blob: 2167c492e5a9511b0b56cacd651b05f1cd553613 [file] [log] [blame]
Christopher Tate487529a2009-04-29 14:03:25 -07001/*
2 * Copyright (C) 2009 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.server;
18
Christopher Tate181fafa2009-05-14 11:12:14 -070019import android.app.ActivityManagerNative;
Christopher Tateb6787f22009-07-02 17:40:45 -070020import android.app.AlarmManager;
Dianne Hackborn01e4cfc2010-06-24 15:07:24 -070021import android.app.AppGlobals;
Christopher Tate181fafa2009-05-14 11:12:14 -070022import android.app.IActivityManager;
23import android.app.IApplicationThread;
24import android.app.IBackupAgent;
Christopher Tateb6787f22009-07-02 17:40:45 -070025import android.app.PendingIntent;
Christopher Tate79ec80d2011-06-24 14:58:49 -070026import android.app.backup.BackupAgent;
Christopher Tate4a627c72011-04-01 14:43:32 -070027import android.app.backup.BackupDataOutput;
28import android.app.backup.FullBackup;
Jason parksa3cdaa52011-01-13 14:15:43 -060029import android.app.backup.RestoreSet;
Christopher Tate45281862010-03-05 15:46:30 -080030import android.app.backup.IBackupManager;
Christopher Tate4a627c72011-04-01 14:43:32 -070031import android.app.backup.IFullBackupRestoreObserver;
Christopher Tate45281862010-03-05 15:46:30 -080032import android.app.backup.IRestoreObserver;
33import android.app.backup.IRestoreSession;
Christopher Tate4a627c72011-04-01 14:43:32 -070034import android.content.ActivityNotFoundException;
Christopher Tate3799bc22009-05-06 16:13:56 -070035import android.content.BroadcastReceiver;
Dan Egnor87a02bc2009-06-17 02:30:10 -070036import android.content.ComponentName;
Christopher Tated2c0cd42011-09-15 15:51:29 -070037import android.content.ContentResolver;
Christopher Tate487529a2009-04-29 14:03:25 -070038import android.content.Context;
39import android.content.Intent;
Christopher Tate3799bc22009-05-06 16:13:56 -070040import android.content.IntentFilter;
Dan Egnor87a02bc2009-06-17 02:30:10 -070041import android.content.ServiceConnection;
Christopher Tate181fafa2009-05-14 11:12:14 -070042import android.content.pm.ApplicationInfo;
Christopher Tatec7b31e32009-06-10 15:49:30 -070043import android.content.pm.IPackageDataObserver;
Christopher Tatea858cb02011-06-03 12:27:51 -070044import android.content.pm.IPackageDeleteObserver;
Christopher Tate75a99702011-05-18 16:28:19 -070045import android.content.pm.IPackageInstallObserver;
Christopher Tate1bb69062010-02-19 17:02:12 -080046import android.content.pm.IPackageManager;
Christopher Tate7b881282009-06-07 13:52:37 -070047import android.content.pm.PackageInfo;
Dan Egnor87a02bc2009-06-17 02:30:10 -070048import android.content.pm.PackageManager;
Jason parks1125d782011-01-12 09:47:26 -060049import android.content.pm.Signature;
Jason parksa3cdaa52011-01-13 14:15:43 -060050import android.content.pm.PackageManager.NameNotFoundException;
Christopher Tate97ea1222012-05-17 14:59:41 -070051import android.database.ContentObserver;
Christopher Tate3799bc22009-05-06 16:13:56 -070052import android.net.Uri;
Christopher Tate487529a2009-04-29 14:03:25 -070053import android.os.Binder;
Christopher Tate75a99702011-05-18 16:28:19 -070054import android.os.Build;
Christopher Tate3799bc22009-05-06 16:13:56 -070055import android.os.Bundle;
Christopher Tate22b87872009-05-04 16:41:53 -070056import android.os.Environment;
Christopher Tate487529a2009-04-29 14:03:25 -070057import android.os.Handler;
Christopher Tate44a27902010-01-27 17:15:49 -080058import android.os.HandlerThread;
Christopher Tate487529a2009-04-29 14:03:25 -070059import android.os.IBinder;
Christopher Tate44a27902010-01-27 17:15:49 -080060import android.os.Looper;
Christopher Tate487529a2009-04-29 14:03:25 -070061import android.os.Message;
Christopher Tate22b87872009-05-04 16:41:53 -070062import android.os.ParcelFileDescriptor;
Christopher Tateb6787f22009-07-02 17:40:45 -070063import android.os.PowerManager;
Christopher Tate043dadc2009-06-02 16:11:00 -070064import android.os.Process;
Christopher Tate487529a2009-04-29 14:03:25 -070065import android.os.RemoteException;
Christopher Tate32418be2011-10-10 13:51:12 -070066import android.os.ServiceManager;
Dan Egnorbb9001c2009-07-27 12:20:13 -070067import android.os.SystemClock;
Dianne Hackborn7e9f4eb2010-09-10 18:43:00 -070068import android.os.WorkSource;
Christopher Tate32418be2011-10-10 13:51:12 -070069import android.os.storage.IMountService;
Oscar Montemayora8529f62009-11-18 10:14:20 -080070import android.provider.Settings;
Dan Egnorbb9001c2009-07-27 12:20:13 -070071import android.util.EventLog;
Christopher Tate79ec80d2011-06-24 14:58:49 -070072import android.util.Log;
Joe Onorato8a9b2202010-02-26 18:56:32 -080073import android.util.Slog;
Christopher Tate487529a2009-04-29 14:03:25 -070074import android.util.SparseArray;
Christopher Tate4a627c72011-04-01 14:43:32 -070075import android.util.StringBuilderPrinter;
76
Jason parksa3cdaa52011-01-13 14:15:43 -060077import com.android.internal.backup.BackupConstants;
78import com.android.internal.backup.IBackupTransport;
79import com.android.internal.backup.LocalTransport;
80import com.android.server.PackageManagerBackupAgent.Metadata;
81
Christopher Tate2efd2db2011-07-19 16:32:49 -070082import java.io.BufferedInputStream;
83import java.io.BufferedOutputStream;
84import java.io.ByteArrayOutputStream;
Christopher Tate7926a692011-07-11 11:31:57 -070085import java.io.DataInputStream;
Christopher Tate2efd2db2011-07-19 16:32:49 -070086import java.io.DataOutputStream;
Christopher Tatecde87f42009-06-12 12:55:53 -070087import java.io.EOFException;
Christopher Tate22b87872009-05-04 16:41:53 -070088import java.io.File;
Joe Onoratob1a7ffe2009-05-06 18:06:21 -070089import java.io.FileDescriptor;
Christopher Tate75a99702011-05-18 16:28:19 -070090import java.io.FileInputStream;
Christopher Tate1168baa2010-02-17 13:03:40 -080091import java.io.FileNotFoundException;
Christopher Tate4cc86e12009-09-21 19:36:51 -070092import java.io.FileOutputStream;
Christopher Tatec7b31e32009-06-10 15:49:30 -070093import java.io.IOException;
Christopher Tate75a99702011-05-18 16:28:19 -070094import java.io.InputStream;
Christopher Tate2efd2db2011-07-19 16:32:49 -070095import java.io.OutputStream;
Joe Onoratob1a7ffe2009-05-06 18:06:21 -070096import java.io.PrintWriter;
Christopher Tatecde87f42009-06-12 12:55:53 -070097import java.io.RandomAccessFile;
Christopher Tate2efd2db2011-07-19 16:32:49 -070098import java.security.InvalidAlgorithmParameterException;
99import java.security.InvalidKeyException;
100import java.security.Key;
101import java.security.NoSuchAlgorithmException;
102import java.security.SecureRandom;
103import java.security.spec.InvalidKeySpecException;
104import java.security.spec.KeySpec;
Christopher Tate75a99702011-05-18 16:28:19 -0700105import java.text.SimpleDateFormat;
Joe Onorato8ad02812009-05-13 01:41:44 -0400106import java.util.ArrayList;
Christopher Tate7bdb0962011-07-13 19:30:21 -0700107import java.util.Arrays;
Christopher Tate75a99702011-05-18 16:28:19 -0700108import java.util.Date;
Joe Onorato8ad02812009-05-13 01:41:44 -0400109import java.util.HashMap;
Christopher Tate487529a2009-04-29 14:03:25 -0700110import java.util.HashSet;
111import java.util.List;
Christopher Tate91717492009-06-26 21:07:13 -0700112import java.util.Map;
Dan Egnorc1c49c02009-10-30 17:35:39 -0700113import java.util.Random;
Christopher Tateb49ceb32010-02-08 16:22:24 -0800114import java.util.Set;
Christopher Tate4a627c72011-04-01 14:43:32 -0700115import java.util.concurrent.atomic.AtomicBoolean;
Christopher Tate7926a692011-07-11 11:31:57 -0700116import java.util.zip.Deflater;
117import java.util.zip.DeflaterOutputStream;
Christopher Tate7926a692011-07-11 11:31:57 -0700118import java.util.zip.InflaterInputStream;
Christopher Tate487529a2009-04-29 14:03:25 -0700119
Christopher Tate2efd2db2011-07-19 16:32:49 -0700120import javax.crypto.BadPaddingException;
121import javax.crypto.Cipher;
122import javax.crypto.CipherInputStream;
123import javax.crypto.CipherOutputStream;
124import javax.crypto.IllegalBlockSizeException;
125import javax.crypto.NoSuchPaddingException;
126import javax.crypto.SecretKey;
127import javax.crypto.SecretKeyFactory;
128import javax.crypto.spec.IvParameterSpec;
129import javax.crypto.spec.PBEKeySpec;
130import javax.crypto.spec.SecretKeySpec;
131
Christopher Tate487529a2009-04-29 14:03:25 -0700132class BackupManagerService extends IBackupManager.Stub {
133 private static final String TAG = "BackupManagerService";
Christopher Tate4a627c72011-04-01 14:43:32 -0700134 private static final boolean DEBUG = true;
Christopher Tateb1543a92011-09-07 12:11:09 -0700135 private static final boolean MORE_DEBUG = false;
Christopher Tate4a627c72011-04-01 14:43:32 -0700136
137 // Name and current contents version of the full-backup manifest file
138 static final String BACKUP_MANIFEST_FILENAME = "_manifest";
139 static final int BACKUP_MANIFEST_VERSION = 1;
Christopher Tate7bdb0962011-07-13 19:30:21 -0700140 static final String BACKUP_FILE_HEADER_MAGIC = "ANDROID BACKUP\n";
141 static final int BACKUP_FILE_VERSION = 1;
Christopher Tate2efd2db2011-07-19 16:32:49 -0700142 static final boolean COMPRESS_FULL_BACKUPS = true; // should be true in production
Christopher Tateaa088442009-06-16 18:25:46 -0700143
Christopher Tate73d73692012-01-20 17:11:31 -0800144 static final String SHARED_BACKUP_AGENT_PACKAGE = "com.android.sharedstoragebackup";
145
Christopher Tate49401dd2009-07-01 12:34:29 -0700146 // How often we perform a backup pass. Privileged external callers can
147 // trigger an immediate pass.
Christopher Tateb6787f22009-07-02 17:40:45 -0700148 private static final long BACKUP_INTERVAL = AlarmManager.INTERVAL_HOUR;
Christopher Tate487529a2009-04-29 14:03:25 -0700149
Dan Egnorc1c49c02009-10-30 17:35:39 -0700150 // Random variation in backup scheduling time to avoid server load spikes
151 private static final int FUZZ_MILLIS = 5 * 60 * 1000;
152
Christopher Tate8031a3d2009-07-06 16:36:05 -0700153 // The amount of time between the initial provisioning of the device and
154 // the first backup pass.
155 private static final long FIRST_BACKUP_INTERVAL = 12 * AlarmManager.INTERVAL_HOUR;
156
Christopher Tate45281862010-03-05 15:46:30 -0800157 private static final String RUN_BACKUP_ACTION = "android.app.backup.intent.RUN";
158 private static final String RUN_INITIALIZE_ACTION = "android.app.backup.intent.INIT";
159 private static final String RUN_CLEAR_ACTION = "android.app.backup.intent.CLEAR";
Christopher Tate487529a2009-04-29 14:03:25 -0700160 private static final int MSG_RUN_BACKUP = 1;
Christopher Tate043dadc2009-06-02 16:11:00 -0700161 private static final int MSG_RUN_FULL_BACKUP = 2;
Christopher Tate9bbc21a2009-06-10 20:23:25 -0700162 private static final int MSG_RUN_RESTORE = 3;
Christopher Tateee0e78a2009-07-02 11:17:03 -0700163 private static final int MSG_RUN_CLEAR = 4;
Christopher Tate4cc86e12009-09-21 19:36:51 -0700164 private static final int MSG_RUN_INITIALIZE = 5;
Christopher Tate2d449afe2010-03-29 19:14:24 -0700165 private static final int MSG_RUN_GET_RESTORE_SETS = 6;
166 private static final int MSG_TIMEOUT = 7;
Christopher Tate73a3cb32010-12-13 18:27:26 -0800167 private static final int MSG_RESTORE_TIMEOUT = 8;
Christopher Tate4a627c72011-04-01 14:43:32 -0700168 private static final int MSG_FULL_CONFIRMATION_TIMEOUT = 9;
169 private static final int MSG_RUN_FULL_RESTORE = 10;
Christopher Tatec7b31e32009-06-10 15:49:30 -0700170
Christopher Tate8e294d42011-08-31 20:37:12 -0700171 // backup task state machine tick
172 static final int MSG_BACKUP_RESTORE_STEP = 20;
173 static final int MSG_OP_COMPLETE = 21;
174
Christopher Tatec7b31e32009-06-10 15:49:30 -0700175 // Timeout interval for deciding that a bind or clear-data has taken too long
176 static final long TIMEOUT_INTERVAL = 10 * 1000;
177
Christopher Tate44a27902010-01-27 17:15:49 -0800178 // Timeout intervals for agent backup & restore operations
179 static final long TIMEOUT_BACKUP_INTERVAL = 30 * 1000;
Christopher Tate4a627c72011-04-01 14:43:32 -0700180 static final long TIMEOUT_FULL_BACKUP_INTERVAL = 5 * 60 * 1000;
Christopher Tateb0628bf2011-06-02 15:08:13 -0700181 static final long TIMEOUT_SHARED_BACKUP_INTERVAL = 30 * 60 * 1000;
Christopher Tate44a27902010-01-27 17:15:49 -0800182 static final long TIMEOUT_RESTORE_INTERVAL = 60 * 1000;
183
Christopher Tate2efd2db2011-07-19 16:32:49 -0700184 // User confirmation timeout for a full backup/restore operation. It's this long in
185 // order to give them time to enter the backup password.
186 static final long TIMEOUT_FULL_CONFIRMATION = 60 * 1000;
Christopher Tate4a627c72011-04-01 14:43:32 -0700187
Christopher Tate487529a2009-04-29 14:03:25 -0700188 private Context mContext;
189 private PackageManager mPackageManager;
Christopher Tate1bb69062010-02-19 17:02:12 -0800190 IPackageManager mPackageManagerBinder;
Christopher Tate6ef58a12009-06-29 14:56:28 -0700191 private IActivityManager mActivityManager;
Christopher Tateb6787f22009-07-02 17:40:45 -0700192 private PowerManager mPowerManager;
193 private AlarmManager mAlarmManager;
Christopher Tate32418be2011-10-10 13:51:12 -0700194 private IMountService mMountService;
Christopher Tate44a27902010-01-27 17:15:49 -0800195 IBackupManager mBackupManagerBinder;
Christopher Tateb6787f22009-07-02 17:40:45 -0700196
Christopher Tate73e02522009-07-15 14:18:26 -0700197 boolean mEnabled; // access to this is synchronized on 'this'
198 boolean mProvisioned;
Christopher Tatecce9da52010-02-03 15:11:15 -0800199 boolean mAutoRestore;
Christopher Tate73e02522009-07-15 14:18:26 -0700200 PowerManager.WakeLock mWakelock;
Christopher Tate0bacfd22012-01-11 14:41:19 -0800201 HandlerThread mHandlerThread;
Christopher Tate44a27902010-01-27 17:15:49 -0800202 BackupHandler mBackupHandler;
Christopher Tate4cc86e12009-09-21 19:36:51 -0700203 PendingIntent mRunBackupIntent, mRunInitIntent;
204 BroadcastReceiver mRunBackupReceiver, mRunInitReceiver;
Christopher Tatea3d55342012-03-27 13:16:18 -0700205 // map UIDs to the set of participating packages under that UID
206 final SparseArray<HashSet<String>> mBackupParticipants
207 = new SparseArray<HashSet<String>>();
Christopher Tate487529a2009-04-29 14:03:25 -0700208 // set of backup services that have pending changes
Christopher Tate73e02522009-07-15 14:18:26 -0700209 class BackupRequest {
Christopher Tatecc55f812011-08-16 16:06:53 -0700210 public String packageName;
Christopher Tateaa088442009-06-16 18:25:46 -0700211
Christopher Tatecc55f812011-08-16 16:06:53 -0700212 BackupRequest(String pkgName) {
213 packageName = pkgName;
Christopher Tate46758122009-05-06 11:22:00 -0700214 }
Christopher Tate181fafa2009-05-14 11:12:14 -0700215
216 public String toString() {
Christopher Tatecc55f812011-08-16 16:06:53 -0700217 return "BackupRequest{pkg=" + packageName + "}";
Christopher Tate181fafa2009-05-14 11:12:14 -0700218 }
Christopher Tate46758122009-05-06 11:22:00 -0700219 }
Christopher Tatec28083a2010-12-14 16:16:44 -0800220 // Backups that we haven't started yet. Keys are package names.
221 HashMap<String,BackupRequest> mPendingBackups
222 = new HashMap<String,BackupRequest>();
Christopher Tate5cb400b2009-06-25 16:03:14 -0700223
224 // Pseudoname that we use for the Package Manager metadata "package"
Christopher Tate73e02522009-07-15 14:18:26 -0700225 static final String PACKAGE_MANAGER_SENTINEL = "@pm@";
Christopher Tate6aa41f42009-06-19 14:14:22 -0700226
227 // locking around the pending-backup management
Christopher Tate73e02522009-07-15 14:18:26 -0700228 final Object mQueueLock = new Object();
Christopher Tate487529a2009-04-29 14:03:25 -0700229
Christopher Tate043dadc2009-06-02 16:11:00 -0700230 // The thread performing the sequence of queued backups binds to each app's agent
231 // in succession. Bind notifications are asynchronously delivered through the
232 // Activity Manager; use this lock object to signal when a requested binding has
233 // completed.
Christopher Tate73e02522009-07-15 14:18:26 -0700234 final Object mAgentConnectLock = new Object();
235 IBackupAgent mConnectedAgent;
Christopher Tate336a6492011-10-05 16:05:43 -0700236 volatile boolean mBackupRunning;
Christopher Tate73e02522009-07-15 14:18:26 -0700237 volatile boolean mConnecting;
Christopher Tate55f931a2009-09-29 17:17:34 -0700238 volatile long mLastBackupPass;
239 volatile long mNextBackupPass;
Christopher Tate043dadc2009-06-02 16:11:00 -0700240
Christopher Tate6de74ff2012-01-17 15:20:32 -0800241 // For debugging, we maintain a progress trace of operations during backup
242 static final boolean DEBUG_BACKUP_TRACE = true;
243 final List<String> mBackupTrace = new ArrayList<String>();
244
Christopher Tate55f931a2009-09-29 17:17:34 -0700245 // A similar synchronization mechanism around clearing apps' data for restore
Christopher Tate73e02522009-07-15 14:18:26 -0700246 final Object mClearDataLock = new Object();
247 volatile boolean mClearingData;
Christopher Tatec7b31e32009-06-10 15:49:30 -0700248
Christopher Tate91717492009-06-26 21:07:13 -0700249 // Transport bookkeeping
Christopher Tate73e02522009-07-15 14:18:26 -0700250 final HashMap<String,IBackupTransport> mTransports
Christopher Tate91717492009-06-26 21:07:13 -0700251 = new HashMap<String,IBackupTransport>();
Christopher Tate73e02522009-07-15 14:18:26 -0700252 String mCurrentTransport;
253 IBackupTransport mLocalTransport, mGoogleTransport;
Christopher Tate80202c82010-01-25 19:37:47 -0800254 ActiveRestoreSession mActiveRestoreSession;
Christopher Tate043dadc2009-06-02 16:11:00 -0700255
Christopher Tate97ea1222012-05-17 14:59:41 -0700256 // Watch the device provisioning operation during setup
257 ContentObserver mProvisionedObserver;
258
259 class ProvisionedObserver extends ContentObserver {
260 public ProvisionedObserver(Handler handler) {
261 super(handler);
262 }
263
264 public void onChange(boolean selfChange) {
265 final boolean wasProvisioned = mProvisioned;
266 final boolean isProvisioned = deviceIsProvisioned();
267 // latch: never unprovision
268 mProvisioned = wasProvisioned || isProvisioned;
269 if (MORE_DEBUG) {
270 Slog.d(TAG, "Provisioning change: was=" + wasProvisioned
271 + " is=" + isProvisioned + " now=" + mProvisioned);
272 }
273
274 synchronized (mQueueLock) {
275 if (mProvisioned && !wasProvisioned && mEnabled) {
276 // we're now good to go, so start the backup alarms
277 if (MORE_DEBUG) Slog.d(TAG, "Now provisioned, so starting backups");
278 startBackupAlarmsLocked(FIRST_BACKUP_INTERVAL);
279 }
280 }
281 }
282 }
283
Christopher Tate2d449afe2010-03-29 19:14:24 -0700284 class RestoreGetSetsParams {
285 public IBackupTransport transport;
286 public ActiveRestoreSession session;
287 public IRestoreObserver observer;
288
289 RestoreGetSetsParams(IBackupTransport _transport, ActiveRestoreSession _session,
290 IRestoreObserver _observer) {
291 transport = _transport;
292 session = _session;
293 observer = _observer;
294 }
295 }
296
Christopher Tate73e02522009-07-15 14:18:26 -0700297 class RestoreParams {
Christopher Tate7d562ec2009-06-25 18:03:43 -0700298 public IBackupTransport transport;
299 public IRestoreObserver observer;
Dan Egnor156411d2009-06-26 13:20:02 -0700300 public long token;
Christopher Tate84725812010-02-04 15:52:40 -0800301 public PackageInfo pkgInfo;
Christopher Tate1bb69062010-02-19 17:02:12 -0800302 public int pmToken; // in post-install restore, the PM's token for this transaction
Chris Tate249345b2010-10-29 12:57:04 -0700303 public boolean needFullBackup;
Christopher Tate284f1bb2011-07-07 14:31:18 -0700304 public String[] filterSet;
Christopher Tate84725812010-02-04 15:52:40 -0800305
306 RestoreParams(IBackupTransport _transport, IRestoreObserver _obs,
Chris Tate249345b2010-10-29 12:57:04 -0700307 long _token, PackageInfo _pkg, int _pmToken, boolean _needFullBackup) {
Christopher Tate84725812010-02-04 15:52:40 -0800308 transport = _transport;
309 observer = _obs;
310 token = _token;
311 pkgInfo = _pkg;
Christopher Tate1bb69062010-02-19 17:02:12 -0800312 pmToken = _pmToken;
Chris Tate249345b2010-10-29 12:57:04 -0700313 needFullBackup = _needFullBackup;
Christopher Tate284f1bb2011-07-07 14:31:18 -0700314 filterSet = null;
Christopher Tate84725812010-02-04 15:52:40 -0800315 }
Christopher Tate7d562ec2009-06-25 18:03:43 -0700316
Chris Tate249345b2010-10-29 12:57:04 -0700317 RestoreParams(IBackupTransport _transport, IRestoreObserver _obs, long _token,
318 boolean _needFullBackup) {
Christopher Tate7d562ec2009-06-25 18:03:43 -0700319 transport = _transport;
320 observer = _obs;
Dan Egnor156411d2009-06-26 13:20:02 -0700321 token = _token;
Christopher Tate84725812010-02-04 15:52:40 -0800322 pkgInfo = null;
Christopher Tate1bb69062010-02-19 17:02:12 -0800323 pmToken = 0;
Chris Tate249345b2010-10-29 12:57:04 -0700324 needFullBackup = _needFullBackup;
Christopher Tate284f1bb2011-07-07 14:31:18 -0700325 filterSet = null;
326 }
327
328 RestoreParams(IBackupTransport _transport, IRestoreObserver _obs, long _token,
329 String[] _filterSet, boolean _needFullBackup) {
330 transport = _transport;
331 observer = _obs;
332 token = _token;
333 pkgInfo = null;
334 pmToken = 0;
335 needFullBackup = _needFullBackup;
336 filterSet = _filterSet;
Christopher Tate7d562ec2009-06-25 18:03:43 -0700337 }
338 }
339
Christopher Tate73e02522009-07-15 14:18:26 -0700340 class ClearParams {
Christopher Tateee0e78a2009-07-02 11:17:03 -0700341 public IBackupTransport transport;
342 public PackageInfo packageInfo;
343
344 ClearParams(IBackupTransport _transport, PackageInfo _info) {
345 transport = _transport;
346 packageInfo = _info;
347 }
348 }
349
Christopher Tate4a627c72011-04-01 14:43:32 -0700350 class FullParams {
351 public ParcelFileDescriptor fd;
352 public final AtomicBoolean latch;
353 public IFullBackupRestoreObserver observer;
Christopher Tate728a1c42011-07-28 18:03:03 -0700354 public String curPassword; // filled in by the confirmation step
355 public String encryptPassword;
Christopher Tate4a627c72011-04-01 14:43:32 -0700356
357 FullParams() {
358 latch = new AtomicBoolean(false);
359 }
360 }
361
362 class FullBackupParams extends FullParams {
363 public boolean includeApks;
364 public boolean includeShared;
365 public boolean allApps;
Christopher Tate240c7d22011-10-03 18:13:44 -0700366 public boolean includeSystem;
Christopher Tate4a627c72011-04-01 14:43:32 -0700367 public String[] packages;
368
369 FullBackupParams(ParcelFileDescriptor output, boolean saveApks, boolean saveShared,
Christopher Tate240c7d22011-10-03 18:13:44 -0700370 boolean doAllApps, boolean doSystem, String[] pkgList) {
Christopher Tate4a627c72011-04-01 14:43:32 -0700371 fd = output;
372 includeApks = saveApks;
373 includeShared = saveShared;
374 allApps = doAllApps;
Christopher Tate240c7d22011-10-03 18:13:44 -0700375 includeSystem = doSystem;
Christopher Tate4a627c72011-04-01 14:43:32 -0700376 packages = pkgList;
377 }
378 }
379
380 class FullRestoreParams extends FullParams {
381 FullRestoreParams(ParcelFileDescriptor input) {
382 fd = input;
383 }
384 }
385
Christopher Tate44a27902010-01-27 17:15:49 -0800386 // Bookkeeping of in-flight operations for timeout etc. purposes. The operation
387 // token is the index of the entry in the pending-operations list.
388 static final int OP_PENDING = 0;
389 static final int OP_ACKNOWLEDGED = 1;
390 static final int OP_TIMEOUT = -1;
391
Christopher Tate8e294d42011-08-31 20:37:12 -0700392 class Operation {
393 public int state;
394 public BackupRestoreTask callback;
395
396 Operation(int initialState, BackupRestoreTask callbackObj) {
397 state = initialState;
398 callback = callbackObj;
399 }
400 }
401 final SparseArray<Operation> mCurrentOperations = new SparseArray<Operation>();
Christopher Tate44a27902010-01-27 17:15:49 -0800402 final Object mCurrentOpLock = new Object();
403 final Random mTokenGenerator = new Random();
404
Christopher Tate4a627c72011-04-01 14:43:32 -0700405 final SparseArray<FullParams> mFullConfirmations = new SparseArray<FullParams>();
406
Christopher Tate5cb400b2009-06-25 16:03:14 -0700407 // Where we keep our journal files and other bookkeeping
Christopher Tate73e02522009-07-15 14:18:26 -0700408 File mBaseStateDir;
409 File mDataDir;
410 File mJournalDir;
411 File mJournal;
Christopher Tate73e02522009-07-15 14:18:26 -0700412
Christopher Tate2efd2db2011-07-19 16:32:49 -0700413 // Backup password, if any, and the file where it's saved. What is stored is not the
414 // password text itself; it's the result of a PBKDF2 hash with a randomly chosen (but
415 // persisted) salt. Validation is performed by running the challenge text through the
416 // same PBKDF2 cycle with the persisted salt; if the resulting derived key string matches
417 // the saved hash string, then the challenge text matches the originally supplied
418 // password text.
419 private final SecureRandom mRng = new SecureRandom();
420 private String mPasswordHash;
421 private File mPasswordHashFile;
422 private byte[] mPasswordSalt;
423
424 // Configuration of PBKDF2 that we use for generating pw hashes and intermediate keys
425 static final int PBKDF2_HASH_ROUNDS = 10000;
426 static final int PBKDF2_KEY_SIZE = 256; // bits
427 static final int PBKDF2_SALT_SIZE = 512; // bits
428 static final String ENCRYPTION_ALGORITHM_NAME = "AES-256";
429
Christopher Tate84725812010-02-04 15:52:40 -0800430 // Keep a log of all the apps we've ever backed up, and what the
431 // dataset tokens are for both the current backup dataset and
432 // the ancestral dataset.
Christopher Tate73e02522009-07-15 14:18:26 -0700433 private File mEverStored;
Christopher Tate73e02522009-07-15 14:18:26 -0700434 HashSet<String> mEverStoredApps = new HashSet<String>();
435
Christopher Tateb49ceb32010-02-08 16:22:24 -0800436 static final int CURRENT_ANCESTRAL_RECORD_VERSION = 1; // increment when the schema changes
Christopher Tate84725812010-02-04 15:52:40 -0800437 File mTokenFile;
Christopher Tateb49ceb32010-02-08 16:22:24 -0800438 Set<String> mAncestralPackages = null;
Christopher Tate84725812010-02-04 15:52:40 -0800439 long mAncestralToken = 0;
440 long mCurrentToken = 0;
441
Christopher Tate4cc86e12009-09-21 19:36:51 -0700442 // Persistently track the need to do a full init
443 static final String INIT_SENTINEL_FILE_NAME = "_need_init_";
444 HashSet<String> mPendingInits = new HashSet<String>(); // transport names
Christopher Tateaa088442009-06-16 18:25:46 -0700445
Christopher Tate4a627c72011-04-01 14:43:32 -0700446 // Utility: build a new random integer token
447 int generateToken() {
448 int token;
449 do {
450 synchronized (mTokenGenerator) {
451 token = mTokenGenerator.nextInt();
452 }
453 } while (token < 0);
454 return token;
455 }
456
Christopher Tate44a27902010-01-27 17:15:49 -0800457 // ----- Asynchronous backup/restore handler thread -----
458
459 private class BackupHandler extends Handler {
460 public BackupHandler(Looper looper) {
461 super(looper);
462 }
463
464 public void handleMessage(Message msg) {
465
466 switch (msg.what) {
467 case MSG_RUN_BACKUP:
468 {
469 mLastBackupPass = System.currentTimeMillis();
470 mNextBackupPass = mLastBackupPass + BACKUP_INTERVAL;
471
472 IBackupTransport transport = getTransport(mCurrentTransport);
473 if (transport == null) {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800474 Slog.v(TAG, "Backup requested but no transport available");
Christopher Tate336a6492011-10-05 16:05:43 -0700475 synchronized (mQueueLock) {
476 mBackupRunning = false;
477 }
Christopher Tate44a27902010-01-27 17:15:49 -0800478 mWakelock.release();
479 break;
480 }
481
482 // snapshot the pending-backup set and work on that
483 ArrayList<BackupRequest> queue = new ArrayList<BackupRequest>();
Christopher Tatec61da312010-02-05 10:41:27 -0800484 File oldJournal = mJournal;
Christopher Tate44a27902010-01-27 17:15:49 -0800485 synchronized (mQueueLock) {
Christopher Tatec61da312010-02-05 10:41:27 -0800486 // Do we have any work to do? Construct the work queue
487 // then release the synchronization lock to actually run
488 // the backup.
Christopher Tate44a27902010-01-27 17:15:49 -0800489 if (mPendingBackups.size() > 0) {
490 for (BackupRequest b: mPendingBackups.values()) {
491 queue.add(b);
492 }
Joe Onorato8a9b2202010-02-26 18:56:32 -0800493 if (DEBUG) Slog.v(TAG, "clearing pending backups");
Christopher Tate44a27902010-01-27 17:15:49 -0800494 mPendingBackups.clear();
495
496 // Start a new backup-queue journal file too
Christopher Tate44a27902010-01-27 17:15:49 -0800497 mJournal = null;
498
Christopher Tate44a27902010-01-27 17:15:49 -0800499 }
500 }
Christopher Tatec61da312010-02-05 10:41:27 -0800501
Christopher Tate8e294d42011-08-31 20:37:12 -0700502 // At this point, we have started a new journal file, and the old
503 // file identity is being passed to the backup processing task.
504 // When it completes successfully, that old journal file will be
505 // deleted. If we crash prior to that, the old journal is parsed
506 // at next boot and the journaled requests fulfilled.
Christopher Tatec61da312010-02-05 10:41:27 -0800507 if (queue.size() > 0) {
Christopher Tate8e294d42011-08-31 20:37:12 -0700508 // Spin up a backup state sequence and set it running
509 PerformBackupTask pbt = new PerformBackupTask(transport, queue, oldJournal);
510 Message pbtMessage = obtainMessage(MSG_BACKUP_RESTORE_STEP, pbt);
511 sendMessage(pbtMessage);
Christopher Tatec61da312010-02-05 10:41:27 -0800512 } else {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800513 Slog.v(TAG, "Backup requested but nothing pending");
Christopher Tate336a6492011-10-05 16:05:43 -0700514 synchronized (mQueueLock) {
515 mBackupRunning = false;
516 }
Christopher Tatec61da312010-02-05 10:41:27 -0800517 mWakelock.release();
518 }
Christopher Tate44a27902010-01-27 17:15:49 -0800519 break;
520 }
521
Christopher Tate8e294d42011-08-31 20:37:12 -0700522 case MSG_BACKUP_RESTORE_STEP:
523 {
524 try {
525 BackupRestoreTask task = (BackupRestoreTask) msg.obj;
526 if (MORE_DEBUG) Slog.v(TAG, "Got next step for " + task + ", executing");
527 task.execute();
528 } catch (ClassCastException e) {
529 Slog.e(TAG, "Invalid backup task in flight, obj=" + msg.obj);
530 }
531 break;
532 }
533
534 case MSG_OP_COMPLETE:
535 {
536 try {
Christopher Tate2982d062011-09-06 20:35:24 -0700537 BackupRestoreTask task = (BackupRestoreTask) msg.obj;
538 task.operationComplete();
Christopher Tate8e294d42011-08-31 20:37:12 -0700539 } catch (ClassCastException e) {
540 Slog.e(TAG, "Invalid completion in flight, obj=" + msg.obj);
541 }
542 break;
543 }
544
Christopher Tate44a27902010-01-27 17:15:49 -0800545 case MSG_RUN_FULL_BACKUP:
Christopher Tate4a627c72011-04-01 14:43:32 -0700546 {
Christopher Tatea28e8542011-09-12 13:45:21 -0700547 // TODO: refactor full backup to be a looper-based state machine
548 // similar to normal backup/restore.
Christopher Tate4a627c72011-04-01 14:43:32 -0700549 FullBackupParams params = (FullBackupParams)msg.obj;
Christopher Tatea28e8542011-09-12 13:45:21 -0700550 PerformFullBackupTask task = new PerformFullBackupTask(params.fd,
551 params.observer, params.includeApks,
Christopher Tate728a1c42011-07-28 18:03:03 -0700552 params.includeShared, params.curPassword, params.encryptPassword,
Christopher Tate240c7d22011-10-03 18:13:44 -0700553 params.allApps, params.includeSystem, params.packages, params.latch);
Christopher Tatea28e8542011-09-12 13:45:21 -0700554 (new Thread(task)).start();
Christopher Tate44a27902010-01-27 17:15:49 -0800555 break;
Christopher Tate4a627c72011-04-01 14:43:32 -0700556 }
Christopher Tate44a27902010-01-27 17:15:49 -0800557
558 case MSG_RUN_RESTORE:
559 {
560 RestoreParams params = (RestoreParams)msg.obj;
Joe Onorato8a9b2202010-02-26 18:56:32 -0800561 Slog.d(TAG, "MSG_RUN_RESTORE observer=" + params.observer);
Christopher Tate2982d062011-09-06 20:35:24 -0700562 PerformRestoreTask task = new PerformRestoreTask(
563 params.transport, params.observer,
Chris Tate249345b2010-10-29 12:57:04 -0700564 params.token, params.pkgInfo, params.pmToken,
Christopher Tate2982d062011-09-06 20:35:24 -0700565 params.needFullBackup, params.filterSet);
566 Message restoreMsg = obtainMessage(MSG_BACKUP_RESTORE_STEP, task);
567 sendMessage(restoreMsg);
Christopher Tate44a27902010-01-27 17:15:49 -0800568 break;
569 }
570
Christopher Tate75a99702011-05-18 16:28:19 -0700571 case MSG_RUN_FULL_RESTORE:
572 {
Christopher Tatea28e8542011-09-12 13:45:21 -0700573 // TODO: refactor full restore to be a looper-based state machine
574 // similar to normal backup/restore.
Christopher Tate75a99702011-05-18 16:28:19 -0700575 FullRestoreParams params = (FullRestoreParams)msg.obj;
Christopher Tatea28e8542011-09-12 13:45:21 -0700576 PerformFullRestoreTask task = new PerformFullRestoreTask(params.fd,
577 params.curPassword, params.encryptPassword,
578 params.observer, params.latch);
579 (new Thread(task)).start();
Christopher Tate75a99702011-05-18 16:28:19 -0700580 break;
581 }
582
Christopher Tate44a27902010-01-27 17:15:49 -0800583 case MSG_RUN_CLEAR:
584 {
585 ClearParams params = (ClearParams)msg.obj;
586 (new PerformClearTask(params.transport, params.packageInfo)).run();
587 break;
588 }
589
590 case MSG_RUN_INITIALIZE:
591 {
592 HashSet<String> queue;
593
594 // Snapshot the pending-init queue and work on that
595 synchronized (mQueueLock) {
596 queue = new HashSet<String>(mPendingInits);
597 mPendingInits.clear();
598 }
599
600 (new PerformInitializeTask(queue)).run();
601 break;
602 }
603
Christopher Tate2d449afe2010-03-29 19:14:24 -0700604 case MSG_RUN_GET_RESTORE_SETS:
605 {
606 // Like other async operations, this is entered with the wakelock held
607 RestoreSet[] sets = null;
608 RestoreGetSetsParams params = (RestoreGetSetsParams)msg.obj;
609 try {
610 sets = params.transport.getAvailableRestoreSets();
611 // cache the result in the active session
612 synchronized (params.session) {
613 params.session.mRestoreSets = sets;
614 }
615 if (sets == null) EventLog.writeEvent(EventLogTags.RESTORE_TRANSPORT_FAILURE);
616 } catch (Exception e) {
617 Slog.e(TAG, "Error from transport getting set list");
618 } finally {
619 if (params.observer != null) {
620 try {
621 params.observer.restoreSetsAvailable(sets);
622 } catch (RemoteException re) {
623 Slog.e(TAG, "Unable to report listing to observer");
624 } catch (Exception e) {
625 Slog.e(TAG, "Restore observer threw", e);
626 }
627 }
628
Christopher Tate2a935092011-03-03 17:30:32 -0800629 // Done: reset the session timeout clock
630 removeMessages(MSG_RESTORE_TIMEOUT);
631 sendEmptyMessageDelayed(MSG_RESTORE_TIMEOUT, TIMEOUT_RESTORE_INTERVAL);
632
Christopher Tate2d449afe2010-03-29 19:14:24 -0700633 mWakelock.release();
634 }
635 break;
636 }
637
Christopher Tate44a27902010-01-27 17:15:49 -0800638 case MSG_TIMEOUT:
639 {
Christopher Tate8e294d42011-08-31 20:37:12 -0700640 handleTimeout(msg.arg1, msg.obj);
Christopher Tate44a27902010-01-27 17:15:49 -0800641 break;
642 }
Christopher Tate73a3cb32010-12-13 18:27:26 -0800643
644 case MSG_RESTORE_TIMEOUT:
645 {
646 synchronized (BackupManagerService.this) {
647 if (mActiveRestoreSession != null) {
648 // Client app left the restore session dangling. We know that it
649 // can't be in the middle of an actual restore operation because
Christopher Tate2982d062011-09-06 20:35:24 -0700650 // the timeout is suspended while a restore is in progress. Clean
Christopher Tate73a3cb32010-12-13 18:27:26 -0800651 // up now.
