A bunch more changes to get the whole system properly booted
This commit is contained in:
parent
3222551702
commit
720b71f1e8
58 changed files with 1835 additions and 532 deletions
|
|
@ -1,4 +1,3 @@
|
|||
add_subdirectory(mir_support)
|
||||
add_subdirectory(GLESv1_dec)
|
||||
add_subdirectory(GLESv2_dec)
|
||||
add_subdirectory(libOpenGLESDispatch)
|
||||
|
|
|
|||
|
|
@ -14,5 +14,11 @@ add_custom_command(
|
|||
set(SOURCES
|
||||
GLESv1Decoder.cpp)
|
||||
|
||||
if ("${cmake_build_type_lower}" STREQUAL "debug")
|
||||
set(OPENGL_DEBUG "-DOPENGL_DEBUG_PRINTOUT -DCHECK_GL_ERROR")
|
||||
set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} ${OPENGL_DEBUG}")
|
||||
set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} ${OPENGL_DEBUG}")
|
||||
endif()
|
||||
|
||||
add_library(GLESv1_dec ${SOURCES} ${GENERATED_SOURCES})
|
||||
target_link_libraries(GLESv1_dec OpenglCodecCommon)
|
||||
|
|
|
|||
|
|
@ -14,5 +14,11 @@ add_custom_command(
|
|||
set(SOURCES
|
||||
GLESv2Decoder.cpp)
|
||||
|
||||
if ("${cmake_build_type_lower}" STREQUAL "debug")
|
||||
set(OPENGL_DEBUG "-DOPENGL_DEBUG_PRINTOUT -DCHECK_GL_ERROR")
|
||||
set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} ${OPENGL_DEBUG}")
|
||||
set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} ${OPENGL_DEBUG}")
|
||||
endif()
|
||||
|
||||
add_library(GLESv2_dec ${SOURCES} ${GENERATED_SOURCES})
|
||||
target_link_libraries(GLESv2_dec OpenglCodecCommon)
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@ set(SOURCES
|
|||
ColorBuffer.cpp
|
||||
FbConfig.cpp
|
||||
FrameBuffer.cpp
|
||||
NativeSubWindow_mir.cpp
|
||||
NativeSubWindow_delegate.cpp
|
||||
ReadBuffer.cpp
|
||||
RenderContext.cpp
|
||||
RenderControl.cpp
|
||||
|
|
@ -19,9 +19,6 @@ set(SOURCES
|
|||
UnixStream.cpp
|
||||
WindowSurface.cpp)
|
||||
|
||||
include_directories(BEFORE
|
||||
${MIRCLIENT_INCLUDE_DIRS})
|
||||
|
||||
add_library(OpenglRender ${SOURCES})
|
||||
target_link_libraries(OpenglRender
|
||||
emugl_common
|
||||
|
|
@ -30,8 +27,5 @@ target_link_libraries(OpenglRender
|
|||
renderControl_dec
|
||||
OpenGLESDispatch
|
||||
OpenglCodecCommon
|
||||
mir_support
|
||||
${EGL_LDFLAGS}
|
||||
${EGL_LIBRARIES}
|
||||
${MIRCLIENT_LDFLAGS}
|
||||
${MIRCLIENT_LIBRARIES})
|
||||
${EGL_LIBRARIES})
|
||||
|
|
|
|||
|
|
@ -28,10 +28,6 @@
|
|||
|
||||
#include <stdio.h>
|
||||
|
||||
#include "mir_support/shared_state.h"
|
||||
|
||||
#define MID_AUBERGINE(x) (x)*0.368627451f, (x)*0.152941176f, (x)*0.31372549f
|
||||
|
||||
namespace {
|
||||
|
||||
// Helper class to call the bind_locked() / unbind_locked() properly.
