1 /*
2  * Copyright (C) 2016 The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *      http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #ifndef ART_LIBNATIVELOADER_INCLUDE_NATIVELOADER_DLEXT_NAMESPACES_H_
18 #define ART_LIBNATIVELOADER_INCLUDE_NATIVELOADER_DLEXT_NAMESPACES_H_
19 
20 #include <android/dlext.h>
21 #include <stdbool.h>
22 
23 __BEGIN_DECLS
24 
25 enum {
26   /* A regular namespace is the namespace with a custom search path that does
27    * not impose any restrictions on the location of native libraries.
28    */
29   ANDROID_NAMESPACE_TYPE_REGULAR = 0,
30 
31   /* An isolated namespace requires all the libraries to be on the search path
32    * or under permitted_when_isolated_path. The search path is the union of
33    * ld_library_path and default_library_path.
34    */
35   ANDROID_NAMESPACE_TYPE_ISOLATED = 1,
36 
37   /* The shared namespace clones the list of libraries of the caller namespace upon creation
38    * which means that they are shared between namespaces - the caller namespace and the new one
39    * will use the same copy of a library if it was loaded prior to android_create_namespace call.
40    *
41    * Note that libraries loaded after the namespace is created will not be shared.
42    *
43    * Shared namespaces can be isolated or regular. Note that they do not inherit the search path nor
44    * permitted_path from the caller's namespace.
45    */
46   ANDROID_NAMESPACE_TYPE_SHARED = 2,
47 
48   /* This flag instructs linker to enable exempt-list workaround for the namespace.
49    * See http://b/26394120 for details.
50    */
51   ANDROID_NAMESPACE_TYPE_EXEMPT_LIST_ENABLED = 0x08000000,
52 
53   /* This flag instructs linker to use this namespace as the anonymous
54    * namespace. The anonymous namespace is used in the case when linker cannot
55    * identify the caller of dlopen/dlsym. This happens for the code not loaded
56    * by dynamic linker; for example calls from the mono-compiled code. There can
57    * be only one anonymous namespace in a process. If there already is an
58    * anonymous namespace in the process, using this flag when creating a new
59    * namespace causes an error.
60    */
61   ANDROID_NAMESPACE_TYPE_ALSO_USED_AS_ANONYMOUS = 0x10000000,
62 
63   ANDROID_NAMESPACE_TYPE_SHARED_ISOLATED =
64       ANDROID_NAMESPACE_TYPE_SHARED | ANDROID_NAMESPACE_TYPE_ISOLATED,
65 };
66 
67 /*
68  * Creates new linker namespace.
69  * ld_library_path and default_library_path represent the search path
70  * for the libraries in the namespace.
71  *
72  * The libraries in the namespace are searched by folowing order:
73  * 1. ld_library_path (Think of this as namespace-local LD_LIBRARY_PATH)
74  * 2. In directories specified by DT_RUNPATH of the "needed by" binary.
75  * 3. deault_library_path (This of this as namespace-local default library path)
76  *
77  * When type is ANDROID_NAMESPACE_TYPE_ISOLATED the resulting namespace requires all of
78  * the libraries to be on the search path or under the permitted_when_isolated_path;
79  * the search_path is ld_library_path:default_library_path. Note that the
80  * permitted_when_isolated_path path is not part of the search_path and
81  * does not affect the search order. It is a way to allow loading libraries from specific
82  * locations when using absolute path.
83  * If a library or any of its dependencies are outside of the permitted_when_isolated_path
84  * and search_path, and it is not part of the public namespace dlopen will fail.
85  */
86 extern struct android_namespace_t* android_create_namespace(
87     const char* name, const char* ld_library_path, const char* default_library_path, uint64_t type,
88     const char* permitted_when_isolated_path, struct android_namespace_t* parent);
89 
90 /*
91  * Creates a link between namespaces. Every link has list of sonames of
92  * shared libraries. These are the libraries which are accessible from
93  * namespace 'from' but loaded within namespace 'to' context.
94  * When to namespace is nullptr this function establishes a link between
95  * 'from' namespace and the default namespace.
96  *
97  * The lookup order of the libraries in namespaces with links is following:
98  * 1. Look inside current namespace using 'this' namespace search path.
99  * 2. Look in linked namespaces
100  * 2.1. Perform soname check - if library soname is not in the list of shared
101  *      libraries sonames skip this link, otherwise
102  * 2.2. Search library using linked namespace search path. Note that this
103  *      step will not go deeper into linked namespaces for this library but
104  *      will do so for DT_NEEDED libraries.
105  */
106 extern bool android_link_namespaces(struct android_namespace_t* from,
107                                     struct android_namespace_t* to,
108                                     const char* shared_libs_sonames);
109 
110 extern struct android_namespace_t* android_get_exported_namespace(const char* name);
111 
112 __END_DECLS
113 
114 #endif  // ART_LIBNATIVELOADER_INCLUDE_NATIVELOADER_DLEXT_NAMESPACES_H_
115