652 Slog.w(TAG, "Restore session timed out; aborting");
653 post(mActiveRestoreSession.new EndRestoreRunnable(
654 BackupManagerService.this, mActiveRestoreSession));
655 }
656 }
657 }
Christopher Tate4a627c72011-04-01 14:43:32 -0700658
659 case MSG_FULL_CONFIRMATION_TIMEOUT:
660 {
661 synchronized (mFullConfirmations) {
662 FullParams params = mFullConfirmations.get(msg.arg1);
663 if (params != null) {
664 Slog.i(TAG, "Full backup/restore timed out waiting for user confirmation");
665
666 // Release the waiter; timeout == completion
667 signalFullBackupRestoreCompletion(params);
668
669 // Remove the token from the set
670 mFullConfirmations.delete(msg.arg1);
671
672 // Report a timeout to the observer, if any
673 if (params.observer != null) {
674 try {
675 params.observer.onTimeout();
676 } catch (RemoteException e) {
677 /* don't care if the app has gone away */
678 }
679 }
680 } else {
681 Slog.d(TAG, "couldn't find params for token " + msg.arg1);
682 }
683 }
684 break;
685 }
Christopher Tate44a27902010-01-27 17:15:49 -0800686 }
687 }
688 }
689
Christopher Tate6de74ff2012-01-17 15:20:32 -0800690 // ----- Debug-only backup operation trace -----
691 void addBackupTrace(String s) {
692 if (DEBUG_BACKUP_TRACE) {
693 synchronized (mBackupTrace) {
694 mBackupTrace.add(s);
695 }
696 }
697 }
698
699 void clearBackupTrace() {
700 if (DEBUG_BACKUP_TRACE) {
701 synchronized (mBackupTrace) {
702 mBackupTrace.clear();
703 }
704 }
705 }
706
Christopher Tate44a27902010-01-27 17:15:49 -0800707 // ----- Main service implementation -----
708
Christopher Tate487529a2009-04-29 14:03:25 -0700709 public BackupManagerService(Context context) {
710 mContext = context;
711 mPackageManager = context.getPackageManager();
Dianne Hackborn01e4cfc2010-06-24 15:07:24 -0700712 mPackageManagerBinder = AppGlobals.getPackageManager();
Christopher Tate181fafa2009-05-14 11:12:14 -0700713 mActivityManager = ActivityManagerNative.getDefault();
Christopher Tate487529a2009-04-29 14:03:25 -0700714
Christopher Tateb6787f22009-07-02 17:40:45 -0700715 mAlarmManager = (AlarmManager) context.getSystemService(Context.ALARM_SERVICE);
716 mPowerManager = (PowerManager) context.getSystemService(Context.POWER_SERVICE);
Christopher Tate32418be2011-10-10 13:51:12 -0700717 mMountService = IMountService.Stub.asInterface(ServiceManager.getService("mount"));
Christopher Tateb6787f22009-07-02 17:40:45 -0700718
Christopher Tate44a27902010-01-27 17:15:49 -0800719 mBackupManagerBinder = asInterface(asBinder());
720
721 // spin up the backup/restore handler thread
722 mHandlerThread = new HandlerThread("backup", Process.THREAD_PRIORITY_BACKGROUND);
723 mHandlerThread.start();
724 mBackupHandler = new BackupHandler(mHandlerThread.getLooper());
725
Christopher Tate22b87872009-05-04 16:41:53 -0700726 // Set up our bookkeeping
Christopher Tate97ea1222012-05-17 14:59:41 -0700727 final ContentResolver resolver = context.getContentResolver();
728 boolean areEnabled = Settings.Secure.getInt(resolver,
Dianne Hackborncf098292009-07-01 19:55:20 -0700729 Settings.Secure.BACKUP_ENABLED, 0) != 0;
Christopher Tate97ea1222012-05-17 14:59:41 -0700730 mProvisioned = Settings.Secure.getInt(resolver,
731 Settings.Secure.DEVICE_PROVISIONED, 0) != 0;
732 mAutoRestore = Settings.Secure.getInt(resolver,
Christopher Tate5035fda2010-02-25 18:01:14 -0800733 Settings.Secure.BACKUP_AUTO_RESTORE, 1) != 0;
Christopher Tate97ea1222012-05-17 14:59:41 -0700734
735 mProvisionedObserver = new ProvisionedObserver(mBackupHandler);
736 resolver.registerContentObserver(
737 Settings.Secure.getUriFor(Settings.Secure.DEVICE_PROVISIONED),
738 false, mProvisionedObserver);
739
Oscar Montemayora8529f62009-11-18 10:14:20 -0800740 // If Encrypted file systems is enabled or disabled, this call will return the
741 // correct directory.
Jason parksa3cdaa52011-01-13 14:15:43 -0600742 mBaseStateDir = new File(Environment.getSecureDataDirectory(), "backup");
Oscar Montemayora8529f62009-11-18 10:14:20 -0800743 mBaseStateDir.mkdirs();
Christopher Tatef4172472009-05-05 15:50:03 -0700744 mDataDir = Environment.getDownloadCacheDirectory();
Christopher Tate9bbc21a2009-06-10 20:23:25 -0700745
Christopher Tate2efd2db2011-07-19 16:32:49 -0700746 mPasswordHashFile = new File(mBaseStateDir, "pwhash");
747 if (mPasswordHashFile.exists()) {
748 FileInputStream fin = null;
749 DataInputStream in = null;
750 try {
751 fin = new FileInputStream(mPasswordHashFile);
752 in = new DataInputStream(new BufferedInputStream(fin));
753 // integer length of the salt array, followed by the salt,
754 // then the hex pw hash string
755 int saltLen = in.readInt();
756 byte[] salt = new byte[saltLen];
757 in.readFully(salt);
758 mPasswordHash = in.readUTF();
759 mPasswordSalt = salt;
760 } catch (IOException e) {
761 Slog.e(TAG, "Unable to read saved backup pw hash");
762 } finally {
763 try {
764 if (in != null) in.close();
765 if (fin != null) fin.close();
766 } catch (IOException e) {
767 Slog.w(TAG, "Unable to close streams");
768 }
769 }
770 }
771
Christopher Tate4cc86e12009-09-21 19:36:51 -0700772 // Alarm receivers for scheduled backups & initialization operations
Christopher Tateb6787f22009-07-02 17:40:45 -0700773 mRunBackupReceiver = new RunBackupReceiver();
Christopher Tate4cc86e12009-09-21 19:36:51 -0700774 IntentFilter filter = new IntentFilter();
775 filter.addAction(RUN_BACKUP_ACTION);
776 context.registerReceiver(mRunBackupReceiver, filter,
777 android.Manifest.permission.BACKUP, null);
778
779 mRunInitReceiver = new RunInitializeReceiver();
780 filter = new IntentFilter();
781 filter.addAction(RUN_INITIALIZE_ACTION);
782 context.registerReceiver(mRunInitReceiver, filter,
783 android.Manifest.permission.BACKUP, null);
Christopher Tateb6787f22009-07-02 17:40:45 -0700784
785 Intent backupIntent = new Intent(RUN_BACKUP_ACTION);
Christopher Tateb6787f22009-07-02 17:40:45 -0700786 backupIntent.addFlags(Intent.FLAG_RECEIVER_REGISTERED_ONLY);
787 mRunBackupIntent = PendingIntent.getBroadcast(context, MSG_RUN_BACKUP, backupIntent, 0);
788
Christopher Tate4cc86e12009-09-21 19:36:51 -0700789 Intent initIntent = new Intent(RUN_INITIALIZE_ACTION);
790 backupIntent.addFlags(Intent.FLAG_RECEIVER_REGISTERED_ONLY);
791 mRunInitIntent = PendingIntent.getBroadcast(context, MSG_RUN_INITIALIZE, initIntent, 0);
792
Christopher Tatecde87f42009-06-12 12:55:53 -0700793 // Set up the backup-request journaling
Christopher Tate5cb400b2009-06-25 16:03:14 -0700794 mJournalDir = new File(mBaseStateDir, "pending");
795 mJournalDir.mkdirs(); // creates mBaseStateDir along the way
Dan Egnor852f8e42009-09-30 11:20:45 -0700796 mJournal = null; // will be created on first use
Christopher Tatecde87f42009-06-12 12:55:53 -0700797
Christopher Tate73e02522009-07-15 14:18:26 -0700798 // Set up the various sorts of package tracking we do
799 initPackageTracking();
800
Christopher Tateabce4e82009-06-18 18:35:32 -0700801 // Build our mapping of uid to backup client services. This implicitly
802 // schedules a backup pass on the Package Manager metadata the first
803 // time anything needs to be backed up.
Christopher Tate3799bc22009-05-06 16:13:56 -0700804 synchronized (mBackupParticipants) {
805 addPackageParticipantsLocked(null);
Christopher Tate487529a2009-04-29 14:03:25 -0700806 }
807
Dan Egnor87a02bc2009-06-17 02:30:10 -0700808 // Set up our transport options and initialize the default transport
809 // TODO: Have transports register themselves somehow?
810 // TODO: Don't create transports that we don't need to?
Dan Egnor87a02bc2009-06-17 02:30:10 -0700811 mLocalTransport = new LocalTransport(context); // This is actually pretty cheap
Christopher Tate91717492009-06-26 21:07:13 -0700812 ComponentName localName = new ComponentName(context, LocalTransport.class);
813 registerTransport(localName.flattenToShortString(), mLocalTransport);
Dan Egnor87a02bc2009-06-17 02:30:10 -0700814
Christopher Tate91717492009-06-26 21:07:13 -0700815 mGoogleTransport = null;
Dianne Hackborncf098292009-07-01 19:55:20 -0700816 mCurrentTransport = Settings.Secure.getString(context.getContentResolver(),
817 Settings.Secure.BACKUP_TRANSPORT);
818 if ("".equals(mCurrentTransport)) {
819 mCurrentTransport = null;
Christopher Tatece0bf062009-07-01 11:43:53 -0700820 }
Joe Onorato8a9b2202010-02-26 18:56:32 -0800821 if (DEBUG) Slog.v(TAG, "Starting with transport " + mCurrentTransport);
Christopher Tate91717492009-06-26 21:07:13 -0700822
823 // Attach to the Google backup transport. When this comes up, it will set
824 // itself as the current transport because we explicitly reset mCurrentTransport
825 // to null.
Christopher Tatea32504f2010-04-21 17:58:07 -0700826 ComponentName transportComponent = new ComponentName("com.google.android.backup",
827 "com.google.android.backup.BackupTransportService");
828 try {
829 // If there's something out there that is supposed to be the Google
830 // backup transport, make sure it's legitimately part of the OS build
831 // and not an app lying about its package name.
832 ApplicationInfo info = mPackageManager.getApplicationInfo(
833 transportComponent.getPackageName(), 0);
834 if ((info.flags & ApplicationInfo.FLAG_SYSTEM) != 0) {
835 if (DEBUG) Slog.v(TAG, "Binding to Google transport");
836 Intent intent = new Intent().setComponent(transportComponent);
837 context.bindService(intent, mGoogleConnection, Context.BIND_AUTO_CREATE);
838 } else {
839 Slog.w(TAG, "Possible Google transport spoof: ignoring " + info);
840 }
841 } catch (PackageManager.NameNotFoundException nnf) {
842 // No such package? No binding.
843 if (DEBUG) Slog.v(TAG, "Google transport not present");
844 }
Christopher Tateaa088442009-06-16 18:25:46 -0700845
Christopher Tatecde87f42009-06-12 12:55:53 -0700846 // Now that we know about valid backup participants, parse any
Christopher Tate49401dd2009-07-01 12:34:29 -0700847 // leftover journal files into the pending backup set
Christopher Tatecde87f42009-06-12 12:55:53 -0700848 parseLeftoverJournals();
849
Christopher Tateb6787f22009-07-02 17:40:45 -0700850 // Power management
Dianne Hackborn7e9f4eb2010-09-10 18:43:00 -0700851 mWakelock = mPowerManager.newWakeLock(PowerManager.PARTIAL_WAKE_LOCK, "*backup*");
Christopher Tateb6787f22009-07-02 17:40:45 -0700852
853 // Start the backup passes going
854 setBackupEnabled(areEnabled);
855 }
856
857 private class RunBackupReceiver extends BroadcastReceiver {
858 public void onReceive(Context context, Intent intent) {
859 if (RUN_BACKUP_ACTION.equals(intent.getAction())) {
Christopher Tateb6787f22009-07-02 17:40:45 -0700860 synchronized (mQueueLock) {
Christopher Tate4cc86e12009-09-21 19:36:51 -0700861 if (mPendingInits.size() > 0) {
862 // If there are pending init operations, we process those
863 // and then settle into the usual periodic backup schedule.
Joe Onorato8a9b2202010-02-26 18:56:32 -0800864 if (DEBUG) Slog.v(TAG, "Init pending at scheduled backup");
Christopher Tate4cc86e12009-09-21 19:36:51 -0700865 try {
866 mAlarmManager.cancel(mRunInitIntent);
867 mRunInitIntent.send();
868 } catch (PendingIntent.CanceledException ce) {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800869 Slog.e(TAG, "Run init intent cancelled");
Christopher Tate4cc86e12009-09-21 19:36:51 -0700870 // can't really do more than bail here
871 }
872 } else {
Christopher Tatec2af5d32010-02-02 15:18:58 -0800873 // Don't run backups now if we're disabled or not yet
874 // fully set up.
875 if (mEnabled && mProvisioned) {
Christopher Tate336a6492011-10-05 16:05:43 -0700876 if (!mBackupRunning) {
877 if (DEBUG) Slog.v(TAG, "Running a backup pass");
Christopher Tate4cc86e12009-09-21 19:36:51 -0700878
Christopher Tate336a6492011-10-05 16:05:43 -0700879 // Acquire the wakelock and pass it to the backup thread. it will
880 // be released once backup concludes.
881 mBackupRunning = true;
882 mWakelock.acquire();
Christopher Tate4cc86e12009-09-21 19:36:51 -0700883
Christopher Tate336a6492011-10-05 16:05:43 -0700884 Message msg = mBackupHandler.obtainMessage(MSG_RUN_BACKUP);
885 mBackupHandler.sendMessage(msg);
886 } else {
887 Slog.i(TAG, "Backup time but one already running");
888 }
Christopher Tate4cc86e12009-09-21 19:36:51 -0700889 } else {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800890 Slog.w(TAG, "Backup pass but e=" + mEnabled + " p=" + mProvisioned);
Christopher Tate4cc86e12009-09-21 19:36:51 -0700891 }
892 }
893 }
894 }
895 }
896 }
897
898 private class RunInitializeReceiver extends BroadcastReceiver {
899 public void onReceive(Context context, Intent intent) {
900 if (RUN_INITIALIZE_ACTION.equals(intent.getAction())) {
901 synchronized (mQueueLock) {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800902 if (DEBUG) Slog.v(TAG, "Running a device init");
Christopher Tate4cc86e12009-09-21 19:36:51 -0700903
904 // Acquire the wakelock and pass it to the init thread. it will
905 // be released once init concludes.
Christopher Tateb6787f22009-07-02 17:40:45 -0700906 mWakelock.acquire();
907
Christopher Tate4cc86e12009-09-21 19:36:51 -0700908 Message msg = mBackupHandler.obtainMessage(MSG_RUN_INITIALIZE);
Christopher Tateb6787f22009-07-02 17:40:45 -0700909 mBackupHandler.sendMessage(msg);
910 }
911 }
Christopher Tate49401dd2009-07-01 12:34:29 -0700912 }
Christopher Tateb6787f22009-07-02 17:40:45 -0700913 }
Christopher Tate3799bc22009-05-06 16:13:56 -0700914
Christopher Tate73e02522009-07-15 14:18:26 -0700915 private void initPackageTracking() {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800916 if (DEBUG) Slog.v(TAG, "Initializing package tracking");
Christopher Tate73e02522009-07-15 14:18:26 -0700917
Christopher Tate84725812010-02-04 15:52:40 -0800918 // Remember our ancestral dataset
919 mTokenFile = new File(mBaseStateDir, "ancestral");
920 try {
921 RandomAccessFile tf = new RandomAccessFile(mTokenFile, "r");
Christopher Tateb49ceb32010-02-08 16:22:24 -0800922 int version = tf.readInt();
923 if (version == CURRENT_ANCESTRAL_RECORD_VERSION) {
924 mAncestralToken = tf.readLong();
925 mCurrentToken = tf.readLong();
926
927 int numPackages = tf.readInt();
928 if (numPackages >= 0) {
929 mAncestralPackages = new HashSet<String>();
930 for (int i = 0; i < numPackages; i++) {
931 String pkgName = tf.readUTF();
932 mAncestralPackages.add(pkgName);
933 }
934 }
935 }
Brad Fitzpatrick725d8f02010-11-15 11:12:42 -0800936 tf.close();
Christopher Tate1168baa2010-02-17 13:03:40 -0800937 } catch (FileNotFoundException fnf) {
938 // Probably innocuous
Joe Onorato8a9b2202010-02-26 18:56:32 -0800939 Slog.v(TAG, "No ancestral data");
Christopher Tate84725812010-02-04 15:52:40 -0800940 } catch (IOException e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800941 Slog.w(TAG, "Unable to read token file", e);
Christopher Tate84725812010-02-04 15:52:40 -0800942 }
943
Christopher Tatee97e8072009-07-15 16:45:50 -0700944 // Keep a log of what apps we've ever backed up. Because we might have
945 // rebooted in the middle of an operation that was removing something from
946 // this log, we sanity-check its contents here and reconstruct it.
Christopher Tate73e02522009-07-15 14:18:26 -0700947 mEverStored = new File(mBaseStateDir, "processed");
Christopher Tatee97e8072009-07-15 16:45:50 -0700948 File tempProcessedFile = new File(mBaseStateDir, "processed.new");
Christopher Tate73e02522009-07-15 14:18:26 -0700949
Christopher Tatee97e8072009-07-15 16:45:50 -0700950 // If we were in the middle of removing something from the ever-backed-up
951 // file, there might be a transient "processed.new" file still present.
Dan Egnor852f8e42009-09-30 11:20:45 -0700952 // Ignore it -- we'll validate "processed" against the current package set.
Christopher Tatee97e8072009-07-15 16:45:50 -0700953 if (tempProcessedFile.exists()) {
954 tempProcessedFile.delete();
955 }
956
Dan Egnor852f8e42009-09-30 11:20:45 -0700957 // If there are previous contents, parse them out then start a new
958 // file to continue the recordkeeping.
959 if (mEverStored.exists()) {
960 RandomAccessFile temp = null;
961 RandomAccessFile in = null;
962
963 try {
964 temp = new RandomAccessFile(tempProcessedFile, "rws");
965 in = new RandomAccessFile(mEverStored, "r");
966
967 while (true) {
968 PackageInfo info;
969 String pkg = in.readUTF();
970 try {
971 info = mPackageManager.getPackageInfo(pkg, 0);
972 mEverStoredApps.add(pkg);
973 temp.writeUTF(pkg);
Christopher Tatec58efa62011-08-01 19:20:14 -0700974 if (MORE_DEBUG) Slog.v(TAG, " + " + pkg);
Dan Egnor852f8e42009-09-30 11:20:45 -0700975 } catch (NameNotFoundException e) {
976 // nope, this package was uninstalled; don't include it
Christopher Tatec58efa62011-08-01 19:20:14 -0700977 if (MORE_DEBUG) Slog.v(TAG, " - " + pkg);
Dan Egnor852f8e42009-09-30 11:20:45 -0700978 }
979 }
980 } catch (EOFException e) {
981 // Once we've rewritten the backup history log, atomically replace the
982 // old one with the new one then reopen the file for continuing use.
983 if (!tempProcessedFile.renameTo(mEverStored)) {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800984 Slog.e(TAG, "Error renaming " + tempProcessedFile + " to " + mEverStored);
Dan Egnor852f8e42009-09-30 11:20:45 -0700985 }
986 } catch (IOException e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -0800987 Slog.e(TAG, "Error in processed file", e);
Dan Egnor852f8e42009-09-30 11:20:45 -0700988 } finally {
989 try { if (temp != null) temp.close(); } catch (IOException e) {}
990 try { if (in != null) in.close(); } catch (IOException e) {}
991 }
992 }
993
Christopher Tate73e02522009-07-15 14:18:26 -0700994 // Register for broadcasts about package install, etc., so we can
995 // update the provider list.
996 IntentFilter filter = new IntentFilter();
997 filter.addAction(Intent.ACTION_PACKAGE_ADDED);
998 filter.addAction(Intent.ACTION_PACKAGE_REMOVED);
999 filter.addDataScheme("package");
1000 mContext.registerReceiver(mBroadcastReceiver, filter);
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001001 // Register for events related to sdcard installation.
1002 IntentFilter sdFilter = new IntentFilter();
Suchi Amalapurapub56ae202010-02-04 22:51:07 -08001003 sdFilter.addAction(Intent.ACTION_EXTERNAL_APPLICATIONS_AVAILABLE);
1004 sdFilter.addAction(Intent.ACTION_EXTERNAL_APPLICATIONS_UNAVAILABLE);
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001005 mContext.registerReceiver(mBroadcastReceiver, sdFilter);
Christopher Tate73e02522009-07-15 14:18:26 -07001006 }
1007
Christopher Tatecde87f42009-06-12 12:55:53 -07001008 private void parseLeftoverJournals() {
Dan Egnor852f8e42009-09-30 11:20:45 -07001009 for (File f : mJournalDir.listFiles()) {
1010 if (mJournal == null || f.compareTo(mJournal) != 0) {
1011 // This isn't the current journal, so it must be a leftover. Read
1012 // out the package names mentioned there and schedule them for
1013 // backup.
1014 RandomAccessFile in = null;
1015 try {
Joe Onorato431bb222010-10-18 19:13:23 -04001016 Slog.i(TAG, "Found stale backup journal, scheduling");
Dan Egnor852f8e42009-09-30 11:20:45 -07001017 in = new RandomAccessFile(f, "r");
1018 while (true) {
1019 String packageName = in.readUTF();
Joe Onorato431bb222010-10-18 19:13:23 -04001020 Slog.i(TAG, " " + packageName);
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07001021 dataChangedImpl(packageName);
Christopher Tatecde87f42009-06-12 12:55:53 -07001022 }
Dan Egnor852f8e42009-09-30 11:20:45 -07001023 } catch (EOFException e) {
1024 // no more data; we're done
1025 } catch (Exception e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001026 Slog.e(TAG, "Can't read " + f, e);
Dan Egnor852f8e42009-09-30 11:20:45 -07001027 } finally {
1028 // close/delete the file
1029 try { if (in != null) in.close(); } catch (IOException e) {}
1030 f.delete();
Christopher Tatecde87f42009-06-12 12:55:53 -07001031 }
1032 }
1033 }
1034 }
1035
Christopher Tate2efd2db2011-07-19 16:32:49 -07001036 private SecretKey buildPasswordKey(String pw, byte[] salt, int rounds) {
1037 return buildCharArrayKey(pw.toCharArray(), salt, rounds);
1038 }
1039
1040 private SecretKey buildCharArrayKey(char[] pwArray, byte[] salt, int rounds) {
1041 try {
1042 SecretKeyFactory keyFactory = SecretKeyFactory.getInstance("PBKDF2WithHmacSHA1");
1043 KeySpec ks = new PBEKeySpec(pwArray, salt, rounds, PBKDF2_KEY_SIZE);
1044 return keyFactory.generateSecret(ks);
1045 } catch (InvalidKeySpecException e) {
1046 Slog.e(TAG, "Invalid key spec for PBKDF2!");
1047 } catch (NoSuchAlgorithmException e) {
1048 Slog.e(TAG, "PBKDF2 unavailable!");
1049 }
1050 return null;
1051 }
1052
1053 private String buildPasswordHash(String pw, byte[] salt, int rounds) {
1054 SecretKey key = buildPasswordKey(pw, salt, rounds);
1055 if (key != null) {
1056 return byteArrayToHex(key.getEncoded());
1057 }
1058 return null;
1059 }
1060
1061 private String byteArrayToHex(byte[] data) {
1062 StringBuilder buf = new StringBuilder(data.length * 2);
1063 for (int i = 0; i < data.length; i++) {
1064 buf.append(Byte.toHexString(data[i], true));
1065 }
1066 return buf.toString();
1067 }
1068
1069 private byte[] hexToByteArray(String digits) {
1070 final int bytes = digits.length() / 2;
1071 if (2*bytes != digits.length()) {
1072 throw new IllegalArgumentException("Hex string must have an even number of digits");
1073 }
1074
1075 byte[] result = new byte[bytes];
1076 for (int i = 0; i < digits.length(); i += 2) {
1077 result[i/2] = (byte) Integer.parseInt(digits.substring(i, i+2), 16);
1078 }
1079 return result;
1080 }
1081
1082 private byte[] makeKeyChecksum(byte[] pwBytes, byte[] salt, int rounds) {
1083 char[] mkAsChar = new char[pwBytes.length];
1084 for (int i = 0; i < pwBytes.length; i++) {
1085 mkAsChar[i] = (char) pwBytes[i];
1086 }
1087
1088 Key checksum = buildCharArrayKey(mkAsChar, salt, rounds);
1089 return checksum.getEncoded();
1090 }
1091
1092 // Used for generating random salts or passwords
1093 private byte[] randomBytes(int bits) {
1094 byte[] array = new byte[bits / 8];
1095 mRng.nextBytes(array);
1096 return array;
1097 }
1098
1099 // Backup password management
1100 boolean passwordMatchesSaved(String candidatePw, int rounds) {
Christopher Tate32418be2011-10-10 13:51:12 -07001101 // First, on an encrypted device we require matching the device pw
1102 final boolean isEncrypted;
1103 try {
1104 isEncrypted = (mMountService.getEncryptionState() != MountService.ENCRYPTION_STATE_NONE);
1105 if (isEncrypted) {
1106 if (DEBUG) {
1107 Slog.i(TAG, "Device encrypted; verifying against device data pw");
1108 }
1109 // 0 means the password validated
1110 // -2 means device not encrypted
1111 // Any other result is either password failure or an error condition,
1112 // so we refuse the match
1113 final int result = mMountService.verifyEncryptionPassword(candidatePw);
1114 if (result == 0) {
1115 if (MORE_DEBUG) Slog.d(TAG, "Pw verifies");
1116 return true;
1117 } else if (result != -2) {
1118 if (MORE_DEBUG) Slog.d(TAG, "Pw mismatch");
1119 return false;
1120 } else {
1121 // ...else the device is supposedly not encrypted. HOWEVER, the
1122 // query about the encryption state said that the device *is*
1123 // encrypted, so ... we may have a problem. Log it and refuse
1124 // the backup.
1125 Slog.e(TAG, "verified encryption state mismatch against query; no match allowed");
1126 return false;
1127 }
1128 }
1129 } catch (Exception e) {
1130 // Something went wrong talking to the mount service. This is very bad;
1131 // assume that we fail password validation.
1132 return false;
1133 }
1134
Christopher Tate2efd2db2011-07-19 16:32:49 -07001135 if (mPasswordHash == null) {
1136 // no current password case -- require that 'currentPw' be null or empty
1137 if (candidatePw == null || "".equals(candidatePw)) {
1138 return true;
1139 } // else the non-empty candidate does not match the empty stored pw
1140 } else {
1141 // hash the stated current pw and compare to the stored one
1142 if (candidatePw != null && candidatePw.length() > 0) {
1143 String currentPwHash = buildPasswordHash(candidatePw, mPasswordSalt, rounds);
1144 if (mPasswordHash.equalsIgnoreCase(currentPwHash)) {
1145 // candidate hash matches the stored hash -- the password matches
1146 return true;
1147 }
1148 } // else the stored pw is nonempty but the candidate is empty; no match
1149 }
1150 return false;
1151 }
1152
1153 @Override
1154 public boolean setBackupPassword(String currentPw, String newPw) {
1155 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
1156 "setBackupPassword");
1157
1158 // If the supplied pw doesn't hash to the the saved one, fail
1159 if (!passwordMatchesSaved(currentPw, PBKDF2_HASH_ROUNDS)) {
1160 return false;
1161 }
1162
1163 // Clearing the password is okay
1164 if (newPw == null || newPw.isEmpty()) {
1165 if (mPasswordHashFile.exists()) {
1166 if (!mPasswordHashFile.delete()) {
1167 // Unable to delete the old pw file, so fail
1168 Slog.e(TAG, "Unable to clear backup password");
1169 return false;
1170 }
1171 }
1172 mPasswordHash = null;
1173 mPasswordSalt = null;
1174 return true;
1175 }
1176
1177 try {
1178 // Okay, build the hash of the new backup password
1179 byte[] salt = randomBytes(PBKDF2_SALT_SIZE);
1180 String newPwHash = buildPasswordHash(newPw, salt, PBKDF2_HASH_ROUNDS);
1181
1182 OutputStream pwf = null, buffer = null;
1183 DataOutputStream out = null;
1184 try {
1185 pwf = new FileOutputStream(mPasswordHashFile);
1186 buffer = new BufferedOutputStream(pwf);
1187 out = new DataOutputStream(buffer);
1188 // integer length of the salt array, followed by the salt,
1189 // then the hex pw hash string
1190 out.writeInt(salt.length);
1191 out.write(salt);
1192 out.writeUTF(newPwHash);
1193 out.flush();
1194 mPasswordHash = newPwHash;
1195 mPasswordSalt = salt;
1196 return true;
1197 } finally {
1198 if (out != null) out.close();
1199 if (buffer != null) buffer.close();
1200 if (pwf != null) pwf.close();
1201 }
1202 } catch (IOException e) {
1203 Slog.e(TAG, "Unable to set backup password");
1204 }
1205 return false;
1206 }
1207
1208 @Override
1209 public boolean hasBackupPassword() {
1210 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
1211 "hasBackupPassword");
Christopher Tate32418be2011-10-10 13:51:12 -07001212
1213 try {
1214 return (mMountService.getEncryptionState() != IMountService.ENCRYPTION_STATE_NONE)
1215 || (mPasswordHash != null && mPasswordHash.length() > 0);
1216 } catch (Exception e) {
1217 // If we can't talk to the mount service we have a serious problem; fail
1218 // "secure" i.e. assuming that we require a password
1219 return true;
1220 }
Christopher Tate2efd2db2011-07-19 16:32:49 -07001221 }
1222
Christopher Tate4cc86e12009-09-21 19:36:51 -07001223 // Maintain persistent state around whether need to do an initialize operation.
1224 // Must be called with the queue lock held.
1225 void recordInitPendingLocked(boolean isPending, String transportName) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001226 if (DEBUG) Slog.i(TAG, "recordInitPendingLocked: " + isPending
Christopher Tate4cc86e12009-09-21 19:36:51 -07001227 + " on transport " + transportName);
1228 try {
1229 IBackupTransport transport = getTransport(transportName);
1230 String transportDirName = transport.transportDirName();
1231 File stateDir = new File(mBaseStateDir, transportDirName);
1232 File initPendingFile = new File(stateDir, INIT_SENTINEL_FILE_NAME);
1233
1234 if (isPending) {
1235 // We need an init before we can proceed with sending backup data.
1236 // Record that with an entry in our set of pending inits, as well as
1237 // journaling it via creation of a sentinel file.
1238 mPendingInits.add(transportName);
1239 try {
1240 (new FileOutputStream(initPendingFile)).close();
1241 } catch (IOException ioe) {
1242 // Something is badly wrong with our permissions; just try to move on
1243 }
1244 } else {
1245 // No more initialization needed; wipe the journal and reset our state.
1246 initPendingFile.delete();
1247 mPendingInits.remove(transportName);
1248 }
1249 } catch (RemoteException e) {
1250 // can't happen; the transport is local
1251 }
1252 }
1253
Christopher Tated55e18a2009-09-21 10:12:59 -07001254 // Reset all of our bookkeeping, in response to having been told that
1255 // the backend data has been wiped [due to idle expiry, for example],
1256 // so we must re-upload all saved settings.
1257 void resetBackupState(File stateFileDir) {
1258 synchronized (mQueueLock) {
1259 // Wipe the "what we've ever backed up" tracking
Christopher Tated55e18a2009-09-21 10:12:59 -07001260 mEverStoredApps.clear();
Dan Egnor852f8e42009-09-30 11:20:45 -07001261 mEverStored.delete();
Christopher Tated55e18a2009-09-21 10:12:59 -07001262
Christopher Tate84725812010-02-04 15:52:40 -08001263 mCurrentToken = 0;
1264 writeRestoreTokens();
1265
Christopher Tated55e18a2009-09-21 10:12:59 -07001266 // Remove all the state files
1267 for (File sf : stateFileDir.listFiles()) {
Christopher Tate4cc86e12009-09-21 19:36:51 -07001268 // ... but don't touch the needs-init sentinel
1269 if (!sf.getName().equals(INIT_SENTINEL_FILE_NAME)) {
1270 sf.delete();
1271 }
Christopher Tated55e18a2009-09-21 10:12:59 -07001272 }
Christopher Tate45597642011-04-04 16:59:21 -07001273 }
Christopher Tated55e18a2009-09-21 10:12:59 -07001274
Christopher Tate45597642011-04-04 16:59:21 -07001275 // Enqueue a new backup of every participant
Christopher Tate8e294d42011-08-31 20:37:12 -07001276 synchronized (mBackupParticipants) {
Christopher Tatea3d55342012-03-27 13:16:18 -07001277 final int N = mBackupParticipants.size();
Christopher Tate8e294d42011-08-31 20:37:12 -07001278 for (int i=0; i<N; i++) {
Christopher Tatea3d55342012-03-27 13:16:18 -07001279 HashSet<String> participants = mBackupParticipants.valueAt(i);
1280 if (participants != null) {
1281 for (String packageName : participants) {
1282 dataChangedImpl(packageName);
1283 }
Christopher Tate8e294d42011-08-31 20:37:12 -07001284 }
Christopher Tated55e18a2009-09-21 10:12:59 -07001285 }
1286 }
1287 }
1288
Christopher Tatedfa47b56e2009-12-22 16:01:32 -08001289 // Add a transport to our set of available backends. If 'transport' is null, this
1290 // is an unregistration, and the transport's entry is removed from our bookkeeping.
Christopher Tate91717492009-06-26 21:07:13 -07001291 private void registerTransport(String name, IBackupTransport transport) {
1292 synchronized (mTransports) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001293 if (DEBUG) Slog.v(TAG, "Registering transport " + name + " = " + transport);
Christopher Tatedfa47b56e2009-12-22 16:01:32 -08001294 if (transport != null) {
1295 mTransports.put(name, transport);
1296 } else {
1297 mTransports.remove(name);
Christopher Tateb0dcaaf2010-01-29 16:27:04 -08001298 if ((mCurrentTransport != null) && mCurrentTransport.equals(name)) {
Christopher Tatedfa47b56e2009-12-22 16:01:32 -08001299 mCurrentTransport = null;
1300 }
1301 // Nothing further to do in the unregistration case
1302 return;
1303 }
Christopher Tate91717492009-06-26 21:07:13 -07001304 }
Christopher Tate4cc86e12009-09-21 19:36:51 -07001305
1306 // If the init sentinel file exists, we need to be sure to perform the init
1307 // as soon as practical. We also create the state directory at registration
1308 // time to ensure it's present from the outset.
1309 try {
1310 String transportName = transport.transportDirName();
1311 File stateDir = new File(mBaseStateDir, transportName);
1312 stateDir.mkdirs();
1313
1314 File initSentinel = new File(stateDir, INIT_SENTINEL_FILE_NAME);
1315 if (initSentinel.exists()) {
1316 synchronized (mQueueLock) {
1317 mPendingInits.add(transportName);
1318
1319 // TODO: pick a better starting time than now + 1 minute
1320 long delay = 1000 * 60; // one minute, in milliseconds
1321 mAlarmManager.set(AlarmManager.RTC_WAKEUP,
1322 System.currentTimeMillis() + delay, mRunInitIntent);
1323 }
1324 }
1325 } catch (RemoteException e) {
1326 // can't happen, the transport is local
1327 }
Christopher Tate91717492009-06-26 21:07:13 -07001328 }
1329
Christopher Tate3799bc22009-05-06 16:13:56 -07001330 // ----- Track installation/removal of packages -----
1331 BroadcastReceiver mBroadcastReceiver = new BroadcastReceiver() {
1332 public void onReceive(Context context, Intent intent) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001333 if (DEBUG) Slog.d(TAG, "Received broadcast " + intent);
Christopher Tate3799bc22009-05-06 16:13:56 -07001334
Christopher Tate3799bc22009-05-06 16:13:56 -07001335 String action = intent.getAction();
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001336 boolean replacing = false;
1337 boolean added = false;
1338 Bundle extras = intent.getExtras();
1339 String pkgList[] = null;
1340 if (Intent.ACTION_PACKAGE_ADDED.equals(action) ||
Christopher Tatea3d55342012-03-27 13:16:18 -07001341 Intent.ACTION_PACKAGE_REMOVED.equals(action)) {
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001342 Uri uri = intent.getData();
1343 if (uri == null) {
1344 return;
1345 }
1346 String pkgName = uri.getSchemeSpecificPart();
1347 if (pkgName != null) {
1348 pkgList = new String[] { pkgName };
1349 }
Christopher Tatea3d55342012-03-27 13:16:18 -07001350 added = Intent.ACTION_PACKAGE_ADDED.equals(action);
1351 replacing = extras.getBoolean(Intent.EXTRA_REPLACING, false);
Suchi Amalapurapub56ae202010-02-04 22:51:07 -08001352 } else if (Intent.ACTION_EXTERNAL_APPLICATIONS_AVAILABLE.equals(action)) {
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001353 added = true;
1354 pkgList = intent.getStringArrayExtra(Intent.EXTRA_CHANGED_PACKAGE_LIST);
Suchi Amalapurapub56ae202010-02-04 22:51:07 -08001355 } else if (Intent.ACTION_EXTERNAL_APPLICATIONS_UNAVAILABLE.equals(action)) {
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001356 added = false;
1357 pkgList = intent.getStringArrayExtra(Intent.EXTRA_CHANGED_PACKAGE_LIST);
1358 }
Christopher Tatecc55f812011-08-16 16:06:53 -07001359
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001360 if (pkgList == null || pkgList.length == 0) {
1361 return;
1362 }
Christopher Tatea3d55342012-03-27 13:16:18 -07001363
1364 final int uid = extras.getInt(Intent.EXTRA_UID);
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001365 if (added) {
Christopher Tate3799bc22009-05-06 16:13:56 -07001366 synchronized (mBackupParticipants) {
Christopher Tate0bacfd22012-01-11 14:41:19 -08001367 if (replacing) {
Christopher Tatea3d55342012-03-27 13:16:18 -07001368 // This is the package-replaced case; we just remove the entry
1369 // under the old uid and fall through to re-add.
1370 removePackageParticipantsLocked(pkgList, uid);
Christopher Tate3799bc22009-05-06 16:13:56 -07001371 }
Christopher Tatea3d55342012-03-27 13:16:18 -07001372 addPackageParticipantsLocked(pkgList);
Christopher Tate3799bc22009-05-06 16:13:56 -07001373 }
Suchi Amalapurapu08675a32010-01-28 09:57:30 -08001374 } else {
1375 if (replacing) {
Christopher Tate3799bc22009-05-06 16:13:56 -07001376 // The package is being updated. We'll receive a PACKAGE_ADDED shortly.
1377 } else {
1378 synchronized (mBackupParticipants) {
Christopher Tatea3d55342012-03-27 13:16:18 -07001379 removePackageParticipantsLocked(pkgList, uid);
Christopher Tate3799bc22009-05-06 16:13:56 -07001380 }
1381 }
1382 }
1383 }
1384 };
1385
Dan Egnor87a02bc2009-06-17 02:30:10 -07001386 // ----- Track connection to GoogleBackupTransport service -----
1387 ServiceConnection mGoogleConnection = new ServiceConnection() {
1388 public void onServiceConnected(ComponentName name, IBinder service) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001389 if (DEBUG) Slog.v(TAG, "Connected to Google transport");
Dan Egnor87a02bc2009-06-17 02:30:10 -07001390 mGoogleTransport = IBackupTransport.Stub.asInterface(service);
Christopher Tate91717492009-06-26 21:07:13 -07001391 registerTransport(name.flattenToShortString(), mGoogleTransport);
Dan Egnor87a02bc2009-06-17 02:30:10 -07001392 }
1393
1394 public void onServiceDisconnected(ComponentName name) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001395 if (DEBUG) Slog.v(TAG, "Disconnected from Google transport");
Dan Egnor87a02bc2009-06-17 02:30:10 -07001396 mGoogleTransport = null;
Christopher Tate91717492009-06-26 21:07:13 -07001397 registerTransport(name.flattenToShortString(), null);
Dan Egnor87a02bc2009-06-17 02:30:10 -07001398 }
1399 };
1400
Christopher Tate0bacfd22012-01-11 14:41:19 -08001401 // Add the backup agents in the given packages to our set of known backup participants.
1402 // If 'packageNames' is null, adds all backup agents in the whole system.