|
||||
|
|
@ -188,8 +184,7 @@ bool FrameBuffer::initialize(int width, int height, bool useSubWindow)
|
|||
//
|
||||
// Initialize backend EGL display
|
||||
//
|
||||
mir::support::SharedState::get()->ensure_connection();
|
||||
fb->m_eglDisplay = s_egl.eglGetDisplay(mir::support::SharedState::get()->native_display());
|
||||
fb->m_eglDisplay = s_egl.eglGetDisplay(EGL_DEFAULT_DISPLAY);
|
||||
if (fb->m_eglDisplay == EGL_NO_DISPLAY) {
|
||||
ERR("Failed to Initialize backend EGL display\n");
|
||||
delete fb;
|
||||
|
|
@ -582,7 +577,6 @@ bool FrameBuffer::setupSubWindow(FBNativeWindowType p_window,
|
|||
if (m_lastPostedColorBuffer) {
|
||||
post(m_lastPostedColorBuffer, false);
|
||||
} else {
|
||||
s_gles2.glClearColor(MID_AUBERGINE(1.0), 1.0);
|
||||
s_gles2.glClear(GL_COLOR_BUFFER_BIT |
|
||||
GL_DEPTH_BUFFER_BIT |
|
||||
GL_STENCIL_BUFFER_BIT);
|
||||
|
|
|
|||
|
|
@ -20,10 +20,21 @@
|
|||
|
||||
#include <EGL/egl.h>
|
||||
|
||||
#include <memory>
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C" {
|
||||
#endif
|
||||
|
||||
class SubWindowHandler {
|
||||
public:
|
||||
virtual ~SubWindowHandler() { }
|
||||
virtual EGLNativeWindowType create_window(int x, int y, int width, int height) = 0;
|
||||
virtual void destroy_window(EGLNativeWindowType win) = 0;
|
||||
};
|
||||
|
||||
void registerSubWindowHandler(const std::shared_ptr<SubWindowHandler> &handler);
|
||||
|
||||
typedef void (*SubWindowRepaintCallback)(void*);
|
||||
|
||||
// Create a new sub-window that will be used to display the content of the
|
||||
|
|
|
|||
72
external/android-emugl/host/libs/libOpenglRender/NativeSubWindow_delegate.cpp
vendored
Normal file
72
external/android-emugl/host/libs/libOpenglRender/NativeSubWindow_delegate.cpp
vendored
Normal file
|
|
@ -0,0 +1,72 @@
|
|||
/*
|
||||
* Copyright (C) 2011 The Android Open Source Project
|
||||
*
|
||||
* Licensed under the Apache License, Version 2.0 (the "License");
|
||||
* you may not use this file except in compliance with the License.
|
||||
* You may obtain a copy of the License at
|
||||
*
|
||||
* http://www.apache.org/licenses/LICENSE-2.0
|
||||
*
|
||||
* Unless required by applicable law or agreed to in writing, software
|
||||
* distributed under the License is distributed on an "AS IS" BASIS,
|
||||
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
* See the License for the specific language governing permissions and
|
||||
* limitations under the License.
