blob: c532f70a6dfbb2d5f496a2edb0ae14ec3c5a9d1c [file] [log] [blame]
// Copyright 2018 The Chromium OS Authors. All rights reserved.
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
#include <limits.h>
#include <sys/socket.h>
#include <syslog.h>
#include <unistd.h>
#include <linux/vm_sockets.h> // Needs to come after sys/socket.h
#include <memory>
#include <string>
// syslog.h and base/logging.h both try to #define LOG_INFO and LOG_WARNING.
// We need to #undef at least these two before including base/logging.h. The
// others are included to be consistent.
namespace {
const int kSyslogDebug = LOG_DEBUG;
const int kSyslogInfo = LOG_INFO;
const int kSyslogWarning = LOG_WARNING;
const int kSyslogError = LOG_ERR;
const int kSyslogCritical = LOG_CRIT;
#undef LOG_INFO
#undef LOG_ERR
#undef LOG_CRIT
} // namespace
#include <base/at_exit.h>
#include <base/bind.h>
#include <base/command_line.h>
#include <base/files/file_descriptor_watcher_posix.h>
#include <base/logging.h>
#include <base/message_loop/message_loop.h>
#include <base/run_loop.h>
#include <base/strings/stringprintf.h>
#include <base/synchronization/waitable_event.h>
#include <base/threading/thread.h>
#include <vm_protos/proto_bindings/container_guest.grpc.pb.h>
#include <chromeos/constants/vm_tools.h>
#include "vm_tools/garcon/host_notifier.h"
#include "vm_tools/garcon/package_kit_proxy.h"
#include "vm_tools/garcon/service_impl.h"
constexpr char kLogPrefix[] = "garcon: ";
constexpr char kAllowAnyUserSwitch[] = "allow_any_user";
constexpr char kServerSwitch[] = "server";
constexpr char kClientSwitch[] = "client";
constexpr char kUrlSwitch[] = "url";
constexpr char kTerminalSwitch[] = "terminal";
constexpr uint32_t kVsockPortStart = 10000;
constexpr uint32_t kVsockPortEnd = 20000;
constexpr uid_t kCrostiniDefaultUid = 1000;
bool LogToSyslog(logging::LogSeverity severity,
const char* /* file */,
int /* line */,
size_t message_start,
const std::string& message) {
switch (severity) {
case logging::LOG_INFO:
severity = kSyslogInfo;
case logging::LOG_WARNING:
severity = kSyslogWarning;
case logging::LOG_ERROR:
severity = kSyslogError;
case logging::LOG_FATAL:
severity = kSyslogCritical;
severity = kSyslogDebug;
syslog(severity, "%s", message.c_str() + message_start);
return true;
void RunGarconService(vm_tools::garcon::PackageKitProxy* pk_proxy,
base::WaitableEvent* event,
std::shared_ptr<grpc::Server>* server_copy,
int* vsock_listen_port,
ansible_playbook_application) {
// We don't want to receive SIGTERM on this thread.
sigset_t mask;
sigaddset(&mask, SIGTERM);
sigprocmask(SIG_BLOCK, &mask, nullptr);
// See for more reference.
// There's a bug in our patched version of gRPC where it uses signed integers
// for ports. VSOCK uses unsigned integers for ports. So if we let the kernel
// choose the port for us, then it can end up choosing one that has the high
// bit set and cause gRPC to assert on the negative port number. This was a
// much easier solution than patching gRPC or updating the kernel to keep the
// VSOCK ports in the signed integer range.