1403 void addPackageParticipantsLocked(String[] packageNames) {
Christopher Tate181fafa2009-05-14 11:12:14 -07001404 // Look for apps that define the android:backupAgent attribute
Dan Egnorefe52642009-06-24 00:16:33 -07001405 List<PackageInfo> targetApps = allAgentPackages();
Christopher Tate0bacfd22012-01-11 14:41:19 -08001406 if (packageNames != null) {
1407 if (DEBUG) Slog.v(TAG, "addPackageParticipantsLocked: #" + packageNames.length);
1408 for (String packageName : packageNames) {
1409 addPackageParticipantsLockedInner(packageName, targetApps);
1410 }
1411 } else {
1412 if (DEBUG) Slog.v(TAG, "addPackageParticipantsLocked: all");
1413 addPackageParticipantsLockedInner(null, targetApps);
1414 }
Christopher Tate3799bc22009-05-06 16:13:56 -07001415 }
1416
Christopher Tate181fafa2009-05-14 11:12:14 -07001417 private void addPackageParticipantsLockedInner(String packageName,
Dan Egnorefe52642009-06-24 00:16:33 -07001418 List<PackageInfo> targetPkgs) {
Christopher Tatec58efa62011-08-01 19:20:14 -07001419 if (MORE_DEBUG) {
Christopher Tate0bacfd22012-01-11 14:41:19 -08001420 Slog.v(TAG, "Examining " + packageName + " for backup agent");
Christopher Tate181fafa2009-05-14 11:12:14 -07001421 }
1422
Dan Egnorefe52642009-06-24 00:16:33 -07001423 for (PackageInfo pkg : targetPkgs) {
1424 if (packageName == null || pkg.packageName.equals(packageName)) {
1425 int uid = pkg.applicationInfo.uid;
Christopher Tatea3d55342012-03-27 13:16:18 -07001426 HashSet<String> set = mBackupParticipants.get(uid);
Christopher Tate3799bc22009-05-06 16:13:56 -07001427 if (set == null) {
Christopher Tatea3d55342012-03-27 13:16:18 -07001428 set = new HashSet<String>();
Christopher Tate3799bc22009-05-06 16:13:56 -07001429 mBackupParticipants.put(uid, set);
1430 }
Christopher Tatea3d55342012-03-27 13:16:18 -07001431 set.add(pkg.packageName);
Christopher Tate0bacfd22012-01-11 14:41:19 -08001432 if (MORE_DEBUG) Slog.v(TAG, "Agent found; added");
Christopher Tate73e02522009-07-15 14:18:26 -07001433
1434 // If we've never seen this app before, schedule a backup for it
1435 if (!mEverStoredApps.contains(pkg.packageName)) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001436 if (DEBUG) Slog.i(TAG, "New app " + pkg.packageName
Christopher Tate73e02522009-07-15 14:18:26 -07001437 + " never backed up; scheduling");
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07001438 dataChangedImpl(pkg.packageName);
Christopher Tate73e02522009-07-15 14:18:26 -07001439 }
Christopher Tate3799bc22009-05-06 16:13:56 -07001440 }
Christopher Tate487529a2009-04-29 14:03:25 -07001441 }
1442 }
1443
Christopher Tate0bacfd22012-01-11 14:41:19 -08001444 // Remove the given packages' entries from our known active set.
Christopher Tatea3d55342012-03-27 13:16:18 -07001445 void removePackageParticipantsLocked(String[] packageNames, int oldUid) {
Christopher Tate0bacfd22012-01-11 14:41:19 -08001446 if (packageNames == null) {
1447 Slog.w(TAG, "removePackageParticipants with null list");
1448 return;
Christopher Tate181fafa2009-05-14 11:12:14 -07001449 }
Christopher Tate0bacfd22012-01-11 14:41:19 -08001450
Christopher Tatea3d55342012-03-27 13:16:18 -07001451 if (DEBUG) Slog.v(TAG, "removePackageParticipantsLocked: uid=" + oldUid
1452 + " #" + packageNames.length);
Christopher Tate0bacfd22012-01-11 14:41:19 -08001453 for (String pkg : packageNames) {
Christopher Tatea3d55342012-03-27 13:16:18 -07001454 // Known previous UID, so we know which package set to check
1455 HashSet<String> set = mBackupParticipants.get(oldUid);
1456 if (set != null && set.contains(pkg)) {
1457 removePackageFromSetLocked(set, pkg);
1458 if (set.isEmpty()) {
1459 if (MORE_DEBUG) Slog.v(TAG, " last one of this uid; purging set");
1460 mBackupParticipants.remove(oldUid);
1461 }
1462 }
Christopher Tate0bacfd22012-01-11 14:41:19 -08001463 }
Christopher Tate3799bc22009-05-06 16:13:56 -07001464 }
1465
Christopher Tatea3d55342012-03-27 13:16:18 -07001466 private void removePackageFromSetLocked(final HashSet<String> set,
1467 final String packageName) {
1468 if (set.contains(packageName)) {
1469 // Found it. Remove this one package from the bookkeeping, and
1470 // if it's the last participating app under this uid we drop the
1471 // (now-empty) set as well.
1472 if (MORE_DEBUG) Slog.v(TAG, " removing participant " + packageName);
1473 removeEverBackedUp(packageName);
1474 set.remove(packageName);
Christopher Tate3799bc22009-05-06 16:13:56 -07001475 }
1476 }
1477
Christopher Tate181fafa2009-05-14 11:12:14 -07001478 // Returns the set of all applications that define an android:backupAgent attribute
Christopher Tate73e02522009-07-15 14:18:26 -07001479 List<PackageInfo> allAgentPackages() {
Christopher Tate6785dd82009-06-18 15:58:25 -07001480 // !!! TODO: cache this and regenerate only when necessary
Dan Egnorefe52642009-06-24 00:16:33 -07001481 int flags = PackageManager.GET_SIGNATURES;
1482 List<PackageInfo> packages = mPackageManager.getInstalledPackages(flags);
1483 int N = packages.size();
1484 for (int a = N-1; a >= 0; a--) {
Christopher Tate0749dcd2009-08-13 15:13:03 -07001485 PackageInfo pkg = packages.get(a);
Christopher Tateb8eb1cb2009-09-16 10:57:21 -07001486 try {
1487 ApplicationInfo app = pkg.applicationInfo;
1488 if (((app.flags&ApplicationInfo.FLAG_ALLOW_BACKUP) == 0)
Christopher Tatea87240c2010-02-12 14:12:34 -08001489 || app.backupAgentName == null) {
Christopher Tateb8eb1cb2009-09-16 10:57:21 -07001490 packages.remove(a);
1491 }
1492 else {
1493 // we will need the shared library path, so look that up and store it here
1494 app = mPackageManager.getApplicationInfo(pkg.packageName,
1495 PackageManager.GET_SHARED_LIBRARY_FILES);
1496 pkg.applicationInfo.sharedLibraryFiles = app.sharedLibraryFiles;
1497 }
1498 } catch (NameNotFoundException e) {
Dan Egnorefe52642009-06-24 00:16:33 -07001499 packages.remove(a);
Christopher Tate181fafa2009-05-14 11:12:14 -07001500 }
1501 }
Dan Egnorefe52642009-06-24 00:16:33 -07001502 return packages;
Christopher Tate181fafa2009-05-14 11:12:14 -07001503 }
Christopher Tateaa088442009-06-16 18:25:46 -07001504
Christopher Tate84725812010-02-04 15:52:40 -08001505 // Called from the backup task: record that the given app has been successfully
Christopher Tate73e02522009-07-15 14:18:26 -07001506 // backed up at least once
1507 void logBackupComplete(String packageName) {
Dan Egnor852f8e42009-09-30 11:20:45 -07001508 if (packageName.equals(PACKAGE_MANAGER_SENTINEL)) return;
1509
1510 synchronized (mEverStoredApps) {
1511 if (!mEverStoredApps.add(packageName)) return;
1512
1513 RandomAccessFile out = null;
1514 try {
1515 out = new RandomAccessFile(mEverStored, "rws");
1516 out.seek(out.length());
1517 out.writeUTF(packageName);
1518 } catch (IOException e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001519 Slog.e(TAG, "Can't log backup of " + packageName + " to " + mEverStored);
Dan Egnor852f8e42009-09-30 11:20:45 -07001520 } finally {
1521 try { if (out != null) out.close(); } catch (IOException e) {}
Christopher Tate73e02522009-07-15 14:18:26 -07001522 }
1523 }
1524 }
1525
Christopher Tatee97e8072009-07-15 16:45:50 -07001526 // Remove our awareness of having ever backed up the given package
1527 void removeEverBackedUp(String packageName) {
Christopher Tatec58efa62011-08-01 19:20:14 -07001528 if (DEBUG) Slog.v(TAG, "Removing backed-up knowledge of " + packageName);
1529 if (MORE_DEBUG) Slog.v(TAG, "New set:");
Christopher Tatee97e8072009-07-15 16:45:50 -07001530
Dan Egnor852f8e42009-09-30 11:20:45 -07001531 synchronized (mEverStoredApps) {
1532 // Rewrite the file and rename to overwrite. If we reboot in the middle,
1533 // we'll recognize on initialization time that the package no longer
1534 // exists and fix it up then.
1535 File tempKnownFile = new File(mBaseStateDir, "processed.new");
1536 RandomAccessFile known = null;
1537 try {
1538 known = new RandomAccessFile(tempKnownFile, "rws");
1539 mEverStoredApps.remove(packageName);
1540 for (String s : mEverStoredApps) {
1541 known.writeUTF(s);
Christopher Tatec58efa62011-08-01 19:20:14 -07001542 if (MORE_DEBUG) Slog.v(TAG, " " + s);
Christopher Tatee97e8072009-07-15 16:45:50 -07001543 }
Dan Egnor852f8e42009-09-30 11:20:45 -07001544 known.close();
1545 known = null;
1546 if (!tempKnownFile.renameTo(mEverStored)) {
1547 throw new IOException("Can't rename " + tempKnownFile + " to " + mEverStored);
1548 }
1549 } catch (IOException e) {
1550 // Bad: we couldn't create the new copy. For safety's sake we
1551 // abandon the whole process and remove all what's-backed-up
1552 // state entirely, meaning we'll force a backup pass for every
1553 // participant on the next boot or [re]install.
Joe Onorato8a9b2202010-02-26 18:56:32 -08001554 Slog.w(TAG, "Error rewriting " + mEverStored, e);
Dan Egnor852f8e42009-09-30 11:20:45 -07001555 mEverStoredApps.clear();
1556 tempKnownFile.delete();
1557 mEverStored.delete();
1558 } finally {
1559 try { if (known != null) known.close(); } catch (IOException e) {}
Christopher Tatee97e8072009-07-15 16:45:50 -07001560 }
1561 }
1562 }
1563
Christopher Tateb49ceb32010-02-08 16:22:24 -08001564 // Persistently record the current and ancestral backup tokens as well
1565 // as the set of packages with data [supposedly] available in the
1566 // ancestral dataset.
Christopher Tate84725812010-02-04 15:52:40 -08001567 void writeRestoreTokens() {
1568 try {
1569 RandomAccessFile af = new RandomAccessFile(mTokenFile, "rwd");
Christopher Tateb49ceb32010-02-08 16:22:24 -08001570
1571 // First, the version number of this record, for futureproofing
1572 af.writeInt(CURRENT_ANCESTRAL_RECORD_VERSION);
1573
1574 // Write the ancestral and current tokens
Christopher Tate84725812010-02-04 15:52:40 -08001575 af.writeLong(mAncestralToken);
1576 af.writeLong(mCurrentToken);
Christopher Tateb49ceb32010-02-08 16:22:24 -08001577
1578 // Now write the set of ancestral packages
1579 if (mAncestralPackages == null) {
1580 af.writeInt(-1);
1581 } else {
1582 af.writeInt(mAncestralPackages.size());
Joe Onorato8a9b2202010-02-26 18:56:32 -08001583 if (DEBUG) Slog.v(TAG, "Ancestral packages: " + mAncestralPackages.size());
Christopher Tateb49ceb32010-02-08 16:22:24 -08001584 for (String pkgName : mAncestralPackages) {
1585 af.writeUTF(pkgName);
Christopher Tatec58efa62011-08-01 19:20:14 -07001586 if (MORE_DEBUG) Slog.v(TAG, " " + pkgName);
Christopher Tateb49ceb32010-02-08 16:22:24 -08001587 }
1588 }
Christopher Tate84725812010-02-04 15:52:40 -08001589 af.close();
1590 } catch (IOException e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001591 Slog.w(TAG, "Unable to write token file:", e);
Christopher Tate84725812010-02-04 15:52:40 -08001592 }
1593 }
1594
Dan Egnor87a02bc2009-06-17 02:30:10 -07001595 // Return the given transport
Christopher Tate91717492009-06-26 21:07:13 -07001596 private IBackupTransport getTransport(String transportName) {
1597 synchronized (mTransports) {
1598 IBackupTransport transport = mTransports.get(transportName);
1599 if (transport == null) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001600 Slog.w(TAG, "Requested unavailable transport: " + transportName);
Christopher Tate91717492009-06-26 21:07:13 -07001601 }
1602 return transport;
Christopher Tate8c850b72009-06-07 19:33:20 -07001603 }
Christopher Tate8c850b72009-06-07 19:33:20 -07001604 }
1605
Christopher Tatedf01dea2009-06-09 20:45:02 -07001606 // fire off a backup agent, blocking until it attaches or times out
1607 IBackupAgent bindToAgentSynchronous(ApplicationInfo app, int mode) {
1608 IBackupAgent agent = null;
1609 synchronized(mAgentConnectLock) {
1610 mConnecting = true;
1611 mConnectedAgent = null;
1612 try {
1613 if (mActivityManager.bindBackupAgent(app, mode)) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001614 Slog.d(TAG, "awaiting agent for " + app);
Christopher Tatedf01dea2009-06-09 20:45:02 -07001615
1616 // success; wait for the agent to arrive
Christopher Tate75a99702011-05-18 16:28:19 -07001617 // only wait 10 seconds for the bind to happen
Christopher Tatec7b31e32009-06-10 15:49:30 -07001618 long timeoutMark = System.currentTimeMillis() + TIMEOUT_INTERVAL;
1619 while (mConnecting && mConnectedAgent == null
1620 && (System.currentTimeMillis() < timeoutMark)) {
Christopher Tatedf01dea2009-06-09 20:45:02 -07001621 try {
Christopher Tatec7b31e32009-06-10 15:49:30 -07001622 mAgentConnectLock.wait(5000);
Christopher Tatedf01dea2009-06-09 20:45:02 -07001623 } catch (InterruptedException e) {
Christopher Tatec7b31e32009-06-10 15:49:30 -07001624 // just bail
Christopher Tate6de74ff2012-01-17 15:20:32 -08001625 if (DEBUG) Slog.w(TAG, "Interrupted: " + e);
Christopher Tatedf01dea2009-06-09 20:45:02 -07001626 return null;
1627 }
1628 }
1629
1630 // if we timed out with no connect, abort and move on
1631 if (mConnecting == true) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001632 Slog.w(TAG, "Timeout waiting for agent " + app);
Christopher Tatedf01dea2009-06-09 20:45:02 -07001633 return null;
1634 }
Christopher Tate6de74ff2012-01-17 15:20:32 -08001635 if (DEBUG) Slog.i(TAG, "got agent " + mConnectedAgent);
Christopher Tatedf01dea2009-06-09 20:45:02 -07001636 agent = mConnectedAgent;
1637 }
1638 } catch (RemoteException e) {
1639 // can't happen
1640 }
1641 }
1642 return agent;
1643 }
1644
Christopher Tatec7b31e32009-06-10 15:49:30 -07001645 // clear an application's data, blocking until the operation completes or times out
1646 void clearApplicationDataSynchronous(String packageName) {
Christopher Tatef7c886b2009-06-26 15:34:09 -07001647 // Don't wipe packages marked allowClearUserData=false
1648 try {
1649 PackageInfo info = mPackageManager.getPackageInfo(packageName, 0);
1650 if ((info.applicationInfo.flags & ApplicationInfo.FLAG_ALLOW_CLEAR_USER_DATA) == 0) {
Christopher Tatec58efa62011-08-01 19:20:14 -07001651 if (MORE_DEBUG) Slog.i(TAG, "allowClearUserData=false so not wiping "
Christopher Tatef7c886b2009-06-26 15:34:09 -07001652 + packageName);
1653 return;
1654 }
1655 } catch (NameNotFoundException e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001656 Slog.w(TAG, "Tried to clear data for " + packageName + " but not found");
Christopher Tatef7c886b2009-06-26 15:34:09 -07001657 return;
1658 }
1659
Christopher Tatec7b31e32009-06-10 15:49:30 -07001660 ClearDataObserver observer = new ClearDataObserver();
1661
1662 synchronized(mClearDataLock) {
1663 mClearingData = true;
Christopher Tate9dfdac52009-08-06 14:57:53 -07001664 try {
Amith Yamasani742a6712011-05-04 14:49:28 -07001665 mActivityManager.clearApplicationUserData(packageName, observer,
1666 Binder.getOrigCallingUser());
Christopher Tate9dfdac52009-08-06 14:57:53 -07001667 } catch (RemoteException e) {
1668 // can't happen because the activity manager is in this process
1669 }
Christopher Tatec7b31e32009-06-10 15:49:30 -07001670
1671 // only wait 10 seconds for the clear data to happen
1672 long timeoutMark = System.currentTimeMillis() + TIMEOUT_INTERVAL;
1673 while (mClearingData && (System.currentTimeMillis() < timeoutMark)) {
1674 try {
1675 mClearDataLock.wait(5000);
1676 } catch (InterruptedException e) {
1677 // won't happen, but still.
1678 mClearingData = false;
1679 }
1680 }
1681 }
1682 }
1683
1684 class ClearDataObserver extends IPackageDataObserver.Stub {
Dan Egnor852f8e42009-09-30 11:20:45 -07001685 public void onRemoveCompleted(String packageName, boolean succeeded) {
Christopher Tatec7b31e32009-06-10 15:49:30 -07001686 synchronized(mClearDataLock) {
1687 mClearingData = false;
Christopher Tatef68eb502009-06-16 11:02:01 -07001688 mClearDataLock.notifyAll();
Christopher Tatec7b31e32009-06-10 15:49:30 -07001689 }
1690 }
1691 }
1692
Christopher Tate1bb69062010-02-19 17:02:12 -08001693 // Get the restore-set token for the best-available restore set for this package:
1694 // the active set if possible, else the ancestral one. Returns zero if none available.
1695 long getAvailableRestoreToken(String packageName) {
1696 long token = mAncestralToken;
1697 synchronized (mQueueLock) {
1698 if (mEverStoredApps.contains(packageName)) {
1699 token = mCurrentToken;
1700 }
1701 }
1702 return token;
1703 }
1704
Christopher Tate44a27902010-01-27 17:15:49 -08001705 // -----
Christopher Tate8e294d42011-08-31 20:37:12 -07001706 // Interface and methods used by the asynchronous-with-timeout backup/restore operations
1707
1708 interface BackupRestoreTask {
1709 // Execute one tick of whatever state machine the task implements
1710 void execute();
1711
1712 // An operation that wanted a callback has completed
1713 void operationComplete();
1714
1715 // An operation that wanted a callback has timed out
1716 void handleTimeout();
1717 }
1718
1719 void prepareOperationTimeout(int token, long interval, BackupRestoreTask callback) {
1720 if (MORE_DEBUG) Slog.v(TAG, "starting timeout: token=" + Integer.toHexString(token)
1721 + " interval=" + interval);
Christopher Tate44a27902010-01-27 17:15:49 -08001722 synchronized (mCurrentOpLock) {
Christopher Tate8e294d42011-08-31 20:37:12 -07001723 mCurrentOperations.put(token, new Operation(OP_PENDING, callback));
1724
1725 Message msg = mBackupHandler.obtainMessage(MSG_TIMEOUT, token, 0, callback);
1726 mBackupHandler.sendMessageDelayed(msg, interval);
1727 }
1728 }
1729
1730 // synchronous waiter case
1731 boolean waitUntilOperationComplete(int token) {
1732 if (MORE_DEBUG) Slog.i(TAG, "Blocking until operation complete for "
1733 + Integer.toHexString(token));
1734 int finalState = OP_PENDING;
1735 Operation op = null;
1736 synchronized (mCurrentOpLock) {
1737 while (true) {
1738 op = mCurrentOperations.get(token);
1739 if (op == null) {
1740 // mysterious disappearance: treat as success with no callback
1741 break;
1742 } else {
1743 if (op.state == OP_PENDING) {
1744 try {
1745 mCurrentOpLock.wait();
1746 } catch (InterruptedException e) {}
1747 // When the wait is notified we loop around and recheck the current state
1748 } else {
1749 // No longer pending; we're done
1750 finalState = op.state;
1751 break;
1752 }
Christopher Tate44a27902010-01-27 17:15:49 -08001753 }
Christopher Tate44a27902010-01-27 17:15:49 -08001754 }
1755 }
Christopher Tate8e294d42011-08-31 20:37:12 -07001756
Christopher Tate44a27902010-01-27 17:15:49 -08001757 mBackupHandler.removeMessages(MSG_TIMEOUT);
Christopher Tatec58efa62011-08-01 19:20:14 -07001758 if (MORE_DEBUG) Slog.v(TAG, "operation " + Integer.toHexString(token)
Christopher Tate1bb69062010-02-19 17:02:12 -08001759 + " complete: finalState=" + finalState);
Christopher Tate44a27902010-01-27 17:15:49 -08001760 return finalState == OP_ACKNOWLEDGED;
1761 }
1762
Christopher Tate8e294d42011-08-31 20:37:12 -07001763 void handleTimeout(int token, Object obj) {
1764 // Notify any synchronous waiters
1765 Operation op = null;
Christopher Tate4a627c72011-04-01 14:43:32 -07001766 synchronized (mCurrentOpLock) {
Christopher Tate8e294d42011-08-31 20:37:12 -07001767 op = mCurrentOperations.get(token);
1768 if (MORE_DEBUG) {
1769 if (op == null) Slog.w(TAG, "Timeout of token " + Integer.toHexString(token)
1770 + " but no op found");
1771 }
1772 int state = (op != null) ? op.state : OP_TIMEOUT;
1773 if (state == OP_PENDING) {
1774 if (DEBUG) Slog.v(TAG, "TIMEOUT: token=" + Integer.toHexString(token));
1775 op.state = OP_TIMEOUT;
1776 mCurrentOperations.put(token, op);
1777 }
1778 mCurrentOpLock.notifyAll();
1779 }
1780
1781 // If there's a TimeoutHandler for this event, call it
1782 if (op != null && op.callback != null) {
1783 op.callback.handleTimeout();
Christopher Tate4a627c72011-04-01 14:43:32 -07001784 }
Christopher Tate44a27902010-01-27 17:15:49 -08001785 }
1786
Christopher Tate043dadc2009-06-02 16:11:00 -07001787 // ----- Back up a set of applications via a worker thread -----
1788
Christopher Tate8e294d42011-08-31 20:37:12 -07001789 enum BackupState {
1790 INITIAL,
1791 RUNNING_QUEUE,
1792 FINAL
1793 }
1794
1795 class PerformBackupTask implements BackupRestoreTask {
1796 private static final String TAG = "PerformBackupTask";
1797
Christopher Tateaa088442009-06-16 18:25:46 -07001798 IBackupTransport mTransport;
Christopher Tate043dadc2009-06-02 16:11:00 -07001799 ArrayList<BackupRequest> mQueue;
Christopher Tate8e294d42011-08-31 20:37:12 -07001800 ArrayList<BackupRequest> mOriginalQueue;
Christopher Tate5cb400b2009-06-25 16:03:14 -07001801 File mStateDir;
Christopher Tatecde87f42009-06-12 12:55:53 -07001802 File mJournal;
Christopher Tate8e294d42011-08-31 20:37:12 -07001803 BackupState mCurrentState;
1804
1805 // carried information about the current in-flight operation
1806 PackageInfo mCurrentPackage;
1807 File mSavedStateName;
1808 File mBackupDataName;
1809 File mNewStateName;
1810 ParcelFileDescriptor mSavedState;
1811 ParcelFileDescriptor mBackupData;
1812 ParcelFileDescriptor mNewState;
1813 int mStatus;
1814 boolean mFinished;
Christopher Tate043dadc2009-06-02 16:11:00 -07001815
Christopher Tate44a27902010-01-27 17:15:49 -08001816 public PerformBackupTask(IBackupTransport transport, ArrayList<BackupRequest> queue,
Christopher Tatecde87f42009-06-12 12:55:53 -07001817 File journal) {
Christopher Tateaa088442009-06-16 18:25:46 -07001818 mTransport = transport;
Christopher Tate8e294d42011-08-31 20:37:12 -07001819 mOriginalQueue = queue;
Christopher Tatecde87f42009-06-12 12:55:53 -07001820 mJournal = journal;
Christopher Tate5cb400b2009-06-25 16:03:14 -07001821
1822 try {
1823 mStateDir = new File(mBaseStateDir, transport.transportDirName());
1824 } catch (RemoteException e) {
1825 // can't happen; the transport is local
1826 }
Christopher Tate8e294d42011-08-31 20:37:12 -07001827
1828 mCurrentState = BackupState.INITIAL;
1829 mFinished = false;
Christopher Tate6de74ff2012-01-17 15:20:32 -08001830
1831 addBackupTrace("STATE => INITIAL");
Christopher Tate043dadc2009-06-02 16:11:00 -07001832 }
1833
Christopher Tate8e294d42011-08-31 20:37:12 -07001834 // Main entry point: perform one chunk of work, updating the state as appropriate
1835 // and reposting the next chunk to the primary backup handler thread.
1836 @Override
1837 public void execute() {
1838 switch (mCurrentState) {
1839 case INITIAL:
1840 beginBackup();
1841 break;
1842
1843 case RUNNING_QUEUE:
1844 invokeNextAgent();
1845 break;
1846
1847 case FINAL:
1848 if (!mFinished) finalizeBackup();
1849 else {
1850 Slog.e(TAG, "Duplicate finish");
1851 }
Christopher Tate2982d062011-09-06 20:35:24 -07001852 mFinished = true;
Christopher Tate8e294d42011-08-31 20:37:12 -07001853 break;
1854 }
1855 }
1856
1857 // We're starting a backup pass. Initialize the transport and send
1858 // the PM metadata blob if we haven't already.
1859 void beginBackup() {
Christopher Tate6de74ff2012-01-17 15:20:32 -08001860 if (DEBUG_BACKUP_TRACE) {
1861 clearBackupTrace();
1862 StringBuilder b = new StringBuilder(256);
1863 b.append("beginBackup: [");
1864 for (BackupRequest req : mOriginalQueue) {
1865 b.append(' ');
1866 b.append(req.packageName);
1867 }
1868 b.append(" ]");
1869 addBackupTrace(b.toString());
1870 }
1871
Christopher Tate8e294d42011-08-31 20:37:12 -07001872 mStatus = BackupConstants.TRANSPORT_OK;
1873
1874 // Sanity check: if the queue is empty we have no work to do.
1875 if (mOriginalQueue.isEmpty()) {
1876 Slog.w(TAG, "Backup begun with an empty queue - nothing to do.");
Christopher Tate6de74ff2012-01-17 15:20:32 -08001877 addBackupTrace("queue empty at begin");
1878 executeNextState(BackupState.FINAL);
Christopher Tate8e294d42011-08-31 20:37:12 -07001879 return;
1880 }
1881
1882 // We need to retain the original queue contents in case of transport
1883 // failure, but we want a working copy that we can manipulate along
1884 // the way.
1885 mQueue = (ArrayList<BackupRequest>) mOriginalQueue.clone();
1886
Joe Onorato8a9b2202010-02-26 18:56:32 -08001887 if (DEBUG) Slog.v(TAG, "Beginning backup of " + mQueue.size() + " targets");
Christopher Tate043dadc2009-06-02 16:11:00 -07001888
Christopher Tate8e294d42011-08-31 20:37:12 -07001889 File pmState = new File(mStateDir, PACKAGE_MANAGER_SENTINEL);
Christopher Tate043dadc2009-06-02 16:11:00 -07001890 try {
Christopher Tate6de74ff2012-01-17 15:20:32 -08001891 final String transportName = mTransport.transportDirName();
1892 EventLog.writeEvent(EventLogTags.BACKUP_START, transportName);
Dan Egnor01445162009-09-21 17:04:05 -07001893
Dan Egnor852f8e42009-09-30 11:20:45 -07001894 // If we haven't stored package manager metadata yet, we must init the transport.
Christopher Tate8e294d42011-08-31 20:37:12 -07001895 if (mStatus == BackupConstants.TRANSPORT_OK && pmState.length() <= 0) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001896 Slog.i(TAG, "Initializing (wiping) backup state and transport storage");
Christopher Tate6de74ff2012-01-17 15:20:32 -08001897 addBackupTrace("initializing transport " + transportName);
Dan Egnor852f8e42009-09-30 11:20:45 -07001898 resetBackupState(mStateDir); // Just to make sure.
Christopher Tate8e294d42011-08-31 20:37:12 -07001899 mStatus = mTransport.initializeDevice();
Christopher Tate6de74ff2012-01-17 15:20:32 -08001900
1901 addBackupTrace("transport.initializeDevice() == " + mStatus);
Christopher Tate8e294d42011-08-31 20:37:12 -07001902 if (mStatus == BackupConstants.TRANSPORT_OK) {
Doug Zongkerab5c49c2009-12-04 10:31:43 -08001903 EventLog.writeEvent(EventLogTags.BACKUP_INITIALIZE);
Dan Egnor726247c2009-09-29 19:12:31 -07001904 } else {
Doug Zongkerab5c49c2009-12-04 10:31:43 -08001905 EventLog.writeEvent(EventLogTags.BACKUP_TRANSPORT_FAILURE, "(initialize)");
Joe Onorato8a9b2202010-02-26 18:56:32 -08001906 Slog.e(TAG, "Transport error in initializeDevice()");
Dan Egnor726247c2009-09-29 19:12:31 -07001907 }
Dan Egnor01445162009-09-21 17:04:05 -07001908 }
Dan Egnorbb9001c2009-07-27 12:20:13 -07001909
1910 // The package manager doesn't have a proper <application> etc, but since
1911 // it's running here in the system process we can just set up its agent
1912 // directly and use a synthetic BackupRequest. We always run this pass
1913 // because it's cheap and this way we guarantee that we don't get out of
1914 // step even if we're selecting among various transports at run time.
Christopher Tate8e294d42011-08-31 20:37:12 -07001915 if (mStatus == BackupConstants.TRANSPORT_OK) {
Dan Egnor01445162009-09-21 17:04:05 -07001916 PackageManagerBackupAgent pmAgent = new PackageManagerBackupAgent(
1917 mPackageManager, allAgentPackages());
Christopher Tate8e294d42011-08-31 20:37:12 -07001918 mStatus = invokeAgentForBackup(PACKAGE_MANAGER_SENTINEL,
Dan Egnor01445162009-09-21 17:04:05 -07001919 IBackupAgent.Stub.asInterface(pmAgent.onBind()), mTransport);
Christopher Tate6de74ff2012-01-17 15:20:32 -08001920 addBackupTrace("PMBA invoke: " + mStatus);
Dan Egnor01445162009-09-21 17:04:05 -07001921 }
Christopher Tate90967f42009-09-20 15:28:33 -07001922
Christopher Tate8e294d42011-08-31 20:37:12 -07001923 if (mStatus == BackupConstants.TRANSPORT_NOT_INITIALIZED) {
1924 // The backend reports that our dataset has been wiped. Note this in
1925 // the event log; the no-success code below will reset the backup
1926 // state as well.
Doug Zongkerab5c49c2009-12-04 10:31:43 -08001927 EventLog.writeEvent(EventLogTags.BACKUP_RESET, mTransport.transportDirName());
Dan Egnorbb9001c2009-07-27 12:20:13 -07001928 }
1929 } catch (Exception e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08001930 Slog.e(TAG, "Error in backup thread", e);
Christopher Tate6de74ff2012-01-17 15:20:32 -08001931 addBackupTrace("Exception in backup thread: " + e);
Christopher Tate8e294d42011-08-31 20:37:12 -07001932 mStatus = BackupConstants.TRANSPORT_ERROR;
Dan Egnorbb9001c2009-07-27 12:20:13 -07001933 } finally {
Christopher Tate8e294d42011-08-31 20:37:12 -07001934 // If we've succeeded so far, invokeAgentForBackup() will have run the PM
1935 // metadata and its completion/timeout callback will continue the state
1936 // machine chain. If it failed that won't happen; we handle that now.
Christopher Tate6de74ff2012-01-17 15:20:32 -08001937 addBackupTrace("exiting prelim: " + mStatus);
Christopher Tate8e294d42011-08-31 20:37:12 -07001938 if (mStatus != BackupConstants.TRANSPORT_OK) {
1939 // if things went wrong at this point, we need to
1940 // restage everything and try again later.
1941 resetBackupState(mStateDir); // Just to make sure.
1942 executeNextState(BackupState.FINAL);
Christopher Tate84725812010-02-04 15:52:40 -08001943 }
Christopher Tatecde87f42009-06-12 12:55:53 -07001944 }
Christopher Tate043dadc2009-06-02 16:11:00 -07001945 }
1946
Christopher Tate8e294d42011-08-31 20:37:12 -07001947 // Transport has been initialized and the PM metadata submitted successfully
1948 // if that was warranted. Now we process the single next thing in the queue.
1949 void invokeNextAgent() {
1950 mStatus = BackupConstants.TRANSPORT_OK;
Christopher Tate6de74ff2012-01-17 15:20:32 -08001951 addBackupTrace("invoke q=" + mQueue.size());
Christopher Tate043dadc2009-06-02 16:11:00 -07001952
Christopher Tate8e294d42011-08-31 20:37:12 -07001953 // Sanity check that we have work to do. If not, skip to the end where
1954 // we reestablish the wakelock invariants etc.
1955 if (mQueue.isEmpty()) {
Christopher Tate6de74ff2012-01-17 15:20:32 -08001956 if (DEBUG) Slog.i(TAG, "queue now empty");
Christopher Tate8e294d42011-08-31 20:37:12 -07001957 executeNextState(BackupState.FINAL);
1958 return;
1959 }
1960
1961 // pop the entry we're going to process on this step
1962 BackupRequest request = mQueue.get(0);
1963 mQueue.remove(0);
1964
1965 Slog.d(TAG, "starting agent for backup of " + request);
Christopher Tate6de74ff2012-01-17 15:20:32 -08001966 addBackupTrace("launch agent for " + request.packageName);
Christopher Tate8e294d42011-08-31 20:37:12 -07001967
1968 // Verify that the requested app exists; it might be something that
1969 // requested a backup but was then uninstalled. The request was
1970 // journalled and rather than tamper with the journal it's safer
1971 // to sanity-check here. This also gives us the classname of the
1972 // package's backup agent.
1973 try {
1974 mCurrentPackage = mPackageManager.getPackageInfo(request.packageName,
1975 PackageManager.GET_SIGNATURES);
Christopher Tate9c2efb32012-03-23 13:00:05 -07001976 if (mCurrentPackage.applicationInfo.backupAgentName == null) {
1977 // The manifest has changed but we had a stale backup request pending.
1978 // This won't happen again because the app won't be requesting further
1979 // backups.
1980 Slog.i(TAG, "Package " + request.packageName
1981 + " no longer supports backup; skipping");
1982 addBackupTrace("skipping - no agent, completion is noop");
1983 executeNextState(BackupState.RUNNING_QUEUE);
1984 return;
1985 }
Christopher Tatec28083a2010-12-14 16:16:44 -08001986
Christopher Tate043dadc2009-06-02 16:11:00 -07001987 IBackupAgent agent = null;
Christopher Tate043dadc2009-06-02 16:11:00 -07001988 try {
Christopher Tate8e294d42011-08-31 20:37:12 -07001989 mWakelock.setWorkSource(new WorkSource(mCurrentPackage.applicationInfo.uid));
1990 agent = bindToAgentSynchronous(mCurrentPackage.applicationInfo,
Christopher Tate4a627c72011-04-01 14:43:32 -07001991 IApplicationThread.BACKUP_MODE_INCREMENTAL);
Christopher Tate6de74ff2012-01-17 15:20:32 -08001992 addBackupTrace("agent bound; a? = " + (agent != null));
Christopher Tatedf01dea2009-06-09 20:45:02 -07001993 if (agent != null) {
Christopher Tate8e294d42011-08-31 20:37:12 -07001994 mStatus = invokeAgentForBackup(request.packageName, agent, mTransport);
1995 // at this point we'll either get a completion callback from the
1996 // agent, or a timeout message on the main handler. either way, we're
1997 // done here as long as we're successful so far.
1998 } else {
1999 // Timeout waiting for the agent
2000 mStatus = BackupConstants.AGENT_ERROR;
Christopher Tate043dadc2009-06-02 16:11:00 -07002001 }
Christopher Tate043dadc2009-06-02 16:11:00 -07002002 } catch (SecurityException ex) {
2003 // Try for the next one.
Joe Onorato8a9b2202010-02-26 18:56:32 -08002004 Slog.d(TAG, "error in bind/backup", ex);
Christopher Tate8e294d42011-08-31 20:37:12 -07002005 mStatus = BackupConstants.AGENT_ERROR;
Christopher Tate6de74ff2012-01-17 15:20:32 -08002006 addBackupTrace("agent SE");
Christopher Tate8e294d42011-08-31 20:37:12 -07002007 }
2008 } catch (NameNotFoundException e) {
2009 Slog.d(TAG, "Package does not exist; skipping");
Christopher Tate6de74ff2012-01-17 15:20:32 -08002010 addBackupTrace("no such package");
2011 mStatus = BackupConstants.AGENT_UNKNOWN;
Christopher Tate8e294d42011-08-31 20:37:12 -07002012 } finally {
2013 mWakelock.setWorkSource(null);
2014
2015 // If there was an agent error, no timeout/completion handling will occur.
Christopher Tate6de74ff2012-01-17 15:20:32 -08002016 // That means we need to direct to the next state ourselves.
Christopher Tate8e294d42011-08-31 20:37:12 -07002017 if (mStatus != BackupConstants.TRANSPORT_OK) {
2018 BackupState nextState = BackupState.RUNNING_QUEUE;
2019
2020 // An agent-level failure means we reenqueue this one agent for
2021 // a later retry, but otherwise proceed normally.
2022 if (mStatus == BackupConstants.AGENT_ERROR) {
2023 if (MORE_DEBUG) Slog.i(TAG, "Agent failure for " + request.packageName
2024 + " - restaging");
2025 dataChangedImpl(request.packageName);
2026 mStatus = BackupConstants.TRANSPORT_OK;
2027 if (mQueue.isEmpty()) nextState = BackupState.FINAL;
Christopher Tate6de74ff2012-01-17 15:20:32 -08002028 } else if (mStatus == BackupConstants.AGENT_UNKNOWN) {
2029 // Failed lookup of the app, so we couldn't bring up an agent, but
2030 // we're otherwise fine. Just drop it and go on to the next as usual.
2031 mStatus = BackupConstants.TRANSPORT_OK;
2032 } else {
Christopher Tate8e294d42011-08-31 20:37:12 -07002033 // Transport-level failure means we reenqueue everything
2034 revertAndEndBackup();
2035 nextState = BackupState.FINAL;
2036 }
2037
2038 executeNextState(nextState);
Christopher Tate6de74ff2012-01-17 15:20:32 -08002039 } else {
2040 addBackupTrace("expecting completion/timeout callback");
Christopher Tate043dadc2009-06-02 16:11:00 -07002041 }
2042 }
2043 }
Christopher Tatec7b31e32009-06-10 15:49:30 -07002044
Christopher Tate8e294d42011-08-31 20:37:12 -07002045 void finalizeBackup() {
Christopher Tate6de74ff2012-01-17 15:20:32 -08002046 addBackupTrace("finishing");
2047
Christopher Tate8e294d42011-08-31 20:37:12 -07002048 // Either backup was successful, in which case we of course do not need
2049 // this pass's journal any more; or it failed, in which case we just
2050 // re-enqueued all of these packages in the current active journal.
2051 // Either way, we no longer need this pass's journal.
2052 if (mJournal != null && !mJournal.delete()) {
2053 Slog.e(TAG, "Unable to remove backup journal file " + mJournal);
2054 }
2055
2056 // If everything actually went through and this is the first time we've
2057 // done a backup, we can now record what the current backup dataset token
2058 // is.
2059 if ((mCurrentToken == 0) && (mStatus == BackupConstants.TRANSPORT_OK)) {
Christopher Tate6de74ff2012-01-17 15:20:32 -08002060 addBackupTrace("success; recording token");
Christopher Tate8e294d42011-08-31 20:37:12 -07002061 try {
2062 mCurrentToken = mTransport.getCurrentRestoreSet();
2063 } catch (RemoteException e) {} // can't happen
2064 writeRestoreTokens();
2065 }
2066
Christopher Tate336a6492011-10-05 16:05:43 -07002067 // Set up the next backup pass - at this point we can set mBackupRunning
2068 // to false to allow another pass to fire, because we're done with the
2069 // state machine sequence and the wakelock is refcounted.
2070 synchronized (mQueueLock) {
2071 mBackupRunning = false;
2072 if (mStatus == BackupConstants.TRANSPORT_NOT_INITIALIZED) {
Christopher Tatee659fb92011-10-10 16:34:50 -07002073 // Make sure we back up everything and perform the one-time init
2074 clearMetadata();
2075 if (DEBUG) Slog.d(TAG, "Server requires init; rerunning");
Christopher Tate6de74ff2012-01-17 15:20:32 -08002076 addBackupTrace("init required; rerunning");
Christopher Tate336a6492011-10-05 16:05:43 -07002077 backupNow();
2078 }
Christopher Tate8e294d42011-08-31 20:37:12 -07002079 }
2080
2081 // Only once we're entirely finished do we release the wakelock
Christopher Tate6de74ff2012-01-17 15:20:32 -08002082 clearBackupTrace();
Christopher Tate8e294d42011-08-31 20:37:12 -07002083 Slog.i(TAG, "Backup pass finished.");
2084 mWakelock.release();
2085 }
2086
Christopher Tatee659fb92011-10-10 16:34:50 -07002087 // Remove the PM metadata state. This will generate an init on the next pass.