|
||||
*/
|
||||
|
||||
#include "NativeSubWindow.h"
|
||||
|
||||
#include <stdexcept>
|
||||
#include <string>
|
||||
#include <map>
|
||||
|
||||
namespace {
|
||||
static std::shared_ptr<SubWindowHandler> current_handler = nullptr;
|
||||
}
|
||||
|
||||
void registerSubWindowHandler(const std::shared_ptr<SubWindowHandler> &handler) {
|
||||
if (current_handler)
|
||||
throw std::runtime_error("A sub window handle is already registered");
|
||||
|
||||
current_handler = handler;
|
||||
}
|
||||
|
||||
EGLNativeWindowType createSubWindow(FBNativeWindowType p_window,
|
||||
int x,
|
||||
int y,
|
||||
int width,
|
||||
int height,
|
||||
SubWindowRepaintCallback repaint_callback,
|
||||
void* repaint_callback_param) {
|
||||
(void) p_window;
|
||||
(void) repaint_callback;
|
||||
(void) repaint_callback_param;
|
||||
|
||||
if (!current_handler)
|
||||
return (EGLNativeWindowType) 0;
|
||||
|
||||
return current_handler->create_window(x, y, width, height);
|
||||
}
|
||||
|
||||
void destroySubWindow(EGLNativeWindowType win) {
|
||||
if (!current_handler)
|
||||
return;
|
||||
|
||||
return current_handler->destroy_window(win);
|
||||
}
|
||||
|
||||
int moveSubWindow(FBNativeWindowType p_parent_window,
|
||||
EGLNativeWindowType p_sub_window,
|
||||
int x,
|
||||
int y,
|
||||
int width,
|
||||
int height) {
|
||||
(void) p_parent_window;
|
||||
(void) p_sub_window;
|
||||
(void) x;
|
||||
(void) y;
|
||||
(void) width;
|
||||
(void) height;
|
||||
|
||||
return true;
|
||||
}
|
||||
|
|
@ -1,10 +0,0 @@
|
|||
set(SOURCES
|
||||
shared_state.cpp)
|
||||
|
||||
include_directories(BEFORE
|
||||
${MIRCLIENT_INCLUDE_DIRS})
|
||||
|
||||
add_library(mir_support ${SOURCES})
|
||||
target_link_libraries(mir_support
|
||||
${MIRCLIENT_LDFLAGS}
|
||||
${MIRCLIENT_LIBRARIES})
|
||||
|
|
@ -1,74 +0,0 @@
|
|||
/*
|
||||
* Copyright (C) 2016 Simon Fels <morphis@gravedo.de>
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License version 3, as published
|
||||
* by the Free Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranties of
|
||||
* MERCHANTABILITY, SATISFACTORY QUALITY, or FITNESS FOR A PARTICULAR
|
||||
* PURPOSE. See the GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License along
|
||||
* with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*
|
||||
*/
|
||||
|
||||
#include "mir_support/shared_state.h"
|
||||
|
||||
namespace mir {
|
||||
namespace support {
|
||||
|
||||
std::shared_ptr<SharedState> SharedState::get() {
|
||||
static auto instance = std::make_shared<SharedState>();
|
||||
return instance;
|
||||
}
|
||||
|
||||
SharedState::SharedState() :
|
||||
connection_(nullptr) {
|
||||
}
|
||||
|
||||
SharedState::~SharedState() {
|
||||
release_connection();
|
||||
}
|
||||
|
||||
void SharedState::ensure_connection() {
|
||||
if (connection_)
|
||||
return;
|
||||
|
||||
auto xdg_runtime_dir = ::getenv("XDG_RUNTIME_DIR");
|
||||
if (!xdg_runtime_dir)
|
||||
throw std::runtime_error("Failed to find XDG_RUNTIME_DIR");
|
||||
|
||||
std::string socket_path = xdg_runtime_dir;
|
||||
socket_path += "/mir_socket";
|
||||
|
||||
connection_ = mir_connect_sync(socket_path.c_str(), "anbox");
|
||||
if (!mir_connection_is_valid(connection_)) {
|
||||
std::string msg;
|
||||
msg += "Failed to connect with Mir server: ";
|
||||
msg += mir_connection_get_error_message(connection_);
|
||||
msg += "\n";
|
||||
throw std::runtime_error(msg.c_str());
|
||||
}
|
||||
}
|
||||
|
||||
void SharedState::release_connection() {
|
||||
if (!connection_)
|
||||
return;
|
||||
|
||||
mir_connection_release(connection_);
|
||||
connection_ = nullptr;
|
||||
}
|
||||
|
||||
MirConnection* SharedState::connection() const {
|
||||
return connection_;
|
||||
}
|
||||
|
||||
EGLNativeDisplayType SharedState::native_display() const {
|
||||
return mir_connection_get_egl_native_display(connection_);
|
||||
}
|
||||
|
||||
} // namespace support