// The end on this for loop only exists to prevent running forever in case
// something else goes wrong.
for (*vsock_listen_port = kVsockPortStart; *vsock_listen_port < kVsockPortEnd;
++(*vsock_listen_port)) {
// Build the server.
grpc::ServerBuilder builder;
base::StringPrintf("vsock:%u:%d", VMADDR_CID_ANY, *vsock_listen_port),
grpc::InsecureServerCredentials(), nullptr);
vm_tools::garcon::ServiceImpl garcon_service(pk_proxy,
std::shared_ptr<grpc::Server> server(builder.BuildAndStart().release());
if (!server) {
LOG(WARNING) << "garcon failed binding requested vsock port "
<< *vsock_listen_port << ", trying again with a new port";
*server_copy = server;
LOG(INFO) << "Server listening on vsock port " << *vsock_listen_port;
// The following call will return once we invoke Shutdown on the gRPC
// server when the main RunLoop exits.
void CreatePackageKitProxy(
base::WaitableEvent* event,
vm_tools::garcon::HostNotifier* host_notifier,
std::unique_ptr<vm_tools::garcon::PackageKitProxy>* proxy_ptr) {
// We don't want to receive SIGTERM on this thread.
sigset_t mask;
sigaddset(&mask, SIGTERM);
sigprocmask(SIG_BLOCK, &mask, nullptr);
*proxy_ptr = vm_tools::garcon::PackageKitProxy::Create(host_notifier);
void CreateAnsiblePlaybookApplication(
base::WaitableEvent* event,
ansible_playbook_application_ptr) {
*ansible_playbook_application_ptr =
void PrintUsage() {
LOG(INFO) << "Garcon: VM container bridge for Chrome OS\n\n"
<< "Mode Switches (must use one):\n"
<< "Mode Switch:\n"
<< " --server: run in background as daemon\n"
<< " --client: run as client and send message to host\n"
<< "Client Switches (only with --client):\n"
<< " --url: opens all arguments as URLs in host browser\n"
<< "Server Switches (only with --server):\n"
<< " --allow_any_user: allow running as non-default uid\n";
int main(int argc, char** argv) {
base::AtExitManager at_exit;
base::MessageLoopForIO message_loop;
base::FileDescriptorWatcher watcher(&message_loop);
base::CommandLine::Init(argc, argv);
base::CommandLine* cl = base::CommandLine::ForCurrentProcess();
bool serverMode = cl->HasSwitch(kServerSwitch);
bool clientMode = cl->HasSwitch(kClientSwitch);
// The standard says that bool to int conversion is implicit and that
// false => 0 and true => 1.
// clang-format off
if (serverMode + clientMode != 1) {
// clang-format on
LOG(ERROR) << "Exactly one of --server or --client must be used.";
return -1;
if (clientMode) {
if (cl->HasSwitch(kUrlSwitch)) {
std::vector<std::string> args = cl->GetArgs();
if (args.empty()) {
LOG(ERROR) << "Missing URL arguments in --url mode";
return -1;
// All arguments are URLs, send them to the host to be opened. The host
// will do its own verification for validity of the URLs.
for (const auto& arg : args) {
if (!vm_tools::garcon::HostNotifier::OpenUrlInHost(arg)) {
return -1;
return 0;
} else if (cl->HasSwitch(kTerminalSwitch)) {
std::vector<std::string> args = cl->GetArgs();
if (vm_tools::garcon::HostNotifier::OpenTerminal(std::move(args)))
return 0;
return -1;
LOG(ERROR) << "Missing client switch for client mode.";
return -1;
// Set up logging to syslog for server mode.
openlog(kLogPrefix, LOG_PID, LOG_DAEMON);
// Exit if not running as the container default user.
if (getuid() != kCrostiniDefaultUid && !cl->HasSwitch(kAllowAnyUserSwitch)) {
LOG(ERROR) << "garcon normally runs only as uid(" << kCrostiniDefaultUid
<< "). Use --allow_any_user to override";
return -1;
// Note on threading model. There are 4 threads used in garcon. One is for the
// incoming gRPC requests. One is for the D-Bus communication with the
// PackageKit daemon. The third is the main thread which is for gRPC requests
// to the host as well as for monitoring filesystem changes (which result in a
// gRPC call to the host under certain conditions). The main thing to be
// careful of is that the gRPC thread for incoming requests is never blocking
// on the gRPC thread for outgoing requests (since they are both talking to
// cicerone, and both of those operations in cicerone are likely going to use
// the same D-Bus thread for communication within cicerone). The fourth thread
// is for running tasks initiated by garcon service.