2088 void clearMetadata() {
2089 final File pmState = new File(mStateDir, PACKAGE_MANAGER_SENTINEL);
2090 if (pmState.exists()) pmState.delete();
2091 }
2092
Christopher Tate8e294d42011-08-31 20:37:12 -07002093 // Invoke an agent's doBackup() and start a timeout message spinning on the main
2094 // handler in case it doesn't get back to us.
2095 int invokeAgentForBackup(String packageName, IBackupAgent agent,
Dan Egnor01445162009-09-21 17:04:05 -07002096 IBackupTransport transport) {
Christopher Tate6de74ff2012-01-17 15:20:32 -08002097 if (DEBUG) Slog.d(TAG, "invokeAgentForBackup on " + packageName);
2098 addBackupTrace("invoking " + packageName);
Christopher Tatec7b31e32009-06-10 15:49:30 -07002099
Christopher Tate8e294d42011-08-31 20:37:12 -07002100 mSavedStateName = new File(mStateDir, packageName);
2101 mBackupDataName = new File(mDataDir, packageName + ".data");
2102 mNewStateName = new File(mStateDir, packageName + ".new");
Dan Egnorbb9001c2009-07-27 12:20:13 -07002103
Christopher Tate8e294d42011-08-31 20:37:12 -07002104 mSavedState = null;
2105 mBackupData = null;
2106 mNewState = null;
Dan Egnorbb9001c2009-07-27 12:20:13 -07002107
Christopher Tate4a627c72011-04-01 14:43:32 -07002108 final int token = generateToken();
Christopher Tatec7b31e32009-06-10 15:49:30 -07002109 try {
2110 // Look up the package info & signatures. This is first so that if it
2111 // throws an exception, there's no file setup yet that would need to
2112 // be unraveled.
Christopher Tateabce4e82009-06-18 18:35:32 -07002113 if (packageName.equals(PACKAGE_MANAGER_SENTINEL)) {
Christopher Tate8e294d42011-08-31 20:37:12 -07002114 // The metadata 'package' is synthetic; construct one and make
2115 // sure our global state is pointed at it
2116 mCurrentPackage = new PackageInfo();
2117 mCurrentPackage.packageName = packageName;
Christopher Tateabce4e82009-06-18 18:35:32 -07002118 }
Christopher Tatec7b31e32009-06-10 15:49:30 -07002119
Christopher Tatec7b31e32009-06-10 15:49:30 -07002120 // In a full backup, we pass a null ParcelFileDescriptor as
Christopher Tate4a627c72011-04-01 14:43:32 -07002121 // the saved-state "file". This is by definition an incremental,
2122 // so we build a saved state file to pass.
Christopher Tate8e294d42011-08-31 20:37:12 -07002123 mSavedState = ParcelFileDescriptor.open(mSavedStateName,
Christopher Tate4a627c72011-04-01 14:43:32 -07002124 ParcelFileDescriptor.MODE_READ_ONLY |
2125 ParcelFileDescriptor.MODE_CREATE); // Make an empty file if necessary
Christopher Tatec7b31e32009-06-10 15:49:30 -07002126
Christopher Tate8e294d42011-08-31 20:37:12 -07002127 mBackupData = ParcelFileDescriptor.open(mBackupDataName,
Dan Egnorbb9001c2009-07-27 12:20:13 -07002128 ParcelFileDescriptor.MODE_READ_WRITE |
2129 ParcelFileDescriptor.MODE_CREATE |
2130 ParcelFileDescriptor.MODE_TRUNCATE);
Christopher Tatec7b31e32009-06-10 15:49:30 -07002131
Christopher Tate8e294d42011-08-31 20:37:12 -07002132 mNewState = ParcelFileDescriptor.open(mNewStateName,
Dan Egnorbb9001c2009-07-27 12:20:13 -07002133 ParcelFileDescriptor.MODE_READ_WRITE |
2134 ParcelFileDescriptor.MODE_CREATE |
2135 ParcelFileDescriptor.MODE_TRUNCATE);
Christopher Tatec7b31e32009-06-10 15:49:30 -07002136
Christopher Tate44a27902010-01-27 17:15:49 -08002137 // Initiate the target's backup pass
Christopher Tate6de74ff2012-01-17 15:20:32 -08002138 addBackupTrace("setting timeout");
Christopher Tate8e294d42011-08-31 20:37:12 -07002139 prepareOperationTimeout(token, TIMEOUT_BACKUP_INTERVAL, this);
Christopher Tate6de74ff2012-01-17 15:20:32 -08002140 addBackupTrace("calling agent doBackup()");
Christopher Tate8e294d42011-08-31 20:37:12 -07002141 agent.doBackup(mSavedState, mBackupData, mNewState, token, mBackupManagerBinder);
Christopher Tatec7b31e32009-06-10 15:49:30 -07002142 } catch (Exception e) {
Christopher Tate8e294d42011-08-31 20:37:12 -07002143 Slog.e(TAG, "Error invoking for backup on " + packageName);
Christopher Tate6de74ff2012-01-17 15:20:32 -08002144 addBackupTrace("exception: " + e);
Christopher Tate8e294d42011-08-31 20:37:12 -07002145 EventLog.writeEvent(EventLogTags.BACKUP_AGENT_FAILURE, packageName,
2146 e.toString());
2147 agentErrorCleanup();
2148 return BackupConstants.AGENT_ERROR;
Dan Egnorbb9001c2009-07-27 12:20:13 -07002149 }
2150
Christopher Tate8e294d42011-08-31 20:37:12 -07002151 // At this point the agent is off and running. The next thing to happen will
2152 // either be a callback from the agent, at which point we'll process its data
2153 // for transport, or a timeout. Either way the next phase will happen in
2154 // response to the TimeoutHandler interface callbacks.
Christopher Tate6de74ff2012-01-17 15:20:32 -08002155 addBackupTrace("invoke success");
Christopher Tate8e294d42011-08-31 20:37:12 -07002156 return BackupConstants.TRANSPORT_OK;
2157 }
2158
2159 @Override
2160 public void operationComplete() {
2161 // Okay, the agent successfully reported back to us. Spin the data off to the
2162 // transport and proceed with the next stage.
2163 if (MORE_DEBUG) Slog.v(TAG, "operationComplete(): sending data to transport for "
2164 + mCurrentPackage.packageName);
2165 mBackupHandler.removeMessages(MSG_TIMEOUT);
2166 clearAgentState();
Christopher Tate6de74ff2012-01-17 15:20:32 -08002167 addBackupTrace("operation complete");
Christopher Tate8e294d42011-08-31 20:37:12 -07002168
2169 ParcelFileDescriptor backupData = null;
2170 mStatus = BackupConstants.TRANSPORT_OK;
Dan Egnorbb9001c2009-07-27 12:20:13 -07002171 try {
Christopher Tate8e294d42011-08-31 20:37:12 -07002172 int size = (int) mBackupDataName.length();
Dan Egnorbb9001c2009-07-27 12:20:13 -07002173 if (size > 0) {
Christopher Tate8e294d42011-08-31 20:37:12 -07002174 if (mStatus == BackupConstants.TRANSPORT_OK) {
2175 backupData = ParcelFileDescriptor.open(mBackupDataName,
Dan Egnor01445162009-09-21 17:04:05 -07002176 ParcelFileDescriptor.MODE_READ_ONLY);
Christopher Tate6de74ff2012-01-17 15:20:32 -08002177 addBackupTrace("sending data to transport");
Christopher Tate8e294d42011-08-31 20:37:12 -07002178 mStatus = mTransport.performBackup(mCurrentPackage, backupData);
Dan Egnor01445162009-09-21 17:04:05 -07002179 }
Dan Egnorbb9001c2009-07-27 12:20:13 -07002180
Dan Egnor83861e72009-09-17 16:17:55 -07002181 // TODO - We call finishBackup() for each application backed up, because
2182 // we need to know now whether it succeeded or failed. Instead, we should
2183 // hold off on finishBackup() until the end, which implies holding off on
2184 // renaming *all* the output state files (see below) until that happens.
2185
Christopher Tate6de74ff2012-01-17 15:20:32 -08002186 addBackupTrace("data delivered: " + mStatus);
Christopher Tate8e294d42011-08-31 20:37:12 -07002187 if (mStatus == BackupConstants.TRANSPORT_OK) {
Christopher Tate6de74ff2012-01-17 15:20:32 -08002188 addBackupTrace("finishing op on transport");
Christopher Tate8e294d42011-08-31 20:37:12 -07002189 mStatus = mTransport.finishBackup();
Christopher Tate6de74ff2012-01-17 15:20:32 -08002190 addBackupTrace("finished: " + mStatus);
Dan Egnor83861e72009-09-17 16:17:55 -07002191 }
Dan Egnorbb9001c2009-07-27 12:20:13 -07002192 } else {
Joe Onorato8a9b2202010-02-26 18:56:32 -08002193 if (DEBUG) Slog.i(TAG, "no backup data written; not calling transport");
Christopher Tate6de74ff2012-01-17 15:20:32 -08002194 addBackupTrace("no data to send");
Dan Egnorbb9001c2009-07-27 12:20:13 -07002195 }
2196
2197 // After successful transport, delete the now-stale data
2198 // and juggle the files so that next time we supply the agent
2199 // with the new state file it just created.
Christopher Tate8e294d42011-08-31 20:37:12 -07002200 if (mStatus == BackupConstants.TRANSPORT_OK) {
2201 mBackupDataName.delete();
2202 mNewStateName.renameTo(mSavedStateName);
2203 EventLog.writeEvent(EventLogTags.BACKUP_PACKAGE,
2204 mCurrentPackage.packageName, size);
2205 logBackupComplete(mCurrentPackage.packageName);
Dan Egnor01445162009-09-21 17:04:05 -07002206 } else {
Christopher Tate8e294d42011-08-31 20:37:12 -07002207 EventLog.writeEvent(EventLogTags.BACKUP_TRANSPORT_FAILURE,
2208 mCurrentPackage.packageName);
Dan Egnor01445162009-09-21 17:04:05 -07002209 }
Dan Egnorbb9001c2009-07-27 12:20:13 -07002210 } catch (Exception e) {
Christopher Tate8e294d42011-08-31 20:37:12 -07002211 Slog.e(TAG, "Transport error backing up " + mCurrentPackage.packageName, e);
2212 EventLog.writeEvent(EventLogTags.BACKUP_TRANSPORT_FAILURE,
2213 mCurrentPackage.packageName);
2214 mStatus = BackupConstants.TRANSPORT_ERROR;
Dan Egnorbb9001c2009-07-27 12:20:13 -07002215 } finally {
2216 try { if (backupData != null) backupData.close(); } catch (IOException e) {}
Christopher Tatec7b31e32009-06-10 15:49:30 -07002217 }
Christopher Tated55e18a2009-09-21 10:12:59 -07002218
Christopher Tate8e294d42011-08-31 20:37:12 -07002219 // If we encountered an error here it's a transport-level failure. That
2220 // means we need to halt everything and reschedule everything for next time.
2221 final BackupState nextState;
2222 if (mStatus != BackupConstants.TRANSPORT_OK) {
2223 revertAndEndBackup();
2224 nextState = BackupState.FINAL;
2225 } else {
2226 // Success! Proceed with the next app if any, otherwise we're done.
2227 nextState = (mQueue.isEmpty()) ? BackupState.FINAL : BackupState.RUNNING_QUEUE;
2228 }
2229
2230 executeNextState(nextState);
2231 }
2232
2233 @Override
2234 public void handleTimeout() {
2235 // Whoops, the current agent timed out running doBackup(). Tidy up and restage
2236 // it for the next time we run a backup pass.
2237 // !!! TODO: keep track of failure counts per agent, and blacklist those which
2238 // fail repeatedly (i.e. have proved themselves to be buggy).
2239 Slog.e(TAG, "Timeout backing up " + mCurrentPackage.packageName);
2240 EventLog.writeEvent(EventLogTags.BACKUP_AGENT_FAILURE, mCurrentPackage.packageName,
2241 "timeout");
Christopher Tate6de74ff2012-01-17 15:20:32 -08002242 addBackupTrace("timeout of " + mCurrentPackage.packageName);
Christopher Tate8e294d42011-08-31 20:37:12 -07002243 agentErrorCleanup();
2244 dataChangedImpl(mCurrentPackage.packageName);
2245 }
2246
2247 void revertAndEndBackup() {
2248 if (MORE_DEBUG) Slog.i(TAG, "Reverting backup queue - restaging everything");
Christopher Tate6de74ff2012-01-17 15:20:32 -08002249 addBackupTrace("transport error; reverting");
Christopher Tate8e294d42011-08-31 20:37:12 -07002250 for (BackupRequest request : mOriginalQueue) {
2251 dataChangedImpl(request.packageName);
2252 }
2253 // We also want to reset the backup schedule based on whatever
2254 // the transport suggests by way of retry/backoff time.
2255 restartBackupAlarm();
2256 }
2257
2258 void agentErrorCleanup() {
2259 mBackupDataName.delete();
2260 mNewStateName.delete();
2261 clearAgentState();
2262
2263 executeNextState(mQueue.isEmpty() ? BackupState.FINAL : BackupState.RUNNING_QUEUE);
2264 }
2265
2266 // Cleanup common to both success and failure cases
2267 void clearAgentState() {
2268 try { if (mSavedState != null) mSavedState.close(); } catch (IOException e) {}
2269 try { if (mBackupData != null) mBackupData.close(); } catch (IOException e) {}
2270 try { if (mNewState != null) mNewState.close(); } catch (IOException e) {}
2271 mSavedState = mBackupData = mNewState = null;
2272 synchronized (mCurrentOpLock) {
2273 mCurrentOperations.clear();
2274 }
2275
2276 // If this was a pseudopackage there's no associated Activity Manager state
2277 if (mCurrentPackage.applicationInfo != null) {
Christopher Tate6de74ff2012-01-17 15:20:32 -08002278 addBackupTrace("unbinding " + mCurrentPackage.packageName);
Christopher Tate8e294d42011-08-31 20:37:12 -07002279 try { // unbind even on timeout, just in case
2280 mActivityManager.unbindBackupAgent(mCurrentPackage.applicationInfo);
2281 } catch (RemoteException e) {}
2282 }
2283 }
2284
2285 void restartBackupAlarm() {
Christopher Tate6de74ff2012-01-17 15:20:32 -08002286 addBackupTrace("setting backup trigger");
Christopher Tate8e294d42011-08-31 20:37:12 -07002287 synchronized (mQueueLock) {
2288 try {
2289 startBackupAlarmsLocked(mTransport.requestBackupTime());
2290 } catch (RemoteException e) { /* cannot happen */ }
2291 }
2292 }
2293
2294 void executeNextState(BackupState nextState) {
2295 if (MORE_DEBUG) Slog.i(TAG, " => executing next step on "
2296 + this + " nextState=" + nextState);
Christopher Tate6de74ff2012-01-17 15:20:32 -08002297 addBackupTrace("executeNextState => " + nextState);
Christopher Tate8e294d42011-08-31 20:37:12 -07002298 mCurrentState = nextState;
2299 Message msg = mBackupHandler.obtainMessage(MSG_BACKUP_RESTORE_STEP, this);
2300 mBackupHandler.sendMessage(msg);
Christopher Tatec7b31e32009-06-10 15:49:30 -07002301 }
Christopher Tate043dadc2009-06-02 16:11:00 -07002302 }
2303
Christopher Tatedf01dea2009-06-09 20:45:02 -07002304
Christopher Tate4a627c72011-04-01 14:43:32 -07002305 // ----- Full backup to a file/socket -----
2306
2307 class PerformFullBackupTask implements Runnable {
2308 ParcelFileDescriptor mOutputFile;
Christopher Tate7926a692011-07-11 11:31:57 -07002309 DeflaterOutputStream mDeflater;
Christopher Tate4a627c72011-04-01 14:43:32 -07002310 IFullBackupRestoreObserver mObserver;
2311 boolean mIncludeApks;
2312 boolean mIncludeShared;
2313 boolean mAllApps;
Christopher Tate240c7d22011-10-03 18:13:44 -07002314 final boolean mIncludeSystem;
Christopher Tate4a627c72011-04-01 14:43:32 -07002315 String[] mPackages;
Christopher Tate728a1c42011-07-28 18:03:03 -07002316 String mCurrentPassword;
2317 String mEncryptPassword;
Christopher Tate4a627c72011-04-01 14:43:32 -07002318 AtomicBoolean mLatchObject;
2319 File mFilesDir;
2320 File mManifestFile;
2321
Christopher Tate7926a692011-07-11 11:31:57 -07002322 class FullBackupRunner implements Runnable {
2323 PackageInfo mPackage;
2324 IBackupAgent mAgent;
2325 ParcelFileDescriptor mPipe;
2326 int mToken;
2327 boolean mSendApk;
Christopher Tate73d73692012-01-20 17:11:31 -08002328 boolean mWriteManifest;
Christopher Tate7926a692011-07-11 11:31:57 -07002329
2330 FullBackupRunner(PackageInfo pack, IBackupAgent agent, ParcelFileDescriptor pipe,
Christopher Tate73d73692012-01-20 17:11:31 -08002331 int token, boolean sendApk, boolean writeManifest) throws IOException {
Christopher Tate7926a692011-07-11 11:31:57 -07002332 mPackage = pack;
2333 mAgent = agent;
2334 mPipe = ParcelFileDescriptor.dup(pipe.getFileDescriptor());
2335 mToken = token;
2336 mSendApk = sendApk;
Christopher Tate73d73692012-01-20 17:11:31 -08002337 mWriteManifest = writeManifest;
Christopher Tate7926a692011-07-11 11:31:57 -07002338 }
2339
2340 @Override
2341 public void run() {
2342 try {
2343 BackupDataOutput output = new BackupDataOutput(
2344 mPipe.getFileDescriptor());
2345
Christopher Tate73d73692012-01-20 17:11:31 -08002346 if (mWriteManifest) {
2347 if (MORE_DEBUG) Slog.d(TAG, "Writing manifest for " + mPackage.packageName);
2348 writeAppManifest(mPackage, mManifestFile, mSendApk);
2349 FullBackup.backupToTar(mPackage.packageName, null, null,
2350 mFilesDir.getAbsolutePath(),
2351 mManifestFile.getAbsolutePath(),
2352 output);
2353 }
Christopher Tate7926a692011-07-11 11:31:57 -07002354
2355 if (mSendApk) {
2356 writeApkToBackup(mPackage, output);
2357 }
2358
Christopher Tatec58efa62011-08-01 19:20:14 -07002359 if (DEBUG) Slog.d(TAG, "Calling doFullBackup() on " + mPackage.packageName);
Christopher Tate8e294d42011-08-31 20:37:12 -07002360 prepareOperationTimeout(mToken, TIMEOUT_FULL_BACKUP_INTERVAL, null);
Christopher Tate7926a692011-07-11 11:31:57 -07002361 mAgent.doFullBackup(mPipe, mToken, mBackupManagerBinder);
2362 } catch (IOException e) {
2363 Slog.e(TAG, "Error running full backup for " + mPackage.packageName);
2364 } catch (RemoteException e) {
2365 Slog.e(TAG, "Remote agent vanished during full backup of "
2366 + mPackage.packageName);
2367 } finally {
2368 try {
2369 mPipe.close();
2370 } catch (IOException e) {}
2371 }
2372 }
2373 }
2374
Christopher Tate4a627c72011-04-01 14:43:32 -07002375 PerformFullBackupTask(ParcelFileDescriptor fd, IFullBackupRestoreObserver observer,
Christopher Tate728a1c42011-07-28 18:03:03 -07002376 boolean includeApks, boolean includeShared, String curPassword,
Christopher Tate240c7d22011-10-03 18:13:44 -07002377 String encryptPassword, boolean doAllApps, boolean doSystem, String[] packages,
Christopher Tate728a1c42011-07-28 18:03:03 -07002378 AtomicBoolean latch) {
Christopher Tate4a627c72011-04-01 14:43:32 -07002379 mOutputFile = fd;
2380 mObserver = observer;
2381 mIncludeApks = includeApks;
2382 mIncludeShared = includeShared;
2383 mAllApps = doAllApps;
Christopher Tate240c7d22011-10-03 18:13:44 -07002384 mIncludeSystem = doSystem;
Christopher Tate4a627c72011-04-01 14:43:32 -07002385 mPackages = packages;
Christopher Tate728a1c42011-07-28 18:03:03 -07002386 mCurrentPassword = curPassword;
2387 // when backing up, if there is a current backup password, we require that
2388 // the user use a nonempty encryption password as well. if one is supplied
2389 // in the UI we use that, but if the UI was left empty we fall back to the
2390 // current backup password (which was supplied by the user as well).
2391 if (encryptPassword == null || "".equals(encryptPassword)) {
2392 mEncryptPassword = curPassword;
2393 } else {
2394 mEncryptPassword = encryptPassword;
2395 }
Christopher Tate4a627c72011-04-01 14:43:32 -07002396 mLatchObject = latch;
2397
2398 mFilesDir = new File("/data/system");
2399 mManifestFile = new File(mFilesDir, BACKUP_MANIFEST_FILENAME);
2400 }
2401
2402 @Override
2403 public void run() {
Christopher Tate240c7d22011-10-03 18:13:44 -07002404 List<PackageInfo> packagesToBackup = new ArrayList<PackageInfo>();
Christopher Tate4a627c72011-04-01 14:43:32 -07002405
Christopher Tateb0628bf2011-06-02 15:08:13 -07002406 Slog.i(TAG, "--- Performing full-dataset backup ---");
Christopher Tate4a627c72011-04-01 14:43:32 -07002407 sendStartBackup();
2408
2409 // doAllApps supersedes the package set if any
2410 if (mAllApps) {
2411 packagesToBackup = mPackageManager.getInstalledPackages(
2412 PackageManager.GET_SIGNATURES);
Christopher Tate240c7d22011-10-03 18:13:44 -07002413 // Exclude system apps if we've been asked to do so
2414 if (mIncludeSystem == false) {
2415 for (int i = 0; i < packagesToBackup.size(); ) {
2416 PackageInfo pkg = packagesToBackup.get(i);
2417 if ((pkg.applicationInfo.flags & ApplicationInfo.FLAG_SYSTEM) != 0) {
2418 packagesToBackup.remove(i);
2419 } else {
2420 i++;
2421 }
2422 }
2423 }
2424 }
2425
2426 // Now process the command line argument packages, if any. Note that explicitly-
2427 // named system-partition packages will be included even if includeSystem was
2428 // set to false.
2429 if (mPackages != null) {
Christopher Tate4a627c72011-04-01 14:43:32 -07002430 for (String pkgName : mPackages) {
2431 try {
2432 packagesToBackup.add(mPackageManager.getPackageInfo(pkgName,
2433 PackageManager.GET_SIGNATURES));
2434 } catch (NameNotFoundException e) {
2435 Slog.w(TAG, "Unknown package " + pkgName + ", skipping");
2436 }
2437 }
2438 }
2439
Christopher Tate73d73692012-01-20 17:11:31 -08002440 // Cull any packages that have indicated that backups are not permitted, as well
2441 // as any explicit mention of the 'special' shared-storage agent package (we
2442 // handle that one at the end).
Christopher Tatea858cb02011-06-03 12:27:51 -07002443 for (int i = 0; i < packagesToBackup.size(); ) {
Christopher Tate240c7d22011-10-03 18:13:44 -07002444 PackageInfo pkg = packagesToBackup.get(i);
Christopher Tate73d73692012-01-20 17:11:31 -08002445 if ((pkg.applicationInfo.flags & ApplicationInfo.FLAG_ALLOW_BACKUP) == 0
2446 || pkg.packageName.equals(SHARED_BACKUP_AGENT_PACKAGE)) {
Christopher Tatea858cb02011-06-03 12:27:51 -07002447 packagesToBackup.remove(i);
2448 } else {
2449 i++;
2450 }
2451 }
2452
Christopher Tate7926a692011-07-11 11:31:57 -07002453 FileOutputStream ofstream = new FileOutputStream(mOutputFile.getFileDescriptor());
Christopher Tate2efd2db2011-07-19 16:32:49 -07002454 OutputStream out = null;
Christopher Tate7926a692011-07-11 11:31:57 -07002455
Christopher Tate4a627c72011-04-01 14:43:32 -07002456 PackageInfo pkg = null;
2457 try {
Christopher Tate728a1c42011-07-28 18:03:03 -07002458 boolean encrypting = (mEncryptPassword != null && mEncryptPassword.length() > 0);
Christopher Tate2efd2db2011-07-19 16:32:49 -07002459 boolean compressing = COMPRESS_FULL_BACKUPS;
2460 OutputStream finalOutput = ofstream;
Christopher Tate7bdb0962011-07-13 19:30:21 -07002461
Christopher Tateeef4ae42011-08-05 13:15:53 -07002462 // Verify that the given password matches the currently-active
2463 // backup password, if any
2464 if (hasBackupPassword()) {
2465 if (!passwordMatchesSaved(mCurrentPassword, PBKDF2_HASH_ROUNDS)) {
2466 if (DEBUG) Slog.w(TAG, "Backup password mismatch; aborting");
2467 return;
2468 }
2469 }
2470
Christopher Tate7bdb0962011-07-13 19:30:21 -07002471 // Write the global file header. All strings are UTF-8 encoded; lines end
2472 // with a '\n' byte. Actual backup data begins immediately following the
2473 // final '\n'.
2474 //
2475 // line 1: "ANDROID BACKUP"
2476 // line 2: backup file format version, currently "1"
2477 // line 3: compressed? "0" if not compressed, "1" if compressed.
Christopher Tate2efd2db2011-07-19 16:32:49 -07002478 // line 4: name of encryption algorithm [currently only "none" or "AES-256"]
2479 //
2480 // When line 4 is not "none", then additional header data follows:
2481 //
2482 // line 5: user password salt [hex]
2483 // line 6: master key checksum salt [hex]
2484 // line 7: number of PBKDF2 rounds to use (same for user & master) [decimal]
2485 // line 8: IV of the user key [hex]
2486 // line 9: master key blob [hex]
2487 // IV of the master key, master key itself, master key checksum hash
2488 //
2489 // The master key checksum is the master key plus its checksum salt, run through
2490 // 10k rounds of PBKDF2. This is used to verify that the user has supplied the
2491 // correct password for decrypting the archive: the master key decrypted from
2492 // the archive using the user-supplied password is also run through PBKDF2 in
2493 // this way, and if the result does not match the checksum as stored in the
2494 // archive, then we know that the user-supplied password does not match the
2495 // archive's.
2496 StringBuilder headerbuf = new StringBuilder(1024);
2497
Christopher Tate7bdb0962011-07-13 19:30:21 -07002498 headerbuf.append(BACKUP_FILE_HEADER_MAGIC);
Christopher Tate2efd2db2011-07-19 16:32:49 -07002499 headerbuf.append(BACKUP_FILE_VERSION); // integer, no trailing \n
2500 headerbuf.append(compressing ? "\n1\n" : "\n0\n");
Christopher Tate7bdb0962011-07-13 19:30:21 -07002501
2502 try {
Christopher Tate2efd2db2011-07-19 16:32:49 -07002503 // Set up the encryption stage if appropriate, and emit the correct header
2504 if (encrypting) {
Christopher Tate2efd2db2011-07-19 16:32:49 -07002505 finalOutput = emitAesBackupHeader(headerbuf, finalOutput);
2506 } else {
2507 headerbuf.append("none\n");
2508 }
2509
Christopher Tate7bdb0962011-07-13 19:30:21 -07002510 byte[] header = headerbuf.toString().getBytes("UTF-8");
2511 ofstream.write(header);
Christopher Tate2efd2db2011-07-19 16:32:49 -07002512
2513 // Set up the compression stage feeding into the encryption stage (if any)
2514 if (compressing) {
2515 Deflater deflater = new Deflater(Deflater.BEST_COMPRESSION);
2516 finalOutput = new DeflaterOutputStream(finalOutput, deflater, true);
2517 }
2518
2519 out = finalOutput;
Christopher Tate7bdb0962011-07-13 19:30:21 -07002520 } catch (Exception e) {
2521 // Should never happen!
2522 Slog.e(TAG, "Unable to emit archive header", e);
2523 return;
2524 }
2525
Christopher Tate73d73692012-01-20 17:11:31 -08002526 // Shared storage if requested
2527 if (mIncludeShared) {
2528 try {
2529 pkg = mPackageManager.getPackageInfo(SHARED_BACKUP_AGENT_PACKAGE, 0);
2530 packagesToBackup.add(pkg);
2531 } catch (NameNotFoundException e) {
2532 Slog.e(TAG, "Unable to find shared-storage backup handler");
2533 }
2534 }
2535
Christopher Tateb0628bf2011-06-02 15:08:13 -07002536 // Now back up the app data via the agent mechanism
Christopher Tate4a627c72011-04-01 14:43:32 -07002537 int N = packagesToBackup.size();
2538 for (int i = 0; i < N; i++) {
2539 pkg = packagesToBackup.get(i);
Christopher Tate7926a692011-07-11 11:31:57 -07002540 backupOnePackage(pkg, out);
Christopher Tateb0628bf2011-06-02 15:08:13 -07002541 }
Christopher Tate4a627c72011-04-01 14:43:32 -07002542
Christopher Tate6853fcf2011-08-10 17:52:21 -07002543 // Done!
2544 finalizeBackup(out);
Christopher Tate4a627c72011-04-01 14:43:32 -07002545 } catch (RemoteException e) {
2546 Slog.e(TAG, "App died during full backup");
Christopher Tateaa0c02d2012-03-23 13:56:34 -07002547 } catch (Exception e) {
2548 Slog.e(TAG, "Internal exception during full backup", e);
Christopher Tate4a627c72011-04-01 14:43:32 -07002549 } finally {
Christopher Tateb0628bf2011-06-02 15:08:13 -07002550 tearDown(pkg);
Christopher Tate4a627c72011-04-01 14:43:32 -07002551 try {
Christopher Tate2efd2db2011-07-19 16:32:49 -07002552 if (out != null) out.close();
Christopher Tate4a627c72011-04-01 14:43:32 -07002553 mOutputFile.close();
2554 } catch (IOException e) {
2555 /* nothing we can do about this */
2556 }
2557 synchronized (mCurrentOpLock) {
2558 mCurrentOperations.clear();
2559 }
2560 synchronized (mLatchObject) {
2561 mLatchObject.set(true);
2562 mLatchObject.notifyAll();
2563 }
2564 sendEndBackup();
Christopher Tate4a627c72011-04-01 14:43:32 -07002565 if (DEBUG) Slog.d(TAG, "Full backup pass complete.");
Christopher Tate336a6492011-10-05 16:05:43 -07002566 mWakelock.release();
Christopher Tate4a627c72011-04-01 14:43:32 -07002567 }
2568 }
2569
Christopher Tate2efd2db2011-07-19 16:32:49 -07002570 private OutputStream emitAesBackupHeader(StringBuilder headerbuf,
2571 OutputStream ofstream) throws Exception {
2572 // User key will be used to encrypt the master key.
2573 byte[] newUserSalt = randomBytes(PBKDF2_SALT_SIZE);
Christopher Tate728a1c42011-07-28 18:03:03 -07002574 SecretKey userKey = buildPasswordKey(mEncryptPassword, newUserSalt,
Christopher Tate2efd2db2011-07-19 16:32:49 -07002575 PBKDF2_HASH_ROUNDS);
2576
2577 // the master key is random for each backup
2578 byte[] masterPw = new byte[256 / 8];
2579 mRng.nextBytes(masterPw);
2580 byte[] checksumSalt = randomBytes(PBKDF2_SALT_SIZE);
2581
2582 // primary encryption of the datastream with the random key
2583 Cipher c = Cipher.getInstance("AES/CBC/PKCS5Padding");
2584 SecretKeySpec masterKeySpec = new SecretKeySpec(masterPw, "AES");
2585 c.init(Cipher.ENCRYPT_MODE, masterKeySpec);
2586 OutputStream finalOutput = new CipherOutputStream(ofstream, c);
2587
2588 // line 4: name of encryption algorithm
2589 headerbuf.append(ENCRYPTION_ALGORITHM_NAME);
2590 headerbuf.append('\n');
2591 // line 5: user password salt [hex]
2592 headerbuf.append(byteArrayToHex(newUserSalt));
2593 headerbuf.append('\n');
2594 // line 6: master key checksum salt [hex]
2595 headerbuf.append(byteArrayToHex(checksumSalt));
2596 headerbuf.append('\n');
2597 // line 7: number of PBKDF2 rounds used [decimal]
2598 headerbuf.append(PBKDF2_HASH_ROUNDS);
2599 headerbuf.append('\n');
2600
2601 // line 8: IV of the user key [hex]
2602 Cipher mkC = Cipher.getInstance("AES/CBC/PKCS5Padding");
2603 mkC.init(Cipher.ENCRYPT_MODE, userKey);
2604
2605 byte[] IV = mkC.getIV();
2606 headerbuf.append(byteArrayToHex(IV));
2607 headerbuf.append('\n');
2608
2609 // line 9: master IV + key blob, encrypted by the user key [hex]. Blob format:
2610 // [byte] IV length = Niv
2611 // [array of Niv bytes] IV itself
2612 // [byte] master key length = Nmk
2613 // [array of Nmk bytes] master key itself
2614 // [byte] MK checksum hash length = Nck
2615 // [array of Nck bytes] master key checksum hash
2616 //
2617 // The checksum is the (master key + checksum salt), run through the
2618 // stated number of PBKDF2 rounds
2619 IV = c.getIV();
2620 byte[] mk = masterKeySpec.getEncoded();
2621 byte[] checksum = makeKeyChecksum(masterKeySpec.getEncoded(),
2622 checksumSalt, PBKDF2_HASH_ROUNDS);
2623
2624 ByteArrayOutputStream blob = new ByteArrayOutputStream(IV.length + mk.length
2625 + checksum.length + 3);
2626 DataOutputStream mkOut = new DataOutputStream(blob);
2627 mkOut.writeByte(IV.length);
2628 mkOut.write(IV);
2629 mkOut.writeByte(mk.length);
2630 mkOut.write(mk);
2631 mkOut.writeByte(checksum.length);
2632 mkOut.write(checksum);
2633 mkOut.flush();
2634 byte[] encryptedMk = mkC.doFinal(blob.toByteArray());
2635 headerbuf.append(byteArrayToHex(encryptedMk));
2636 headerbuf.append('\n');
2637
2638 return finalOutput;
2639 }
2640
2641 private void backupOnePackage(PackageInfo pkg, OutputStream out)
Christopher Tate7926a692011-07-11 11:31:57 -07002642 throws RemoteException {
Christopher Tateb0628bf2011-06-02 15:08:13 -07002643 Slog.d(TAG, "Binding to full backup agent : " + pkg.packageName);
2644
2645 IBackupAgent agent = bindToAgentSynchronous(pkg.applicationInfo,
2646 IApplicationThread.BACKUP_MODE_FULL);
2647 if (agent != null) {
Christopher Tate7926a692011-07-11 11:31:57 -07002648 ParcelFileDescriptor[] pipes = null;
Christopher Tateb0628bf2011-06-02 15:08:13 -07002649 try {
Christopher Tate73d73692012-01-20 17:11:31 -08002650 pipes = ParcelFileDescriptor.createPipe();
Christopher Tate7926a692011-07-11 11:31:57 -07002651
Christopher Tateb0628bf2011-06-02 15:08:13 -07002652 ApplicationInfo app = pkg.applicationInfo;
Christopher Tate73d73692012-01-20 17:11:31 -08002653 final boolean isSharedStorage = pkg.packageName.equals(SHARED_BACKUP_AGENT_PACKAGE);
Christopher Tate79ec80d2011-06-24 14:58:49 -07002654 final boolean sendApk = mIncludeApks
Christopher Tate73d73692012-01-20 17:11:31 -08002655 && !isSharedStorage
Christopher Tateb0628bf2011-06-02 15:08:13 -07002656 && ((app.flags & ApplicationInfo.FLAG_FORWARD_LOCK) == 0)
2657 && ((app.flags & ApplicationInfo.FLAG_SYSTEM) == 0 ||
2658 (app.flags & ApplicationInfo.FLAG_UPDATED_SYSTEM_APP) != 0);
2659
Christopher Tate73d73692012-01-20 17:11:31 -08002660 sendOnBackupPackage(isSharedStorage ? "Shared storage" : pkg.packageName);
Christopher Tateb0628bf2011-06-02 15:08:13 -07002661
Christopher Tate7926a692011-07-11 11:31:57 -07002662 final int token = generateToken();
2663 FullBackupRunner runner = new FullBackupRunner(pkg, agent, pipes[1],
Christopher Tate73d73692012-01-20 17:11:31 -08002664 token, sendApk, !isSharedStorage);
Christopher Tate7926a692011-07-11 11:31:57 -07002665 pipes[1].close(); // the runner has dup'd it
2666 pipes[1] = null;
2667 Thread t = new Thread(runner);
2668 t.start();
Christopher Tateb0628bf2011-06-02 15:08:13 -07002669
Christopher Tate7926a692011-07-11 11:31:57 -07002670 // Now pull data from the app and stuff it into the compressor
2671 try {
2672 FileInputStream raw = new FileInputStream(pipes[0].getFileDescriptor());
2673 DataInputStream in = new DataInputStream(raw);
Christopher Tate79ec80d2011-06-24 14:58:49 -07002674
Christopher Tate7926a692011-07-11 11:31:57 -07002675 byte[] buffer = new byte[16 * 1024];
2676 int chunkTotal;
2677 while ((chunkTotal = in.readInt()) > 0) {
2678 while (chunkTotal > 0) {
2679 int toRead = (chunkTotal > buffer.length)
2680 ? buffer.length : chunkTotal;
2681 int nRead = in.read(buffer, 0, toRead);
2682 out.write(buffer, 0, nRead);
2683 chunkTotal -= nRead;
2684 }
2685 }
2686 } catch (IOException e) {
2687 Slog.i(TAG, "Caught exception reading from agent", e);
Christopher Tateb0628bf2011-06-02 15:08:13 -07002688 }
2689
Christopher Tateb0628bf2011-06-02 15:08:13 -07002690 if (!waitUntilOperationComplete(token)) {
2691 Slog.e(TAG, "Full backup failed on package " + pkg.packageName);
2692 } else {
Christopher Tate7926a692011-07-11 11:31:57 -07002693 if (DEBUG) Slog.d(TAG, "Full package backup success: " + pkg.packageName);
Christopher Tateb0628bf2011-06-02 15:08:13 -07002694 }
Christopher Tate7926a692011-07-11 11:31:57 -07002695
Christopher Tateb0628bf2011-06-02 15:08:13 -07002696 } catch (IOException e) {
2697 Slog.e(TAG, "Error backing up " + pkg.packageName, e);
Christopher Tate7926a692011-07-11 11:31:57 -07002698 } finally {
2699 try {
Christopher Tate2efd2db2011-07-19 16:32:49 -07002700 // flush after every package
2701 out.flush();
Christopher Tate7926a692011-07-11 11:31:57 -07002702 if (pipes != null) {
2703 if (pipes[0] != null) pipes[0].close();
2704 if (pipes[1] != null) pipes[1].close();
2705 }
Christopher Tate7926a692011-07-11 11:31:57 -07002706 } catch (IOException e) {
2707 Slog.w(TAG, "Error bringing down backup stack");
2708 }
Christopher Tateb0628bf2011-06-02 15:08:13 -07002709 }
2710 } else {
2711 Slog.w(TAG, "Unable to bind to full agent for " + pkg.packageName);
2712 }
2713 tearDown(pkg);
2714 }
2715
Christopher Tate79ec80d2011-06-24 14:58:49 -07002716 private void writeApkToBackup(PackageInfo pkg, BackupDataOutput output) {
2717 // Forward-locked apps, system-bundled .apks, etc are filtered out before we get here
2718 final String appSourceDir = pkg.applicationInfo.sourceDir;
2719 final String apkDir = new File(appSourceDir).getParent();
2720 FullBackup.backupToTar(pkg.packageName, FullBackup.APK_TREE_TOKEN, null,
2721 apkDir, appSourceDir, output);
2722
2723 // Save associated .obb content if it exists and we did save the apk
2724 // check for .obb and save those too
2725 final File obbDir = Environment.getExternalStorageAppObbDirectory(pkg.packageName);
2726 if (obbDir != null) {
Christopher Tatec58efa62011-08-01 19:20:14 -07002727 if (MORE_DEBUG) Log.i(TAG, "obb dir: " + obbDir.getAbsolutePath());
Christopher Tate79ec80d2011-06-24 14:58:49 -07002728 File[] obbFiles = obbDir.listFiles();
2729 if (obbFiles != null) {
2730 final String obbDirName = obbDir.getAbsolutePath();
2731 for (File obb : obbFiles) {
2732 FullBackup.backupToTar(pkg.packageName, FullBackup.OBB_TREE_TOKEN, null,
2733 obbDirName, obb.getAbsolutePath(), output);
2734 }
2735 }
2736 }
2737 }
2738
Christopher Tate6853fcf2011-08-10 17:52:21 -07002739 private void finalizeBackup(OutputStream out) {
2740 try {
2741 // A standard 'tar' EOF sequence: two 512-byte blocks of all zeroes.