|
||||
} // namespace mir
|
||||
|
|
@ -1,50 +0,0 @@
|
|||
/*
|
||||
* Copyright (C) 2016 Simon Fels <morphis@gravedo.de>
|
||||
*
|
||||
* This program is free software: you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License version 3, as published
|
||||
* by the Free Software Foundation.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranties of
|
||||
* MERCHANTABILITY, SATISFACTORY QUALITY, or FITNESS FOR A PARTICULAR
|
||||
* PURPOSE. See the GNU General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU General Public License along
|
||||
* with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
*
|
||||
*/
|
||||
|
||||
#ifndef MIR_SUPPORT_SHARED_STATE_H_
|
||||
#define MIR_SUPPORT_SHARED_STATE_H_
|
||||
|
||||
#define MIR_EGL_PLATFORM
|
||||
|
||||
#include <mirclient/mir_toolkit/mir_client_library.h>
|
||||
|
||||
#include <EGL/egl.h>
|
||||
|
||||
#include <memory>
|
||||
|
||||
namespace mir {
|
||||
namespace support {
|
||||
class SharedState {
|
||||
public:
|
||||
static std::shared_ptr<SharedState> get();
|
||||
|
||||
SharedState();
|
||||
~SharedState();
|
||||
|
||||
void ensure_connection();
|
||||
void release_connection();
|
||||
|
||||
MirConnection* connection() const;
|
||||
EGLNativeDisplayType native_display() const;
|
||||
|
||||
private:
|
||||
MirConnection *connection_;
|
||||
};
|
||||
} // namespace support
|
||||
} // namespace mir
|
||||
|
||||
#endif
|
||||
|
|
@ -10,5 +10,11 @@ add_custom_command(
|
|||
WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}
|
||||
DEPENDS emugen)
|
||||
|
||||
if ("${cmake_build_type_lower}" STREQUAL "debug")
|
||||
set(OPENGL_DEBUG "-DOPENGL_DEBUG_PRINTOUT -DCHECK_GL_ERROR")
|
||||
set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} ${OPENGL_DEBUG}")
|
||||
set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} ${OPENGL_DEBUG}")
|
||||
endif()
|
||||
|
||||
add_library(renderControl_dec ${GENERATED_SOURCES})
|
||||
target_link_libraries(renderControl_dec OpenglCodecCommon)
|
||||
|
|
|
|||
138
external/bubblewrap/bubblewrap.c
vendored
138
external/bubblewrap/bubblewrap.c
vendored
|
|
@ -1319,10 +1319,6 @@ bwrap_main (int argc,
|
|||
/* Get the (optional) capabilities we need, drop root */
|
||||
acquire_caps ();
|
||||
|
||||
/* Never gain any more privs during exec */
|
||||
if (prctl (PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) < 0)
|
||||
die_with_error ("prctl(PR_SET_NO_NEW_CAPS) failed");
|
||||
|
||||
/* The initial code is run with high permissions
|
||||
(i.e. CAP_SYS_ADMIN), so take lots of care. */
|
||||
|
||||
|
|
@ -1390,9 +1386,7 @@ bwrap_main (int argc,
|
|||
/* We block sigchild here so that we can use signalfd in the monitor. */
|
||||
block_sigchild ();
|
||||
|
||||
clone_flags = SIGCHLD | CLONE_NEWNS;
|
||||
if (opt_unshare_user)
|
||||
clone_flags |= CLONE_NEWUSER;
|
||||
clone_flags = SIGCHLD;
|
||||
if (opt_unshare_pid)
|
||||
clone_flags |= CLONE_NEWPID;
|
||||
if (opt_unshare_net)
|
||||
|
|
@ -1423,14 +1417,6 @@ bwrap_main (int argc,
|
|||
pid = raw_clone (clone_flags, NULL);
|
||||
if (pid == -1)
|
||||
{
|
||||
if (opt_unshare_user)
|
||||
{
|
||||
if (errno == EINVAL)
|
||||
die ("Creating new namespace failed, likely because the kernel does not support user namespaces. bwrap must be installed setuid on such systems.");
|
||||
else if (errno == EPERM && !is_privileged)
|
||||
die ("No permissions to creating new namespace, likely because the kernel does not allow non-privileged user namespaces. On e.g. debian this can be enabled with 'sysctl kernel.unprivileged_userns_clone=1'.");
|
||||
}
|
||||
|
||||
die_with_error ("Creating new namespace failed");
|
||||
}
|
||||
|
||||
|
|
@ -1439,18 +1425,6 @@ bwrap_main (int argc,
|
|||
|
||||
if (pid != 0)
|
||||
{
|
||||
if (is_privileged && opt_unshare_user)
|
||||
{
|
||||
/* Map the uid/gid 0 if opt_needs_devpts, as otherwise
|
||||
* mounting it will fail.
