::OnProcessLaunchFailed() {
317 if (!client_.get())
318 return;
320 client_task_runner_->PostTask(
321 FROM_HERE,
322 base::Bind(&UtilityProcessHostClient::OnProcessLaunchFailed,
323 client_.get()));
326 void UtilityProcessHostImpl::OnProcessCrashed(int exit_code) {
327 if (!client_.get())
328 return;
330 client_task_runner_->PostTask(
331 FROM_HERE,
332 base::Bind(&UtilityProcessHostClient::OnProcessCrashed, client_.get(),
333 exit_code));
336 void UtilityProcessHostImpl::OnProcessLaunched() {
337 if (mojo_application_host_) {
338 base::ProcessHandle handle;
339 if (RenderProcessHost::run_renderer_in_process())
340 handle = base::GetCurrentProcessHandle();
341 else
342 handle = process_->GetData().handle;
344 mojo_application_host_->Activate(this, handle);
348 } // namespace content