2742 byte[] eof = new byte[512 * 2]; // newly allocated == zero filled
2743 out.write(eof);
2744 } catch (IOException e) {
2745 Slog.w(TAG, "Error attempting to finalize backup stream");
2746 }
2747 }
2748
Christopher Tate4a627c72011-04-01 14:43:32 -07002749 private void writeAppManifest(PackageInfo pkg, File manifestFile, boolean withApk)
2750 throws IOException {
2751 // Manifest format. All data are strings ending in LF:
2752 // BACKUP_MANIFEST_VERSION, currently 1
2753 //
2754 // Version 1:
2755 // package name
2756 // package's versionCode
Christopher Tate75a99702011-05-18 16:28:19 -07002757 // platform versionCode
2758 // getInstallerPackageName() for this package (maybe empty)
2759 // boolean: "1" if archive includes .apk; any other string means not
Christopher Tate4a627c72011-04-01 14:43:32 -07002760 // number of signatures == N
2761 // N*: signature byte array in ascii format per Signature.toCharsString()
2762 StringBuilder builder = new StringBuilder(4096);
2763 StringBuilderPrinter printer = new StringBuilderPrinter(builder);
2764
2765 printer.println(Integer.toString(BACKUP_MANIFEST_VERSION));
2766 printer.println(pkg.packageName);
2767 printer.println(Integer.toString(pkg.versionCode));
Christopher Tate75a99702011-05-18 16:28:19 -07002768 printer.println(Integer.toString(Build.VERSION.SDK_INT));
2769
2770 String installerName = mPackageManager.getInstallerPackageName(pkg.packageName);
2771 printer.println((installerName != null) ? installerName : "");
2772
Christopher Tate4a627c72011-04-01 14:43:32 -07002773 printer.println(withApk ? "1" : "0");
2774 if (pkg.signatures == null) {
2775 printer.println("0");
2776 } else {
2777 printer.println(Integer.toString(pkg.signatures.length));
2778 for (Signature sig : pkg.signatures) {
2779 printer.println(sig.toCharsString());
2780 }
2781 }
2782
2783 FileOutputStream outstream = new FileOutputStream(manifestFile);
Christopher Tate4a627c72011-04-01 14:43:32 -07002784 outstream.write(builder.toString().getBytes());
2785 outstream.close();
2786 }
2787
2788 private void tearDown(PackageInfo pkg) {
Christopher Tateb0628bf2011-06-02 15:08:13 -07002789 if (pkg != null) {
2790 final ApplicationInfo app = pkg.applicationInfo;
2791 if (app != null) {
2792 try {
2793 // unbind and tidy up even on timeout or failure, just in case
2794 mActivityManager.unbindBackupAgent(app);
Christopher Tate4a627c72011-04-01 14:43:32 -07002795
Christopher Tateb0628bf2011-06-02 15:08:13 -07002796 // The agent was running with a stub Application object, so shut it down.
Christopher Tate2efd2db2011-07-19 16:32:49 -07002797 if (app.uid != Process.SYSTEM_UID
2798 && app.uid != Process.PHONE_UID) {
Christopher Tatec58efa62011-08-01 19:20:14 -07002799 if (MORE_DEBUG) Slog.d(TAG, "Backup complete, killing host process");
Christopher Tateb0628bf2011-06-02 15:08:13 -07002800 mActivityManager.killApplicationProcess(app.processName, app.uid);
2801 } else {
Christopher Tatec58efa62011-08-01 19:20:14 -07002802 if (MORE_DEBUG) Slog.d(TAG, "Not killing after restore: " + app.processName);
Christopher Tateb0628bf2011-06-02 15:08:13 -07002803 }
2804 } catch (RemoteException e) {
2805 Slog.d(TAG, "Lost app trying to shut down");
2806 }
Christopher Tate4a627c72011-04-01 14:43:32 -07002807 }
Christopher Tate4a627c72011-04-01 14:43:32 -07002808 }
2809 }
2810
2811 // wrappers for observer use
2812 void sendStartBackup() {
2813 if (mObserver != null) {
2814 try {
2815 mObserver.onStartBackup();
2816 } catch (RemoteException e) {
2817 Slog.w(TAG, "full backup observer went away: startBackup");
2818 mObserver = null;
2819 }
2820 }
2821 }
2822
2823 void sendOnBackupPackage(String name) {
2824 if (mObserver != null) {
2825 try {
2826 // TODO: use a more user-friendly name string
2827 mObserver.onBackupPackage(name);
2828 } catch (RemoteException e) {
2829 Slog.w(TAG, "full backup observer went away: backupPackage");
2830 mObserver = null;
2831 }
2832 }
2833 }
2834
2835 void sendEndBackup() {
2836 if (mObserver != null) {
2837 try {
2838 mObserver.onEndBackup();
2839 } catch (RemoteException e) {
2840 Slog.w(TAG, "full backup observer went away: endBackup");
2841 mObserver = null;
2842 }
2843 }
2844 }
2845 }
2846
2847
Christopher Tate75a99702011-05-18 16:28:19 -07002848 // ----- Full restore from a file/socket -----
2849
2850 // Description of a file in the restore datastream
2851 static class FileMetadata {
2852 String packageName; // name of the owning app
2853 String installerPackageName; // name of the market-type app that installed the owner
Christopher Tate79ec80d2011-06-24 14:58:49 -07002854 int type; // e.g. BackupAgent.TYPE_DIRECTORY
Christopher Tate75a99702011-05-18 16:28:19 -07002855 String domain; // e.g. FullBackup.DATABASE_TREE_TOKEN
2856 String path; // subpath within the semantic domain
2857 long mode; // e.g. 0666 (actually int)
2858 long mtime; // last mod time, UTC time_t (actually int)
2859 long size; // bytes of content
Christopher Tatee9e78ec2011-06-08 20:09:31 -07002860
2861 @Override
2862 public String toString() {
2863 StringBuilder sb = new StringBuilder(128);
2864 sb.append("FileMetadata{");
2865 sb.append(packageName); sb.append(',');
2866 sb.append(type); sb.append(',');
2867 sb.append(domain); sb.append(':'); sb.append(path); sb.append(',');
2868 sb.append(size);
2869 sb.append('}');
2870 return sb.toString();
2871 }
Christopher Tate75a99702011-05-18 16:28:19 -07002872 }
2873
2874 enum RestorePolicy {
2875 IGNORE,
2876 ACCEPT,
2877 ACCEPT_IF_APK
2878 }
2879
2880 class PerformFullRestoreTask implements Runnable {
2881 ParcelFileDescriptor mInputFile;
Christopher Tate728a1c42011-07-28 18:03:03 -07002882 String mCurrentPassword;
2883 String mDecryptPassword;
Christopher Tate75a99702011-05-18 16:28:19 -07002884 IFullBackupRestoreObserver mObserver;
2885 AtomicBoolean mLatchObject;
2886 IBackupAgent mAgent;
2887 String mAgentPackage;
2888 ApplicationInfo mTargetApp;
2889 ParcelFileDescriptor[] mPipes = null;
2890
Christopher Tatee9e78ec2011-06-08 20:09:31 -07002891 long mBytes;
2892
Christopher Tate75a99702011-05-18 16:28:19 -07002893 // possible handling states for a given package in the restore dataset
2894 final HashMap<String, RestorePolicy> mPackagePolicies
2895 = new HashMap<String, RestorePolicy>();
2896
2897 // installer package names for each encountered app, derived from the manifests
2898 final HashMap<String, String> mPackageInstallers = new HashMap<String, String>();
2899
2900 // Signatures for a given package found in its manifest file
2901 final HashMap<String, Signature[]> mManifestSignatures
2902 = new HashMap<String, Signature[]>();
2903
2904 // Packages we've already wiped data on when restoring their first file
2905 final HashSet<String> mClearedPackages = new HashSet<String>();
2906
Christopher Tate728a1c42011-07-28 18:03:03 -07002907 PerformFullRestoreTask(ParcelFileDescriptor fd, String curPassword, String decryptPassword,
Christopher Tate2efd2db2011-07-19 16:32:49 -07002908 IFullBackupRestoreObserver observer, AtomicBoolean latch) {
Christopher Tate75a99702011-05-18 16:28:19 -07002909 mInputFile = fd;
Christopher Tate728a1c42011-07-28 18:03:03 -07002910 mCurrentPassword = curPassword;
2911 mDecryptPassword = decryptPassword;
Christopher Tate75a99702011-05-18 16:28:19 -07002912 mObserver = observer;
2913 mLatchObject = latch;
2914 mAgent = null;
2915 mAgentPackage = null;
2916 mTargetApp = null;
2917
2918 // Which packages we've already wiped data on. We prepopulate this
2919 // with a whitelist of packages known to be unclearable.
2920 mClearedPackages.add("android");
Christopher Tate75a99702011-05-18 16:28:19 -07002921 mClearedPackages.add("com.android.providers.settings");
Christopher Tateb0628bf2011-06-02 15:08:13 -07002922
Christopher Tate75a99702011-05-18 16:28:19 -07002923 }
2924
2925 class RestoreFileRunnable implements Runnable {
2926 IBackupAgent mAgent;
2927 FileMetadata mInfo;
2928 ParcelFileDescriptor mSocket;
2929 int mToken;
2930
2931 RestoreFileRunnable(IBackupAgent agent, FileMetadata info,
2932 ParcelFileDescriptor socket, int token) throws IOException {
2933 mAgent = agent;
2934 mInfo = info;
2935 mToken = token;
2936
2937 // This class is used strictly for process-local binder invocations. The
2938 // semantics of ParcelFileDescriptor differ in this case; in particular, we
2939 // do not automatically get a 'dup'ed descriptor that we can can continue
2940 // to use asynchronously from the caller. So, we make sure to dup it ourselves
2941 // before proceeding to do the restore.
2942 mSocket = ParcelFileDescriptor.dup(socket.getFileDescriptor());
2943 }
2944
2945 @Override
2946 public void run() {
2947 try {
2948 mAgent.doRestoreFile(mSocket, mInfo.size, mInfo.type,
2949 mInfo.domain, mInfo.path, mInfo.mode, mInfo.mtime,
2950 mToken, mBackupManagerBinder);
2951 } catch (RemoteException e) {
2952 // never happens; this is used strictly for local binder calls
2953 }
2954 }
2955 }
2956
2957 @Override
2958 public void run() {
2959 Slog.i(TAG, "--- Performing full-dataset restore ---");
2960 sendStartRestore();
2961
Christopher Tateb0628bf2011-06-02 15:08:13 -07002962 // Are we able to restore shared-storage data?
2963 if (Environment.getExternalStorageState().equals(Environment.MEDIA_MOUNTED)) {
Christopher Tate73d73692012-01-20 17:11:31 -08002964 mPackagePolicies.put(SHARED_BACKUP_AGENT_PACKAGE, RestorePolicy.ACCEPT);
Christopher Tateb0628bf2011-06-02 15:08:13 -07002965 }
2966
Christopher Tate2efd2db2011-07-19 16:32:49 -07002967 FileInputStream rawInStream = null;
2968 DataInputStream rawDataIn = null;
Christopher Tate75a99702011-05-18 16:28:19 -07002969 try {
Christopher Tate728a1c42011-07-28 18:03:03 -07002970 if (hasBackupPassword()) {
2971 if (!passwordMatchesSaved(mCurrentPassword, PBKDF2_HASH_ROUNDS)) {
2972 if (DEBUG) Slog.w(TAG, "Backup password mismatch; aborting");
2973 return;
2974 }
2975 }
2976
Christopher Tatee9e78ec2011-06-08 20:09:31 -07002977 mBytes = 0;
Christopher Tate75a99702011-05-18 16:28:19 -07002978 byte[] buffer = new byte[32 * 1024];
Christopher Tate2efd2db2011-07-19 16:32:49 -07002979 rawInStream = new FileInputStream(mInputFile.getFileDescriptor());
2980 rawDataIn = new DataInputStream(rawInStream);
Christopher Tate7bdb0962011-07-13 19:30:21 -07002981
2982 // First, parse out the unencrypted/uncompressed header
2983 boolean compressed = false;
Christopher Tate2efd2db2011-07-19 16:32:49 -07002984 InputStream preCompressStream = rawInStream;
Christopher Tate7bdb0962011-07-13 19:30:21 -07002985 final InputStream in;
2986
2987 boolean okay = false;
2988 final int headerLen = BACKUP_FILE_HEADER_MAGIC.length();
2989 byte[] streamHeader = new byte[headerLen];
Christopher Tate2efd2db2011-07-19 16:32:49 -07002990 rawDataIn.readFully(streamHeader);
2991 byte[] magicBytes = BACKUP_FILE_HEADER_MAGIC.getBytes("UTF-8");
2992 if (Arrays.equals(magicBytes, streamHeader)) {
2993 // okay, header looks good. now parse out the rest of the fields.
2994 String s = readHeaderLine(rawInStream);
2995 if (Integer.parseInt(s) == BACKUP_FILE_VERSION) {
2996 // okay, it's a version we recognize
2997 s = readHeaderLine(rawInStream);
2998 compressed = (Integer.parseInt(s) != 0);
2999 s = readHeaderLine(rawInStream);
3000 if (s.equals("none")) {
3001 // no more header to parse; we're good to go
3002 okay = true;
Christopher Tate728a1c42011-07-28 18:03:03 -07003003 } else if (mDecryptPassword != null && mDecryptPassword.length() > 0) {
Christopher Tate2efd2db2011-07-19 16:32:49 -07003004 preCompressStream = decodeAesHeaderAndInitialize(s, rawInStream);
3005 if (preCompressStream != null) {
Christopher Tate7bdb0962011-07-13 19:30:21 -07003006 okay = true;
Christopher Tate2efd2db2011-07-19 16:32:49 -07003007 }
3008 } else Slog.w(TAG, "Archive is encrypted but no password given");
3009 } else Slog.w(TAG, "Wrong header version: " + s);
3010 } else Slog.w(TAG, "Didn't read the right header magic");
Christopher Tate7bdb0962011-07-13 19:30:21 -07003011
3012 if (!okay) {
Christopher Tate2efd2db2011-07-19 16:32:49 -07003013 Slog.w(TAG, "Invalid restore data; aborting.");
Christopher Tate7bdb0962011-07-13 19:30:21 -07003014 return;
3015 }
3016
3017 // okay, use the right stream layer based on compression
Christopher Tate2efd2db2011-07-19 16:32:49 -07003018 in = (compressed) ? new InflaterInputStream(preCompressStream) : preCompressStream;
Christopher Tate75a99702011-05-18 16:28:19 -07003019
3020 boolean didRestore;
3021 do {
Christopher Tate7926a692011-07-11 11:31:57 -07003022 didRestore = restoreOneFile(in, buffer);
Christopher Tate75a99702011-05-18 16:28:19 -07003023 } while (didRestore);
3024
Christopher Tatec58efa62011-08-01 19:20:14 -07003025 if (MORE_DEBUG) Slog.v(TAG, "Done consuming input tarfile, total bytes=" + mBytes);
Christopher Tate7bdb0962011-07-13 19:30:21 -07003026 } catch (IOException e) {
3027 Slog.e(TAG, "Unable to read restore input");
Christopher Tate75a99702011-05-18 16:28:19 -07003028 } finally {
3029 tearDownPipes();
3030 tearDownAgent(mTargetApp);
3031
3032 try {
Christopher Tate2efd2db2011-07-19 16:32:49 -07003033 if (rawDataIn != null) rawDataIn.close();
3034 if (rawInStream != null) rawInStream.close();
Christopher Tate75a99702011-05-18 16:28:19 -07003035 mInputFile.close();
3036 } catch (IOException e) {
Christopher Tatee9e78ec2011-06-08 20:09:31 -07003037 Slog.w(TAG, "Close of restore data pipe threw", e);
Christopher Tate75a99702011-05-18 16:28:19 -07003038 /* nothing we can do about this */
3039 }
3040 synchronized (mCurrentOpLock) {
3041 mCurrentOperations.clear();
3042 }
3043 synchronized (mLatchObject) {
3044 mLatchObject.set(true);
3045 mLatchObject.notifyAll();
3046 }
3047 sendEndRestore();
Christopher Tatec58efa62011-08-01 19:20:14 -07003048 Slog.d(TAG, "Full restore pass complete.");
Christopher Tate336a6492011-10-05 16:05:43 -07003049 mWakelock.release();
Christopher Tate75a99702011-05-18 16:28:19 -07003050 }
3051 }
3052
Christopher Tate7bdb0962011-07-13 19:30:21 -07003053 String readHeaderLine(InputStream in) throws IOException {
3054 int c;
Christopher Tate2efd2db2011-07-19 16:32:49 -07003055 StringBuilder buffer = new StringBuilder(80);
Christopher Tate7bdb0962011-07-13 19:30:21 -07003056 while ((c = in.read()) >= 0) {
3057 if (c == '\n') break; // consume and discard the newlines
3058 buffer.append((char)c);
3059 }
3060 return buffer.toString();
3061 }
3062
Christopher Tate2efd2db2011-07-19 16:32:49 -07003063 InputStream decodeAesHeaderAndInitialize(String encryptionName, InputStream rawInStream) {
3064 InputStream result = null;
3065 try {
3066 if (encryptionName.equals(ENCRYPTION_ALGORITHM_NAME)) {
3067
3068 String userSaltHex = readHeaderLine(rawInStream); // 5
3069 byte[] userSalt = hexToByteArray(userSaltHex);
3070
3071 String ckSaltHex = readHeaderLine(rawInStream); // 6
3072 byte[] ckSalt = hexToByteArray(ckSaltHex);
3073
3074 int rounds = Integer.parseInt(readHeaderLine(rawInStream)); // 7
3075 String userIvHex = readHeaderLine(rawInStream); // 8
3076
3077 String masterKeyBlobHex = readHeaderLine(rawInStream); // 9
3078
3079 // decrypt the master key blob
3080 Cipher c = Cipher.getInstance("AES/CBC/PKCS5Padding");
Christopher Tate728a1c42011-07-28 18:03:03 -07003081 SecretKey userKey = buildPasswordKey(mDecryptPassword, userSalt,
Christopher Tate2efd2db2011-07-19 16:32:49 -07003082 rounds);
3083 byte[] IV = hexToByteArray(userIvHex);
3084 IvParameterSpec ivSpec = new IvParameterSpec(IV);
3085 c.init(Cipher.DECRYPT_MODE,
3086 new SecretKeySpec(userKey.getEncoded(), "AES"),
3087 ivSpec);
3088 byte[] mkCipher = hexToByteArray(masterKeyBlobHex);
3089 byte[] mkBlob = c.doFinal(mkCipher);
3090
3091 // first, the master key IV
3092 int offset = 0;
3093 int len = mkBlob[offset++];
3094 IV = Arrays.copyOfRange(mkBlob, offset, offset + len);
3095 offset += len;
3096 // then the master key itself
3097 len = mkBlob[offset++];
3098 byte[] mk = Arrays.copyOfRange(mkBlob,
3099 offset, offset + len);
3100 offset += len;
3101 // and finally the master key checksum hash
3102 len = mkBlob[offset++];
3103 byte[] mkChecksum = Arrays.copyOfRange(mkBlob,
3104 offset, offset + len);
3105
3106 // now validate the decrypted master key against the checksum
3107 byte[] calculatedCk = makeKeyChecksum(mk, ckSalt, rounds);
3108 if (Arrays.equals(calculatedCk, mkChecksum)) {
3109 ivSpec = new IvParameterSpec(IV);
3110 c.init(Cipher.DECRYPT_MODE,
3111 new SecretKeySpec(mk, "AES"),
3112 ivSpec);
3113 // Only if all of the above worked properly will 'result' be assigned
3114 result = new CipherInputStream(rawInStream, c);
3115 } else Slog.w(TAG, "Incorrect password");
3116 } else Slog.w(TAG, "Unsupported encryption method: " + encryptionName);
3117 } catch (InvalidAlgorithmParameterException e) {
3118 Slog.e(TAG, "Needed parameter spec unavailable!", e);
3119 } catch (BadPaddingException e) {
3120 // This case frequently occurs when the wrong password is used to decrypt
3121 // the master key. Use the identical "incorrect password" log text as is
3122 // used in the checksum failure log in order to avoid providing additional
3123 // information to an attacker.
3124 Slog.w(TAG, "Incorrect password");
3125 } catch (IllegalBlockSizeException e) {
3126 Slog.w(TAG, "Invalid block size in master key");
3127 } catch (NoSuchAlgorithmException e) {
3128 Slog.e(TAG, "Needed decryption algorithm unavailable!");
3129 } catch (NoSuchPaddingException e) {
3130 Slog.e(TAG, "Needed padding mechanism unavailable!");
3131 } catch (InvalidKeyException e) {
3132 Slog.w(TAG, "Illegal password; aborting");
3133 } catch (NumberFormatException e) {
3134 Slog.w(TAG, "Can't parse restore data header");
3135 } catch (IOException e) {
3136 Slog.w(TAG, "Can't read input header");
3137 }
3138
3139 return result;
3140 }
3141
Christopher Tate75a99702011-05-18 16:28:19 -07003142 boolean restoreOneFile(InputStream instream, byte[] buffer) {
3143 FileMetadata info;
3144 try {
3145 info = readTarHeaders(instream);
3146 if (info != null) {
Christopher Tatec58efa62011-08-01 19:20:14 -07003147 if (MORE_DEBUG) {
Christopher Tate75a99702011-05-18 16:28:19 -07003148 dumpFileMetadata(info);
3149 }
3150
3151 final String pkg = info.packageName;
3152 if (!pkg.equals(mAgentPackage)) {
3153 // okay, change in package; set up our various
3154 // bookkeeping if we haven't seen it yet
3155 if (!mPackagePolicies.containsKey(pkg)) {
3156 mPackagePolicies.put(pkg, RestorePolicy.IGNORE);
3157 }
3158
3159 // Clean up the previous agent relationship if necessary,
3160 // and let the observer know we're considering a new app.
3161 if (mAgent != null) {
3162 if (DEBUG) Slog.d(TAG, "Saw new package; tearing down old one");
3163 tearDownPipes();
3164 tearDownAgent(mTargetApp);
3165 mTargetApp = null;
3166 mAgentPackage = null;
3167 }
3168 }
3169
3170 if (info.path.equals(BACKUP_MANIFEST_FILENAME)) {
3171 mPackagePolicies.put(pkg, readAppManifest(info, instream));
3172 mPackageInstallers.put(pkg, info.installerPackageName);
3173 // We've read only the manifest content itself at this point,
3174 // so consume the footer before looping around to the next
3175 // input file
3176 skipTarPadding(info.size, instream);
3177 sendOnRestorePackage(pkg);
3178 } else {
3179 // Non-manifest, so it's actual file data. Is this a package
3180 // we're ignoring?
3181 boolean okay = true;
3182 RestorePolicy policy = mPackagePolicies.get(pkg);
3183 switch (policy) {
3184 case IGNORE:
3185 okay = false;
3186 break;
3187
3188 case ACCEPT_IF_APK:
3189 // If we're in accept-if-apk state, then the first file we
3190 // see MUST be the apk.
3191 if (info.domain.equals(FullBackup.APK_TREE_TOKEN)) {
3192 if (DEBUG) Slog.d(TAG, "APK file; installing");
3193 // Try to install the app.
3194 String installerName = mPackageInstallers.get(pkg);
3195 okay = installApk(info, installerName, instream);
3196 // good to go; promote to ACCEPT
3197 mPackagePolicies.put(pkg, (okay)
3198 ? RestorePolicy.ACCEPT
3199 : RestorePolicy.IGNORE);
3200 // At this point we've consumed this file entry
3201 // ourselves, so just strip the tar footer and
3202 // go on to the next file in the input stream
3203 skipTarPadding(info.size, instream);
3204 return true;
3205 } else {
3206 // File data before (or without) the apk. We can't
3207 // handle it coherently in this case so ignore it.
3208 mPackagePolicies.put(pkg, RestorePolicy.IGNORE);
3209 okay = false;
3210 }
3211 break;
3212
3213 case ACCEPT:
3214 if (info.domain.equals(FullBackup.APK_TREE_TOKEN)) {
3215 if (DEBUG) Slog.d(TAG, "apk present but ACCEPT");
3216 // we can take the data without the apk, so we
3217 // *want* to do so. skip the apk by declaring this
3218 // one file not-okay without changing the restore
3219 // policy for the package.
3220 okay = false;
3221 }
3222 break;
3223
3224 default:
3225 // Something has gone dreadfully wrong when determining
3226 // the restore policy from the manifest. Ignore the
3227 // rest of this package's data.
3228 Slog.e(TAG, "Invalid policy from manifest");
3229 okay = false;
3230 mPackagePolicies.put(pkg, RestorePolicy.IGNORE);
3231 break;
3232 }
3233
3234 // If the policy is satisfied, go ahead and set up to pipe the
3235 // data to the agent.
3236 if (DEBUG && okay && mAgent != null) {
3237 Slog.i(TAG, "Reusing existing agent instance");
3238 }
3239 if (okay && mAgent == null) {
3240 if (DEBUG) Slog.d(TAG, "Need to launch agent for " + pkg);
3241
3242 try {
3243 mTargetApp = mPackageManager.getApplicationInfo(pkg, 0);
3244
3245 // If we haven't sent any data to this app yet, we probably
3246 // need to clear it first. Check that.
3247 if (!mClearedPackages.contains(pkg)) {
Christopher Tate79ec80d2011-06-24 14:58:49 -07003248 // apps with their own backup agents are
Christopher Tate75a99702011-05-18 16:28:19 -07003249 // responsible for coherently managing a full
3250 // restore.
Christopher Tate79ec80d2011-06-24 14:58:49 -07003251 if (mTargetApp.backupAgentName == null) {
Christopher Tate75a99702011-05-18 16:28:19 -07003252 if (DEBUG) Slog.d(TAG, "Clearing app data preparatory to full restore");
3253 clearApplicationDataSynchronous(pkg);
3254 } else {
Christopher Tate79ec80d2011-06-24 14:58:49 -07003255 if (DEBUG) Slog.d(TAG, "backup agent ("
3256 + mTargetApp.backupAgentName + ") => no clear");
Christopher Tate75a99702011-05-18 16:28:19 -07003257 }
3258 mClearedPackages.add(pkg);
3259 } else {
3260 if (DEBUG) Slog.d(TAG, "We've initialized this app already; no clear required");
3261 }
3262
3263 // All set; now set up the IPC and launch the agent
3264 setUpPipes();
3265 mAgent = bindToAgentSynchronous(mTargetApp,
3266 IApplicationThread.BACKUP_MODE_RESTORE_FULL);
3267 mAgentPackage = pkg;
3268 } catch (IOException e) {
3269 // fall through to error handling
3270 } catch (NameNotFoundException e) {
3271 // fall through to error handling
3272 }
3273
3274 if (mAgent == null) {
3275 if (DEBUG) Slog.d(TAG, "Unable to create agent for " + pkg);
3276 okay = false;
3277 tearDownPipes();
3278 mPackagePolicies.put(pkg, RestorePolicy.IGNORE);
3279 }
3280 }
3281
3282 // Sanity check: make sure we never give data to the wrong app. This
3283 // should never happen but a little paranoia here won't go amiss.
3284 if (okay && !pkg.equals(mAgentPackage)) {
3285 Slog.e(TAG, "Restoring data for " + pkg
3286 + " but agent is for " + mAgentPackage);
3287 okay = false;
3288 }
3289
3290 // At this point we have an agent ready to handle the full
3291 // restore data as well as a pipe for sending data to
3292 // that agent. Tell the agent to start reading from the
3293 // pipe.
3294 if (okay) {
3295 boolean agentSuccess = true;
3296 long toCopy = info.size;
3297 final int token = generateToken();
3298 try {
3299 if (DEBUG) Slog.d(TAG, "Invoking agent to restore file "
3300 + info.path);
Christopher Tate8e294d42011-08-31 20:37:12 -07003301 prepareOperationTimeout(token, TIMEOUT_FULL_BACKUP_INTERVAL, null);
Christopher Tate75a99702011-05-18 16:28:19 -07003302 // fire up the app's agent listening on the socket. If
3303 // the agent is running in the system process we can't
3304 // just invoke it asynchronously, so we provide a thread
3305 // for it here.
3306 if (mTargetApp.processName.equals("system")) {
3307 Slog.d(TAG, "system process agent - spinning a thread");
3308 RestoreFileRunnable runner = new RestoreFileRunnable(
3309 mAgent, info, mPipes[0], token);
3310 new Thread(runner).start();
3311 } else {
3312 mAgent.doRestoreFile(mPipes[0], info.size, info.type,
3313 info.domain, info.path, info.mode, info.mtime,
3314 token, mBackupManagerBinder);
3315 }
3316 } catch (IOException e) {
3317 // couldn't dup the socket for a process-local restore
3318 Slog.d(TAG, "Couldn't establish restore");
3319 agentSuccess = false;
3320 okay = false;
3321 } catch (RemoteException e) {
3322 // whoops, remote agent went away. We'll eat the content
3323 // ourselves, then, and not copy it over.
3324 Slog.e(TAG, "Agent crashed during full restore");
3325 agentSuccess = false;
3326 okay = false;
3327 }
3328
3329 // Copy over the data if the agent is still good
3330 if (okay) {
3331 boolean pipeOkay = true;
3332 FileOutputStream pipe = new FileOutputStream(
3333 mPipes[1].getFileDescriptor());
Christopher Tate75a99702011-05-18 16:28:19 -07003334 while (toCopy > 0) {
3335 int toRead = (toCopy > buffer.length)
3336 ? buffer.length : (int)toCopy;
3337 int nRead = instream.read(buffer, 0, toRead);
Christopher Tatee9e78ec2011-06-08 20:09:31 -07003338 if (nRead >= 0) mBytes += nRead;
Christopher Tate75a99702011-05-18 16:28:19 -07003339 if (nRead <= 0) break;
3340 toCopy -= nRead;
3341
3342 // send it to the output pipe as long as things
3343 // are still good
3344 if (pipeOkay) {
3345 try {
3346 pipe.write(buffer, 0, nRead);
3347 } catch (IOException e) {
Christopher Tatee9e78ec2011-06-08 20:09:31 -07003348 Slog.e(TAG, "Failed to write to restore pipe", e);
Christopher Tate75a99702011-05-18 16:28:19 -07003349 pipeOkay = false;
3350 }
3351 }
3352 }
3353
3354 // done sending that file! Now we just need to consume
3355 // the delta from info.size to the end of block.
3356 skipTarPadding(info.size, instream);
3357
3358 // and now that we've sent it all, wait for the remote
3359 // side to acknowledge receipt
3360 agentSuccess = waitUntilOperationComplete(token);
3361 }
3362
3363 // okay, if the remote end failed at any point, deal with
3364 // it by ignoring the rest of the restore on it
3365 if (!agentSuccess) {
3366 mBackupHandler.removeMessages(MSG_TIMEOUT);
3367 tearDownPipes();
3368 tearDownAgent(mTargetApp);
3369 mAgent = null;
3370 mPackagePolicies.put(pkg, RestorePolicy.IGNORE);
3371 }
3372 }
3373
3374 // Problems setting up the agent communication, or an already-
3375 // ignored package: skip to the next tar stream entry by
3376 // reading and discarding this file.
3377 if (!okay) {
3378 if (DEBUG) Slog.d(TAG, "[discarding file content]");
3379 long bytesToConsume = (info.size + 511) & ~511;
3380 while (bytesToConsume > 0) {
3381 int toRead = (bytesToConsume > buffer.length)
3382 ? buffer.length : (int)bytesToConsume;
3383 long nRead = instream.read(buffer, 0, toRead);
Christopher Tatee9e78ec2011-06-08 20:09:31 -07003384 if (nRead >= 0) mBytes += nRead;
Christopher Tate75a99702011-05-18 16:28:19 -07003385 if (nRead <= 0) break;
3386 bytesToConsume -= nRead;
3387 }
3388 }
3389 }
3390 }
3391 } catch (IOException e) {
Christopher Tate2efd2db2011-07-19 16:32:49 -07003392 if (DEBUG) Slog.w(TAG, "io exception on restore socket read", e);
Christopher Tate75a99702011-05-18 16:28:19 -07003393 // treat as EOF
3394 info = null;
3395 }
3396
3397 return (info != null);
3398 }
3399
3400 void setUpPipes() throws IOException {
3401 mPipes = ParcelFileDescriptor.createPipe();
3402 }
3403
3404 void tearDownPipes() {
3405 if (mPipes != null) {
Christopher Tatee9e78ec2011-06-08 20:09:31 -07003406 try {
3407 mPipes[0].close();
3408 mPipes[0] = null;
3409 mPipes[1].close();
3410 mPipes[1] = null;
3411 } catch (IOException e) {
3412 Slog.w(TAG, "Couldn't close agent pipes", e);
Christopher Tate75a99702011-05-18 16:28:19 -07003413 }
3414 mPipes = null;
3415 }
3416 }
3417
3418 void tearDownAgent(ApplicationInfo app) {
3419 if (mAgent != null) {
3420 try {
3421 // unbind and tidy up even on timeout or failure, just in case
3422 mActivityManager.unbindBackupAgent(app);
3423
3424 // The agent was running with a stub Application object, so shut it down.
3425 // !!! We hardcode the confirmation UI's package name here rather than use a
3426 // manifest flag! TODO something less direct.
3427 if (app.uid != Process.SYSTEM_UID
3428 && !app.packageName.equals("com.android.backupconfirm")) {
3429 if (DEBUG) Slog.d(TAG, "Killing host process");
3430 mActivityManager.killApplicationProcess(app.processName, app.uid);
3431 } else {
3432 if (DEBUG) Slog.d(TAG, "Not killing after full restore");
3433 }
3434 } catch (RemoteException e) {
3435 Slog.d(TAG, "Lost app trying to shut down");
3436 }
3437 mAgent = null;
3438 }
3439 }
3440
3441 class RestoreInstallObserver extends IPackageInstallObserver.Stub {
3442 final AtomicBoolean mDone = new AtomicBoolean();
Christopher Tatea858cb02011-06-03 12:27:51 -07003443 String mPackageName;
Christopher Tate75a99702011-05-18 16:28:19 -07003444 int mResult;
3445
3446 public void reset() {
3447 synchronized (mDone) {
3448 mDone.set(false);
3449 }
3450 }
3451
3452 public void waitForCompletion() {
3453 synchronized (mDone) {
3454 while (mDone.get() == false) {
3455 try {
3456 mDone.wait();
3457 } catch (InterruptedException e) { }
3458 }
3459 }
3460 }
3461
3462 int getResult() {
3463 return mResult;
3464 }
3465
3466 @Override
3467 public void packageInstalled(String packageName, int returnCode)
3468 throws RemoteException {
3469 synchronized (mDone) {
3470 mResult = returnCode;
Christopher Tatea858cb02011-06-03 12:27:51 -07003471 mPackageName = packageName;
Christopher Tate75a99702011-05-18 16:28:19 -07003472 mDone.set(true);
3473 mDone.notifyAll();
3474 }
3475 }
3476 }
Christopher Tatea858cb02011-06-03 12:27:51 -07003477
3478 class RestoreDeleteObserver extends IPackageDeleteObserver.Stub {
3479 final AtomicBoolean mDone = new AtomicBoolean();
3480 int mResult;
3481
3482 public void reset() {
3483 synchronized (mDone) {
3484 mDone.set(false);
3485 }
3486 }
3487
3488 public void waitForCompletion() {
3489 synchronized (mDone) {
3490 while (mDone.get() == false) {
3491 try {
3492 mDone.wait();
3493 } catch (InterruptedException e) { }
3494 }
3495 }
3496 }
3497
3498 @Override
3499 public void packageDeleted(String packageName, int returnCode) throws RemoteException {
3500 synchronized (mDone) {
3501 mResult = returnCode;
3502 mDone.set(true);
3503 mDone.notifyAll();
3504 }
3505 }
3506 }
3507
Christopher Tate75a99702011-05-18 16:28:19 -07003508 final RestoreInstallObserver mInstallObserver = new RestoreInstallObserver();
Christopher Tatea858cb02011-06-03 12:27:51 -07003509 final RestoreDeleteObserver mDeleteObserver = new RestoreDeleteObserver();
Christopher Tate75a99702011-05-18 16:28:19 -07003510
3511 boolean installApk(FileMetadata info, String installerPackage, InputStream instream) {
3512 boolean okay = true;
3513
3514 if (DEBUG) Slog.d(TAG, "Installing from backup: " + info.packageName);
3515
3516 // The file content is an .apk file. Copy it out to a staging location and
3517 // attempt to install it.
3518 File apkFile = new File(mDataDir, info.packageName);
3519 try {
3520 FileOutputStream apkStream = new FileOutputStream(apkFile);
3521 byte[] buffer = new byte[32 * 1024];
3522 long size = info.size;
3523 while (size > 0) {
3524 long toRead = (buffer.length < size) ? buffer.length : size;
3525 int didRead = instream.read(buffer, 0, (int)toRead);
Christopher Tatee9e78ec2011-06-08 20:09:31 -07003526 if (didRead >= 0) mBytes += didRead;
Christopher Tate75a99702011-05-18 16:28:19 -07003527 apkStream.write(buffer, 0, didRead);
3528 size -= didRead;
3529 }
3530 apkStream.close();
3531
3532 // make sure the installer can read it
3533 apkFile.setReadable(true, false);
3534
3535 // Now install it
3536 Uri packageUri = Uri.fromFile(apkFile);
3537 mInstallObserver.reset();
3538 mPackageManager.installPackage(packageUri, mInstallObserver,
Christopher Tateab63aa82011-09-26 16:30:30 -07003539 PackageManager.INSTALL_REPLACE_EXISTING | PackageManager.INSTALL_FROM_ADB,
3540 installerPackage);
Christopher Tate75a99702011-05-18 16:28:19 -07003541 mInstallObserver.waitForCompletion();
3542
3543 if (mInstallObserver.getResult() != PackageManager.INSTALL_SUCCEEDED) {
3544 // The only time we continue to accept install of data even if the
3545 // apk install failed is if we had already determined that we could
3546 // accept the data regardless.
3547 if (mPackagePolicies.get(info.packageName) != RestorePolicy.ACCEPT) {
3548 okay = false;
3549 }
Christopher Tatea858cb02011-06-03 12:27:51 -07003550 } else {
3551 // Okay, the install succeeded. Make sure it was the right app.
3552 boolean uninstall = false;
3553 if (!mInstallObserver.mPackageName.equals(info.packageName)) {
3554 Slog.w(TAG, "Restore stream claimed to include apk for "
3555 + info.packageName + " but apk was really "
3556 + mInstallObserver.mPackageName);
3557 // delete the package we just put in place; it might be fraudulent
3558 okay = false;
3559 uninstall = true;
3560 } else {
3561 try {
3562 PackageInfo pkg = mPackageManager.getPackageInfo(info.packageName,
3563 PackageManager.GET_SIGNATURES);
3564 if ((pkg.applicationInfo.flags & ApplicationInfo.FLAG_ALLOW_BACKUP) == 0) {
3565 Slog.w(TAG, "Restore stream contains apk of package "
3566 + info.packageName + " but it disallows backup/restore");
3567 okay = false;
3568 } else {
3569 // So far so good -- do the signatures match the manifest?
3570 Signature[] sigs = mManifestSignatures.get(info.packageName);
3571 if (!signaturesMatch(sigs, pkg)) {
3572 Slog.w(TAG, "Installed app " + info.packageName
3573 + " signatures do not match restore manifest");
3574 okay = false;
3575 uninstall = true;
3576 }
3577 }
3578 } catch (NameNotFoundException e) {
3579 Slog.w(TAG, "Install of package " + info.packageName
3580 + " succeeded but now not found");
3581 okay = false;
3582 }
3583 }
3584
3585 // If we're not okay at this point, we need to delete the package
3586 // that we just installed.
3587 if (uninstall) {
3588 mDeleteObserver.reset();
3589 mPackageManager.deletePackage(mInstallObserver.mPackageName,
3590 mDeleteObserver, 0);
3591 mDeleteObserver.waitForCompletion();
3592 }
Christopher Tate75a99702011-05-18 16:28:19 -07003593 }
3594 } catch (IOException e) {
3595 Slog.e(TAG, "Unable to transcribe restored apk for install");
3596 okay = false;
3597 } finally {
3598 apkFile.delete();
3599 }
3600
3601 return okay;
3602 }
3603
3604 // Given an actual file content size, consume the post-content padding mandated
3605 // by the tar format.
3606 void skipTarPadding(long size, InputStream instream) throws IOException {
3607 long partial = (size + 512) % 512;
3608 if (partial > 0) {
Christopher Tate6853fcf2011-08-10 17:52:21 -07003609 final int needed = 512 - (int)partial;
3610 byte[] buffer = new byte[needed];
3611 if (readExactly(instream, buffer, 0, needed) == needed) {
3612 mBytes += needed;
3613 } else throw new IOException("Unexpected EOF in padding");
Christopher Tate75a99702011-05-18 16:28:19 -07003614 }
3615 }
3616
3617 // Returns a policy constant; takes a buffer arg to reduce memory churn
3618 RestorePolicy readAppManifest(FileMetadata info, InputStream instream)
3619 throws IOException {
3620 // Fail on suspiciously large manifest files
3621 if (info.size > 64 * 1024) {
3622 throw new IOException("Restore manifest too big; corrupt? size=" + info.size);
3623 }
Christopher Tate6853fcf2011-08-10 17:52:21 -07003624
Christopher Tate75a99702011-05-18 16:28:19 -07003625 byte[] buffer = new byte[(int) info.size];
Christopher Tate6853fcf2011-08-10 17:52:21 -07003626 if (readExactly(instream, buffer, 0, (int)info.size) == info.size) {
3627 mBytes += info.size;
3628 } else throw new IOException("Unexpected EOF in manifest");
Christopher Tate75a99702011-05-18 16:28:19 -07003629
3630 RestorePolicy policy = RestorePolicy.IGNORE;
3631 String[] str = new String[1];
3632 int offset = 0;
3633
3634 try {
3635 offset = extractLine(buffer, offset, str);
3636 int version = Integer.parseInt(str[0]);
3637 if (version == BACKUP_MANIFEST_VERSION) {
3638 offset = extractLine(buffer, offset, str);
3639 String manifestPackage = str[0];
3640 // TODO: handle <original-package>
3641 if (manifestPackage.equals(info.packageName)) {
3642 offset = extractLine(buffer, offset, str);
3643 version = Integer.parseInt(str[0]); // app version
3644 offset = extractLine(buffer, offset, str);
3645 int platformVersion = Integer.parseInt(str[0]);
3646 offset = extractLine(buffer, offset, str);
3647 info.installerPackageName = (str[0].length() > 0) ? str[0] : null;
3648 offset = extractLine(buffer, offset, str);
3649 boolean hasApk = str[0].equals("1");
3650 offset = extractLine(buffer, offset, str);
3651 int numSigs = Integer.parseInt(str[0]);
Christopher Tate75a99702011-05-18 16:28:19 -07003652 if (numSigs > 0) {
Christopher Tatea858cb02011-06-03 12:27:51 -07003653 Signature[] sigs = new Signature[numSigs];
Christopher Tate75a99702011-05-18 16:28:19 -07003654 for (int i = 0; i < numSigs; i++) {
3655 offset = extractLine(buffer, offset, str);
3656 sigs[i] = new Signature(str[0]);
3657 }
Christopher Tatea858cb02011-06-03 12:27:51 -07003658 mManifestSignatures.put(info.packageName, sigs);
Christopher Tate75a99702011-05-18 16:28:19 -07003659
3660 // Okay, got the manifest info we need...
3661 try {
Christopher Tate75a99702011-05-18 16:28:19 -07003662 PackageInfo pkgInfo = mPackageManager.getPackageInfo(
3663 info.packageName, PackageManager.GET_SIGNATURES);
Christopher Tatea858cb02011-06-03 12:27:51 -07003664 // Fall through to IGNORE if the app explicitly disallows backup
3665 final int flags = pkgInfo.applicationInfo.flags;
3666 if ((flags & ApplicationInfo.FLAG_ALLOW_BACKUP) != 0) {
3667 // Verify signatures against any installed version; if they
3668 // don't match, then we fall though and ignore the data. The
3669 // signatureMatch() method explicitly ignores the signature
3670 // check for packages installed on the system partition, because
3671 // such packages are signed with the platform cert instead of
3672 // the app developer's cert, so they're different on every
3673 // device.
3674 if (signaturesMatch(sigs, pkgInfo)) {
3675 if (pkgInfo.versionCode >= version) {
3676 Slog.i(TAG, "Sig + version match; taking data");
3677 policy = RestorePolicy.ACCEPT;
3678 } else {
3679 // The data is from a newer version of the app than
3680 // is presently installed. That means we can only
3681 // use it if the matching apk is also supplied.
3682 Slog.d(TAG, "Data version " + version
3683 + " is newer than installed version "
3684 + pkgInfo.versionCode + " - requiring apk");
3685 policy = RestorePolicy.ACCEPT_IF_APK;
3686 }
Christopher Tate75a99702011-05-18 16:28:19 -07003687 } else {
Christopher Tatea858cb02011-06-03 12:27:51 -07003688 Slog.w(TAG, "Restore manifest signatures do not match "
3689 + "installed application for " + info.packageName);
Christopher Tate75a99702011-05-18 16:28:19 -07003690 }
Christopher Tatea858cb02011-06-03 12:27:51 -07003691 } else {
3692 if (DEBUG) Slog.i(TAG, "Restore manifest from "
3693 + info.packageName + " but allowBackup=false");
Christopher Tate75a99702011-05-18 16:28:19 -07003694 }
3695 } catch (NameNotFoundException e) {
3696 // Okay, the target app isn't installed. We can process
3697 // the restore properly only if the dataset provides the
3698 // apk file and we can successfully install it.
3699 if (DEBUG) Slog.i(TAG, "Package " + info.packageName
3700 + " not installed; requiring apk in dataset");
3701 policy = RestorePolicy.ACCEPT_IF_APK;
3702 }
3703
3704 if (policy == RestorePolicy.ACCEPT_IF_APK && !hasApk) {
3705 Slog.i(TAG, "Cannot restore package " + info.packageName
3706 + " without the matching .apk");
3707 }
3708 } else {
3709 Slog.i(TAG, "Missing signature on backed-up package "
3710 + info.packageName);
3711 }
3712 } else {
3713 Slog.i(TAG, "Expected package " + info.packageName
3714 + " but restore manifest claims " + manifestPackage);
3715 }
3716 } else {
3717 Slog.i(TAG, "Unknown restore manifest version " + version
3718 + " for package " + info.packageName);
3719 }
3720 } catch (NumberFormatException e) {
3721 Slog.w(TAG, "Corrupt restore manifest for package " + info.packageName);
Kenny Root11373412011-07-28 15:13:33 -07003722 } catch (IllegalArgumentException e) {
3723 Slog.w(TAG, e.getMessage());
Christopher Tate75a99702011-05-18 16:28:19 -07003724 }
3725
3726 return policy;
3727 }
3728
3729 // Builds a line from a byte buffer starting at 'offset', and returns
3730 // the index of the next unconsumed data in the buffer.
3731 int extractLine(byte[] buffer, int offset, String[] outStr) throws IOException {
3732 final int end = buffer.length;
3733 if (offset >= end) throw new IOException("Incomplete data");
3734
3735 int pos;
3736 for (pos = offset; pos < end; pos++) {
3737 byte c = buffer[pos];
3738 // at LF we declare end of line, and return the next char as the
3739 // starting point for the next time through
3740 if (c == '\n') {
3741 break;
3742 }
3743 }
3744 outStr[0] = new String(buffer, offset, pos - offset);
3745 pos++; // may be pointing an extra byte past the end but that's okay
3746 return pos;
3747 }
3748
3749 void dumpFileMetadata(FileMetadata info) {
3750 if (DEBUG) {
3751 StringBuilder b = new StringBuilder(128);
3752
3753 // mode string
Christopher Tate79ec80d2011-06-24 14:58:49 -07003754 b.append((info.type == BackupAgent.TYPE_DIRECTORY) ? 'd' : '-');
Christopher Tate75a99702011-05-18 16:28:19 -07003755 b.append(((info.mode & 0400) != 0) ? 'r' : '-');
3756 b.append(((info.mode & 0200) != 0) ? 'w' : '-');
3757 b.append(((info.mode & 0100) != 0) ? 'x' : '-');
3758 b.append(((info.mode & 0040) != 0) ? 'r' : '-');
3759 b.append(((info.mode & 0020) != 0) ? 'w' : '-');
3760 b.append(((info.mode & 0010) != 0) ? 'x' : '-');
3761 b.append(((info.mode & 0004) != 0) ? 'r' : '-');
3762 b.append(((info.mode & 0002) != 0) ? 'w' : '-');
3763 b.append(((info.mode & 0001) != 0) ? 'x' : '-');
3764 b.append(String.format(" %9d ", info.size));
3765
3766 Date stamp = new Date(info.mtime);
3767 b.append(new SimpleDateFormat("MMM dd kk:mm:ss ").format(stamp));
3768
3769 b.append(info.packageName);
3770 b.append(" :: ");
3771 b.append(info.domain);
3772 b.append(" :: ");
3773 b.append(info.path);
3774
3775 Slog.i(TAG, b.toString());
3776 }
3777 }
3778 // Consume a tar file header block [sequence] and accumulate the relevant metadata
3779 FileMetadata readTarHeaders(InputStream instream) throws IOException {
3780 byte[] block = new byte[512];
3781 FileMetadata info = null;
3782
3783 boolean gotHeader = readTarHeader(instream, block);
3784 if (gotHeader) {
Christopher Tate2efd2db2011-07-19 16:32:49 -07003785 try {
3786 // okay, presume we're okay, and extract the various metadata
3787 info = new FileMetadata();
3788 info.size = extractRadix(block, 124, 12, 8);
3789 info.mtime = extractRadix(block, 136, 12, 8);
3790 info.mode = extractRadix(block, 100, 8, 8);
Christopher Tate75a99702011-05-18 16:28:19 -07003791
Christopher Tate2efd2db2011-07-19 16:32:49 -07003792 info.path = extractString(block, 345, 155); // prefix
3793 String path = extractString(block, 0, 100);
3794 if (path.length() > 0) {
3795 if (info.path.length() > 0) info.path += '/';
3796 info.path += path;
Christopher Tate75a99702011-05-18 16:28:19 -07003797 }
Christopher Tate75a99702011-05-18 16:28:19 -07003798
Christopher Tate2efd2db2011-07-19 16:32:49 -07003799 // tar link indicator field: 1 byte at offset 156 in the header.
3800 int typeChar = block[156];
3801 if (typeChar == 'x') {
3802 // pax extended header, so we need to read that
3803 gotHeader = readPaxExtendedHeader(instream, info);
3804 if (gotHeader) {
3805 // and after a pax extended header comes another real header -- read
3806 // that to find the real file type
3807 gotHeader = readTarHeader(instream, block);
Christopher Tatee9e78ec2011-06-08 20:09:31 -07003808 }
Christopher Tate2efd2db2011-07-19 16:32:49 -07003809 if (!gotHeader) throw new IOException("Bad or missing pax header");
3810
3811 typeChar = block[156];
Christopher Tatee9e78ec2011-06-08 20:09:31 -07003812 }
Christopher Tate75a99702011-05-18 16:28:19 -07003813
Christopher Tate2efd2db2011-07-19 16:32:49 -07003814 switch (typeChar) {
3815 case '0': info.type = BackupAgent.TYPE_FILE; break;
3816 case '5': {
3817 info.type = BackupAgent.TYPE_DIRECTORY;
3818 if (info.size != 0) {
3819 Slog.w(TAG, "Directory entry with nonzero size in header");
3820 info.size = 0;
3821 }
3822 break;
Christopher Tate75a99702011-05-18 16:28:19 -07003823 }
Christopher Tate2efd2db2011-07-19 16:32:49 -07003824 case 0: {
3825 // presume EOF
3826 if (DEBUG) Slog.w(TAG, "Saw type=0 in tar header block, info=" + info);
3827 return null;
3828 }
3829 default: {
3830 Slog.e(TAG, "Unknown tar entity type: " + typeChar);
3831 throw new IOException("Unknown entity type " + typeChar);
3832 }
Christopher Tate75a99702011-05-18 16:28:19 -07003833 }
Christopher Tate2efd2db2011-07-19 16:32:49 -07003834
3835 // Parse out the path
3836 //
3837 // first: apps/shared/unrecognized
3838 if (FullBackup.SHARED_PREFIX.regionMatches(0,
3839 info.path, 0, FullBackup.SHARED_PREFIX.length())) {
3840 // File in shared storage. !!! TODO: implement this.
3841 info.path = info.path.substring(FullBackup.SHARED_PREFIX.length());
Christopher Tate73d73692012-01-20 17:11:31 -08003842 info.packageName = SHARED_BACKUP_AGENT_PACKAGE;
Christopher Tate2efd2db2011-07-19 16:32:49 -07003843 info.domain = FullBackup.SHARED_STORAGE_TOKEN;
3844 if (DEBUG) Slog.i(TAG, "File in shared storage: " + info.path);
3845 } else if (FullBackup.APPS_PREFIX.regionMatches(0,
3846 info.path, 0, FullBackup.APPS_PREFIX.length())) {
3847 // App content! Parse out the package name and domain
3848
3849 // strip the apps/ prefix
3850 info.path = info.path.substring(FullBackup.APPS_PREFIX.length());
3851
3852 // extract the package name
3853 int slash = info.path.indexOf('/');
3854 if (slash < 0) throw new IOException("Illegal semantic path in " + info.path);
3855 info.packageName = info.path.substring(0, slash);
3856 info.path = info.path.substring(slash+1);
3857
3858 // if it's a manifest we're done, otherwise parse out the domains
3859 if (!info.path.equals(BACKUP_MANIFEST_FILENAME)) {
3860 slash = info.path.indexOf('/');
3861 if (slash < 0) throw new IOException("Illegal semantic path in non-manifest " + info.path);
3862 info.domain = info.path.substring(0, slash);
3863 // validate that it's one of the domains we understand
3864 if (!info.domain.equals(FullBackup.APK_TREE_TOKEN)
3865 && !info.domain.equals(FullBackup.DATA_TREE_TOKEN)
3866 && !info.domain.equals(FullBackup.DATABASE_TREE_TOKEN)
3867 && !info.domain.equals(FullBackup.ROOT_TREE_TOKEN)
3868 && !info.domain.equals(FullBackup.SHAREDPREFS_TREE_TOKEN)
3869 && !info.domain.equals(FullBackup.OBB_TREE_TOKEN)
3870 && !info.domain.equals(FullBackup.CACHE_TREE_TOKEN)) {
3871 throw new IOException("Unrecognized domain " + info.domain);
3872 }
3873
3874 info.path = info.path.substring(slash + 1);
3875 }
3876 }
3877 } catch (IOException e) {
3878 if (DEBUG) {
Christopher Tate6853fcf2011-08-10 17:52:21 -07003879 Slog.e(TAG, "Parse error in header: " + e.getMessage());
Christopher Tate2efd2db2011-07-19 16:32:49 -07003880 HEXLOG(block);
3881 }
3882 throw e;
Christopher Tate75a99702011-05-18 16:28:19 -07003883 }
3884 }
3885 return info;
3886 }
3887
Christopher Tate2efd2db2011-07-19 16:32:49 -07003888 private void HEXLOG(byte[] block) {
3889 int offset = 0;
3890 int todo = block.length;
3891 StringBuilder buf = new StringBuilder(64);
3892 while (todo > 0) {
3893 buf.append(String.format("%04x ", offset));
3894 int numThisLine = (todo > 16) ? 16 : todo;
3895 for (int i = 0; i < numThisLine; i++) {
3896 buf.append(String.format("%02x ", block[offset+i]));
3897 }
3898 Slog.i("hexdump", buf.toString());
3899 buf.setLength(0);
3900 todo -= numThisLine;
3901 offset += numThisLine;
Christopher Tate75a99702011-05-18 16:28:19 -07003902 }
Christopher Tate2efd2db2011-07-19 16:32:49 -07003903 }
3904
Christopher Tate6853fcf2011-08-10 17:52:21 -07003905 // Read exactly the given number of bytes into a buffer at the stated offset.
3906 // Returns false if EOF is encountered before the requested number of bytes
3907 // could be read.
3908 int readExactly(InputStream in, byte[] buffer, int offset, int size)
3909 throws IOException {
3910 if (size <= 0) throw new IllegalArgumentException("size must be > 0");
3911
3912 int soFar = 0;
3913 while (soFar < size) {
3914 int nRead = in.read(buffer, offset + soFar, size - soFar);
3915 if (nRead <= 0) {
3916 if (MORE_DEBUG) Slog.w(TAG, "- wanted exactly " + size + " but got only " + soFar);
3917 break;
Christopher Tate2efd2db2011-07-19 16:32:49 -07003918 }
Christopher Tate6853fcf2011-08-10 17:52:21 -07003919 soFar += nRead;
Christopher Tate2efd2db2011-07-19 16:32:49 -07003920 }
Christopher Tate6853fcf2011-08-10 17:52:21 -07003921 return soFar;
3922 }
3923
3924 boolean readTarHeader(InputStream instream, byte[] block) throws IOException {
3925 final int got = readExactly(instream, block, 0, 512);
3926 if (got == 0) return false; // Clean EOF
3927 if (got < 512) throw new IOException("Unable to read full block header");
3928 mBytes += 512;
3929 return true;
Christopher Tate75a99702011-05-18 16:28:19 -07003930 }
3931
3932 // overwrites 'info' fields based on the pax extended header
3933 boolean readPaxExtendedHeader(InputStream instream, FileMetadata info)
3934 throws IOException {
3935 // We should never see a pax extended header larger than this
3936 if (info.size > 32*1024) {
3937 Slog.w(TAG, "Suspiciously large pax header size " + info.size
3938 + " - aborting");
3939 throw new IOException("Sanity failure: pax header size " + info.size);
3940 }
3941
3942 // read whole blocks, not just the content size
3943 int numBlocks = (int)((info.size + 511) >> 9);
3944 byte[] data = new byte[numBlocks * 512];
Christopher Tate6853fcf2011-08-10 17:52:21 -07003945 if (readExactly(instream, data, 0, data.length) < data.length) {
3946 throw new IOException("Unable to read full pax header");
Christopher Tate75a99702011-05-18 16:28:19 -07003947 }
Christopher Tate6853fcf2011-08-10 17:52:21 -07003948 mBytes += data.length;
Christopher Tate75a99702011-05-18 16:28:19 -07003949
3950 final int contentSize = (int) info.size;
3951 int offset = 0;
3952 do {
3953 // extract the line at 'offset'
3954 int eol = offset+1;
3955 while (eol < contentSize && data[eol] != ' ') eol++;
3956 if (eol >= contentSize) {
3957 // error: we just hit EOD looking for the end of the size field
3958 throw new IOException("Invalid pax data");
3959 }
3960 // eol points to the space between the count and the key
3961 int linelen = (int) extractRadix(data, offset, eol - offset, 10);
3962 int key = eol + 1; // start of key=value
3963 eol = offset + linelen - 1; // trailing LF
3964 int value;
3965 for (value = key+1; data[value] != '=' && value <= eol; value++);
3966 if (value > eol) {
3967 throw new IOException("Invalid pax declaration");
3968 }
3969
3970 // pax requires that key/value strings be in UTF-8
3971 String keyStr = new String(data, key, value-key, "UTF-8");
3972 // -1 to strip the trailing LF
3973 String valStr = new String(data, value+1, eol-value-1, "UTF-8");
3974
3975 if ("path".equals(keyStr)) {
3976 info.path = valStr;
3977 } else if ("size".equals(keyStr)) {
3978 info.size = Long.parseLong(valStr);
3979 } else {
3980 if (DEBUG) Slog.i(TAG, "Unhandled pax key: " + key);
3981 }
3982
3983 offset += linelen;
3984 } while (offset < contentSize);
3985
3986 return true;
3987 }
3988
3989 long extractRadix(byte[] data, int offset, int maxChars, int radix)
3990 throws IOException {
3991 long value = 0;
3992 final int end = offset + maxChars;
3993 for (int i = offset; i < end; i++) {
3994 final byte b = data[i];
Christopher Tate3f6c77b2011-06-07 13:17:17 -07003995 // Numeric fields in tar can terminate with either NUL or SPC
Christopher Tate75a99702011-05-18 16:28:19 -07003996 if (b == 0 || b == ' ') break;
3997 if (b < '0' || b > ('0' + radix - 1)) {
Christopher Tate2efd2db2011-07-19 16:32:49 -07003998 throw new IOException("Invalid number in header: '" + (char)b + "' for radix " + radix);
Christopher Tate75a99702011-05-18 16:28:19 -07003999 }
4000 value = radix * value + (b - '0');
4001 }
4002 return value;
4003 }
4004
4005 String extractString(byte[] data, int offset, int maxChars) throws IOException {
4006 final int end = offset + maxChars;
4007 int eos = offset;
Christopher Tate3f6c77b2011-06-07 13:17:17 -07004008 // tar string fields terminate early with a NUL
4009 while (eos < end && data[eos] != 0) eos++;
Christopher Tate75a99702011-05-18 16:28:19 -07004010 return new String(data, offset, eos-offset, "US-ASCII");
4011 }
4012
4013 void sendStartRestore() {
4014 if (mObserver != null) {
4015 try {
4016 mObserver.onStartRestore();
4017 } catch (RemoteException e) {
4018 Slog.w(TAG, "full restore observer went away: startRestore");
4019 mObserver = null;
4020 }
4021 }
4022 }
4023
4024 void sendOnRestorePackage(String name) {
4025 if (mObserver != null) {
4026 try {
4027 // TODO: use a more user-friendly name string
4028 mObserver.onRestorePackage(name);
4029 } catch (RemoteException e) {
4030 Slog.w(TAG, "full restore observer went away: restorePackage");
4031 mObserver = null;
4032 }
4033 }
4034 }
4035
4036 void sendEndRestore() {
4037 if (mObserver != null) {
4038 try {
4039 mObserver.onEndRestore();
4040 } catch (RemoteException e) {
4041 Slog.w(TAG, "full restore observer went away: endRestore");
4042 mObserver = null;
4043 }
4044 }
4045 }
4046 }
4047
Christopher Tatedf01dea2009-06-09 20:45:02 -07004048 // ----- Restore handling -----
4049
Christopher Tate78dd4a72009-11-04 11:49:08 -08004050 private boolean signaturesMatch(Signature[] storedSigs, PackageInfo target) {
4051 // If the target resides on the system partition, we allow it to restore
4052 // data from the like-named package in a restore set even if the signatures
4053 // do not match. (Unlike general applications, those flashed to the system
4054 // partition will be signed with the device's platform certificate, so on
4055 // different phones the same system app will have different signatures.)
4056 if ((target.applicationInfo.flags & ApplicationInfo.FLAG_SYSTEM) != 0) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004057 if (DEBUG) Slog.v(TAG, "System app " + target.packageName + " - skipping sig check");
Christopher Tate78dd4a72009-11-04 11:49:08 -08004058 return true;
4059 }
4060
Christopher Tate20efdf6b2009-06-18 19:41:36 -07004061 // Allow unsigned apps, but not signed on one device and unsigned on the other
4062 // !!! TODO: is this the right policy?
Christopher Tate78dd4a72009-11-04 11:49:08 -08004063 Signature[] deviceSigs = target.signatures;
Christopher Tatec58efa62011-08-01 19:20:14 -07004064 if (MORE_DEBUG) Slog.v(TAG, "signaturesMatch(): stored=" + storedSigs
Christopher Tate6aa41f42009-06-19 14:14:22 -07004065 + " device=" + deviceSigs);
Christopher Tate20efdf6b2009-06-18 19:41:36 -07004066 if ((storedSigs == null || storedSigs.length == 0)
4067 && (deviceSigs == null || deviceSigs.length == 0)) {
4068 return true;
4069 }
4070 if (storedSigs == null || deviceSigs == null) {
4071 return false;
4072 }
4073
Christopher Tateabce4e82009-06-18 18:35:32 -07004074 // !!! TODO: this demands that every stored signature match one
4075 // that is present on device, and does not demand the converse.
4076 // Is this this right policy?
4077 int nStored = storedSigs.length;
4078 int nDevice = deviceSigs.length;
4079
4080 for (int i=0; i < nStored; i++) {
4081 boolean match = false;
4082 for (int j=0; j < nDevice; j++) {
4083 if (storedSigs[i].equals(deviceSigs[j])) {
4084 match = true;
4085 break;
4086 }
4087 }
4088 if (!match) {
4089 return false;
4090 }
4091 }
4092 return true;
4093 }
4094
Christopher Tate2982d062011-09-06 20:35:24 -07004095 enum RestoreState {
4096 INITIAL,
4097 DOWNLOAD_DATA,
4098 PM_METADATA,
4099 RUNNING_QUEUE,
4100 FINAL
4101 }
4102
4103 class PerformRestoreTask implements BackupRestoreTask {
Christopher Tatedf01dea2009-06-09 20:45:02 -07004104 private IBackupTransport mTransport;
Christopher Tate7d562ec2009-06-25 18:03:43 -07004105 private IRestoreObserver mObserver;
Dan Egnor156411d2009-06-26 13:20:02 -07004106 private long mToken;
Christopher Tate84725812010-02-04 15:52:40 -08004107 private PackageInfo mTargetPackage;
Christopher Tate5cb400b2009-06-25 16:03:14 -07004108 private File mStateDir;
Christopher Tate1bb69062010-02-19 17:02:12 -08004109 private int mPmToken;
Chris Tate249345b2010-10-29 12:57:04 -07004110 private boolean mNeedFullBackup;
Christopher Tate284f1bb2011-07-07 14:31:18 -07004111 private HashSet<String> mFilterSet;
Christopher Tate2982d062011-09-06 20:35:24 -07004112 private long mStartRealtime;
4113 private PackageManagerBackupAgent mPmAgent;
4114 private List<PackageInfo> mAgentPackages;
4115 private ArrayList<PackageInfo> mRestorePackages;
4116 private RestoreState mCurrentState;
4117 private int mCount;
4118 private boolean mFinished;
4119 private int mStatus;
4120 private File mBackupDataName;
4121 private File mNewStateName;
4122 private File mSavedStateName;
4123 private ParcelFileDescriptor mBackupData;
4124 private ParcelFileDescriptor mNewState;
4125 private PackageInfo mCurrentPackage;
4126
Christopher Tatedf01dea2009-06-09 20:45:02 -07004127
Christopher Tate5cbbf562009-06-22 16:44:51 -07004128 class RestoreRequest {
4129 public PackageInfo app;
4130 public int storedAppVersion;
4131
4132 RestoreRequest(PackageInfo _app, int _version) {
4133 app = _app;
4134 storedAppVersion = _version;
4135 }
4136 }
4137
Christopher Tate44a27902010-01-27 17:15:49 -08004138 PerformRestoreTask(IBackupTransport transport, IRestoreObserver observer,
Chris Tate249345b2010-10-29 12:57:04 -07004139 long restoreSetToken, PackageInfo targetPackage, int pmToken,
Christopher Tate284f1bb2011-07-07 14:31:18 -07004140 boolean needFullBackup, String[] filterSet) {
Christopher Tate2982d062011-09-06 20:35:24 -07004141 mCurrentState = RestoreState.INITIAL;
4142 mFinished = false;
4143 mPmAgent = null;
4144
Christopher Tatedf01dea2009-06-09 20:45:02 -07004145 mTransport = transport;
Christopher Tate7d562ec2009-06-25 18:03:43 -07004146 mObserver = observer;
Christopher Tate9bbc21a2009-06-10 20:23:25 -07004147 mToken = restoreSetToken;
Christopher Tate84725812010-02-04 15:52:40 -08004148 mTargetPackage = targetPackage;
Christopher Tate1bb69062010-02-19 17:02:12 -08004149 mPmToken = pmToken;
Chris Tate249345b2010-10-29 12:57:04 -07004150 mNeedFullBackup = needFullBackup;
Christopher Tate5cb400b2009-06-25 16:03:14 -07004151
Christopher Tate284f1bb2011-07-07 14:31:18 -07004152 if (filterSet != null) {
4153 mFilterSet = new HashSet<String>();
4154 for (String pkg : filterSet) {
4155 mFilterSet.add(pkg);
4156 }
4157 } else {
4158 mFilterSet = null;
4159 }
4160
Christopher Tate5cb400b2009-06-25 16:03:14 -07004161 try {
4162 mStateDir = new File(mBaseStateDir, transport.transportDirName());
4163 } catch (RemoteException e) {
4164 // can't happen; the transport is local
4165 }
Christopher Tatedf01dea2009-06-09 20:45:02 -07004166 }
4167
Christopher Tate2982d062011-09-06 20:35:24 -07004168 // Execute one tick of whatever state machine the task implements
4169 @Override
4170 public void execute() {
4171 if (MORE_DEBUG) Slog.v(TAG, "*** Executing restore step: " + mCurrentState);
4172 switch (mCurrentState) {
4173 case INITIAL:
4174 beginRestore();
4175 break;
Christopher Tatedf01dea2009-06-09 20:45:02 -07004176
Christopher Tate2982d062011-09-06 20:35:24 -07004177 case DOWNLOAD_DATA:
4178 downloadRestoreData();
4179 break;
Christopher Tate7d562ec2009-06-25 18:03:43 -07004180
Christopher Tate2982d062011-09-06 20:35:24 -07004181 case PM_METADATA:
4182 restorePmMetadata();
4183 break;
4184
4185 case RUNNING_QUEUE:
4186 restoreNextAgent();
4187 break;
4188
4189 case FINAL:
4190 if (!mFinished) finalizeRestore();
4191 else {
4192 Slog.e(TAG, "Duplicate finish");
4193 }
4194 mFinished = true;
4195 break;
4196 }
4197 }
4198
4199 // Initialize and set up for the PM metadata restore, which comes first
4200 void beginRestore() {
4201 // Don't account time doing the restore as inactivity of the app
4202 // that has opened a restore session.
4203 mBackupHandler.removeMessages(MSG_RESTORE_TIMEOUT);
4204
4205 // Assume error until we successfully init everything
4206 mStatus = BackupConstants.TRANSPORT_ERROR;
4207
Christopher Tatedf01dea2009-06-09 20:45:02 -07004208 try {
Dan Egnorbb9001c2009-07-27 12:20:13 -07004209 // TODO: Log this before getAvailableRestoreSets, somehow
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004210 EventLog.writeEvent(EventLogTags.RESTORE_START, mTransport.transportDirName(), mToken);
Christopher Tateabce4e82009-06-18 18:35:32 -07004211
Dan Egnorefe52642009-06-24 00:16:33 -07004212 // Get the list of all packages which have backup enabled.
4213 // (Include the Package Manager metadata pseudo-package first.)
Christopher Tate2982d062011-09-06 20:35:24 -07004214 mRestorePackages = new ArrayList<PackageInfo>();
Dan Egnorefe52642009-06-24 00:16:33 -07004215 PackageInfo omPackage = new PackageInfo();
4216 omPackage.packageName = PACKAGE_MANAGER_SENTINEL;
Christopher Tate2982d062011-09-06 20:35:24 -07004217 mRestorePackages.add(omPackage);
Christopher Tatedf01dea2009-06-09 20:45:02 -07004218
Christopher Tate2982d062011-09-06 20:35:24 -07004219 mAgentPackages = allAgentPackages();
Christopher Tate84725812010-02-04 15:52:40 -08004220 if (mTargetPackage == null) {
Christopher Tate284f1bb2011-07-07 14:31:18 -07004221 // if there's a filter set, strip out anything that isn't
4222 // present before proceeding
4223 if (mFilterSet != null) {
Christopher Tate2982d062011-09-06 20:35:24 -07004224 for (int i = mAgentPackages.size() - 1; i >= 0; i--) {
4225 final PackageInfo pkg = mAgentPackages.get(i);
Christopher Tate284f1bb2011-07-07 14:31:18 -07004226 if (! mFilterSet.contains(pkg.packageName)) {
Christopher Tate2982d062011-09-06 20:35:24 -07004227 mAgentPackages.remove(i);
Christopher Tate284f1bb2011-07-07 14:31:18 -07004228 }
4229 }
Christopher Tate2982d062011-09-06 20:35:24 -07004230 if (MORE_DEBUG) {
Christopher Tate284f1bb2011-07-07 14:31:18 -07004231 Slog.i(TAG, "Post-filter package set for restore:");
Christopher Tate2982d062011-09-06 20:35:24 -07004232 for (PackageInfo p : mAgentPackages) {
Christopher Tate284f1bb2011-07-07 14:31:18 -07004233 Slog.i(TAG, " " + p);
4234 }
4235 }
4236 }
Christopher Tate2982d062011-09-06 20:35:24 -07004237 mRestorePackages.addAll(mAgentPackages);
Christopher Tate84725812010-02-04 15:52:40 -08004238 } else {
4239 // Just one package to attempt restore of
Christopher Tate2982d062011-09-06 20:35:24 -07004240 mRestorePackages.add(mTargetPackage);
Christopher Tate84725812010-02-04 15:52:40 -08004241 }
Dan Egnorefe52642009-06-24 00:16:33 -07004242
Christopher Tate7d562ec2009-06-25 18:03:43 -07004243 // let the observer know that we're running
4244 if (mObserver != null) {
4245 try {
4246 // !!! TODO: get an actual count from the transport after
4247 // its startRestore() runs?
Christopher Tate2982d062011-09-06 20:35:24 -07004248 mObserver.restoreStarting(mRestorePackages.size());
Christopher Tate7d562ec2009-06-25 18:03:43 -07004249 } catch (RemoteException e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004250 Slog.d(TAG, "Restore observer died at restoreStarting");
Christopher Tate7d562ec2009-06-25 18:03:43 -07004251 mObserver = null;
4252 }
4253 }
Christopher Tate2982d062011-09-06 20:35:24 -07004254 } catch (RemoteException e) {
4255 // Something has gone catastrophically wrong with the transport
4256 Slog.e(TAG, "Error communicating with transport for restore");
4257 executeNextState(RestoreState.FINAL);
4258 return;
4259 }
Christopher Tate7d562ec2009-06-25 18:03:43 -07004260
Christopher Tate2982d062011-09-06 20:35:24 -07004261 mStatus = BackupConstants.TRANSPORT_OK;
4262 executeNextState(RestoreState.DOWNLOAD_DATA);
4263 }
4264
4265 void downloadRestoreData() {
4266 // Note that the download phase can be very time consuming, but we're executing
4267 // it inline here on the looper. This is "okay" because it is not calling out to
4268 // third party code; the transport is "trusted," and so we assume it is being a
4269 // good citizen and timing out etc when appropriate.
4270 //
4271 // TODO: when appropriate, move the download off the looper and rearrange the
4272 // error handling around that.
4273 try {
4274 mStatus = mTransport.startRestore(mToken,
4275 mRestorePackages.toArray(new PackageInfo[0]));
4276 if (mStatus != BackupConstants.TRANSPORT_OK) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004277 Slog.e(TAG, "Error starting restore operation");
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004278 EventLog.writeEvent(EventLogTags.RESTORE_TRANSPORT_FAILURE);
Christopher Tate2982d062011-09-06 20:35:24 -07004279 executeNextState(RestoreState.FINAL);
Dan Egnorefe52642009-06-24 00:16:33 -07004280 return;
4281 }
Christopher Tate2982d062011-09-06 20:35:24 -07004282 } catch (RemoteException e) {
4283 Slog.e(TAG, "Error communicating with transport for restore");
4284 EventLog.writeEvent(EventLogTags.RESTORE_TRANSPORT_FAILURE);
4285 mStatus = BackupConstants.TRANSPORT_ERROR;
4286 executeNextState(RestoreState.FINAL);
4287 return;
4288 }
Dan Egnorefe52642009-06-24 00:16:33 -07004289
Christopher Tate2982d062011-09-06 20:35:24 -07004290 // Successful download of the data to be parceled out to the apps, so off we go.
4291 executeNextState(RestoreState.PM_METADATA);
4292 }
4293
4294 void restorePmMetadata() {
4295 try {
Dan Egnorefe52642009-06-24 00:16:33 -07004296 String packageName = mTransport.nextRestorePackage();
4297 if (packageName == null) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004298 Slog.e(TAG, "Error getting first restore package");
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004299 EventLog.writeEvent(EventLogTags.RESTORE_TRANSPORT_FAILURE);
Christopher Tate2982d062011-09-06 20:35:24 -07004300 mStatus = BackupConstants.TRANSPORT_ERROR;
4301 executeNextState(RestoreState.FINAL);
Dan Egnorefe52642009-06-24 00:16:33 -07004302 return;
4303 } else if (packageName.equals("")) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004304 Slog.i(TAG, "No restore data available");
Christopher Tate2982d062011-09-06 20:35:24 -07004305 int millis = (int) (SystemClock.elapsedRealtime() - mStartRealtime);
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004306 EventLog.writeEvent(EventLogTags.RESTORE_SUCCESS, 0, millis);
Christopher Tate2982d062011-09-06 20:35:24 -07004307 mStatus = BackupConstants.TRANSPORT_OK;
4308 executeNextState(RestoreState.FINAL);
Dan Egnorefe52642009-06-24 00:16:33 -07004309 return;
4310 } else if (!packageName.equals(PACKAGE_MANAGER_SENTINEL)) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004311 Slog.e(TAG, "Expected restore data for \"" + PACKAGE_MANAGER_SENTINEL
Christopher Tate2982d062011-09-06 20:35:24 -07004312 + "\", found only \"" + packageName + "\"");
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004313 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE, PACKAGE_MANAGER_SENTINEL,
Dan Egnorbb9001c2009-07-27 12:20:13 -07004314 "Package manager data missing");
Christopher Tate2982d062011-09-06 20:35:24 -07004315 executeNextState(RestoreState.FINAL);
Dan Egnorefe52642009-06-24 00:16:33 -07004316 return;
4317 }
4318
4319 // Pull the Package Manager metadata from the restore set first
Christopher Tate2982d062011-09-06 20:35:24 -07004320 PackageInfo omPackage = new PackageInfo();
4321 omPackage.packageName = PACKAGE_MANAGER_SENTINEL;
4322 mPmAgent = new PackageManagerBackupAgent(
4323 mPackageManager, mAgentPackages);
4324 initiateOneRestore(omPackage, 0, IBackupAgent.Stub.asInterface(mPmAgent.onBind()),
Chris Tate249345b2010-10-29 12:57:04 -07004325 mNeedFullBackup);
Christopher Tate2982d062011-09-06 20:35:24 -07004326 // The PM agent called operationComplete() already, because our invocation
4327 // of it is process-local and therefore synchronous. That means that a
4328 // RUNNING_QUEUE message is already enqueued. Only if we're unable to
4329 // proceed with running the queue do we remove that pending message and
4330 // jump straight to the FINAL state.
Dan Egnorefe52642009-06-24 00:16:33 -07004331
Christopher Tate8c032472009-07-02 14:28:47 -07004332 // Verify that the backup set includes metadata. If not, we can't do
4333 // signature/version verification etc, so we simply do not proceed with
4334 // the restore operation.
Christopher Tate2982d062011-09-06 20:35:24 -07004335 if (!mPmAgent.hasMetadata()) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004336 Slog.e(TAG, "No restore metadata available, so not restoring settings");
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004337 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE, PACKAGE_MANAGER_SENTINEL,
Christopher Tate2982d062011-09-06 20:35:24 -07004338 "Package manager restore metadata missing");
4339 mStatus = BackupConstants.TRANSPORT_ERROR;
4340 mBackupHandler.removeMessages(MSG_BACKUP_RESTORE_STEP, this);
4341 executeNextState(RestoreState.FINAL);
Christopher Tate8c032472009-07-02 14:28:47 -07004342 return;
4343 }
Christopher Tate2982d062011-09-06 20:35:24 -07004344 } catch (RemoteException e) {
4345 Slog.e(TAG, "Error communicating with transport for restore");
4346 EventLog.writeEvent(EventLogTags.RESTORE_TRANSPORT_FAILURE);
4347 mStatus = BackupConstants.TRANSPORT_ERROR;
4348 mBackupHandler.removeMessages(MSG_BACKUP_RESTORE_STEP, this);
4349 executeNextState(RestoreState.FINAL);
4350 return;
4351 }
Christopher Tate8c032472009-07-02 14:28:47 -07004352
Christopher Tate2982d062011-09-06 20:35:24 -07004353 // Metadata is intact, so we can now run the restore queue. If we get here,
4354 // we have already enqueued the necessary next-step message on the looper.
4355 }
Dan Egnorbb9001c2009-07-27 12:20:13 -07004356
Christopher Tate2982d062011-09-06 20:35:24 -07004357 void restoreNextAgent() {
4358 try {
4359 String packageName = mTransport.nextRestorePackage();
Christopher Tatedf01dea2009-06-09 20:45:02 -07004360
Christopher Tate2982d062011-09-06 20:35:24 -07004361 if (packageName == null) {
4362 Slog.e(TAG, "Error getting next restore package");
4363 EventLog.writeEvent(EventLogTags.RESTORE_TRANSPORT_FAILURE);
4364 executeNextState(RestoreState.FINAL);
4365 return;
4366 } else if (packageName.equals("")) {
4367 if (DEBUG) Slog.v(TAG, "No next package, finishing restore");
4368 int millis = (int) (SystemClock.elapsedRealtime() - mStartRealtime);
4369 EventLog.writeEvent(EventLogTags.RESTORE_SUCCESS, mCount, millis);
4370 executeNextState(RestoreState.FINAL);
4371 return;
Dan Egnorefe52642009-06-24 00:16:33 -07004372 }
Christopher Tate7d562ec2009-06-25 18:03:43 -07004373
4374 if (mObserver != null) {
4375 try {
Christopher Tate2982d062011-09-06 20:35:24 -07004376 mObserver.onUpdate(mCount, packageName);
Christopher Tate7d562ec2009-06-25 18:03:43 -07004377 } catch (RemoteException e) {
Christopher Tate2982d062011-09-06 20:35:24 -07004378 Slog.d(TAG, "Restore observer died in onUpdate");
4379 mObserver = null;
Christopher Tate7d562ec2009-06-25 18:03:43 -07004380 }
4381 }
Christopher Tateb6787f22009-07-02 17:40:45 -07004382
Christopher Tate2982d062011-09-06 20:35:24 -07004383 Metadata metaInfo = mPmAgent.getRestoredMetadata(packageName);
4384 if (metaInfo == null) {
4385 Slog.e(TAG, "Missing metadata for " + packageName);
4386 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE, packageName,
4387 "Package metadata missing");
4388 executeNextState(RestoreState.RUNNING_QUEUE);
4389 return;
Christopher Tate84725812010-02-04 15:52:40 -08004390 }
4391
Christopher Tate2982d062011-09-06 20:35:24 -07004392 PackageInfo packageInfo;
4393 try {
4394 int flags = PackageManager.GET_SIGNATURES;
4395 packageInfo = mPackageManager.getPackageInfo(packageName, flags);
4396 } catch (NameNotFoundException e) {
4397 Slog.e(TAG, "Invalid package restoring data", e);
4398 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE, packageName,
4399 "Package missing on device");
4400 executeNextState(RestoreState.RUNNING_QUEUE);
4401 return;
Christopher Tate1bb69062010-02-19 17:02:12 -08004402 }
4403
Christopher Tate2982d062011-09-06 20:35:24 -07004404 if (metaInfo.versionCode > packageInfo.versionCode) {
4405 // Data is from a "newer" version of the app than we have currently
4406 // installed. If the app has not declared that it is prepared to
4407 // handle this case, we do not attempt the restore.
4408 if ((packageInfo.applicationInfo.flags
4409 & ApplicationInfo.FLAG_RESTORE_ANY_VERSION) == 0) {
4410 String message = "Version " + metaInfo.versionCode
4411 + " > installed version " + packageInfo.versionCode;
4412 Slog.w(TAG, "Package " + packageName + ": " + message);
4413 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE,
4414 packageName, message);
4415 executeNextState(RestoreState.RUNNING_QUEUE);
4416 return;
4417 } else {
4418 if (DEBUG) Slog.v(TAG, "Version " + metaInfo.versionCode
4419 + " > installed " + packageInfo.versionCode
4420 + " but restoreAnyVersion");
4421 }
4422 }
Christopher Tate73a3cb32010-12-13 18:27:26 -08004423
Christopher Tate2982d062011-09-06 20:35:24 -07004424 if (!signaturesMatch(metaInfo.signatures, packageInfo)) {
4425 Slog.w(TAG, "Signature mismatch restoring " + packageName);
4426 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE, packageName,
4427 "Signature mismatch");
4428 executeNextState(RestoreState.RUNNING_QUEUE);
4429 return;
4430 }
4431
4432 if (DEBUG) Slog.v(TAG, "Package " + packageName
4433 + " restore version [" + metaInfo.versionCode
4434 + "] is compatible with installed version ["
4435 + packageInfo.versionCode + "]");
4436
4437 // Then set up and bind the agent
4438 IBackupAgent agent = bindToAgentSynchronous(
4439 packageInfo.applicationInfo,
4440 IApplicationThread.BACKUP_MODE_INCREMENTAL);
4441 if (agent == null) {
4442 Slog.w(TAG, "Can't find backup agent for " + packageName);
4443 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE, packageName,
4444 "Restore agent missing");
4445 executeNextState(RestoreState.RUNNING_QUEUE);
4446 return;
4447 }
4448
4449 // And then finally start the restore on this agent
4450 try {
4451 initiateOneRestore(packageInfo, metaInfo.versionCode, agent, mNeedFullBackup);
4452 ++mCount;
4453 } catch (Exception e) {
4454 Slog.e(TAG, "Error when attempting restore: " + e.toString());
4455 agentErrorCleanup();
4456 executeNextState(RestoreState.RUNNING_QUEUE);
4457 }
4458 } catch (RemoteException e) {
4459 Slog.e(TAG, "Unable to fetch restore data from transport");
4460 mStatus = BackupConstants.TRANSPORT_ERROR;
4461 executeNextState(RestoreState.FINAL);
Christopher Tatedf01dea2009-06-09 20:45:02 -07004462 }
4463 }
4464
Christopher Tate2982d062011-09-06 20:35:24 -07004465 void finalizeRestore() {
4466 if (MORE_DEBUG) Slog.d(TAG, "finishing restore mObserver=" + mObserver);
4467
4468 try {
4469 mTransport.finishRestore();
4470 } catch (RemoteException e) {
4471 Slog.e(TAG, "Error finishing restore", e);
4472 }
4473
4474 if (mObserver != null) {
4475 try {
4476 mObserver.restoreFinished(mStatus);
4477 } catch (RemoteException e) {
4478 Slog.d(TAG, "Restore observer died at restoreFinished");
4479 }
4480 }
4481
4482 // If this was a restoreAll operation, record that this was our
4483 // ancestral dataset, as well as the set of apps that are possibly
4484 // restoreable from the dataset
4485 if (mTargetPackage == null && mPmAgent != null) {
4486 mAncestralPackages = mPmAgent.getRestoredPackages();
4487 mAncestralToken = mToken;
4488 writeRestoreTokens();
4489 }
4490
4491 // We must under all circumstances tell the Package Manager to
4492 // proceed with install notifications if it's waiting for us.
4493 if (mPmToken > 0) {
4494 if (MORE_DEBUG) Slog.v(TAG, "finishing PM token " + mPmToken);
4495 try {
4496 mPackageManagerBinder.finishPackageInstall(mPmToken);
4497 } catch (RemoteException e) { /* can't happen */ }
4498 }
4499
4500 // Furthermore we need to reset the session timeout clock
4501 mBackupHandler.removeMessages(MSG_RESTORE_TIMEOUT);
4502 mBackupHandler.sendEmptyMessageDelayed(MSG_RESTORE_TIMEOUT,
4503 TIMEOUT_RESTORE_INTERVAL);
4504
4505 // done; we can finally release the wakelock
4506 Slog.i(TAG, "Restore complete.");
4507 mWakelock.release();
4508 }
4509
4510 // Call asynchronously into the app, passing it the restore data. The next step
4511 // after this is always a callback, either operationComplete() or handleTimeout().
4512 void initiateOneRestore(PackageInfo app, int appVersionCode, IBackupAgent agent,
Chris Tate249345b2010-10-29 12:57:04 -07004513 boolean needFullBackup) {
Christopher Tate2982d062011-09-06 20:35:24 -07004514 mCurrentPackage = app;
Christopher Tatec7b31e32009-06-10 15:49:30 -07004515 final String packageName = app.packageName;
4516
Christopher Tate2982d062011-09-06 20:35:24 -07004517 if (DEBUG) Slog.d(TAG, "initiateOneRestore packageName=" + packageName);
Joe Onorato9a5e3e12009-07-01 21:04:03 -04004518
Christopher Tatec7b31e32009-06-10 15:49:30 -07004519 // !!! TODO: get the dirs from the transport
Christopher Tate2982d062011-09-06 20:35:24 -07004520 mBackupDataName = new File(mDataDir, packageName + ".restore");
4521 mNewStateName = new File(mStateDir, packageName + ".new");
4522 mSavedStateName = new File(mStateDir, packageName);
Dan Egnorbb9001c2009-07-27 12:20:13 -07004523
Christopher Tate4a627c72011-04-01 14:43:32 -07004524 final int token = generateToken();
Dan Egnorbb9001c2009-07-27 12:20:13 -07004525 try {
Christopher Tatec7b31e32009-06-10 15:49:30 -07004526 // Run the transport's restore pass
Christopher Tate2982d062011-09-06 20:35:24 -07004527 mBackupData = ParcelFileDescriptor.open(mBackupDataName,
Dan Egnorbb9001c2009-07-27 12:20:13 -07004528 ParcelFileDescriptor.MODE_READ_WRITE |
4529 ParcelFileDescriptor.MODE_CREATE |
4530 ParcelFileDescriptor.MODE_TRUNCATE);
4531
Christopher Tate2982d062011-09-06 20:35:24 -07004532 if (mTransport.getRestoreData(mBackupData) != BackupConstants.TRANSPORT_OK) {
Christopher Tate5f2f4132011-09-26 13:10:38 -07004533 // Transport-level failure, so we wind everything up and
4534 // terminate the restore operation.
Joe Onorato8a9b2202010-02-26 18:56:32 -08004535 Slog.e(TAG, "Error getting restore data for " + packageName);
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004536 EventLog.writeEvent(EventLogTags.RESTORE_TRANSPORT_FAILURE);
Christopher Tate5f2f4132011-09-26 13:10:38 -07004537 mBackupData.close();
4538 mBackupDataName.delete();
4539 executeNextState(RestoreState.FINAL);
Dan Egnorbb9001c2009-07-27 12:20:13 -07004540 return;
Christopher Tatec7b31e32009-06-10 15:49:30 -07004541 }
4542
4543 // Okay, we have the data. Now have the agent do the restore.
Christopher Tate2982d062011-09-06 20:35:24 -07004544 mBackupData.close();
4545 mBackupData = ParcelFileDescriptor.open(mBackupDataName,
Christopher Tatec7b31e32009-06-10 15:49:30 -07004546 ParcelFileDescriptor.MODE_READ_ONLY);
4547
Christopher Tate2982d062011-09-06 20:35:24 -07004548 mNewState = ParcelFileDescriptor.open(mNewStateName,
Dan Egnorbb9001c2009-07-27 12:20:13 -07004549 ParcelFileDescriptor.MODE_READ_WRITE |
4550 ParcelFileDescriptor.MODE_CREATE |
4551 ParcelFileDescriptor.MODE_TRUNCATE);
4552
Christopher Tate44a27902010-01-27 17:15:49 -08004553 // Kick off the restore, checking for hung agents
Christopher Tate2982d062011-09-06 20:35:24 -07004554 prepareOperationTimeout(token, TIMEOUT_RESTORE_INTERVAL, this);
4555 agent.doRestore(mBackupData, appVersionCode, mNewState, token, mBackupManagerBinder);
Christopher Tatec7b31e32009-06-10 15:49:30 -07004556 } catch (Exception e) {
Christopher Tate2982d062011-09-06 20:35:24 -07004557 Slog.e(TAG, "Unable to call app for restore: " + packageName, e);
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004558 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE, packageName, e.toString());
Christopher Tate2982d062011-09-06 20:35:24 -07004559 agentErrorCleanup(); // clears any pending timeout messages as well
Dan Egnorbb9001c2009-07-27 12:20:13 -07004560
Christopher Tate2982d062011-09-06 20:35:24 -07004561 // After a restore failure we go back to running the queue. If there
4562 // are no more packages to be restored that will be handled by the
4563 // next step.
4564 executeNextState(RestoreState.RUNNING_QUEUE);
4565 }
4566 }
Chris Tate249345b2010-10-29 12:57:04 -07004567
Christopher Tate2982d062011-09-06 20:35:24 -07004568 void agentErrorCleanup() {
4569 // If the agent fails restore, it might have put the app's data
4570 // into an incoherent state. For consistency we wipe its data
4571 // again in this case before continuing with normal teardown
4572 clearApplicationDataSynchronous(mCurrentPackage.packageName);
4573 agentCleanup();
4574 }
4575
4576 void agentCleanup() {
4577 mBackupDataName.delete();
4578 try { if (mBackupData != null) mBackupData.close(); } catch (IOException e) {}
4579 try { if (mNewState != null) mNewState.close(); } catch (IOException e) {}
4580 mBackupData = mNewState = null;
4581
4582 // if everything went okay, remember the recorded state now
4583 //
4584 // !!! TODO: the restored data should be migrated on the server
4585 // side into the current dataset. In that case the new state file
4586 // we just created would reflect the data already extant in the
4587 // backend, so there'd be nothing more to do. Until that happens,
4588 // however, we need to make sure that we record the data to the
4589 // current backend dataset. (Yes, this means shipping the data over
4590 // the wire in both directions. That's bad, but consistency comes
4591 // first, then efficiency.) Once we introduce server-side data
4592 // migration to the newly-restored device's dataset, we will change
4593 // the following from a discard of the newly-written state to the
4594 // "correct" operation of renaming into the canonical state blob.
4595 mNewStateName.delete(); // TODO: remove; see above comment
4596 //mNewStateName.renameTo(mSavedStateName); // TODO: replace with this
4597
4598 // If this wasn't the PM pseudopackage, tear down the agent side
4599 if (mCurrentPackage.applicationInfo != null) {
4600 // unbind and tidy up even on timeout or failure
4601 try {
4602 mActivityManager.unbindBackupAgent(mCurrentPackage.applicationInfo);
4603
4604 // The agent was probably running with a stub Application object,
4605 // which isn't a valid run mode for the main app logic. Shut
4606 // down the app so that next time it's launched, it gets the
4607 // usual full initialization. Note that this is only done for
4608 // full-system restores: when a single app has requested a restore,
4609 // it is explicitly not killed following that operation.
4610 if (mTargetPackage == null && (mCurrentPackage.applicationInfo.flags
4611 & ApplicationInfo.FLAG_KILL_AFTER_RESTORE) != 0) {
4612 if (DEBUG) Slog.d(TAG, "Restore complete, killing host process of "
4613 + mCurrentPackage.applicationInfo.processName);
4614 mActivityManager.killApplicationProcess(
4615 mCurrentPackage.applicationInfo.processName,
4616 mCurrentPackage.applicationInfo.uid);
4617 }
4618 } catch (RemoteException e) {
4619 // can't happen; we run in the same process as the activity manager
Chris Tate249345b2010-10-29 12:57:04 -07004620 }
Christopher Tatec7b31e32009-06-10 15:49:30 -07004621 }
Christopher Tate2982d062011-09-06 20:35:24 -07004622
4623 // The caller is responsible for reestablishing the state machine; our
4624 // responsibility here is to clear the decks for whatever comes next.
4625 mBackupHandler.removeMessages(MSG_TIMEOUT, this);
4626 synchronized (mCurrentOpLock) {
4627 mCurrentOperations.clear();
4628 }
4629 }
4630
4631 // A call to agent.doRestore() has been positively acknowledged as complete
4632 @Override
4633 public void operationComplete() {
4634 int size = (int) mBackupDataName.length();
4635 EventLog.writeEvent(EventLogTags.RESTORE_PACKAGE, mCurrentPackage.packageName, size);
4636 // Just go back to running the restore queue
4637 agentCleanup();
4638
4639 executeNextState(RestoreState.RUNNING_QUEUE);
4640 }
4641
4642 // A call to agent.doRestore() has timed out
4643 @Override
4644 public void handleTimeout() {
4645 Slog.e(TAG, "Timeout restoring application " + mCurrentPackage.packageName);
4646 EventLog.writeEvent(EventLogTags.RESTORE_AGENT_FAILURE,
4647 mCurrentPackage.packageName, "restore timeout");
4648 // Handle like an agent that threw on invocation: wipe it and go on to the next
4649 agentErrorCleanup();
4650 executeNextState(RestoreState.RUNNING_QUEUE);
4651 }
4652
4653 void executeNextState(RestoreState nextState) {
4654 if (MORE_DEBUG) Slog.i(TAG, " => executing next step on "
4655 + this + " nextState=" + nextState);
4656 mCurrentState = nextState;
4657 Message msg = mBackupHandler.obtainMessage(MSG_BACKUP_RESTORE_STEP, this);
4658 mBackupHandler.sendMessage(msg);
Christopher Tatedf01dea2009-06-09 20:45:02 -07004659 }
4660 }
4661
Christopher Tate44a27902010-01-27 17:15:49 -08004662 class PerformClearTask implements Runnable {
Christopher Tateee0e78a2009-07-02 11:17:03 -07004663 IBackupTransport mTransport;
4664 PackageInfo mPackage;
4665
Christopher Tate44a27902010-01-27 17:15:49 -08004666 PerformClearTask(IBackupTransport transport, PackageInfo packageInfo) {
Christopher Tateee0e78a2009-07-02 11:17:03 -07004667 mTransport = transport;
4668 mPackage = packageInfo;
4669 }
4670
Christopher Tateee0e78a2009-07-02 11:17:03 -07004671 public void run() {
4672 try {
4673 // Clear the on-device backup state to ensure a full backup next time
4674 File stateDir = new File(mBaseStateDir, mTransport.transportDirName());
4675 File stateFile = new File(stateDir, mPackage.packageName);
4676 stateFile.delete();
4677
4678 // Tell the transport to remove all the persistent storage for the app
Christopher Tate13f4a642009-09-30 20:06:45 -07004679 // TODO - need to handle failures
Christopher Tateee0e78a2009-07-02 11:17:03 -07004680 mTransport.clearBackupData(mPackage);
4681 } catch (RemoteException e) {
4682 // can't happen; the transport is local
Christopher Tate0abf6a02012-03-23 17:45:15 -07004683 } catch (Exception e) {
4684 Slog.e(TAG, "Transport threw attempting to clear data for " + mPackage);
Christopher Tateee0e78a2009-07-02 11:17:03 -07004685 } finally {
4686 try {
Christopher Tate13f4a642009-09-30 20:06:45 -07004687 // TODO - need to handle failures
Christopher Tateee0e78a2009-07-02 11:17:03 -07004688 mTransport.finishBackup();
4689 } catch (RemoteException e) {
4690 // can't happen; the transport is local
4691 }
Christopher Tateb6787f22009-07-02 17:40:45 -07004692
4693 // Last but not least, release the cpu
4694 mWakelock.release();
Christopher Tateee0e78a2009-07-02 11:17:03 -07004695 }
4696 }
4697 }
4698
Christopher Tate44a27902010-01-27 17:15:49 -08004699 class PerformInitializeTask implements Runnable {
Christopher Tate4cc86e12009-09-21 19:36:51 -07004700 HashSet<String> mQueue;
4701
Christopher Tate44a27902010-01-27 17:15:49 -08004702 PerformInitializeTask(HashSet<String> transportNames) {
Christopher Tate4cc86e12009-09-21 19:36:51 -07004703 mQueue = transportNames;
4704 }
4705
Christopher Tate4cc86e12009-09-21 19:36:51 -07004706 public void run() {
Christopher Tate4cc86e12009-09-21 19:36:51 -07004707 try {
4708 for (String transportName : mQueue) {
4709 IBackupTransport transport = getTransport(transportName);
4710 if (transport == null) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004711 Slog.e(TAG, "Requested init for " + transportName + " but not found");
Christopher Tate4cc86e12009-09-21 19:36:51 -07004712 continue;
4713 }
4714
Joe Onorato8a9b2202010-02-26 18:56:32 -08004715 Slog.i(TAG, "Initializing (wiping) backup transport storage: " + transportName);
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004716 EventLog.writeEvent(EventLogTags.BACKUP_START, transport.transportDirName());
Dan Egnor726247c2009-09-29 19:12:31 -07004717 long startRealtime = SystemClock.elapsedRealtime();
4718 int status = transport.initializeDevice();
Christopher Tate4cc86e12009-09-21 19:36:51 -07004719
Christopher Tate4cc86e12009-09-21 19:36:51 -07004720 if (status == BackupConstants.TRANSPORT_OK) {
4721 status = transport.finishBackup();
4722 }
4723
4724 // Okay, the wipe really happened. Clean up our local bookkeeping.
4725 if (status == BackupConstants.TRANSPORT_OK) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004726 Slog.i(TAG, "Device init successful");
Dan Egnor726247c2009-09-29 19:12:31 -07004727 int millis = (int) (SystemClock.elapsedRealtime() - startRealtime);
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004728 EventLog.writeEvent(EventLogTags.BACKUP_INITIALIZE);
Dan Egnor726247c2009-09-29 19:12:31 -07004729 resetBackupState(new File(mBaseStateDir, transport.transportDirName()));
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004730 EventLog.writeEvent(EventLogTags.BACKUP_SUCCESS, 0, millis);
Christopher Tate4cc86e12009-09-21 19:36:51 -07004731 synchronized (mQueueLock) {
4732 recordInitPendingLocked(false, transportName);
4733 }
Dan Egnor726247c2009-09-29 19:12:31 -07004734 } else {
4735 // If this didn't work, requeue this one and try again
4736 // after a suitable interval
Joe Onorato8a9b2202010-02-26 18:56:32 -08004737 Slog.e(TAG, "Transport error in initializeDevice()");
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004738 EventLog.writeEvent(EventLogTags.BACKUP_TRANSPORT_FAILURE, "(initialize)");
Christopher Tate4cc86e12009-09-21 19:36:51 -07004739 synchronized (mQueueLock) {
4740 recordInitPendingLocked(true, transportName);
4741 }
4742 // do this via another alarm to make sure of the wakelock states
4743 long delay = transport.requestBackupTime();
Joe Onorato8a9b2202010-02-26 18:56:32 -08004744 if (DEBUG) Slog.w(TAG, "init failed on "
Christopher Tate4cc86e12009-09-21 19:36:51 -07004745 + transportName + " resched in " + delay);
4746 mAlarmManager.set(AlarmManager.RTC_WAKEUP,
4747 System.currentTimeMillis() + delay, mRunInitIntent);
Christopher Tate4cc86e12009-09-21 19:36:51 -07004748 }
Christopher Tate4cc86e12009-09-21 19:36:51 -07004749 }
4750 } catch (RemoteException e) {
4751 // can't happen; the transports are local
4752 } catch (Exception e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004753 Slog.e(TAG, "Unexpected error performing init", e);
Christopher Tate4cc86e12009-09-21 19:36:51 -07004754 } finally {
Christopher Tatec2af5d32010-02-02 15:18:58 -08004755 // Done; release the wakelock
Christopher Tate4cc86e12009-09-21 19:36:51 -07004756 mWakelock.release();
4757 }
4758 }
4759 }
4760
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004761 private void dataChangedImpl(String packageName) {
Christopher Tatea3d55342012-03-27 13:16:18 -07004762 HashSet<String> targets = dataChangedTargets(packageName);
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004763 dataChangedImpl(packageName, targets);
4764 }
Christopher Tatedf01dea2009-06-09 20:45:02 -07004765
Christopher Tatea3d55342012-03-27 13:16:18 -07004766 private void dataChangedImpl(String packageName, HashSet<String> targets) {
Christopher Tate487529a2009-04-29 14:03:25 -07004767 // Record that we need a backup pass for the caller. Since multiple callers
4768 // may share a uid, we need to note all candidates within that uid and schedule
4769 // a backup pass for each of them.
Doug Zongkerab5c49c2009-12-04 10:31:43 -08004770 EventLog.writeEvent(EventLogTags.BACKUP_DATA_CHANGED, packageName);
Joe Onoratob1a7ffe2009-05-06 18:06:21 -07004771
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004772 if (targets == null) {
4773 Slog.w(TAG, "dataChanged but no participant pkg='" + packageName + "'"
4774 + " uid=" + Binder.getCallingUid());
4775 return;
4776 }
4777
4778 synchronized (mQueueLock) {
4779 // Note that this client has made data changes that need to be backed up
Christopher Tatea3d55342012-03-27 13:16:18 -07004780 if (targets.contains(packageName)) {
4781 // Add the caller to the set of pending backups. If there is
4782 // one already there, then overwrite it, but no harm done.
4783 BackupRequest req = new BackupRequest(packageName);
4784 if (mPendingBackups.put(packageName, req) == null) {
4785 if (DEBUG) Slog.d(TAG, "Now staging backup of " + packageName);
Christopher Tate6de74ff2012-01-17 15:20:32 -08004786
Christopher Tatea3d55342012-03-27 13:16:18 -07004787 // Journal this request in case of crash. The put()
4788 // operation returned null when this package was not already
4789 // in the set; we want to avoid touching the disk redundantly.
4790 writeToJournalLocked(packageName);
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004791
Christopher Tatea3d55342012-03-27 13:16:18 -07004792 if (MORE_DEBUG) {
4793 int numKeys = mPendingBackups.size();
4794 Slog.d(TAG, "Now awaiting backup for " + numKeys + " participants:");
4795 for (BackupRequest b : mPendingBackups.values()) {
4796 Slog.d(TAG, " + " + b);
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004797 }
4798 }
4799 }
4800 }
4801 }
4802 }
4803
4804 // Note: packageName is currently unused, but may be in the future
Christopher Tatea3d55342012-03-27 13:16:18 -07004805 private HashSet<String> dataChangedTargets(String packageName) {
Christopher Tate63d27002009-06-16 17:16:42 -07004806 // If the caller does not hold the BACKUP permission, it can only request a
4807 // backup of its own data.
Dianne Hackborncf098292009-07-01 19:55:20 -07004808 if ((mContext.checkPermission(android.Manifest.permission.BACKUP, Binder.getCallingPid(),
Christopher Tate63d27002009-06-16 17:16:42 -07004809 Binder.getCallingUid())) == PackageManager.PERMISSION_DENIED) {
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004810 synchronized (mBackupParticipants) {
4811 return mBackupParticipants.get(Binder.getCallingUid());
4812 }
4813 }
4814
4815 // a caller with full permission can ask to back up any participating app
4816 // !!! TODO: allow backup of ANY app?
Christopher Tatea3d55342012-03-27 13:16:18 -07004817 HashSet<String> targets = new HashSet<String>();
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004818 synchronized (mBackupParticipants) {
Christopher Tate63d27002009-06-16 17:16:42 -07004819 int N = mBackupParticipants.size();
4820 for (int i = 0; i < N; i++) {
Christopher Tatea3d55342012-03-27 13:16:18 -07004821 HashSet<String> s = mBackupParticipants.valueAt(i);
Christopher Tate63d27002009-06-16 17:16:42 -07004822 if (s != null) {
4823 targets.addAll(s);
4824 }
4825 }
4826 }
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004827 return targets;
Christopher Tate487529a2009-04-29 14:03:25 -07004828 }
Christopher Tate46758122009-05-06 11:22:00 -07004829
Christopher Tatecde87f42009-06-12 12:55:53 -07004830 private void writeToJournalLocked(String str) {
Dan Egnor852f8e42009-09-30 11:20:45 -07004831 RandomAccessFile out = null;
4832 try {
4833 if (mJournal == null) mJournal = File.createTempFile("journal", null, mJournalDir);
4834 out = new RandomAccessFile(mJournal, "rws");
4835 out.seek(out.length());
4836 out.writeUTF(str);
4837 } catch (IOException e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004838 Slog.e(TAG, "Can't write " + str + " to backup journal", e);
Dan Egnor852f8e42009-09-30 11:20:45 -07004839 mJournal = null;
4840 } finally {
4841 try { if (out != null) out.close(); } catch (IOException e) {}
Christopher Tatecde87f42009-06-12 12:55:53 -07004842 }
4843 }
4844
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004845 // ----- IBackupManager binder interface -----
4846
4847 public void dataChanged(final String packageName) {
Christopher Tatea3d55342012-03-27 13:16:18 -07004848 final HashSet<String> targets = dataChangedTargets(packageName);
Brad Fitzpatrick3dd42332010-09-07 23:40:30 -07004849 if (targets == null) {
4850 Slog.w(TAG, "dataChanged but no participant pkg='" + packageName + "'"
4851 + " uid=" + Binder.getCallingUid());
4852 return;
4853 }
4854
4855 mBackupHandler.post(new Runnable() {
4856 public void run() {
4857 dataChangedImpl(packageName, targets);
4858 }
4859 });
4860 }
4861
Christopher Tateee0e78a2009-07-02 11:17:03 -07004862 // Clear the given package's backup data from the current transport
4863 public void clearBackupData(String packageName) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004864 if (DEBUG) Slog.v(TAG, "clearBackupData() of " + packageName);
Christopher Tateee0e78a2009-07-02 11:17:03 -07004865 PackageInfo info;
4866 try {
4867 info = mPackageManager.getPackageInfo(packageName, PackageManager.GET_SIGNATURES);
4868 } catch (NameNotFoundException e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08004869 Slog.d(TAG, "No such package '" + packageName + "' - not clearing backup data");
Christopher Tateee0e78a2009-07-02 11:17:03 -07004870 return;
4871 }
4872
4873 // If the caller does not hold the BACKUP permission, it can only request a
4874 // wipe of its own backed-up data.
Christopher Tatea3d55342012-03-27 13:16:18 -07004875 HashSet<String> apps;
Christopher Tate4e3e50c2009-07-02 12:14:05 -07004876 if ((mContext.checkPermission(android.Manifest.permission.BACKUP, Binder.getCallingPid(),
Christopher Tateee0e78a2009-07-02 11:17:03 -07004877 Binder.getCallingUid())) == PackageManager.PERMISSION_DENIED) {
4878 apps = mBackupParticipants.get(Binder.getCallingUid());
4879 } else {
4880 // a caller with full permission can ask to back up any participating app
4881 // !!! TODO: allow data-clear of ANY app?
Joe Onorato8a9b2202010-02-26 18:56:32 -08004882 if (DEBUG) Slog.v(TAG, "Privileged caller, allowing clear of other apps");
Christopher Tatea3d55342012-03-27 13:16:18 -07004883 apps = new HashSet<String>();
Christopher Tateee0e78a2009-07-02 11:17:03 -07004884 int N = mBackupParticipants.size();
4885 for (int i = 0; i < N; i++) {
Christopher Tatea3d55342012-03-27 13:16:18 -07004886 HashSet<String> s = mBackupParticipants.valueAt(i);
Christopher Tateee0e78a2009-07-02 11:17:03 -07004887 if (s != null) {
4888 apps.addAll(s);
4889 }
4890 }
4891 }
4892
Christopher Tatea3d55342012-03-27 13:16:18 -07004893 // Is the given app an available participant?
4894 if (apps.contains(packageName)) {
4895 if (DEBUG) Slog.v(TAG, "Found the app - running clear process");
4896 // found it; fire off the clear request
4897 synchronized (mQueueLock) {
4898 long oldId = Binder.clearCallingIdentity();
4899 mWakelock.acquire();
4900 Message msg = mBackupHandler.obtainMessage(MSG_RUN_CLEAR,
4901 new ClearParams(getTransport(mCurrentTransport), info));
4902 mBackupHandler.sendMessage(msg);
4903 Binder.restoreCallingIdentity(oldId);
Christopher Tateee0e78a2009-07-02 11:17:03 -07004904 }
4905 }
4906 }
4907
Christopher Tateace7f092009-06-15 18:07:25 -07004908 // Run a backup pass immediately for any applications that have declared
4909 // that they have pending updates.
Dan Egnor852f8e42009-09-30 11:20:45 -07004910 public void backupNow() {
Joe Onorato5933a492009-07-23 18:24:08 -04004911 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP, "backupNow");
Christopher Tate043dadc2009-06-02 16:11:00 -07004912
Joe Onorato8a9b2202010-02-26 18:56:32 -08004913 if (DEBUG) Slog.v(TAG, "Scheduling immediate backup pass");
Christopher Tate46758122009-05-06 11:22:00 -07004914 synchronized (mQueueLock) {
Christopher Tate21ab6a52009-09-24 18:01:46 -07004915 // Because the alarms we are using can jitter, and we want an *immediate*
4916 // backup pass to happen, we restart the timer beginning with "next time,"
4917 // then manually fire the backup trigger intent ourselves.
4918 startBackupAlarmsLocked(BACKUP_INTERVAL);
Christopher Tateb6787f22009-07-02 17:40:45 -07004919 try {
Christopher Tateb6787f22009-07-02 17:40:45 -07004920 mRunBackupIntent.send();
4921 } catch (PendingIntent.CanceledException e) {
4922 // should never happen
Joe Onorato8a9b2202010-02-26 18:56:32 -08004923 Slog.e(TAG, "run-backup intent cancelled!");
Christopher Tateb6787f22009-07-02 17:40:45 -07004924 }
Christopher Tate46758122009-05-06 11:22:00 -07004925 }
4926 }
Joe Onoratob1a7ffe2009-05-06 18:06:21 -07004927
Christopher Tated2c0cd42011-09-15 15:51:29 -07004928 boolean deviceIsProvisioned() {
4929 final ContentResolver resolver = mContext.getContentResolver();
4930 return (Settings.Secure.getInt(resolver, Settings.Secure.DEVICE_PROVISIONED, 0) != 0);
4931 }
4932
Christopher Tate4a627c72011-04-01 14:43:32 -07004933 // Run a *full* backup pass for the given package, writing the resulting data stream
4934 // to the supplied file descriptor. This method is synchronous and does not return
4935 // to the caller until the backup has been completed.
4936 public void fullBackup(ParcelFileDescriptor fd, boolean includeApks, boolean includeShared,
Christopher Tate240c7d22011-10-03 18:13:44 -07004937 boolean doAllApps, boolean includeSystem, String[] pkgList) {
Christopher Tate4a627c72011-04-01 14:43:32 -07004938 mContext.enforceCallingPermission(android.Manifest.permission.BACKUP, "fullBackup");
4939
4940 // Validate
4941 if (!doAllApps) {
4942 if (!includeShared) {
4943 // If we're backing up shared data (sdcard or equivalent), then we can run
4944 // without any supplied app names. Otherwise, we'd be doing no work, so
4945 // report the error.
4946 if (pkgList == null || pkgList.length == 0) {
4947 throw new IllegalArgumentException(
4948 "Backup requested but neither shared nor any apps named");
4949 }
4950 }
4951 }
4952
Christopher Tate4a627c72011-04-01 14:43:32 -07004953 long oldId = Binder.clearCallingIdentity();
4954 try {
Christopher Tated2c0cd42011-09-15 15:51:29 -07004955 // Doesn't make sense to do a full backup prior to setup
4956 if (!deviceIsProvisioned()) {
4957 Slog.i(TAG, "Full backup not supported before setup");
4958 return;
4959 }
4960
4961 if (DEBUG) Slog.v(TAG, "Requesting full backup: apks=" + includeApks
4962 + " shared=" + includeShared + " all=" + doAllApps
4963 + " pkgs=" + pkgList);
4964 Slog.i(TAG, "Beginning full backup...");
4965
Christopher Tate4a627c72011-04-01 14:43:32 -07004966 FullBackupParams params = new FullBackupParams(fd, includeApks, includeShared,
Christopher Tate240c7d22011-10-03 18:13:44 -07004967 doAllApps, includeSystem, pkgList);
Christopher Tate4a627c72011-04-01 14:43:32 -07004968 final int token = generateToken();
4969 synchronized (mFullConfirmations) {
4970 mFullConfirmations.put(token, params);
4971 }
4972
Christopher Tate75a99702011-05-18 16:28:19 -07004973 // start up the confirmation UI
4974 if (DEBUG) Slog.d(TAG, "Starting backup confirmation UI, token=" + token);
4975 if (!startConfirmationUi(token, FullBackup.FULL_BACKUP_INTENT_ACTION)) {
4976 Slog.e(TAG, "Unable to launch full backup confirmation");
Christopher Tate4a627c72011-04-01 14:43:32 -07004977 mFullConfirmations.delete(token);
4978 return;
4979 }
Christopher Tate75a99702011-05-18 16:28:19 -07004980
4981 // make sure the screen is lit for the user interaction
Christopher Tate4a627c72011-04-01 14:43:32 -07004982 mPowerManager.userActivity(SystemClock.uptimeMillis(), false);
4983
4984 // start the confirmation countdown
Christopher Tate75a99702011-05-18 16:28:19 -07004985 startConfirmationTimeout(token, params);
Christopher Tate4a627c72011-04-01 14:43:32 -07004986
4987 // wait for the backup to be performed
4988 if (DEBUG) Slog.d(TAG, "Waiting for full backup completion...");
4989 waitForCompletion(params);
Christopher Tate4a627c72011-04-01 14:43:32 -07004990 } finally {
Christopher Tate4a627c72011-04-01 14:43:32 -07004991 try {
4992 fd.close();
4993 } catch (IOException e) {
4994 // just eat it
4995 }
Christopher Tate75a99702011-05-18 16:28:19 -07004996 Binder.restoreCallingIdentity(oldId);
Christopher Tated2c0cd42011-09-15 15:51:29 -07004997 Slog.d(TAG, "Full backup processing complete.");
Christopher Tate4a627c72011-04-01 14:43:32 -07004998 }
Christopher Tate75a99702011-05-18 16:28:19 -07004999 }
5000
5001 public void fullRestore(ParcelFileDescriptor fd) {
Christopher Tate2efd2db2011-07-19 16:32:49 -07005002 mContext.enforceCallingPermission(android.Manifest.permission.BACKUP, "fullRestore");
Christopher Tate75a99702011-05-18 16:28:19 -07005003
5004 long oldId = Binder.clearCallingIdentity();
5005
5006 try {
Christopher Tated2c0cd42011-09-15 15:51:29 -07005007 // Check whether the device has been provisioned -- we don't handle
5008 // full restores prior to completing the setup process.
5009 if (!deviceIsProvisioned()) {
5010 Slog.i(TAG, "Full restore not permitted before setup");
5011 return;
5012 }
5013
5014 Slog.i(TAG, "Beginning full restore...");
5015
Christopher Tate75a99702011-05-18 16:28:19 -07005016 FullRestoreParams params = new FullRestoreParams(fd);
5017 final int token = generateToken();
5018 synchronized (mFullConfirmations) {
5019 mFullConfirmations.put(token, params);
5020 }
5021
5022 // start up the confirmation UI
5023 if (DEBUG) Slog.d(TAG, "Starting restore confirmation UI, token=" + token);
5024 if (!startConfirmationUi(token, FullBackup.FULL_RESTORE_INTENT_ACTION)) {
5025 Slog.e(TAG, "Unable to launch full restore confirmation");
5026 mFullConfirmations.delete(token);
5027 return;
5028 }
5029
5030 // make sure the screen is lit for the user interaction
5031 mPowerManager.userActivity(SystemClock.uptimeMillis(), false);
5032
5033 // start the confirmation countdown
5034 startConfirmationTimeout(token, params);
5035
5036 // wait for the restore to be performed
5037 if (DEBUG) Slog.d(TAG, "Waiting for full restore completion...");
5038 waitForCompletion(params);
5039 } finally {
5040 try {
5041 fd.close();
5042 } catch (IOException e) {
5043 Slog.w(TAG, "Error trying to close fd after full restore: " + e);
5044 }
5045 Binder.restoreCallingIdentity(oldId);
Christopher Tated2c0cd42011-09-15 15:51:29 -07005046 Slog.i(TAG, "Full restore processing complete.");
Christopher Tate75a99702011-05-18 16:28:19 -07005047 }
5048 }
5049
5050 boolean startConfirmationUi(int token, String action) {
5051 try {
5052 Intent confIntent = new Intent(action);
5053 confIntent.setClassName("com.android.backupconfirm",
5054 "com.android.backupconfirm.BackupRestoreConfirmation");
5055 confIntent.putExtra(FullBackup.CONF_TOKEN_INTENT_EXTRA, token);
5056 confIntent.addFlags(Intent.FLAG_ACTIVITY_NEW_TASK);
5057 mContext.startActivity(confIntent);
5058 } catch (ActivityNotFoundException e) {
5059 return false;
5060 }
5061 return true;
5062 }
5063
5064 void startConfirmationTimeout(int token, FullParams params) {
Christopher Tatec58efa62011-08-01 19:20:14 -07005065 if (MORE_DEBUG) Slog.d(TAG, "Posting conf timeout msg after "
Christopher Tate75a99702011-05-18 16:28:19 -07005066 + TIMEOUT_FULL_CONFIRMATION + " millis");
5067 Message msg = mBackupHandler.obtainMessage(MSG_FULL_CONFIRMATION_TIMEOUT,
5068 token, 0, params);
5069 mBackupHandler.sendMessageDelayed(msg, TIMEOUT_FULL_CONFIRMATION);
Christopher Tate4a627c72011-04-01 14:43:32 -07005070 }
5071
5072 void waitForCompletion(FullParams params) {
5073 synchronized (params.latch) {
5074 while (params.latch.get() == false) {
5075 try {
5076 params.latch.wait();
5077 } catch (InterruptedException e) { /* never interrupted */ }
5078 }
5079 }
5080 }
5081
5082 void signalFullBackupRestoreCompletion(FullParams params) {
5083 synchronized (params.latch) {
5084 params.latch.set(true);
5085 params.latch.notifyAll();
5086 }
5087 }
5088
5089 // Confirm that the previously-requested full backup/restore operation can proceed. This
5090 // is used to require a user-facing disclosure about the operation.
Christopher Tate2efd2db2011-07-19 16:32:49 -07005091 @Override
Christopher Tate4a627c72011-04-01 14:43:32 -07005092 public void acknowledgeFullBackupOrRestore(int token, boolean allow,
Christopher Tate728a1c42011-07-28 18:03:03 -07005093 String curPassword, String encPpassword, IFullBackupRestoreObserver observer) {
Christopher Tate4a627c72011-04-01 14:43:32 -07005094 if (DEBUG) Slog.d(TAG, "acknowledgeFullBackupOrRestore : token=" + token
5095 + " allow=" + allow);
5096
5097 // TODO: possibly require not just this signature-only permission, but even
5098 // require that the specific designated confirmation-UI app uid is the caller?
Christopher Tate2efd2db2011-07-19 16:32:49 -07005099 mContext.enforceCallingPermission(android.Manifest.permission.BACKUP, "acknowledgeFullBackupOrRestore");
Christopher Tate4a627c72011-04-01 14:43:32 -07005100
5101 long oldId = Binder.clearCallingIdentity();
5102 try {
5103
5104 FullParams params;
5105 synchronized (mFullConfirmations) {
5106 params = mFullConfirmations.get(token);
5107 if (params != null) {
5108 mBackupHandler.removeMessages(MSG_FULL_CONFIRMATION_TIMEOUT, params);
5109 mFullConfirmations.delete(token);
5110
5111 if (allow) {
Christopher Tate4a627c72011-04-01 14:43:32 -07005112 final int verb = params instanceof FullBackupParams
Christopher Tate75a99702011-05-18 16:28:19 -07005113 ? MSG_RUN_FULL_BACKUP
Christopher Tate4a627c72011-04-01 14:43:32 -07005114 : MSG_RUN_FULL_RESTORE;
5115
Christopher Tate728a1c42011-07-28 18:03:03 -07005116 params.observer = observer;
5117 params.curPassword = curPassword;
Christopher Tate32418be2011-10-10 13:51:12 -07005118
5119 boolean isEncrypted;
5120 try {
5121 isEncrypted = (mMountService.getEncryptionState() != MountService.ENCRYPTION_STATE_NONE);
5122 if (isEncrypted) Slog.w(TAG, "Device is encrypted; forcing enc password");
5123 } catch (RemoteException e) {
5124 // couldn't contact the mount service; fail "safe" and assume encryption
5125 Slog.e(TAG, "Unable to contact mount service!");
5126 isEncrypted = true;
5127 }
5128 params.encryptPassword = (isEncrypted) ? curPassword : encPpassword;
Christopher Tate728a1c42011-07-28 18:03:03 -07005129
Christopher Tate75a99702011-05-18 16:28:19 -07005130 if (DEBUG) Slog.d(TAG, "Sending conf message with verb " + verb);
Christopher Tate4a627c72011-04-01 14:43:32 -07005131 mWakelock.acquire();
5132 Message msg = mBackupHandler.obtainMessage(verb, params);
5133 mBackupHandler.sendMessage(msg);
5134 } else {
5135 Slog.w(TAG, "User rejected full backup/restore operation");
5136 // indicate completion without having actually transferred any data
5137 signalFullBackupRestoreCompletion(params);
5138 }
5139 } else {
5140 Slog.w(TAG, "Attempted to ack full backup/restore with invalid token");
5141 }
5142 }
5143 } finally {
5144 Binder.restoreCallingIdentity(oldId);
5145 }
5146 }
5147
Christopher Tate8031a3d2009-07-06 16:36:05 -07005148 // Enable/disable the backup service
Christopher Tate6ef58a12009-06-29 14:56:28 -07005149 public void setBackupEnabled(boolean enable) {
Christopher Tateb6787f22009-07-02 17:40:45 -07005150 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
Christopher Tate2efd2db2011-07-19 16:32:49 -07005151 "setBackupEnabled");
Christopher Tate6ef58a12009-06-29 14:56:28 -07005152
Joe Onorato8a9b2202010-02-26 18:56:32 -08005153 Slog.i(TAG, "Backup enabled => " + enable);
Christopher Tate4cc86e12009-09-21 19:36:51 -07005154
Christopher Tate6ef58a12009-06-29 14:56:28 -07005155 boolean wasEnabled = mEnabled;
5156 synchronized (this) {
Dianne Hackborncf098292009-07-01 19:55:20 -07005157 Settings.Secure.putInt(mContext.getContentResolver(),
5158 Settings.Secure.BACKUP_ENABLED, enable ? 1 : 0);
Christopher Tate6ef58a12009-06-29 14:56:28 -07005159 mEnabled = enable;
5160 }
5161
Christopher Tate49401dd2009-07-01 12:34:29 -07005162 synchronized (mQueueLock) {
Christopher Tate8031a3d2009-07-06 16:36:05 -07005163 if (enable && !wasEnabled && mProvisioned) {
Christopher Tate49401dd2009-07-01 12:34:29 -07005164 // if we've just been enabled, start scheduling backup passes
Christopher Tate8031a3d2009-07-06 16:36:05 -07005165 startBackupAlarmsLocked(BACKUP_INTERVAL);
Christopher Tate49401dd2009-07-01 12:34:29 -07005166 } else if (!enable) {
Christopher Tateb6787f22009-07-02 17:40:45 -07005167 // No longer enabled, so stop running backups
Joe Onorato8a9b2202010-02-26 18:56:32 -08005168 if (DEBUG) Slog.i(TAG, "Opting out of backup");
Christopher Tate4cc86e12009-09-21 19:36:51 -07005169
Christopher Tateb6787f22009-07-02 17:40:45 -07005170 mAlarmManager.cancel(mRunBackupIntent);
Christopher Tate4cc86e12009-09-21 19:36:51 -07005171
5172 // This also constitutes an opt-out, so we wipe any data for
5173 // this device from the backend. We start that process with
5174 // an alarm in order to guarantee wakelock states.
5175 if (wasEnabled && mProvisioned) {
5176 // NOTE: we currently flush every registered transport, not just
5177 // the currently-active one.
5178 HashSet<String> allTransports;
5179 synchronized (mTransports) {
5180 allTransports = new HashSet<String>(mTransports.keySet());
5181 }
5182 // build the set of transports for which we are posting an init
5183 for (String transport : allTransports) {
5184 recordInitPendingLocked(true, transport);
5185 }
5186 mAlarmManager.set(AlarmManager.RTC_WAKEUP, System.currentTimeMillis(),
5187 mRunInitIntent);
5188 }
Christopher Tate6ef58a12009-06-29 14:56:28 -07005189 }
5190 }
Christopher Tate49401dd2009-07-01 12:34:29 -07005191 }
Christopher Tate6ef58a12009-06-29 14:56:28 -07005192
Christopher Tatecce9da52010-02-03 15:11:15 -08005193 // Enable/disable automatic restore of app data at install time
5194 public void setAutoRestore(boolean doAutoRestore) {
5195 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
Christopher Tate2efd2db2011-07-19 16:32:49 -07005196 "setAutoRestore");
Christopher Tatecce9da52010-02-03 15:11:15 -08005197
Joe Onorato8a9b2202010-02-26 18:56:32 -08005198 Slog.i(TAG, "Auto restore => " + doAutoRestore);
Christopher Tatecce9da52010-02-03 15:11:15 -08005199
5200 synchronized (this) {
5201 Settings.Secure.putInt(mContext.getContentResolver(),
5202 Settings.Secure.BACKUP_AUTO_RESTORE, doAutoRestore ? 1 : 0);
5203 mAutoRestore = doAutoRestore;
5204 }
5205 }
5206
Christopher Tate8031a3d2009-07-06 16:36:05 -07005207 // Mark the backup service as having been provisioned
5208 public void setBackupProvisioned(boolean available) {
5209 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
5210 "setBackupProvisioned");
Christopher Tate97ea1222012-05-17 14:59:41 -07005211 /*
5212 * This is now a no-op; provisioning is simply the device's own setup state.
5213 */
Christopher Tate8031a3d2009-07-06 16:36:05 -07005214 }
5215
5216 private void startBackupAlarmsLocked(long delayBeforeFirstBackup) {
Dan Egnorc1c49c02009-10-30 17:35:39 -07005217 // We used to use setInexactRepeating(), but that may be linked to
5218 // backups running at :00 more often than not, creating load spikes.
5219 // Schedule at an exact time for now, and also add a bit of "fuzz".
5220
5221 Random random = new Random();
5222 long when = System.currentTimeMillis() + delayBeforeFirstBackup +
5223 random.nextInt(FUZZ_MILLIS);
5224 mAlarmManager.setRepeating(AlarmManager.RTC_WAKEUP, when,
5225 BACKUP_INTERVAL + random.nextInt(FUZZ_MILLIS), mRunBackupIntent);
Christopher Tate55f931a2009-09-29 17:17:34 -07005226 mNextBackupPass = when;
Christopher Tate8031a3d2009-07-06 16:36:05 -07005227 }
5228
Christopher Tate6ef58a12009-06-29 14:56:28 -07005229 // Report whether the backup mechanism is currently enabled
5230 public boolean isBackupEnabled() {
Joe Onorato5933a492009-07-23 18:24:08 -04005231 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP, "isBackupEnabled");
Christopher Tate6ef58a12009-06-29 14:56:28 -07005232 return mEnabled; // no need to synchronize just to read it
5233 }
5234
Christopher Tate91717492009-06-26 21:07:13 -07005235 // Report the name of the currently active transport
5236 public String getCurrentTransport() {
Joe Onorato5933a492009-07-23 18:24:08 -04005237 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
Christopher Tate4e3e50c2009-07-02 12:14:05 -07005238 "getCurrentTransport");
Christopher Tatec58efa62011-08-01 19:20:14 -07005239 if (MORE_DEBUG) Slog.v(TAG, "... getCurrentTransport() returning " + mCurrentTransport);
Christopher Tate91717492009-06-26 21:07:13 -07005240 return mCurrentTransport;
Christopher Tateace7f092009-06-15 18:07:25 -07005241 }
5242
Christopher Tate91717492009-06-26 21:07:13 -07005243 // Report all known, available backup transports
5244 public String[] listAllTransports() {
Christopher Tate34ebd0e2009-07-06 15:44:54 -07005245 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP, "listAllTransports");
Christopher Tate043dadc2009-06-02 16:11:00 -07005246
Christopher Tate91717492009-06-26 21:07:13 -07005247 String[] list = null;
5248 ArrayList<String> known = new ArrayList<String>();
5249 for (Map.Entry<String, IBackupTransport> entry : mTransports.entrySet()) {
5250 if (entry.getValue() != null) {
5251 known.add(entry.getKey());
5252 }
5253 }
5254
5255 if (known.size() > 0) {
5256 list = new String[known.size()];
5257 known.toArray(list);
5258 }
5259 return list;
5260 }
5261
5262 // Select which transport to use for the next backup operation. If the given
5263 // name is not one of the available transports, no action is taken and the method
5264 // returns null.
5265 public String selectBackupTransport(String transport) {
Joe Onorato5933a492009-07-23 18:24:08 -04005266 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP, "selectBackupTransport");
Christopher Tate91717492009-06-26 21:07:13 -07005267
5268 synchronized (mTransports) {
5269 String prevTransport = null;
5270 if (mTransports.get(transport) != null) {
5271 prevTransport = mCurrentTransport;
5272 mCurrentTransport = transport;
Dianne Hackborncf098292009-07-01 19:55:20 -07005273 Settings.Secure.putString(mContext.getContentResolver(),
5274 Settings.Secure.BACKUP_TRANSPORT, transport);
Joe Onorato8a9b2202010-02-26 18:56:32 -08005275 Slog.v(TAG, "selectBackupTransport() set " + mCurrentTransport
Christopher Tate91717492009-06-26 21:07:13 -07005276 + " returning " + prevTransport);
5277 } else {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005278 Slog.w(TAG, "Attempt to select unavailable transport " + transport);
Christopher Tate91717492009-06-26 21:07:13 -07005279 }
5280 return prevTransport;
5281 }
Christopher Tate043dadc2009-06-02 16:11:00 -07005282 }
5283
Christopher Tatef5e1c292010-12-08 18:40:26 -08005284 // Supply the configuration Intent for the given transport. If the name is not one
5285 // of the available transports, or if the transport does not supply any configuration
5286 // UI, the method returns null.
5287 public Intent getConfigurationIntent(String transportName) {
5288 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
5289 "getConfigurationIntent");
5290
5291 synchronized (mTransports) {
5292 final IBackupTransport transport = mTransports.get(transportName);
5293 if (transport != null) {
5294 try {
5295 final Intent intent = transport.configurationIntent();
Christopher Tatec58efa62011-08-01 19:20:14 -07005296 if (MORE_DEBUG) Slog.d(TAG, "getConfigurationIntent() returning config intent "
Christopher Tatef5e1c292010-12-08 18:40:26 -08005297 + intent);
5298 return intent;
5299 } catch (RemoteException e) {
5300 /* fall through to return null */
5301 }
5302 }
5303 }
5304
5305 return null;
5306 }
5307
5308 // Supply the configuration summary string for the given transport. If the name is
5309 // not one of the available transports, or if the transport does not supply any
5310 // summary / destination string, the method can return null.
5311 //
5312 // This string is used VERBATIM as the summary text of the relevant Settings item!
5313 public String getDestinationString(String transportName) {
5314 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
Christopher Tate2efd2db2011-07-19 16:32:49 -07005315 "getDestinationString");
Christopher Tatef5e1c292010-12-08 18:40:26 -08005316
5317 synchronized (mTransports) {
5318 final IBackupTransport transport = mTransports.get(transportName);
5319 if (transport != null) {
5320 try {
5321 final String text = transport.currentDestinationString();
Christopher Tatec58efa62011-08-01 19:20:14 -07005322 if (MORE_DEBUG) Slog.d(TAG, "getDestinationString() returning " + text);
Christopher Tatef5e1c292010-12-08 18:40:26 -08005323 return text;
5324 } catch (RemoteException e) {
5325 /* fall through to return null */
5326 }
5327 }
5328 }
5329
5330 return null;
5331 }
5332
Christopher Tate043dadc2009-06-02 16:11:00 -07005333 // Callback: a requested backup agent has been instantiated. This should only
5334 // be called from the Activity Manager.
Christopher Tate181fafa2009-05-14 11:12:14 -07005335 public void agentConnected(String packageName, IBinder agentBinder) {
Christopher Tate043dadc2009-06-02 16:11:00 -07005336 synchronized(mAgentConnectLock) {
5337 if (Binder.getCallingUid() == Process.SYSTEM_UID) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005338 Slog.d(TAG, "agentConnected pkg=" + packageName + " agent=" + agentBinder);
Christopher Tate043dadc2009-06-02 16:11:00 -07005339 IBackupAgent agent = IBackupAgent.Stub.asInterface(agentBinder);
5340 mConnectedAgent = agent;
5341 mConnecting = false;
5342 } else {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005343 Slog.w(TAG, "Non-system process uid=" + Binder.getCallingUid()
Christopher Tate043dadc2009-06-02 16:11:00 -07005344 + " claiming agent connected");
5345 }
5346 mAgentConnectLock.notifyAll();
5347 }
Christopher Tate181fafa2009-05-14 11:12:14 -07005348 }
5349
5350 // Callback: a backup agent has failed to come up, or has unexpectedly quit.
5351 // If the agent failed to come up in the first place, the agentBinder argument
Christopher Tate043dadc2009-06-02 16:11:00 -07005352 // will be null. This should only be called from the Activity Manager.
Christopher Tate181fafa2009-05-14 11:12:14 -07005353 public void agentDisconnected(String packageName) {
5354 // TODO: handle backup being interrupted
Christopher Tate043dadc2009-06-02 16:11:00 -07005355 synchronized(mAgentConnectLock) {
5356 if (Binder.getCallingUid() == Process.SYSTEM_UID) {
5357 mConnectedAgent = null;
5358 mConnecting = false;
5359 } else {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005360 Slog.w(TAG, "Non-system process uid=" + Binder.getCallingUid()
Christopher Tate043dadc2009-06-02 16:11:00 -07005361 + " claiming agent disconnected");
5362 }
5363 mAgentConnectLock.notifyAll();
5364 }
Christopher Tate181fafa2009-05-14 11:12:14 -07005365 }
Christopher Tate181fafa2009-05-14 11:12:14 -07005366
Christopher Tate1bb69062010-02-19 17:02:12 -08005367 // An application being installed will need a restore pass, then the Package Manager
5368 // will need to be told when the restore is finished.
5369 public void restoreAtInstall(String packageName, int token) {
5370 if (Binder.getCallingUid() != Process.SYSTEM_UID) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005371 Slog.w(TAG, "Non-system process uid=" + Binder.getCallingUid()
Christopher Tate1bb69062010-02-19 17:02:12 -08005372 + " attemping install-time restore");
5373 return;
5374 }
5375
5376 long restoreSet = getAvailableRestoreToken(packageName);
Joe Onorato8a9b2202010-02-26 18:56:32 -08005377 if (DEBUG) Slog.v(TAG, "restoreAtInstall pkg=" + packageName
Christopher Tate1bb69062010-02-19 17:02:12 -08005378 + " token=" + Integer.toHexString(token));
5379
Christopher Tatef0872722010-02-25 15:22:48 -08005380 if (mAutoRestore && mProvisioned && restoreSet != 0) {
Christopher Tate1bb69062010-02-19 17:02:12 -08005381 // okay, we're going to attempt a restore of this package from this restore set.
5382 // The eventual message back into the Package Manager to run the post-install
5383 // steps for 'token' will be issued from the restore handling code.
5384
5385 // We can use a synthetic PackageInfo here because:
5386 // 1. We know it's valid, since the Package Manager supplied the name
5387 // 2. Only the packageName field will be used by the restore code
5388 PackageInfo pkg = new PackageInfo();
5389 pkg.packageName = packageName;
5390
5391 mWakelock.acquire();
5392 Message msg = mBackupHandler.obtainMessage(MSG_RUN_RESTORE);
5393 msg.obj = new RestoreParams(getTransport(mCurrentTransport), null,
Chris Tate249345b2010-10-29 12:57:04 -07005394 restoreSet, pkg, token, true);
Christopher Tate1bb69062010-02-19 17:02:12 -08005395 mBackupHandler.sendMessage(msg);
5396 } else {
Christopher Tatef0872722010-02-25 15:22:48 -08005397 // Auto-restore disabled or no way to attempt a restore; just tell the Package
5398 // Manager to proceed with the post-install handling for this package.
Joe Onorato8a9b2202010-02-26 18:56:32 -08005399 if (DEBUG) Slog.v(TAG, "No restore set -- skipping restore");
Christopher Tate1bb69062010-02-19 17:02:12 -08005400 try {
5401 mPackageManagerBinder.finishPackageInstall(token);
5402 } catch (RemoteException e) { /* can't happen */ }
5403 }
5404 }
5405
Christopher Tate8c850b72009-06-07 19:33:20 -07005406 // Hand off a restore session
Chris Tate44ab8452010-11-16 15:10:49 -08005407 public IRestoreSession beginRestoreSession(String packageName, String transport) {
5408 if (DEBUG) Slog.v(TAG, "beginRestoreSession: pkg=" + packageName
5409 + " transport=" + transport);
5410
5411 boolean needPermission = true;
5412 if (transport == null) {
5413 transport = mCurrentTransport;
5414
5415 if (packageName != null) {
5416 PackageInfo app = null;
5417 try {
5418 app = mPackageManager.getPackageInfo(packageName, 0);
5419 } catch (NameNotFoundException nnf) {
5420 Slog.w(TAG, "Asked to restore nonexistent pkg " + packageName);
5421 throw new IllegalArgumentException("Package " + packageName + " not found");
5422 }
5423
5424 if (app.applicationInfo.uid == Binder.getCallingUid()) {
5425 // So: using the current active transport, and the caller has asked
5426 // that its own package will be restored. In this narrow use case
5427 // we do not require the caller to hold the permission.
5428 needPermission = false;
5429 }
5430 }
5431 }
5432
5433 if (needPermission) {
5434 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
5435 "beginRestoreSession");
5436 } else {
5437 if (DEBUG) Slog.d(TAG, "restoring self on current transport; no permission needed");
5438 }
Christopher Tatef68eb502009-06-16 11:02:01 -07005439
5440 synchronized(this) {
5441 if (mActiveRestoreSession != null) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005442 Slog.d(TAG, "Restore session requested but one already active");
Christopher Tatef68eb502009-06-16 11:02:01 -07005443 return null;
5444 }
Chris Tate44ab8452010-11-16 15:10:49 -08005445 mActiveRestoreSession = new ActiveRestoreSession(packageName, transport);
Christopher Tate73a3cb32010-12-13 18:27:26 -08005446 mBackupHandler.sendEmptyMessageDelayed(MSG_RESTORE_TIMEOUT, TIMEOUT_RESTORE_INTERVAL);
Christopher Tatef68eb502009-06-16 11:02:01 -07005447 }
5448 return mActiveRestoreSession;
Christopher Tate8c850b72009-06-07 19:33:20 -07005449 }
Christopher Tate043dadc2009-06-02 16:11:00 -07005450
Christopher Tate73a3cb32010-12-13 18:27:26 -08005451 void clearRestoreSession(ActiveRestoreSession currentSession) {
5452 synchronized(this) {
5453 if (currentSession != mActiveRestoreSession) {
5454 Slog.e(TAG, "ending non-current restore session");
5455 } else {
5456 if (DEBUG) Slog.v(TAG, "Clearing restore session and halting timeout");
5457 mActiveRestoreSession = null;
5458 mBackupHandler.removeMessages(MSG_RESTORE_TIMEOUT);
5459 }
5460 }
5461 }
5462
Christopher Tate44a27902010-01-27 17:15:49 -08005463 // Note that a currently-active backup agent has notified us that it has
5464 // completed the given outstanding asynchronous backup/restore operation.
Christopher Tate8e294d42011-08-31 20:37:12 -07005465 @Override
Christopher Tate44a27902010-01-27 17:15:49 -08005466 public void opComplete(int token) {
Christopher Tate8e294d42011-08-31 20:37:12 -07005467 if (MORE_DEBUG) Slog.v(TAG, "opComplete: " + Integer.toHexString(token));
5468 Operation op = null;
Christopher Tate44a27902010-01-27 17:15:49 -08005469 synchronized (mCurrentOpLock) {
Christopher Tate8e294d42011-08-31 20:37:12 -07005470 op = mCurrentOperations.get(token);
5471 if (op != null) {
5472 op.state = OP_ACKNOWLEDGED;
5473 }
Christopher Tate44a27902010-01-27 17:15:49 -08005474 mCurrentOpLock.notifyAll();
5475 }
Christopher Tate8e294d42011-08-31 20:37:12 -07005476
5477 // The completion callback, if any, is invoked on the handler
5478 if (op != null && op.callback != null) {
5479 Message msg = mBackupHandler.obtainMessage(MSG_OP_COMPLETE, op.callback);
5480 mBackupHandler.sendMessage(msg);
5481 }
Christopher Tate44a27902010-01-27 17:15:49 -08005482 }
5483
Christopher Tate9b3905c2009-06-08 15:24:01 -07005484 // ----- Restore session -----
5485
Christopher Tate80202c82010-01-25 19:37:47 -08005486 class ActiveRestoreSession extends IRestoreSession.Stub {
Christopher Tatef68eb502009-06-16 11:02:01 -07005487 private static final String TAG = "RestoreSession";
5488
Chris Tate44ab8452010-11-16 15:10:49 -08005489 private String mPackageName;
Christopher Tate9b3905c2009-06-08 15:24:01 -07005490 private IBackupTransport mRestoreTransport = null;
5491 RestoreSet[] mRestoreSets = null;
Christopher Tate73a3cb32010-12-13 18:27:26 -08005492 boolean mEnded = false;
Christopher Tate9b3905c2009-06-08 15:24:01 -07005493
Chris Tate44ab8452010-11-16 15:10:49 -08005494 ActiveRestoreSession(String packageName, String transport) {
5495 mPackageName = packageName;
Christopher Tate91717492009-06-26 21:07:13 -07005496 mRestoreTransport = getTransport(transport);
Christopher Tate9b3905c2009-06-08 15:24:01 -07005497 }
5498
5499 // --- Binder interface ---
Christopher Tate2d449afe2010-03-29 19:14:24 -07005500 public synchronized int getAvailableRestoreSets(IRestoreObserver observer) {
Joe Onorato5933a492009-07-23 18:24:08 -04005501 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
Christopher Tate9bbc21a2009-06-10 20:23:25 -07005502 "getAvailableRestoreSets");
Christopher Tate2d449afe2010-03-29 19:14:24 -07005503 if (observer == null) {
5504 throw new IllegalArgumentException("Observer must not be null");
5505 }
Christopher Tate9bbc21a2009-06-10 20:23:25 -07005506
Christopher Tate73a3cb32010-12-13 18:27:26 -08005507 if (mEnded) {
5508 throw new IllegalStateException("Restore session already ended");
5509 }
5510
Christopher Tate1bb69062010-02-19 17:02:12 -08005511 long oldId = Binder.clearCallingIdentity();
Christopher Tatef68eb502009-06-16 11:02:01 -07005512 try {
Christopher Tate43383042009-07-13 15:17:13 -07005513 if (mRestoreTransport == null) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005514 Slog.w(TAG, "Null transport getting restore sets");
Christopher Tate2d449afe2010-03-29 19:14:24 -07005515 return -1;
Dan Egnor0084da52009-07-29 12:57:16 -07005516 }
Christopher Tate2d449afe2010-03-29 19:14:24 -07005517 // spin off the transport request to our service thread
5518 mWakelock.acquire();
5519 Message msg = mBackupHandler.obtainMessage(MSG_RUN_GET_RESTORE_SETS,
5520 new RestoreGetSetsParams(mRestoreTransport, this, observer));
5521 mBackupHandler.sendMessage(msg);
5522 return 0;
Dan Egnor0084da52009-07-29 12:57:16 -07005523 } catch (Exception e) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005524 Slog.e(TAG, "Error in getAvailableRestoreSets", e);
Christopher Tate2d449afe2010-03-29 19:14:24 -07005525 return -1;
Christopher Tate1bb69062010-02-19 17:02:12 -08005526 } finally {
5527 Binder.restoreCallingIdentity(oldId);
Christopher Tatef68eb502009-06-16 11:02:01 -07005528 }
Christopher Tate9b3905c2009-06-08 15:24:01 -07005529 }
5530
Christopher Tate84725812010-02-04 15:52:40 -08005531 public synchronized int restoreAll(long token, IRestoreObserver observer) {
Dan Egnor0084da52009-07-29 12:57:16 -07005532 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
5533 "performRestore");
Christopher Tate9bbc21a2009-06-10 20:23:25 -07005534
Chris Tate44ab8452010-11-16 15:10:49 -08005535 if (DEBUG) Slog.d(TAG, "restoreAll token=" + Long.toHexString(token)
Christopher Tatef2c321a2009-08-10 15:43:36 -07005536 + " observer=" + observer);
Joe Onorato9a5e3e12009-07-01 21:04:03 -04005537
Christopher Tate73a3cb32010-12-13 18:27:26 -08005538 if (mEnded) {
5539 throw new IllegalStateException("Restore session already ended");
5540 }
5541
Dan Egnor0084da52009-07-29 12:57:16 -07005542 if (mRestoreTransport == null || mRestoreSets == null) {
Chris Tate44ab8452010-11-16 15:10:49 -08005543 Slog.e(TAG, "Ignoring restoreAll() with no restore set");
5544 return -1;
5545 }
5546
5547 if (mPackageName != null) {
5548 Slog.e(TAG, "Ignoring restoreAll() on single-package session");
Dan Egnor0084da52009-07-29 12:57:16 -07005549 return -1;
5550 }
5551
Christopher Tate21ab6a52009-09-24 18:01:46 -07005552 synchronized (mQueueLock) {
Christopher Tate21ab6a52009-09-24 18:01:46 -07005553 for (int i = 0; i < mRestoreSets.length; i++) {
5554 if (token == mRestoreSets[i].token) {
5555 long oldId = Binder.clearCallingIdentity();
Christopher Tate21ab6a52009-09-24 18:01:46 -07005556 mWakelock.acquire();
5557 Message msg = mBackupHandler.obtainMessage(MSG_RUN_RESTORE);
Chris Tate249345b2010-10-29 12:57:04 -07005558 msg.obj = new RestoreParams(mRestoreTransport, observer, token, true);
Christopher Tate21ab6a52009-09-24 18:01:46 -07005559 mBackupHandler.sendMessage(msg);
5560 Binder.restoreCallingIdentity(oldId);
5561 return 0;
5562 }
Christopher Tate9bbc21a2009-06-10 20:23:25 -07005563 }
5564 }
Christopher Tate0e0b4ae2009-08-10 16:13:47 -07005565
Joe Onorato8a9b2202010-02-26 18:56:32 -08005566 Slog.w(TAG, "Restore token " + Long.toHexString(token) + " not found");
Christopher Tate9b3905c2009-06-08 15:24:01 -07005567 return -1;
5568 }
5569
Christopher Tate284f1bb2011-07-07 14:31:18 -07005570 public synchronized int restoreSome(long token, IRestoreObserver observer,
5571 String[] packages) {
5572 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.BACKUP,
5573 "performRestore");
5574
5575 if (DEBUG) {
5576 StringBuilder b = new StringBuilder(128);
5577 b.append("restoreSome token=");
5578 b.append(Long.toHexString(token));
5579 b.append(" observer=");
5580 b.append(observer.toString());
5581 b.append(" packages=");
5582 if (packages == null) {
5583 b.append("null");
5584 } else {
5585 b.append('{');
5586 boolean first = true;
5587 for (String s : packages) {
5588 if (!first) {
5589 b.append(", ");
5590 } else first = false;
5591 b.append(s);
5592 }
5593 b.append('}');
5594 }
5595 Slog.d(TAG, b.toString());
5596 }
5597
5598 if (mEnded) {
5599 throw new IllegalStateException("Restore session already ended");
5600 }
5601
5602 if (mRestoreTransport == null || mRestoreSets == null) {
5603 Slog.e(TAG, "Ignoring restoreAll() with no restore set");
5604 return -1;
5605 }
5606
5607 if (mPackageName != null) {
5608 Slog.e(TAG, "Ignoring restoreAll() on single-package session");
5609 return -1;
5610 }
5611
5612 synchronized (mQueueLock) {
5613 for (int i = 0; i < mRestoreSets.length; i++) {
5614 if (token == mRestoreSets[i].token) {
5615 long oldId = Binder.clearCallingIdentity();
5616 mWakelock.acquire();
5617 Message msg = mBackupHandler.obtainMessage(MSG_RUN_RESTORE);
5618 msg.obj = new RestoreParams(mRestoreTransport, observer, token,
5619 packages, true);
5620 mBackupHandler.sendMessage(msg);
5621 Binder.restoreCallingIdentity(oldId);
5622 return 0;
5623 }
5624 }
5625 }
5626
5627 Slog.w(TAG, "Restore token " + Long.toHexString(token) + " not found");
5628 return -1;
5629 }
5630
Christopher Tate84725812010-02-04 15:52:40 -08005631 public synchronized int restorePackage(String packageName, IRestoreObserver observer) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005632 if (DEBUG) Slog.v(TAG, "restorePackage pkg=" + packageName + " obs=" + observer);
Christopher Tate84725812010-02-04 15:52:40 -08005633
Christopher Tate73a3cb32010-12-13 18:27:26 -08005634 if (mEnded) {
5635 throw new IllegalStateException("Restore session already ended");
5636 }
5637
Chris Tate44ab8452010-11-16 15:10:49 -08005638 if (mPackageName != null) {
5639 if (! mPackageName.equals(packageName)) {
5640 Slog.e(TAG, "Ignoring attempt to restore pkg=" + packageName
5641 + " on session for package " + mPackageName);
5642 return -1;
5643 }
5644 }
5645
Christopher Tate84725812010-02-04 15:52:40 -08005646 PackageInfo app = null;
5647 try {
5648 app = mPackageManager.getPackageInfo(packageName, 0);
5649 } catch (NameNotFoundException nnf) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005650 Slog.w(TAG, "Asked to restore nonexistent pkg " + packageName);
Christopher Tate84725812010-02-04 15:52:40 -08005651 return -1;
5652 }
5653
5654 // If the caller is not privileged and is not coming from the target
5655 // app's uid, throw a permission exception back to the caller.
5656 int perm = mContext.checkPermission(android.Manifest.permission.BACKUP,
5657 Binder.getCallingPid(), Binder.getCallingUid());
5658 if ((perm == PackageManager.PERMISSION_DENIED) &&
5659 (app.applicationInfo.uid != Binder.getCallingUid())) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005660 Slog.w(TAG, "restorePackage: bad packageName=" + packageName
Christopher Tate84725812010-02-04 15:52:40 -08005661 + " or calling uid=" + Binder.getCallingUid());
5662 throw new SecurityException("No permission to restore other packages");
5663 }
5664
Christopher Tate7d411a32010-02-26 11:27:08 -08005665 // If the package has no backup agent, we obviously cannot proceed
5666 if (app.applicationInfo.backupAgentName == null) {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005667 Slog.w(TAG, "Asked to restore package " + packageName + " with no agent");
Christopher Tate7d411a32010-02-26 11:27:08 -08005668 return -1;
5669 }
5670
Christopher Tate84725812010-02-04 15:52:40 -08005671 // So far so good; we're allowed to try to restore this package. Now
5672 // check whether there is data for it in the current dataset, falling back
5673 // to the ancestral dataset if not.
Christopher Tate1bb69062010-02-19 17:02:12 -08005674 long token = getAvailableRestoreToken(packageName);
Christopher Tate84725812010-02-04 15:52:40 -08005675
5676 // If we didn't come up with a place to look -- no ancestral dataset and
5677 // the app has never been backed up from this device -- there's nothing
5678 // to do but return failure.
5679 if (token == 0) {
Chris Tate44ab8452010-11-16 15:10:49 -08005680 if (DEBUG) Slog.w(TAG, "No data available for this package; not restoring");
Christopher Tate84725812010-02-04 15:52:40 -08005681 return -1;
5682 }
5683
5684 // Ready to go: enqueue the restore request and claim success
5685 long oldId = Binder.clearCallingIdentity();
5686 mWakelock.acquire();
5687 Message msg = mBackupHandler.obtainMessage(MSG_RUN_RESTORE);
Chris Tate249345b2010-10-29 12:57:04 -07005688 msg.obj = new RestoreParams(mRestoreTransport, observer, token, app, 0, false);
Christopher Tate84725812010-02-04 15:52:40 -08005689 mBackupHandler.sendMessage(msg);
5690 Binder.restoreCallingIdentity(oldId);
5691 return 0;
5692 }
5693
Christopher Tate73a3cb32010-12-13 18:27:26 -08005694 // Posted to the handler to tear down a restore session in a cleanly synchronized way
5695 class EndRestoreRunnable implements Runnable {
5696 BackupManagerService mBackupManager;
5697 ActiveRestoreSession mSession;
5698
5699 EndRestoreRunnable(BackupManagerService manager, ActiveRestoreSession session) {
5700 mBackupManager = manager;
5701 mSession = session;
5702 }
5703
5704 public void run() {
5705 // clean up the session's bookkeeping
5706 synchronized (mSession) {
5707 try {
5708 if (mSession.mRestoreTransport != null) {
5709 mSession.mRestoreTransport.finishRestore();
5710 }
5711 } catch (Exception e) {
5712 Slog.e(TAG, "Error in finishRestore", e);
5713 } finally {
5714 mSession.mRestoreTransport = null;
5715 mSession.mEnded = true;
5716 }
5717 }
5718
5719 // clean up the BackupManagerService side of the bookkeeping
5720 // and cancel any pending timeout message
5721 mBackupManager.clearRestoreSession(mSession);
5722 }
5723 }
5724
Dan Egnor0084da52009-07-29 12:57:16 -07005725 public synchronized void endRestoreSession() {
Joe Onorato8a9b2202010-02-26 18:56:32 -08005726 if (DEBUG) Slog.d(TAG, "endRestoreSession");
Joe Onorato9a5e3e12009-07-01 21:04:03 -04005727
Christopher Tate73a3cb32010-12-13 18:27:26 -08005728 if (mEnded) {
5729 throw new IllegalStateException("Restore session already ended");
Dan Egnor0084da52009-07-29 12:57:16 -07005730 }
5731
Christopher Tate73a3cb32010-12-13 18:27:26 -08005732 mBackupHandler.post(new EndRestoreRunnable(BackupManagerService.this, this));
Christopher Tate9b3905c2009-06-08 15:24:01 -07005733 }
5734 }
5735
Joe Onoratob1a7ffe2009-05-06 18:06:21 -07005736 @Override
5737 public void dump(FileDescriptor fd, PrintWriter pw, String[] args) {
Jeff Sharkeyeb4cc4922012-04-26 18:17:29 -07005738 mContext.enforceCallingOrSelfPermission(android.Manifest.permission.DUMP, TAG);
5739
Fabrice Di Meglio8aac3ee2011-01-12 18:47:14 -08005740 long identityToken = Binder.clearCallingIdentity();
5741 try {
5742 dumpInternal(pw);
5743 } finally {
5744 Binder.restoreCallingIdentity(identityToken);
5745 }
5746 }
5747
5748 private void dumpInternal(PrintWriter pw) {
Joe Onoratob1a7ffe2009-05-06 18:06:21 -07005749 synchronized (mQueueLock) {
Christopher Tate8031a3d2009-07-06 16:36:05 -07005750 pw.println("Backup Manager is " + (mEnabled ? "enabled" : "disabled")
Christopher Tate55f931a2009-09-29 17:17:34 -07005751 + " / " + (!mProvisioned ? "not " : "") + "provisioned / "
Christopher Tatec2af5d32010-02-02 15:18:58 -08005752 + (this.mPendingInits.size() == 0 ? "not " : "") + "pending init");
Christopher Tateae06ed92010-02-25 17:13:28 -08005753 pw.println("Auto-restore is " + (mAutoRestore ? "enabled" : "disabled"));
Christopher Tate336a6492011-10-05 16:05:43 -07005754 if (mBackupRunning) pw.println("Backup currently running");
5755 pw.println("Last backup pass started: " + mLastBackupPass
Christopher Tate55f931a2009-09-29 17:17:34 -07005756 + " (now = " + System.currentTimeMillis() + ')');
5757 pw.println(" next scheduled: " + mNextBackupPass);
5758
Christopher Tate91717492009-06-26 21:07:13 -07005759 pw.println("Available transports:");
5760 for (String t : listAllTransports()) {
Dan Egnor852f8e42009-09-30 11:20:45 -07005761 pw.println((t.equals(mCurrentTransport) ? " * " : " ") + t);
5762 try {
Fabrice Di Meglio8aac3ee2011-01-12 18:47:14 -08005763 IBackupTransport transport = getTransport(t);
5764 File dir = new File(mBaseStateDir, transport.transportDirName());
5765 pw.println(" destination: " + transport.currentDestinationString());
5766 pw.println(" intent: " + transport.configurationIntent());
Dan Egnor852f8e42009-09-30 11:20:45 -07005767 for (File f : dir.listFiles()) {
5768 pw.println(" " + f.getName() + " - " + f.length() + " state bytes");
5769 }
Fabrice Di Meglio8aac3ee2011-01-12 18:47:14 -08005770 } catch (Exception e) {
5771 Slog.e(TAG, "Error in transport", e);
Dan Egnor852f8e42009-09-30 11:20:45 -07005772 pw.println(" Error: " + e);
5773 }
Christopher Tate91717492009-06-26 21:07:13 -07005774 }
Christopher Tate55f931a2009-09-29 17:17:34 -07005775
5776 pw.println("Pending init: " + mPendingInits.size());
5777 for (String s : mPendingInits) {
5778 pw.println(" " + s);
5779 }
5780
Christopher Tate6de74ff2012-01-17 15:20:32 -08005781 if (DEBUG_BACKUP_TRACE) {
5782 synchronized (mBackupTrace) {
5783 if (!mBackupTrace.isEmpty()) {
5784 pw.println("Most recent backup trace:");
5785 for (String s : mBackupTrace) {
5786 pw.println(" " + s);
5787 }
5788 }
5789 }
5790 }
5791
Joe Onoratob1a7ffe2009-05-06 18:06:21 -07005792 int N = mBackupParticipants.size();
Christopher Tate55f931a2009-09-29 17:17:34 -07005793 pw.println("Participants:");
Joe Onoratob1a7ffe2009-05-06 18:06:21 -07005794 for (int i=0; i<N; i++) {
5795 int uid = mBackupParticipants.keyAt(i);
5796 pw.print(" uid: ");
5797 pw.println(uid);
Christopher Tatea3d55342012-03-27 13:16:18 -07005798 HashSet<String> participants = mBackupParticipants.valueAt(i);
5799 for (String app: participants) {
5800 pw.println(" " + app);
Joe Onoratob1a7ffe2009-05-06 18:06:21 -07005801 }
5802 }
Christopher Tate55f931a2009-09-29 17:17:34 -07005803
Christopher Tateb49ceb32010-02-08 16:22:24 -08005804 pw.println("Ancestral packages: "
5805 + (mAncestralPackages == null ? "none" : mAncestralPackages.size()));
Christopher Tate5923c972010-04-04 17:45:35 -07005806 if (mAncestralPackages != null) {
5807 for (String pkg : mAncestralPackages) {
5808 pw.println(" " + pkg);
5809 }
Christopher Tateb49ceb32010-02-08 16:22:24 -08005810 }
5811
Christopher Tate73e02522009-07-15 14:18:26 -07005812 pw.println("Ever backed up: " + mEverStoredApps.size());
5813 for (String pkg : mEverStoredApps) {
5814 pw.println(" " + pkg);
5815 }
Christopher Tate55f931a2009-09-29 17:17:34 -07005816
5817 pw.println("Pending backup: " + mPendingBackups.size());
Christopher Tate6aa41f42009-06-19 14:14:22 -07005818 for (BackupRequest req : mPendingBackups.values()) {
Christopher Tate6ef58a12009-06-29 14:56:28 -07005819 pw.println(" " + req);
Christopher Tate181fafa2009-05-14 11:12:14 -07005820 }
Joe Onoratob1a7ffe2009-05-06 18:06:21 -07005821 }
5822 }
Christopher Tate487529a2009-04-29 14:03:25 -07005823}