|
||||
* Due to this non-direct mapping we need to have set[ug]id
|
||||
* caps in the parent namespaces, and thus we need to write
|
||||
* the map in the parent namespace, not the child. */
|
||||
write_uid_gid_map (ns_uid, uid,
|
||||
ns_gid, gid,
|
||||
pid, TRUE, opt_needs_devpts);
|
||||
}
|
||||
|
||||
/* Initial launched process, wait for exec:ed command to exit */
|
||||
|
||||
if (opt_pid_file) {
|
||||
|
|
@ -1464,9 +1438,6 @@ bwrap_main (int argc,
|
|||
close(pid_file_fd);
|
||||
}
|
||||
|
||||
/* We don't need any caps in the launcher, drop them immediately. */
|
||||
drop_caps ();
|
||||
|
||||
/* Let child run */
|
||||
val = 1;
|
||||
res = write (child_wait_fd, &val, 8);
|
||||
|
|
@ -1486,25 +1457,6 @@ bwrap_main (int argc,
|
|||
|
||||
ns_uid = opt_sandbox_uid;
|
||||
ns_gid = opt_sandbox_gid;
|
||||
if (!is_privileged && opt_unshare_user)
|
||||
{
|
||||
/* In the unprivileged case we have to write the uid/gid maps in
|
||||
* the child, because we have no caps in the parent */
|
||||
|
||||
if (opt_needs_devpts)
|
||||
{
|
||||
/* This is a bit hacky, but we need to first map the real uid/gid to
|
||||
0, otherwise we can't mount the devpts filesystem because root is
|
||||
not mapped. Later we will create another child user namespace and
|
||||
map back to the real uid */
|
||||
ns_uid = 0;
|
||||
ns_gid = 0;
|
||||
}
|
||||
|
||||
write_uid_gid_map (ns_uid, uid,
|
||||
ns_gid, gid,
|
||||
-1, TRUE, FALSE);
|
||||
}
|
||||
|
||||
old_umask = umask (0);
|
||||
|
||||
|
|
@ -1542,53 +1494,7 @@ bwrap_main (int argc,
|
|||
if (chdir ("/") != 0)
|
||||
die_with_error ("chdir / (base path)");
|
||||
|
||||
if (is_privileged)
|
||||
{
|
||||
pid_t child;
|
||||
int privsep_sockets[2];
|
||||
|
||||
if (socketpair (AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC, 0, privsep_sockets) != 0)
|
||||
die_with_error ("Can't create privsep socket");
|
||||
|
||||
child = fork ();
|
||||
if (child == -1)
|
||||
die_with_error ("Can't fork unprivileged helper");
|
||||
|
||||
if (child == 0)
|
||||
{
|
||||
/* Unprivileged setup process */
|
||||
drop_caps ();
|
||||
close (privsep_sockets[0]);
|
||||
setup_newroot (opt_unshare_pid, privsep_sockets[1]);
|
||||
exit (0);
|
||||
}
|
||||
else
|
||||
{
|
||||
uint32_t buffer[2048]; /* 8k, but is int32 to guarantee nice alignment */
|
||||
uint32_t op, flags;
|
||||
const char *arg1, *arg2;
|
||||
cleanup_fd int unpriv_socket = -1;
|
||||
|
||||
unpriv_socket = privsep_sockets[0];
