From 44deb053252a3bd2f57a007ab9560f4924f62394 Mon Sep 17 00:00:00 2001 From: Glenn Kasten Date: Sun, 5 Feb 2012 18:09:08 -0800 Subject: Factor out and speed up permission-checking code Use the caching permission check for dump to save IPC. Cache getpid() to save kernel call for other permission checks. The C runtime library getpid() can't cache due to a fork race condition, but we know that mediaserver doesn't fork. Don't construct String16 on the stack. Change-Id: I6be6161dae5155d39ba6ed6228e7683e67be34ed --- services/audioflinger/ServiceUtilities.cpp | 55 ++++++++++++++++++++++++++++++ 1 file changed, 55 insertions(+) create mode 100644 services/audioflinger/ServiceUtilities.cpp (limited to 'services/audioflinger/ServiceUtilities.cpp') diff --git a/services/audioflinger/ServiceUtilities.cpp b/services/audioflinger/ServiceUtilities.cpp new file mode 100644 index 0000000..6a58852 --- /dev/null +++ b/services/audioflinger/ServiceUtilities.cpp @@ -0,0 +1,55 @@ +/* + * Copyright (C) 2012 The Android Open Source Project + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#include +#include +#include +#include "ServiceUtilities.h" + +namespace android { + +// This optimization assumes mediaserver process doesn't fork, which it doesn't +const pid_t getpid_cached = getpid(); + +bool recordingAllowed() { + if (getpid_cached == IPCThreadState::self()->getCallingPid()) return true; + static const String16 sRecordAudio("android.permission.RECORD_AUDIO"); + // don't use PermissionCache; this is not a system permission + bool ok = checkCallingPermission(sRecordAudio); + if (!ok) ALOGE("Request requires android.permission.RECORD_AUDIO"); + return ok; +} + +bool settingsAllowed() { + if (getpid_cached == IPCThreadState::self()->getCallingPid()) return true; + static const String16 sAudioSettings("android.permission.MODIFY_AUDIO_SETTINGS"); + // don't use PermissionCache; this is not a system permission + bool ok = checkCallingPermission(sAudioSettings); + if (!ok) ALOGE("Request requires android.permission.MODIFY_AUDIO_SETTINGS"); + return ok; +} + +bool dumpAllowed() { + // don't optimize for same pid, since mediaserver never dumps itself + static const String16 sDump("android.permission.DUMP"); + // OK to use PermissionCache; this is a system permission + bool ok = PermissionCache::checkCallingPermission(sDump); + // convention is for caller to dump an error message to fd instead of logging here + //if (!ok) ALOGE("Request requires android.permission.DUMP"); + return ok; +} + +} // namespace android -- cgit v1.1