// Thread that the gRPC server is running on.
base::Thread grpc_thread{"gRPC Server Thread"};
if (!grpc_thread.Start()) {
LOG(ERROR) << "Failed starting the gRPC thread";
return -1;
// Thread that D-Bus communication runs on.
base::Thread dbus_thread{"D-Bus Thread"};
if (!dbus_thread.StartWithOptions(
base::Thread::Options(base::MessageLoop::TYPE_IO, 0))) {
LOG(ERROR) << "Failed starting the D-Bus thread";
return -1;
// Thread that tasks started from garcon service run on.
// Specifically, Ansible playbook application runs on
// |garcon_service_tasks_thread|.
base::Thread garcon_service_tasks_thread{"Garcon Service Tasks Thread"};
if (!garcon_service_tasks_thread.StartWithOptions(
base::Thread::Options(base::MessageLoop::TYPE_IO, 0))) {
LOG(ERROR) << "Failed starting the garcon service tasks thread";
return -1;
// Setup the HostNotifier on the run loop for the main thread. It needs to
// have its own run loop separate from the gRPC server & D-Bus server since it
// will be using base::FilePathWatcher to identify installed application and
// mime type changes.
base::RunLoop run_loop;
std::unique_ptr<vm_tools::garcon::HostNotifier> host_notifier =
if (!host_notifier) {
LOG(ERROR) << "Failure setting up the HostNotifier";
return -1;
base::WaitableEvent event(base::WaitableEvent::ResetPolicy::AUTOMATIC,
// This needs to be created on the D-Bus thread.
std::unique_ptr<vm_tools::garcon::PackageKitProxy> pk_proxy;
bool ret = dbus_thread.task_runner()->PostTask(
FROM_HERE, base::Bind(&CreatePackageKitProxy, &event, host_notifier.get(),
if (!ret) {
LOG(ERROR) << "Failed to post PackageKit proxy creation to D-Bus thread";
return -1;
// Wait for the creation to complete.
if (!pk_proxy) {
LOG(ERROR) << "Failed in creating the PackageKit proxy";
return -1;
// AnsiblePlaybookApplication is created on garcon service tasks thread,
// because Ansible playbook application task is using
// base::FileDescriptorWatcher to watch ansible-playbook process stdio.
ret = garcon_service_tasks_thread.task_runner()->PostTask(
FROM_HERE, base::Bind(&CreateAnsiblePlaybookApplication, &event,
if (!ret) {
LOG(ERROR) << "Failed to post AnsiblePlaybookApplication creation to "
<< "garcon service tasks thread";
return -1;
// Wait for the creation to complete.
if (!ansible_playbook_application) {
LOG(ERROR) << "Failed in creating the AnsiblePlaybookApplication";
return -1;
// Launch the gRPC server on the gRPC thread.
std::shared_ptr<grpc::Server> server_copy;
int vsock_listen_port = 0;
ret = grpc_thread.task_runner()->PostTask(
base::Bind(&RunGarconService, pk_proxy.get(), &event, &server_copy,
&vsock_listen_port, ansible_playbook_application.get()));
if (!ret) {
LOG(ERROR) << "Failed to post server startup task to grpc thread";
return -1;
// Wait for the gRPC server to start.
if (!server_copy) {
LOG(ERROR) << "gRPC server failed to start";
return -1;
if (signal(SIGCHLD, SIG_IGN) == SIG_ERR) {
PLOG(ERROR) << "Unable to explicitly ignore SIGCHILD";
return -1;
if (!host_notifier->Init(static_cast<uint32_t>(vsock_listen_port),
pk_proxy.get())) {
LOG(ERROR) << "Failed to set up host notifier";
return -1;
// Start the main run loop now for the HostNotifier.
// We get here after a SIGTERM gets posted and the main run loop has exited.
// We then shutdown the gRPC server (which will terminate that thread) and
// then stop the D-Bus thread. We will be the only remaining thread at that
// point so everything can be safely destructed and we remove the need for
// any weak pointers.
return 0;