|
||||
close (privsep_sockets[1]);
|
||||
|
||||
do
|
||||
{
|
||||
op = read_priv_sec_op (unpriv_socket, buffer, sizeof (buffer),
|
||||
&flags, &arg1, &arg2);
|
||||
privileged_op (-1, op, flags, arg1, arg2);
|
||||
if (write (unpriv_socket, buffer, 1) != 1)
|
||||
die ("Can't write to op_socket");
|
||||
}
|
||||
while (op != PRIV_SEP_OP_DONE);
|
||||
|
||||
/* Continue post setup */
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
setup_newroot (opt_unshare_pid, -1);
|
||||
}
|
||||
setup_newroot (opt_unshare_pid, -1);
|
||||
|
||||
/* The old root better be rprivate or we will send unmount events to the parent namespace */
|
||||
if (mount ("oldroot", "oldroot", NULL, MS_REC | MS_PRIVATE, NULL) != 0)
|
||||
|
|
@ -1597,21 +1503,6 @@ bwrap_main (int argc,
|
|||
if (umount2 ("oldroot", MNT_DETACH))
|
||||
die_with_error ("unmount old root");
|
||||
|
||||
if (opt_unshare_user &&
|
||||
(ns_uid != opt_sandbox_uid || ns_gid != opt_sandbox_gid))
|
||||
{
|
||||
/* Now that devpts is mounted and we've no need for mount
|
||||
permissions we can create a new userspace and map our uid
|
||||
1:1 */
|
||||
|
||||
if (unshare (CLONE_NEWUSER))
|
||||
die_with_error ("unshare user ns");
|
||||
|
||||
write_uid_gid_map (opt_sandbox_uid, ns_uid,
|
||||
opt_sandbox_gid, ns_gid,
|
||||
-1, FALSE, FALSE);
|
||||
}
|
||||
|
||||
/* Now make /newroot the real root */
|
||||
if (chdir ("/newroot") != 0)
|
||||
die_with_error ("chdir newroot");
|
||||
|
|
@ -1620,31 +1511,6 @@ bwrap_main (int argc,
|
|||
if (chdir ("/") != 0)
|
||||
die_with_error ("chdir /");
|
||||
|
||||
/* Now we have everything we need CAP_SYS_ADMIN for, so drop it */
|
||||
drop_caps ();
|
||||
|
||||
if (opt_seccomp_fd != -1)
|
||||
{
|
||||
cleanup_free char *seccomp_data = NULL;
|
||||
size_t seccomp_len;
|
||||
struct sock_fprog prog;
|
||||
|
||||
seccomp_data = load_file_data (opt_seccomp_fd, &seccomp_len);
|
||||
if (seccomp_data == NULL)
|
||||
die_with_error ("Can't read seccomp data");
|
||||
|
||||
if (seccomp_len % 8 != 0)
|
||||
die ("Invalide seccomp data, must be multiple of 8");
|
||||
|
||||
prog.len = seccomp_len / 8;
|
||||
prog.filter = (struct sock_filter *) seccomp_data;
|
||||
|
||||
close (opt_seccomp_fd);
|
||||
|
||||
if (prctl (PR_SET_SECCOMP, SECCOMP_MODE_FILTER, &prog) != 0)
|
||||
die_with_error ("prctl(PR_SET_SECCOMP)");
|
||||
}
|
||||
|
||||
umask (old_umask);
|
||||
|
||||
new_cwd = "/";
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue