From f379b93d52bf0dbd3816ec3f64d165314771d2a6 Mon Sep 17 00:00:00 2001 From: Lena Date: Sat, 1 Aug 2026 00:00:00 +0000 Subject: adb: reduce and harden wireless transport --- .../muntashirakon/adb/AbsAdbConnectionManager.java | 509 ------------------- .../adb/AdbAuthenticationFailedException.java | 14 - .../io/github/muntashirakon/adb/AdbConnection.java | 550 ++++++--------------- .../github/muntashirakon/adb/AdbInputStream.java | 5 +- .../adb/AdbPairingRequiredException.java | 7 - .../io/github/muntashirakon/adb/AdbProtocol.java | 114 ++--- .../io/github/muntashirakon/adb/AdbStream.java | 199 +++++--- .../io/github/muntashirakon/adb/AndroidPubkey.java | 159 ++---- .../adb/ByteArrayNoThrowOutputStream.java | 24 - .../java/io/github/muntashirakon/adb/KeyPair.java | 9 - .../io/github/muntashirakon/adb/LocalServices.java | 271 ---------- .../io/github/muntashirakon/adb/PRNGFixes.java | 319 ------------ .../github/muntashirakon/adb/PairingAuthCtx.java | 28 +- .../muntashirakon/adb/PairingConnectionCtx.java | 151 +++--- .../java/io/github/muntashirakon/adb/SslUtils.java | 91 ++-- .../io/github/muntashirakon/adb/StringCompat.java | 26 - .../github/muntashirakon/adb/android/AdbMdns.java | 193 -------- .../muntashirakon/adb/android/AndroidUtils.java | 58 --- .../github/muntashirakon/adb/android/package.html | 1 - .../github/muntashirakon/adb/AdbProtocolTest.java | 113 +++++ .../io/github/muntashirakon/adb/AdbStreamTest.java | 186 +++++++ .../muntashirakon/adb/AndroidPubkeyTest.java | 152 +++--- 22 files changed, 849 insertions(+), 2330 deletions(-) delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AbsAdbConnectionManager.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbAuthenticationFailedException.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbPairingRequiredException.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/ByteArrayNoThrowOutputStream.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/LocalServices.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PRNGFixes.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/StringCompat.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/AdbMdns.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/AndroidUtils.java delete mode 100644 vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/package.html create mode 100644 vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AdbProtocolTest.java create mode 100644 vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AdbStreamTest.java (limited to 'vendor/libadb-android/libadb/src') diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AbsAdbConnectionManager.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AbsAdbConnectionManager.java deleted file mode 100644 index 8452a86..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AbsAdbConnectionManager.java +++ /dev/null @@ -1,509 +0,0 @@ -// SPDX-License-Identifier: GPL-3.0-or-later OR Apache-2.0 - -package io.github.muntashirakon.adb; - -import android.content.Context; -import android.os.Build; - -import androidx.annotation.CallSuper; -import androidx.annotation.NonNull; -import androidx.annotation.Nullable; -import androidx.annotation.RequiresApi; -import androidx.annotation.WorkerThread; - -import java.io.Closeable; -import java.io.IOException; -import java.io.UnsupportedEncodingException; -import java.security.PrivateKey; -import java.security.cert.Certificate; -import java.util.Objects; -import java.util.concurrent.CountDownLatch; -import java.util.concurrent.TimeUnit; -import java.util.concurrent.atomic.AtomicInteger; -import java.util.concurrent.atomic.AtomicReference; - -import javax.security.auth.DestroyFailedException; - -import io.github.muntashirakon.adb.android.AdbMdns; - -@SuppressWarnings("unused") -public abstract class AbsAdbConnectionManager implements Closeable { - private final Object mLock = new Object(); - @Nullable - private AdbConnection mAdbConnection; - private String mHostAddress = "127.0.0.1"; - private int mApi = Build.VERSION_CODES.BASE; - private long mTimeout = Long.MAX_VALUE; - private TimeUnit mTimeoutUnit = TimeUnit.MILLISECONDS; - private boolean mThrowOnUnauthorised = false; - - /** - * Return generated/stored private key. - */ - @NonNull - protected abstract PrivateKey getPrivateKey(); - - /** - * Return public key wrapped around a certificate. - */ - @NonNull - protected abstract Certificate getCertificate(); - - /** - * Return a name for the device. This can be the app label, hostname or user@hostname. - */ - @NonNull - protected abstract String getDeviceName(); - - /** - * Set host address for this connection. On the same device, this should be {@code 127.0.0.1}. - */ - @CallSuper - public void setHostAddress(@NonNull String hostAddress) { - mHostAddress = Objects.requireNonNull(hostAddress); - } - - /** - * Get host address for this connection. Default value is {@code 127.0.0.1}. - */ - @NonNull - public String getHostAddress() { - return mHostAddress; - } - - /** - * Set Android API (i.e. SDK) version for this connection. If the daemon and the client are located in the same - * directory, the value should be {@link Build.VERSION#SDK_INT} in order to improve performance as well as security. - * - * @param api The API version, default is {@link Build.VERSION_CODES#BASE}. - */ - public void setApi(int api) { - this.mApi = api; - } - - /** - * Get Android API (i.e. SDK) version for this connection. Default value is {@link Build.VERSION_CODES#BASE}. - */ - public int getApi() { - return mApi; - } - - /** - * Set time to wait for the connection to be made. - * - * @param timeout Timeout value - * @param unit Timeout unit - */ - @CallSuper - public void setTimeout(long timeout, TimeUnit unit) { - mTimeout = timeout; - mTimeoutUnit = unit; - } - - /** - * Get time to wait for the connection to be made. If not set using {@link #setTimeout(long, TimeUnit)}, the default - * timeout is {@link Long#MAX_VALUE} milliseconds. - * - * @return Timeout in milliseconds - */ - public long getTimeout() { - return mTimeoutUnit.toMillis(mTimeout); - } - - /** - * Get the unit for the timeout. If not set using {@link #setTimeout(long, TimeUnit)}, the default timeout unit is - * {@link TimeUnit#MILLISECONDS}. - */ - @NonNull - public TimeUnit getTimeoutUnit() { - return mTimeoutUnit; - } - - /** - * Set whether to throw {@link AdbAuthenticationFailedException} if the daemon rejects the first authentication - * attempt. - * - * @param throwOnUnauthorised {@code true} to throw {@link AdbAuthenticationFailedException} or {@code false} - * otherwise. - */ - @CallSuper - public void setThrowOnUnauthorised(boolean throwOnUnauthorised) { - mThrowOnUnauthorised = throwOnUnauthorised; - } - - /** - * Get whether to throw {@link AdbAuthenticationFailedException} if the daemon rejects the first authentication - * attempt. - * - * @return {@code true} if the system is configured to throw {@link AdbAuthenticationFailedException} or - * {@code false} otherwise. The default value is {@code false}. - */ - public boolean isThrowOnUnauthorised() { - return mThrowOnUnauthorised; - } - - /** - * Get the {@link AdbConnection} backed by this object. - * - * @return Underlying {@link AdbConnection}, or {@code null} if the connection hasn't been made yet. - */ - @CallSuper - @Nullable - public AdbConnection getAdbConnection() { - synchronized (mLock) { - return mAdbConnection; - } - } - - /** - * Check if it is connected to an ADB daemon. - * - * @return {@code true} if connected, {@code false} otherwise. - */ - public boolean isConnected() { - synchronized (mLock) { - return mAdbConnection != null && mAdbConnection.isConnected() && mAdbConnection.isConnectionEstablished(); - } - } - - /** - * Attempt to connect to ADB by performing an automatic network discovery of TLS host and port. Host address set by - * {@link #setHostAddress(String)} is ignored. - * - * @param context Application context - * @param timeoutMillis Amount of time spent in searching for a host and a port. - * @return {@code true} if and only if the connection is successful. It returns {@code false} if the connection - * attempt is unsuccessful, or it has already been made. - * @throws IOException If the socket connection could not be made. - * @throws InterruptedException If timeout has reached. - * @throws AdbAuthenticationFailedException If {@link #isThrowOnUnauthorised()} is set to {@code true}, and the ADB - * daemon has rejected the first authentication attempt, which indicates - * that the daemon has not saved the public key from a previous connection. - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - @WorkerThread - @RequiresApi(Build.VERSION_CODES.JELLY_BEAN) - public boolean connectTls(@NonNull Context context, long timeoutMillis) - throws IOException, InterruptedException, AdbPairingRequiredException { - return autoConnect(context, AdbMdns.SERVICE_TYPE_TLS_CONNECT, timeoutMillis); - } - - /** - * Attempt to connect to ADB by performing an automatic network discovery of TCP host and port. Host address set by - * {@link #setHostAddress(String)} is ignored. - * - * @param context Application context - * @param timeoutMillis Amount of time spent in searching for a host and a port. - * @return {@code true} if and only if the connection is successful. It returns {@code false} if the connection - * attempt is unsuccessful, or it has already been made. - * @throws IOException If the socket connection could not be made. - * @throws InterruptedException If timeout has reached. - * @throws AdbAuthenticationFailedException If {@link #isThrowOnUnauthorised()} is set to {@code true}, and the ADB - * daemon has rejected the first authentication attempt, which indicates - * that the daemon has not saved the public key from a previous connection. - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - @WorkerThread - @RequiresApi(Build.VERSION_CODES.JELLY_BEAN) - public boolean connectTcp(@NonNull Context context, long timeoutMillis) - throws IOException, InterruptedException, AdbPairingRequiredException { - return autoConnect(context, AdbMdns.SERVICE_TYPE_ADB, timeoutMillis); - } - - /** - * Attempt to connect to ADB by performing an automatic network discovery of host and port. Host address set by - * {@link #setHostAddress(String)} is ignored. - * - * @param context Application context - * @param timeoutMillis Amount of time spent in searching for a host and a port. - * @return {@code true} if and only if the connection is successful. It returns {@code false} if the connection - * attempt is unsuccessful, or it has already been made. - * @throws IOException If the socket connection could not be made. - * @throws InterruptedException If timeout has reached. - * @throws AdbAuthenticationFailedException If {@link #isThrowOnUnauthorised()} is set to {@code true}, and the ADB - * daemon has rejected the first authentication attempt, which indicates - * that the daemon has not saved the public key from a previous connection. - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - @WorkerThread - @RequiresApi(Build.VERSION_CODES.JELLY_BEAN) - public boolean autoConnect(@NonNull Context context, long timeoutMillis) - throws IOException, InterruptedException, AdbPairingRequiredException { - synchronized (mLock) { - AtomicInteger atomicPort = new AtomicInteger(-1); - AtomicReference atomicHostAddress = new AtomicReference<>(null); - CountDownLatch resolveHostAndPort = new CountDownLatch(1); - - AdbMdns adbMdnsTcp = new AdbMdns(context, AdbMdns.SERVICE_TYPE_ADB, (hostAddress, port) -> { - if (hostAddress != null) { - atomicHostAddress.set(hostAddress.getHostAddress()); - atomicPort.set(port); - } - resolveHostAndPort.countDown(); - }); - adbMdnsTcp.start(); - - AdbMdns adbMdnsTls = new AdbMdns(context, AdbMdns.SERVICE_TYPE_TLS_CONNECT, (hostAddress, port) -> { - if (hostAddress != null) { - atomicHostAddress.set(hostAddress.getHostAddress()); - atomicPort.set(port); - } - resolveHostAndPort.countDown(); - }); - adbMdnsTls.start(); - - try { - if (!resolveHostAndPort.await(timeoutMillis, TimeUnit.MILLISECONDS)) { - throw new InterruptedException("Timed out while trying to find a valid host address and port"); - } - } finally { - adbMdnsTcp.stop(); - adbMdnsTls.stop(); - } - - String host = atomicHostAddress.get(); - int port = atomicPort.get(); - - if (host == null || port == -1) { - throw new IOException("Could not find any valid host address or port"); - } - - mHostAddress = host; - mAdbConnection = new AdbConnection.Builder(host, port) - .setApi(mApi) - .setKeyPair(getAdbKeyPair()) - .setDeviceName(Objects.requireNonNull(getDeviceName())) - .build(); - return mAdbConnection.connect(mTimeout, mTimeoutUnit, mThrowOnUnauthorised); - } - } - - @WorkerThread - @RequiresApi(Build.VERSION_CODES.JELLY_BEAN) - private boolean autoConnect(@NonNull Context context, @AdbMdns.ServiceType @NonNull String serviceType, long timeoutMillis) - throws IOException, InterruptedException, AdbPairingRequiredException { - synchronized (mLock) { - AtomicInteger atomicPort = new AtomicInteger(-1); - AtomicReference atomicHostAddress = new AtomicReference<>(null); - CountDownLatch resolveHostAndPort = new CountDownLatch(1); - - AdbMdns adbMdns = new AdbMdns(context, serviceType, (hostAddress, port) -> { - if (hostAddress != null) { - atomicHostAddress.set(hostAddress.getHostAddress()); - atomicPort.set(port); - } - resolveHostAndPort.countDown(); - }); - adbMdns.start(); - - try { - if (!resolveHostAndPort.await(timeoutMillis, TimeUnit.MILLISECONDS)) { - throw new InterruptedException("Timed out while trying to find a valid host address and port"); - } - } finally { - adbMdns.stop(); - } - - String host = atomicHostAddress.get(); - int port = atomicPort.get(); - - if (host == null || port == -1) { - throw new IOException("Could not find any valid host address or port"); - } - - mHostAddress = host; - mAdbConnection = new AdbConnection.Builder(host, port) - .setApi(mApi) - .setKeyPair(getAdbKeyPair()) - .setDeviceName(Objects.requireNonNull(getDeviceName())) - .build(); - return mAdbConnection.connect(mTimeout, mTimeoutUnit, mThrowOnUnauthorised); - } - } - - /** - * Attempt to connect to ADB given a port number. Host address is set via {@link #setHostAddress(String)}. - * - * @param port Port number - * @return {@code true} if and only if the connection is successful. It returns {@code false} if the connection - * attempt is unsuccessful, or it has already been made. - * @throws IOException If the socket connection could not be made. - * @throws InterruptedException If timeout has reached. - * @throws AdbAuthenticationFailedException If {@link #isThrowOnUnauthorised()} is set to {@code true}, and the ADB - * daemon has rejected the first authentication attempt, which indicates - * that the daemon has not saved the public key from a previous connection. - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - @WorkerThread - public boolean connect(int port) throws IOException, InterruptedException, AdbPairingRequiredException { - synchronized (mLock) { - if (isConnected()) { - return false; - } - mAdbConnection = new AdbConnection.Builder(mHostAddress, port) - .setApi(mApi) - .setKeyPair(getAdbKeyPair()) - .setDeviceName(Objects.requireNonNull(getDeviceName())) - .build(); - return mAdbConnection.connect(mTimeout, mTimeoutUnit, mThrowOnUnauthorised); - } - } - - /** - * Attempt to connect to ADB via a host address and a port number. - * - * @param host Host address to use instead of taking it from the {@link #getHostAddress()} - * @param port Port number - * @return {@code true} if and only if the connection is successful. It returns {@code false} if the connection - * attempt is unsuccessful, or it has already been made. - * @throws IOException If the socket connection could not be made. - * @throws InterruptedException If timeout has reached. - * @throws AdbAuthenticationFailedException If {@link #isThrowOnUnauthorised()} is set to {@code true}, and the - * ADB daemon has rejected the first authentication attempt, which - * indicates that the daemon has not saved the public key from a previous - * connection. - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - @WorkerThread - public boolean connect(@NonNull String host, int port) - throws IOException, InterruptedException, AdbPairingRequiredException { - synchronized (mLock) { - if (isConnected()) { - return false; - } - mHostAddress = host; - mAdbConnection = new AdbConnection.Builder(host, port) - .setApi(mApi) - .setKeyPair(getAdbKeyPair()) - .setDeviceName(Objects.requireNonNull(getDeviceName())) - .build(); - return mAdbConnection.connect(mTimeout, mTimeoutUnit, mThrowOnUnauthorised); - } - } - - /** - * Disconnect the underlying {@link AdbConnection}. - * - * @throws IOException If the underlying socket fails to close - */ - public void disconnect() throws IOException { - synchronized (mLock) { - if (mAdbConnection != null) { - mAdbConnection.close(); - mAdbConnection = null; - } - } - } - - /** - * Opens an {@link AdbStream} object corresponding to the specified destination. - * This routine will block until the connection completes. - * - * @param destination The destination to open on the target - * @return {@link AdbStream} object corresponding to the specified destination - * @throws IOException If the steam fails or no connection has been made - * @throws InterruptedException If the stream fails while sending the packet - * @throws UnsupportedEncodingException If the destination cannot be encoded to UTF-8. - */ - @WorkerThread - @NonNull - public AdbStream openStream(String destination) throws IOException, InterruptedException { - synchronized (mLock) { - if (mAdbConnection != null && mAdbConnection.isConnected()) { - try { - return mAdbConnection.open(destination, mTimeout, mTimeoutUnit); - } catch (AdbPairingRequiredException e) { - throw new IllegalStateException(e); - } - } - throw new IOException("Not connected to ADB."); - } - } - - /** - * Opens an {@link AdbStream} object corresponding to the specified destination. - * This routine will block until the connection completes. - * - * @param service The service to open. One of the services under {@link LocalServices.Services}. - * @param args Additional arguments supported by the service (see the corresponding constant to learn more). - * @return AdbStream object corresponding to the specified destination - * @throws UnsupportedEncodingException If the destination cannot be encoded to UTF-8 - * @throws IOException If the stream fails while sending the packet - * @throws InterruptedException If we are unable to wait for the connection to finish - */ - @NonNull - public AdbStream openStream(@LocalServices.Services int service, @NonNull String... args) - throws IOException, InterruptedException { - synchronized (mLock) { - if (mAdbConnection != null && mAdbConnection.isConnected()) { - try { - return mAdbConnection.open(LocalServices.getDestination(service, args), - mTimeout, mTimeoutUnit); - } catch (AdbPairingRequiredException e) { - throw new IllegalStateException(e); - } - } - throw new IOException("Not connected to ADB."); - } - } - - /** - * Pair with an ADB daemon given port number and pairing code. - * - * @param port Port number - * @param pairingCode The six-digit pairing code as string - * @return {@code true} if the pairing is successful and {@code false} otherwise. - * @throws Exception If pairing failed for some reason. - */ - @WorkerThread - @RequiresApi(Build.VERSION_CODES.GINGERBREAD) - public boolean pair(int port, @NonNull String pairingCode) throws Exception { - return pair(mHostAddress, port, pairingCode); - } - - /** - * Pair with an ADB daemon given host address, port number and pairing code. - * - * @param host Host address to use instead of taking it from the {@link #getHostAddress()} - * @param port Port number - * @param pairingCode The six-digit pairing code as string - * @return {@code true} if the pairing is successful and {@code false} otherwise. - * @throws Exception If pairing failed for some reason. - */ - @WorkerThread - @RequiresApi(Build.VERSION_CODES.GINGERBREAD) - public boolean pair(@NonNull String host, int port, @NonNull String pairingCode) throws Exception { - synchronized (mLock) { - KeyPair keyPair = getAdbKeyPair(); - try (PairingConnectionCtx pairingClient = new PairingConnectionCtx(Objects.requireNonNull(host), port, - StringCompat.getBytes(Objects.requireNonNull(pairingCode), "UTF-8"), keyPair, getDeviceName())) { - // TODO: 5/12/21 Return true/false instead of only exceptions - pairingClient.start(); - } - return true; - } - } - - /** - * Close the underlying {@link AdbConnection} and destroy the private key. - * - * @throws IOException If socket fails to close. - */ - @Override - public void close() throws IOException { - try { - getPrivateKey().destroy(); - } catch (DestroyFailedException | NoSuchMethodError e) { - e.printStackTrace(); - } - if (mAdbConnection != null) { - mAdbConnection.close(); - mAdbConnection = null; - } - } - - @NonNull - private KeyPair getAdbKeyPair() { - return new KeyPair(Objects.requireNonNull(getPrivateKey()), Objects.requireNonNull(getCertificate())); - } -} diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbAuthenticationFailedException.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbAuthenticationFailedException.java deleted file mode 100644 index bf50eeb..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbAuthenticationFailedException.java +++ /dev/null @@ -1,14 +0,0 @@ -// SPDX-License-Identifier: BSD-3-Clause AND (GPL-3.0-or-later OR Apache-2.0) - -package io.github.muntashirakon.adb; - -/** - * Thrown when the ADB daemon rejects our initial authentication attempt, which typically means that the peer has not - * previously saved our public key. - */ -// Copyright 2020 Sam Palmer -public class AdbAuthenticationFailedException extends RuntimeException { - public AdbAuthenticationFailedException() { - super("Initial authentication attempt rejected by peer."); - } -} diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbConnection.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbConnection.java index 7674adc..2abcb72 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbConnection.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbConnection.java @@ -14,27 +14,24 @@ import java.io.Closeable; import java.io.IOException; import java.io.InputStream; import java.io.OutputStream; -import java.io.UnsupportedEncodingException; +import java.net.InetSocketAddress; import java.net.ConnectException; -import java.net.SocketTimeoutException; import java.net.Socket; +import java.net.SocketTimeoutException; import java.security.PrivateKey; import java.security.cert.Certificate; -import java.security.interfaces.RSAPublicKey; import java.util.Objects; import java.util.concurrent.ConcurrentHashMap; import java.util.concurrent.TimeUnit; import javax.net.ssl.SSLContext; import javax.net.ssl.SSLSocket; -import javax.security.auth.DestroyFailedException; - /** * This class represents an ADB connection. */ // Copyright 2013 Cameron Gutman -public class AdbConnection implements Closeable { - public static final String TAG = AdbConnection.class.getSimpleName(); +public class AdbConnection implements Closeable, AdbStream.Transport { + public static final String TAG = "scrcpy-android"; /** * The underlying socket that this class uses to communicate with the target device. @@ -47,8 +44,6 @@ public class AdbConnection implements Closeable { private final int mPort; - private final int mApi; - /** * The last allocated local stream ID. The ID chosen for the next stream will be this value + 1. */ @@ -93,15 +88,8 @@ public class AdbConnection implements Closeable { */ private volatile boolean mConnectAttempted; - /** - * Whether the connection thread should give up if the first authentication attempt fails. - */ - private volatile boolean mAbortOnUnauthorised; - - /** - * Whether the first authentication attempt failed and {@link #mAbortOnUnauthorised} was {@code true}. - */ - private volatile boolean mAuthorisationFailed; + /** The worker thread is one-shot, even after a failed connection. */ + private boolean mConnectionThreadStarted; /** * Specifies whether a CNXN packet has been received from the peer. @@ -122,16 +110,12 @@ public class AdbConnection implements Closeable { private volatile int mProtocolVersion; - @NonNull - private final KeyPair mKeyPair; + private final int mLocalMaxData; - @NonNull - private volatile String mDeviceName = "Unknown Device"; + private final int mLocalProtocolVersion; - /** - * Specifies whether this connection has already sent a signed token. - */ - private volatile boolean mSentSignature; + @NonNull + private final KeyPair mKeyPair; /** * A hash map of our opened streams indexed by local ID. @@ -146,68 +130,49 @@ public class AdbConnection implements Closeable { private final Object mLock = new Object(); /** - * Creates a AdbConnection object associated with the socket and crypto object specified. - * - * @return A new AdbConnection object. - * @throws IOException If there is a socket error + * Internal constructor to initialize some internal state */ - @WorkerThread - @NonNull - public static AdbConnection create(@NonNull String host, int port, @NonNull PrivateKey privateKey, - @NonNull Certificate certificate) - throws IOException { - return create(host, port, privateKey, certificate, Build.VERSION_CODES.BASE); - } + // LOCAL PATCH: bound on the TCP connect; see the constructor. + private static final int CONNECT_TIMEOUT_MS = 10_000; + private static final int CLOSE_TIMEOUT_MS = 5_000; - /** - * Creates a AdbConnection object associated with the socket and crypto object specified. - * - * @return A new AdbConnection object. - * @throws IOException If there is a socket error - */ @WorkerThread - @NonNull - public static AdbConnection create(@NonNull String host, int port, @NonNull PrivateKey privateKey, - @NonNull Certificate certificate, int api) + private AdbConnection(@NonNull String host, int port, @NonNull KeyPair keyPair) throws IOException { - return create(host, port, new KeyPair(Objects.requireNonNull(privateKey), Objects.requireNonNull(certificate)), - api); - } - - /** - * Creates a AdbConnection object associated with the socket and crypto object specified. - * - * @return A new AdbConnection object. - * @throws IOException If there is a socket error - */ - @WorkerThread - @NonNull - static AdbConnection create(@NonNull String host, int port, @NonNull KeyPair keyPair, int api) throws IOException { - return new AdbConnection(host, port, keyPair, api); - } - - /** - * Internal constructor to initialize some internal state - */ - @WorkerThread - private AdbConnection(@NonNull String host, int port, @NonNull KeyPair keyPair, int api) throws IOException { this.mHost = Objects.requireNonNull(host); this.mPort = port; - this.mApi = api; - this.mProtocolVersion = AdbProtocol.getProtocolVersion(mApi); - this.mMaxData = AdbProtocol.getMaxData(api); + this.mLocalProtocolVersion = AdbProtocol.getProtocolVersion(Build.VERSION_CODES.R); + this.mLocalMaxData = AdbProtocol.getMaxData(Build.VERSION_CODES.R); + this.mProtocolVersion = mLocalProtocolVersion; + this.mMaxData = mLocalMaxData; this.mKeyPair = Objects.requireNonNull(keyPair); + Socket socket = new Socket(); try { - this.mSocket = new Socket(host, port); - } catch (Throwable th) { + // LOCAL PATCH: was `new Socket(host, port)`, which blocks on + // the OS default TCP timeout - minutes on a mobile network - + // with no way to cancel. A target that is off or on another + // network is the common case, not an edge case, so bound it. + socket.connect(new InetSocketAddress(host, port), CONNECT_TIMEOUT_MS); + } catch (IOException e) { + try { socket.close(); } catch (IOException ignored) {} //noinspection UnnecessaryInitCause - throw (IOException) new IOException().initCause(th); + throw (IOException) new IOException("cannot reach " + host + ":" + port + + " within " + CONNECT_TIMEOUT_MS + " ms").initCause(e); } - this.mPlainInputStream = mSocket.getInputStream(); - this.mPlainOutputStream = mSocket.getOutputStream(); - - // Disable Nagle because we're sending tiny packets - mSocket.setTcpNoDelay(true); + InputStream plainInput; + OutputStream plainOutput; + try { + // Disable Nagle because we're sending tiny packets. + socket.setTcpNoDelay(true); + plainInput = socket.getInputStream(); + plainOutput = socket.getOutputStream(); + } catch (IOException e) { + try { socket.close(); } catch (IOException ignored) {} + throw (IOException) new IOException("cannot initialize ADB socket").initCause(e); + } + this.mSocket = socket; + this.mPlainInputStream = plainInput; + this.mPlainOutputStream = plainOutput; this.mOpenedStreams = new ConcurrentHashMap<>(); this.mLastLocalId = 0; @@ -234,7 +199,6 @@ public class AdbConnection implements Closeable { @NonNull private Thread createConnectionThread() { return new Thread(() -> { - loop: while (!mConnectionThread.isInterrupted()) { try { // Read and parse a message off the socket's input stream @@ -253,6 +217,9 @@ public class AdbConnection implements Closeable { // Get the stream object corresponding to the packet AdbStream waitingStream = mOpenedStreams.get(msg.arg1); if (waitingStream == null) { + if (msg.command == AdbProtocol.A_WRTE) { + throw new IOException("WRTE for unknown local stream " + msg.arg1); + } continue; } @@ -261,16 +228,16 @@ public class AdbConnection implements Closeable { // We're ready for writes waitingStream.updateRemoteId(msg.arg0); waitingStream.readyForWrite(); - - // Notify an open/write - waitingStream.notify(); } else if (msg.command == AdbProtocol.A_WRTE) { + if (!waitingStream.hasRemoteId(msg.arg0)) { + throw new IOException("WRTE remote stream ID mismatch"); + } // Got some data from our partner waitingStream.addPayload(msg.payload); - - // Tell it we're ready for more - waitingStream.sendReady(); } else { // if (msg.command == AdbProtocol.A_CLSE) { + if (!waitingStream.hasRemoteId(msg.arg0) && msg.arg0 != 0) { + throw new IOException("CLSE remote stream ID mismatch"); + } mOpenedStreams.remove(msg.arg1); // Notify readers and writers waitingStream.notifyClose(true); @@ -279,71 +246,57 @@ public class AdbConnection implements Closeable { break; } case AdbProtocol.A_STLS: { - if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.GINGERBREAD) { - sendPacket(AdbProtocol.generateStls()); - - SSLContext sslContext = SslUtils.getSslContext(mKeyPair); - SSLSocket tlsSocket = (SSLSocket) sslContext.getSocketFactory() - .createSocket(mSocket, mHost, mPort, true); - tlsSocket.startHandshake(); - Log.d(TAG, "Handshake succeeded."); - - synchronized (AdbConnection.this) { - mTlsInputStream = tlsSocket.getInputStream(); - mTlsOutputStream = tlsSocket.getOutputStream(); - mIsTls = true; - } + if (mIsTls || mConnectionEstablished + || msg.arg0 < AdbProtocol.A_STLS_VERSION_MIN) { + throw new IOException("Invalid or repeated STLS request"); } - break; - } - case AdbProtocol.A_AUTH: { - if (mIsTls) { - break; - } - if (msg.arg0 != AdbProtocol.ADB_AUTH_TOKEN) { - break; - } - byte[] packet; - // This is an authentication challenge - if (mSentSignature) { - if (mAbortOnUnauthorised) { - mAuthorisationFailed = true; - break loop; - } + sendPacket(AdbProtocol.generateStls()); - // We've already tried our signature, so send our public key - packet = AdbProtocol.generateAuth(AdbProtocol.ADB_AUTH_RSAPUBLICKEY, AndroidPubkey - .encodeWithName((RSAPublicKey) mKeyPair.getPublicKey(), mDeviceName)); - } else { - // Sign the token - packet = AdbProtocol.generateAuth(AdbProtocol.ADB_AUTH_SIGNATURE, AndroidPubkey - .adbAuthSign(mKeyPair.getPrivateKey(), msg.payload)); - mSentSignature = true; - } + SSLContext sslContext = SslUtils.getSslContext(mKeyPair); + SSLSocket tlsSocket = (SSLSocket) sslContext.getSocketFactory() + .createSocket(mSocket, mHost, mPort, true); + tlsSocket.startHandshake(); + Log.d(TAG, "Handshake succeeded."); - // Write the AUTH reply - sendPacket(packet); + synchronized (AdbConnection.this) { + mTlsInputStream = tlsSocket.getInputStream(); + mTlsOutputStream = tlsSocket.getOutputStream(); + mIsTls = true; + } break; } + case AdbProtocol.A_AUTH: { + throw new IOException("ADB peer requested legacy authentication without TLS"); + } case AdbProtocol.A_CNXN: { + if (!mIsTls) { + throw new IOException("ADB peer did not negotiate TLS"); + } + if (msg.arg0 < AdbProtocol.A_VERSION_MIN || msg.arg1 <= 0) { + throw new IOException("Invalid CNXN parameters: version=" + + msg.arg0 + " maxData=" + msg.arg1); + } synchronized (AdbConnection.this) { - mProtocolVersion = msg.arg0; - mMaxData = msg.arg1; + // Both fields come from an unauthenticated + // peer. Negotiate down, never let the peer + // raise our allocation or checksum limits. + mProtocolVersion = Math.min(msg.arg0, mLocalProtocolVersion); + mMaxData = Math.min(msg.arg1, mLocalMaxData); mConnectionEstablished = true; AdbConnection.this.notifyAll(); } break; } case AdbProtocol.A_OPEN: - case AdbProtocol.A_SYNC: default: - Log.e(TAG, String.format("Unrecognized command = 0x%x", msg.command)); - // Unrecognized packet, just drop it - break; + throw new IOException(String.format( + "Unexpected ADB command 0x%x", msg.command)); } } catch (Exception e) { - mConnectionException = e; - e.printStackTrace(); + if (!mSocket.isClosed()) { + mConnectionException = e; + Log.e(TAG, "ADB connection failed", e); + } // The cleanup is taken care of by a combination of this thread and close() break; } @@ -359,48 +312,6 @@ public class AdbConnection implements Closeable { }); } - /** - * Set a name for the device. Default is “Unknown Device”. - * - * @param deviceName Name of the device, could be the app label, hostname or user@hostname. - */ - public void setDeviceName(@NonNull String deviceName) { - this.mDeviceName = Objects.requireNonNull(deviceName); - } - - /** - * Get the version of the ADB protocol supported by the ADB daemon. The result may depend on the API version - * specified and whether the connection has been established. In API 29 (Android 9) or later, the daemon returns - * {@link AdbProtocol#A_VERSION_SKIP_CHECKSUM} regardless of the protocol used to create the connection. So, if - * {@link #mApi} is set to API 28 or earlier but the OS version is Android 9 or later, before establishing the - * connection, it returns {@link AdbProtocol#A_VERSION_MIN}, and after establishing the connection, it returns - * {@link AdbProtocol#A_VERSION_SKIP_CHECKSUM}. In other cases, it always returns {@link AdbProtocol#A_VERSION_MIN}. - * - * @see #isConnectionEstablished() - */ - public int getProtocolVersion() { - return mProtocolVersion; - } - - /** - * Get the max data size supported by the ADB daemon. A connection have to be attempted before calling this method - * and shall be blocked if the connection is in progress. - * - * @return The maximum data size indicated in the CONNECT packet. - * @throws InterruptedException If a connection cannot be waited on. - * @throws IOException if the connection fails. - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - public int getMaxData() throws InterruptedException, IOException, AdbPairingRequiredException { - if (!mConnectAttempted) { - throw new IllegalStateException("connect() must be called first"); - } - - waitForConnection(Long.MAX_VALUE, TimeUnit.MILLISECONDS); - - return mMaxData; - } - /** * Whether a connection has been established. A connection has been established if a CONNECT request has been * received from the ADB daemon. @@ -409,101 +320,43 @@ public class AdbConnection implements Closeable { return mConnectionEstablished; } - /** - * Whether the underlying socket is connected to an ADB daemon and is not in a closed state. - */ - public boolean isConnected() { - return !mSocket.isClosed() && mSocket.isConnected(); - } - - /** - * Same as {@link #connect(long, TimeUnit, boolean)} without throwing anything if the first authentication attempt - * fails. - * - * @return {@code true} if the connection was established, or {@code false} if the connection timed out - * @throws IOException If the socket fails while connecting - * @throws InterruptedException If timeout has reached - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - public boolean connect() throws IOException, InterruptedException, AdbPairingRequiredException { - return connect(Long.MAX_VALUE, TimeUnit.MILLISECONDS, false); + @Override + public int getMaxData() { + return mMaxData; } /** * Connects to the remote device. This routine will block until the connection completes or the timeout elapses. * - * @param timeout the time to wait for the lock - * @param unit the time unit of the timeout argument - * @param throwOnUnauthorised Whether to throw an {@link AdbAuthenticationFailedException} - * if the peer rejects out first authentication attempt + * @param timeout the time to wait for the lock + * @param unit the time unit of the timeout argument * @return {@code true} if the connection was established, or {@code false} if the connection timed out * @throws IOException If the socket fails while connecting * @throws InterruptedException If timeout has reached - * @throws AdbAuthenticationFailedException If {@code throwOnUnauthorised} is {@code true} and the peer rejects the - * first authentication attempt, which indicates that the peer has not - * saved the public key from a previous connection - * @throws AdbPairingRequiredException If ADB lacks pairing */ - public boolean connect(long timeout, @NonNull TimeUnit unit, boolean throwOnUnauthorised) - throws IOException, InterruptedException, AdbAuthenticationFailedException, AdbPairingRequiredException { - if (mConnectionEstablished) { - throw new IllegalStateException("Already connected"); + public synchronized boolean connect(long timeout, @NonNull TimeUnit unit) + throws IOException, InterruptedException { + validateTimeout(timeout, unit); + if (mConnectionThreadStarted) { + throw new IllegalStateException("Connection already attempted"); } // Send CONNECT - sendPacket(AdbProtocol.generateConnect(mApi)); + sendPacket(AdbProtocol.generateConnect(Build.VERSION_CODES.R)); // Start the connection thread to respond to the peer mConnectAttempted = true; - mAbortOnUnauthorised = throwOnUnauthorised; - mAuthorisationFailed = false; + mConnectionThreadStarted = true; mConnectionThread.start(); return waitForConnection(timeout, Objects.requireNonNull(unit)); } - /** - * Opens an {@link AdbStream} object corresponding to the specified destination. - * This routine will block until the connection completes. - * - * @param service The service to open. One of the services under {@link LocalServices.Services}. - * @param args Additional arguments supported by the service (see the corresponding constant to learn more). - * @return AdbStream object corresponding to the specified destination - * @throws UnsupportedEncodingException If the destination cannot be encoded to UTF-8 - * @throws IOException If the stream fails while sending the packet - * @throws InterruptedException If we are unable to wait for the connection to finish - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - @NonNull - public AdbStream open(@LocalServices.Services int service, @NonNull String... args) - throws IOException, InterruptedException, AdbPairingRequiredException { - if (service < LocalServices.SERVICE_FIRST || service > LocalServices.SERVICE_LAST) { - throw new IllegalArgumentException("Invalid service: " + service); - } - return open(LocalServices.getDestination(service, args)); - } - - /** - * Opens an AdbStream object corresponding to the specified destination. - * This routine will block until the connection completes. - * - * @param destination The destination to open on the target - * @return AdbStream object corresponding to the specified destination - * @throws UnsupportedEncodingException If the destination cannot be encoded to UTF-8 - * @throws IOException If the stream fails while sending the packet - * @throws InterruptedException If we are unable to wait for the connection to finish - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - @NonNull - public AdbStream open(@NonNull String destination) - throws IOException, InterruptedException, AdbPairingRequiredException { - return open(destination, Long.MAX_VALUE, TimeUnit.MILLISECONDS); - } - @NonNull public AdbStream open(@NonNull String destination, long timeout, @NonNull TimeUnit unit) - throws IOException, InterruptedException, AdbPairingRequiredException { - int localId = ++mLastLocalId; + throws IOException, InterruptedException { + validateTimeout(timeout, unit); + Objects.requireNonNull(destination); if (!mConnectAttempted) { throw new IllegalStateException("connect() must be called first"); @@ -513,24 +366,26 @@ public class AdbConnection implements Closeable { throw new SocketTimeoutException("ADB connection timed out."); } + int localId = nextLocalId(); + // Add this stream to this list of half-open streams AdbStream stream = new AdbStream(this, localId); mOpenedStreams.put(localId, stream); long timeoutMillis = unit.toMillis(timeout); - long deadline = timeoutMillis == Long.MAX_VALUE - ? Long.MAX_VALUE : System.currentTimeMillis() + timeoutMillis; + long started = System.nanoTime(); try { // Send OPEN only after publishing the half-open stream so an // immediate response cannot race past the lookup table. - sendPacket(AdbProtocol.generateOpen(localId, Objects.requireNonNull(destination))); + sendPacket(AdbProtocol.generateOpen(localId, destination)); synchronized (stream) { while (!stream.isOpen() && !stream.isClosed()) { - if (deadline == Long.MAX_VALUE) { + if (timeoutMillis == Long.MAX_VALUE) { stream.wait(); continue; } - long remaining = deadline - System.currentTimeMillis(); + long elapsed = TimeUnit.NANOSECONDS.toMillis(System.nanoTime() - started); + long remaining = timeoutMillis - elapsed; if (remaining <= 0) { throw new SocketTimeoutException("ADB stream open timed out: " + destination); } @@ -552,32 +407,35 @@ public class AdbConnection implements Closeable { return stream; } + private synchronized int nextLocalId() throws IOException { + if (mLastLocalId == Integer.MAX_VALUE) { + throw new IOException("ADB stream ID space exhausted"); + } + return ++mLastLocalId; + } + private boolean waitForConnection(long timeout, @NonNull TimeUnit unit) - throws InterruptedException, IOException, AdbPairingRequiredException { + throws InterruptedException, IOException { synchronized (this) { // Block if a connection is pending, but not yet complete - long timeoutEndMillis = System.currentTimeMillis() + Objects.requireNonNull(unit).toMillis(timeout); - while (!mConnectionEstablished && mConnectAttempted && timeoutEndMillis - System.currentTimeMillis() > 0) { - wait(timeoutEndMillis - System.currentTimeMillis()); + long timeoutMillis = Objects.requireNonNull(unit).toMillis(timeout); + long started = System.nanoTime(); + while (!mConnectionEstablished && mConnectAttempted) { + if (timeoutMillis == Long.MAX_VALUE) { + wait(); + continue; + } + long elapsedMillis = TimeUnit.NANOSECONDS.toMillis(System.nanoTime() - started); + long remainingMillis = timeoutMillis - elapsedMillis; + if (remainingMillis <= 0) break; + wait(remainingMillis); } if (!mConnectionEstablished) { if (mConnectAttempted) { return false; - } else if (mAuthorisationFailed) { - // The peer may not have saved the public key in the past connections, or they've been removed. - throw new AdbAuthenticationFailedException(); } else { - Exception connectionException = mConnectionException; - if (connectionException != null) { - if (connectionException instanceof javax.net.ssl.SSLProtocolException) { - String message = connectionException.getMessage(); - if (message != null && message.contains("protocol error")) { - throw (AdbPairingRequiredException) (new AdbPairingRequiredException("ADB pairing is required.").initCause(connectionException)); - } - } - } - throw new IOException("Connection failed"); + throw new IOException("Connection failed", mConnectionException); } } } @@ -585,16 +443,19 @@ public class AdbConnection implements Closeable { return true; } + private static void validateTimeout(long timeout, @NonNull TimeUnit unit) { + Objects.requireNonNull(unit); + if (timeout < 0) throw new IllegalArgumentException("negative timeout"); + } + /** * This function terminates all I/O on streams associated with this ADB connection */ private void cleanupStreams() { - // Close all streams on this connection + // The socket is already unusable. Wake every stream without trying + // to write CLSE packets back through the failed transport. for (AdbStream s : mOpenedStreams.values()) { - try { - s.close(); - } catch (IOException ignored) { - } + s.notifyClose(false); } mOpenedStreams.clear(); } @@ -612,18 +473,26 @@ public class AdbConnection implements Closeable { // Wait for the connection thread to die mConnectionThread.interrupt(); try { - mConnectionThread.join(); - } catch (InterruptedException ignored) { + if (mConnectionThread != Thread.currentThread()) { + mConnectionThread.join(CLOSE_TIMEOUT_MS); + } + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + throw (IOException) new IOException("interrupted while closing ADB connection") + .initCause(e); } - - // Destroy keypair - try { - mKeyPair.destroy(); - } catch (DestroyFailedException ignore) { + if (mConnectionThread.isAlive()) { + throw new IOException("ADB connection thread did not stop within " + + CLOSE_TIMEOUT_MS + " ms"); } + + // The connection manager owns the keypair. A disconnect is routine + // during reconnect and must not destroy the key reused by the next + // connection. } - void sendPacket(byte[] packet) throws IOException { + @Override + public void sendPacket(byte[] packet) throws IOException { synchronized (mLock) { OutputStream os = getOutputStream(); os.write(packet); @@ -631,67 +500,24 @@ public class AdbConnection implements Closeable { } } - void flushPacket() throws IOException { + @Override + public void flushPacket() throws IOException { synchronized (mLock) { getOutputStream().flush(); } } public static class Builder { - private String mHost = "127.0.0.1"; - private int mPort = 5555; - private int mApi = Build.VERSION_CODES.BASE; + private final String mHost; + private final int mPort; private PrivateKey mPrivateKey; private Certificate mCertificate; - private KeyPair mKeyPair; - private String mDeviceName; - - public Builder() { - } public Builder(String host, int port) { mHost = host; mPort = port; } - /** - * Set host address. Default is 127.0.0.1 - */ - public Builder setHost(String host) { - this.mHost = host; - return this; - } - - /** - * Set port number. Default is 5555. - */ - public Builder setPort(int port) { - this.mPort = port; - return this; - } - - /** - * Set a name for the device. Default is “Unknown Device”. - * - * @param deviceName Name of the device, could be the app label, hostname or user@hostname. - */ - public Builder setDeviceName(String deviceName) { - this.mDeviceName = deviceName; - return this; - } - - /** - * Set Android API (i.e. SDK) version for this connection. If the ADB daemon and the client are located in the - * same device, the value should be {@link Build.VERSION#SDK_INT} in order to improve performance as well as - * security. - * - * @param api The API version, default is {@link Build.VERSION_CODES#BASE}. - */ - public Builder setApi(int api) { - this.mApi = api; - return this; - } - /** * Set generated/stored private key. */ @@ -708,69 +534,19 @@ public class AdbConnection implements Closeable { return this; } - Builder setKeyPair(KeyPair keyPair) { - this.mKeyPair = keyPair; - return this; - } - /** * Creates a new {@link AdbConnection} associated with the socket and crypto object specified. * * @throws IOException If there was an error while establishing a socket connection */ public AdbConnection build() throws IOException { - if (mKeyPair == null) { - if (mPrivateKey == null || mCertificate == null) { - throw new UnsupportedOperationException("Private key and certificate must be set."); - } - mKeyPair = new KeyPair(mPrivateKey, mCertificate); - } - AdbConnection adbConnection = create(mHost, mPort, mKeyPair, mApi); - if (mDeviceName != null) { - adbConnection.setDeviceName(mDeviceName); - } - return adbConnection; - } - - /** - * Same as {@link #connect(long, TimeUnit, boolean)} without throwing anything if the first authentication - * attempt fails. - * - * @return The underlying {@link AdbConnection} - * @throws IOException If the socket fails while connecting - * @throws InterruptedException If timeout has reached - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - public AdbConnection connect() throws IOException, InterruptedException, AdbPairingRequiredException { - AdbConnection adbConnection = build(); - if (adbConnection.connect()) { - throw new IOException("Unable to establish a new connection."); - } - return adbConnection; - } - - /** - * Connects to the remote device. This routine will block until the connection completes or the timeout elapses. - * - * @param timeout the time to wait for the lock - * @param unit the time unit of the timeout argument - * @param throwOnUnauthorised Whether to throw an {@link AdbAuthenticationFailedException} - * if the peer rejects out first authentication attempt - * @return {@code true} if the connection was established, or {@code false} if the connection timed out - * @throws IOException If the socket fails while connecting - * @throws InterruptedException If timeout has reached - * @throws AdbAuthenticationFailedException If {@code throwOnUnauthorised} is {@code true} and the peer rejects - * the first authentication attempt, which indicates that the peer has - * not saved the public key from a previous connection - * @throws AdbPairingRequiredException If ADB lacks pairing - */ - public AdbConnection connect(long timeout, @NonNull TimeUnit unit, boolean throwOnUnauthorised) - throws IOException, InterruptedException, AdbPairingRequiredException { - AdbConnection adbConnection = build(); - if (adbConnection.connect(timeout, unit, throwOnUnauthorised)) { - throw new IOException("Unable to establish a new connection."); + if (mHost == null || mHost.isEmpty()) throw new IllegalArgumentException("host is empty"); + if (mPort < 1 || mPort > 65535) throw new IllegalArgumentException("port is invalid"); + if (mPrivateKey == null || mCertificate == null) { + throw new UnsupportedOperationException("Private key and certificate must be set."); } - return adbConnection; + return new AdbConnection(mHost, mPort, + new KeyPair(mPrivateKey, mCertificate)); } } } diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbInputStream.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbInputStream.java index 6d0676f..c609e98 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbInputStream.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbInputStream.java @@ -6,7 +6,7 @@ import java.io.IOException; import java.io.InputStream; public class AdbInputStream extends InputStream { - public AdbStream mAdbStream; + private final AdbStream mAdbStream; public AdbInputStream(AdbStream adbStream) { this.mAdbStream = adbStream; @@ -18,7 +18,7 @@ public class AdbInputStream extends InputStream { if (read(bytes) == -1) { return -1; } - return bytes[0]; + return bytes[0] & 0xff; } @Override @@ -28,7 +28,6 @@ public class AdbInputStream extends InputStream { @Override public int read(byte[] b, int off, int len) throws IOException { - if (mAdbStream.isClosed()) return -1; return mAdbStream.read(b, off, len); } diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbPairingRequiredException.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbPairingRequiredException.java deleted file mode 100644 index f324cb0..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbPairingRequiredException.java +++ /dev/null @@ -1,7 +0,0 @@ -package io.github.muntashirakon.adb; - -public class AdbPairingRequiredException extends Exception { - public AdbPairingRequiredException(String message) { - super(message); - } -} diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbProtocol.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbProtocol.java index 4c58206..79de3b5 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbProtocol.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbProtocol.java @@ -15,6 +15,7 @@ import java.lang.annotation.Retention; import java.lang.annotation.RetentionPolicy; import java.nio.ByteBuffer; import java.nio.ByteOrder; +import java.nio.charset.StandardCharsets; import java.util.Arrays; /** @@ -27,13 +28,6 @@ final class AdbProtocol { */ public static final int ADB_HEADER_LENGTH = 24; - /** - * SYNC(online, sequence, "") - * - * @deprecated Obsolete, no longer used. Never used on the client side. - */ - public static final int A_SYNC = 0x434e5953; - /** * CNXN is the connect message. No messages (except AUTH) are valid before this message is received. */ @@ -42,7 +36,8 @@ final class AdbProtocol { /** * The payload sent with the CONNECT message. */ - public static final byte[] SYSTEM_IDENTITY_STRING_HOST = StringCompat.getBytes("host::\0", "UTF-8"); + public static final byte[] SYSTEM_IDENTITY_STRING_HOST = + "host::\0".getBytes(StandardCharsets.UTF_8); /** * AUTH is the authentication message. It is part of the RSA public key authentication added in Android 4.2.2 @@ -76,7 +71,7 @@ final class AdbProtocol { public static final int A_STLS = 0x534c5453; @Retention(RetentionPolicy.SOURCE) - @IntDef({A_SYNC, A_CNXN, A_OPEN, A_OKAY, A_CLSE, A_WRTE, A_AUTH, A_STLS}) + @IntDef({A_CNXN, A_OPEN, A_OKAY, A_CLSE, A_WRTE, A_AUTH, A_STLS}) private @interface Command { } @@ -92,11 +87,6 @@ final class AdbProtocol { * Supported payload size since Android 9 (P) */ public static final int MAX_PAYLOAD_V3 = 1024 * 1024; - /** - * Maximum supported payload size is set to the original to support all APIs - */ - public static final int MAX_PAYLOAD = MAX_PAYLOAD_V1; - /** * The original version of the ADB protocol */ @@ -105,34 +95,12 @@ final class AdbProtocol { * The new version of the ADB protocol introduced in Android 9 (P) with the introduction of TLS */ public static final int A_VERSION_SKIP_CHECKSUM = 0x01000001; - public static final int A_VERSION = A_VERSION_MIN; - /** * The current version of the Stream-based TLS */ public static final int A_STLS_VERSION_MIN = 0x01000000; public static final int A_STLS_VERSION = A_STLS_VERSION_MIN; - /** - * This authentication type represents a SHA1 hash to sign. - */ - public static final int ADB_AUTH_TOKEN = 1; - - /** - * This authentication type represents the signed SHA1 hash. - */ - public static final int ADB_AUTH_SIGNATURE = 2; - - /** - * This authentication type represents an RSA public key. - */ - public static final int ADB_AUTH_RSAPUBLICKEY = 3; - - @Retention(RetentionPolicy.SOURCE) - @IntDef({ADB_AUTH_TOKEN, ADB_AUTH_SIGNATURE, ADB_AUTH_RSAPUBLICKEY}) - private @interface AuthType { - } - public static int getMaxData(int api) { if (api >= Build.VERSION_CODES.P) { return MAX_PAYLOAD_V3; @@ -202,8 +170,14 @@ final class AdbProtocol { * @return Byte array containing the message */ @NonNull - public static byte[] generateMessage(@Command int command, int arg0, int arg1, @Nullable byte[] data, int offset, int length) { - // Protocol as defined at https://github.com/aosp-mirror/platform_system_core/blob/6072de17cd812daf238092695f26a552d3122f8c/adb/protocol.txt + public static byte[] generateMessage(@Command int command, int arg0, int arg1, + @Nullable byte[] data, int offset, int length) { + if (length < 0 || offset < 0 || data == null && (offset != 0 || length != 0) + || data != null && (offset > data.length || length > data.length - offset)) { + throw new IndexOutOfBoundsException( + "invalid payload range: offset=" + offset + " length=" + length); + } + // Protocol: AOSP platform_system_core commit 6072de17, adb/protocol.txt. // struct message { // unsigned command; // command identifier constant // unsigned arg0; // first argument @@ -255,20 +229,6 @@ final class AdbProtocol { return generateMessage(A_CNXN, getProtocolVersion(api), getMaxData(api), SYSTEM_IDENTITY_STRING_HOST); } - /** - * Generates an AUTH message with the specified type and payload. - *

- * AUTH(type, 0, "data") - * - * @param type Authentication type (see ADB_AUTH_* constants) - * @param data The data - * @return Byte array containing the message - */ - @NonNull - public static byte[] generateAuth(@AuthType int type, byte[] data) { - return generateMessage(A_AUTH, type, 0, data); - } - /** * Generates an STLS message with default parameters. *

@@ -292,8 +252,9 @@ final class AdbProtocol { */ @NonNull public static byte[] generateOpen(int localId, @NonNull String destination) { - ByteBuffer bbuf = ByteBuffer.allocate(destination.length() + 1); - bbuf.put(StringCompat.getBytes(destination, "UTF-8")); + byte[] encoded = destination.getBytes(StandardCharsets.UTF_8); + ByteBuffer bbuf = ByteBuffer.allocate(encoded.length + 1); + bbuf.put(encoded); bbuf.put((byte) 0); return generateMessage(A_OPEN, localId, 0, bbuf.array()); } @@ -389,16 +350,13 @@ final class AdbProtocol { */ @NonNull public static Message parse(@NonNull InputStream in, int protocolVersion, int maxData) throws IOException { + if (maxData <= 0 || maxData > MAX_PAYLOAD_V3) { + throw new IllegalArgumentException("invalid maximum ADB payload: " + maxData); + } ByteBuffer header = ByteBuffer.allocate(ADB_HEADER_LENGTH).order(ByteOrder.LITTLE_ENDIAN); // Read header - int dataRead = 0; - do { - int bytesRead = in.read(header.array(), dataRead, ADB_HEADER_LENGTH - dataRead); - if (bytesRead < 0) { - throw new IOException("Stream closed"); - } else dataRead += bytesRead; - } while (dataRead < ADB_HEADER_LENGTH); + readFully(in, header.array(), ADB_HEADER_LENGTH); Message msg = new Message(header); @@ -406,13 +364,19 @@ final class AdbProtocol { if (msg.command != (~msg.magic)) { // magic = cmd ^ 0xFFFFFFFF throw new StreamCorruptedException(String.format("Invalid header: Invalid magic 0x%x.", msg.magic)); } - if (msg.command != A_SYNC && msg.command != A_CNXN && msg.command != A_OPEN && msg.command != A_OKAY + if (msg.command != A_CNXN && msg.command != A_OPEN && msg.command != A_OKAY && msg.command != A_CLSE && msg.command != A_WRTE && msg.command != A_AUTH && msg.command != A_STLS) { throw new StreamCorruptedException(String.format("Invalid header: Invalid command 0x%x.", msg.command)); } if (msg.dataLength < 0 || msg.dataLength > maxData) { - throw new StreamCorruptedException(String.format("Invalid header: Invalid data length %d", msg.dataLength)); + throw new StreamCorruptedException( + String.format("Invalid header: Invalid data length %d", msg.dataLength)); + } + if (msg.dataLength != 0 && (msg.command == A_OKAY + || msg.command == A_CLSE || msg.command == A_STLS)) { + throw new StreamCorruptedException( + String.format("Invalid header: Command 0x%x has a payload", msg.command)); } if (msg.dataLength == 0) { @@ -422,13 +386,7 @@ final class AdbProtocol { // Read payload msg.payload = new byte[msg.dataLength]; - dataRead = 0; - do { - int bytesRead = in.read(msg.payload, dataRead, msg.dataLength - dataRead); - if (bytesRead < 0) { - throw new IOException("Stream closed"); - } else dataRead += bytesRead; - } while (dataRead < msg.dataLength); + readFully(in, msg.payload, msg.dataLength); // Verify payload if ((protocolVersion <= A_VERSION_MIN || (msg.command == A_CNXN && msg.arg0 <= A_VERSION_MIN)) @@ -440,6 +398,19 @@ final class AdbProtocol { return msg; } + // InputStream permits unusual implementations to return zero even + // when len is non-zero. Treat that as a broken transport instead of + // spinning forever on an attacker-controlled connection thread. + private static void readFully(InputStream in, byte[] data, int length) throws IOException { + int offset = 0; + while (offset < length) { + int count = in.read(data, offset, length - offset); + if (count < 0) throw new IOException("Stream closed"); + if (count == 0) throw new IOException("ADB input made no progress"); + offset += count; + } + } + private Message(@NonNull ByteBuffer header) { command = header.getInt(); arg0 = header.getInt(); @@ -454,9 +425,6 @@ final class AdbProtocol { public String toString() { String tag; switch (command) { - case A_SYNC: - tag = "SYNC"; - break; case A_CNXN: tag = "CNXN"; break; diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbStream.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbStream.java index 62754b0..1700831 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbStream.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AdbStream.java @@ -4,6 +4,7 @@ package io.github.muntashirakon.adb; import java.io.Closeable; import java.io.IOException; +import java.io.StreamCorruptedException; import java.nio.ByteBuffer; import java.util.Queue; import java.util.concurrent.ConcurrentLinkedQueue; @@ -15,10 +16,18 @@ import java.util.concurrent.atomic.AtomicBoolean; // Copyright 2013 Cameron Gutman public class AdbStream implements Closeable { + // Small transport seam around the connection. It keeps this stream state + // machine testable without a socket or Android runtime. + interface Transport { + int getMaxData(); + void sendPacket(byte[] packet) throws IOException; + void flushPacket() throws IOException; + } + /** * The AdbConnection object that the stream communicates over */ - private final AdbConnection mAdbConnection; + private final Transport mTransport; /** * The local ID of the stream @@ -55,6 +64,9 @@ public class AdbStream implements Closeable { */ private volatile boolean mPendingClose; + /** One WRTE has been received and has not yet been fully consumed. */ + private boolean mReadPacketPending; + /** * Creates a new AdbStream object on the specified AdbConnection * with the given local ID. @@ -62,12 +74,11 @@ public class AdbStream implements Closeable { * @param adbConnection AdbConnection that this stream is running on * @param localId Local ID of the stream */ - AdbStream(AdbConnection adbConnection, int localId) - throws IOException, InterruptedException, AdbPairingRequiredException { - this.mAdbConnection = adbConnection; + AdbStream(Transport transport, int localId) { + this.mTransport = transport; this.mLocalId = localId; this.mReadQueue = new ConcurrentLinkedQueue<>(); - this.mReadBuffer = (ByteBuffer) ByteBuffer.allocate(adbConnection.getMaxData()).flip(); + this.mReadBuffer = (ByteBuffer) ByteBuffer.allocate(transport.getMaxData()).flip(); this.mWriteReady = new AtomicBoolean(false); this.mIsClosed = false; } @@ -85,8 +96,13 @@ public class AdbStream implements Closeable { * * @param payload Data inside the WRTE message */ - void addPayload(byte[] payload) { + void addPayload(byte[] payload) throws IOException { synchronized (mReadQueue) { + if (mReadPacketPending) { + throw new StreamCorruptedException( + "ADB peer sent WRTE before the previous packet was acknowledged"); + } + mReadPacketPending = true; mReadQueue.add(payload); mReadQueue.notifyAll(); } @@ -100,7 +116,7 @@ public class AdbStream implements Closeable { */ void sendReady() throws IOException { // Generate and send a OKAY packet - mAdbConnection.sendPacket(AdbProtocol.generateReady(mLocalId, mRemoteId)); + mTransport.sendPacket(AdbProtocol.generateReady(mLocalId, mRemoteId)); } /** @@ -109,14 +125,25 @@ public class AdbStream implements Closeable { * @param remoteId New remote ID */ void updateRemoteId(int remoteId) { + if (remoteId == 0) throw new IllegalArgumentException("remote stream ID is zero"); + if (mRemoteId != 0 && mRemoteId != remoteId) { + throw new IllegalStateException("remote stream ID changed"); + } this.mRemoteId = remoteId; } + boolean hasRemoteId(int remoteId) { + return mRemoteId != 0 && mRemoteId == remoteId; + } + /** * Called by the connection thread to indicate the stream is okay to send data. */ void readyForWrite() { - mWriteReady.set(true); + synchronized (this) { + mWriteReady.set(true); + notifyAll(); + } } boolean isOpen() { @@ -128,7 +155,7 @@ public class AdbStream implements Closeable { */ void notifyClose(boolean closedByPeer) { // We don't call close() because it sends another CLSE - if (closedByPeer && !mReadQueue.isEmpty()) { + if (closedByPeer && hasUnreadData()) { // The remote peer closed the stream, but we haven't finished reading the remaining data mPendingClose = true; } else { @@ -151,42 +178,51 @@ public class AdbStream implements Closeable { * @throws IOException If the stream fails while waiting */ public int read(byte[] bytes, int offset, int length) throws IOException { + if (bytes == null) throw new NullPointerException("bytes"); + if (offset < 0 || length < 0 || offset > bytes.length || length > bytes.length - offset) { + throw new IndexOutOfBoundsException(); + } + if (length == 0) return 0; if (mReadBuffer.hasRemaining()) { - return readBuffer(bytes, offset, length); + return readBufferAndAcknowledge(bytes, offset, length); } - // Buffer has no data, grab from the queue - synchronized (mReadQueue) { - byte[] data; - // Wait for the connection to close or data to be received - while ((data = mReadQueue.poll()) == null && !mIsClosed) { - try { - mReadQueue.wait(); - } catch (InterruptedException e) { - //noinspection UnnecessaryInitCause - throw (IOException) new IOException().initCause(e); + while (true) { + // Buffer has no data, grab from the queue + synchronized (mReadQueue) { + byte[] data; + // Wait for the connection to close or data to be received + while ((data = mReadQueue.poll()) == null && !mIsClosed) { + try { + mReadQueue.wait(); + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + throw (IOException) new IOException("interrupted while reading ADB stream") + .initCause(e); + } } - } - // Add data to the buffer - if (data != null) { - mReadBuffer.clear(); - mReadBuffer.put(data); - mReadBuffer.flip(); - if (mReadBuffer.hasRemaining()) { - return readBuffer(bytes, offset, length); + + // Add data to the buffer + if (data != null) { + mReadBuffer.clear(); + mReadBuffer.put(data); + mReadBuffer.flip(); + if (mReadBuffer.hasRemaining()) { + return readBufferAndAcknowledge(bytes, offset, length); + } + // Empty WRTE packets are legal but carry no bytes. Ack + // and continue instead of returning a false EOF. + finishReadPacket(); } - } - if (mIsClosed) { - throw new IOException("Stream closed."); - } + if (mIsClosed) return -1; - if (mPendingClose && mReadQueue.isEmpty()) { - // The peer closed the stream, and we've finished reading the stream data, so this stream is finished - mIsClosed = true; + if (mPendingClose && !hasUnreadData()) { + mPendingClose = false; + mIsClosed = true; + return -1; + } } } - - return -1; } private int readBuffer(byte[] bytes, int offset, int length) { @@ -200,6 +236,32 @@ public class AdbStream implements Closeable { return count; } + private int readBufferAndAcknowledge(byte[] bytes, int offset, int length) throws IOException { + int count = readBuffer(bytes, offset, length); + if (!mReadBuffer.hasRemaining()) finishReadPacket(); + return count; + } + + private void finishReadPacket() throws IOException { + boolean closeAfterDrain; + synchronized (mReadQueue) { + mReadPacketPending = false; + closeAfterDrain = mPendingClose && mReadQueue.isEmpty(); + if (closeAfterDrain) { + mPendingClose = false; + mIsClosed = true; + } + } + // A peer that already sent CLSE neither needs nor expects OKAY. + if (!closeAfterDrain && !mIsClosed) sendReady(); + } + + private boolean hasUnreadData() { + synchronized (mReadQueue) { + return mReadPacketPending || mReadBuffer.hasRemaining() || !mReadQueue.isEmpty(); + } + } + /** * Sends a WRTE packet with a given byte array payload. It does not flush the stream. * @@ -207,44 +269,37 @@ public class AdbStream implements Closeable { * @throws IOException If the stream fails while sending data */ public void write(byte[] bytes, int offset, int length) throws IOException { + if (bytes == null) throw new NullPointerException("bytes"); + if (offset < 0 || length < 0 || offset > bytes.length || length > bytes.length - offset) { + throw new IndexOutOfBoundsException(); + } + if (length == 0) return; + // Split and send data as WRTE packet + int maxData = mTransport.getMaxData(); + while (length != 0) { + int count = Math.min(length, maxData); + sendWrite(bytes, offset, count); + offset += count; + length -= count; + } + } + + private void sendWrite(byte[] bytes, int offset, int count) throws IOException { synchronized (this) { - // Make sure we're ready for a WRTE while (!mIsClosed && !mWriteReady.compareAndSet(true, false)) { try { wait(); } catch (InterruptedException e) { - //noinspection UnnecessaryInitCause - throw (IOException) new IOException().initCause(e); + Thread.currentThread().interrupt(); + throw (IOException) new IOException("interrupted while writing ADB stream") + .initCause(e); } } - - if (mIsClosed) { - throw new IOException("Stream closed"); - } - } - // Split and send data as WRTE packet - // TODO: A WRITE message may not be sent until a READY message is received. - // Once a WRITE message is sent, an additional WRITE message may not be - // sent until another READY message has been received. Recipients of - // a WRITE message that is in violation of this requirement will CLOSE - // the connection. - int maxData; - try { - maxData = mAdbConnection.getMaxData(); - } catch (InterruptedException | AdbPairingRequiredException e) { - //noinspection UnnecessaryInitCause - throw (IOException) new IOException().initCause(e); - } - while (length != 0) { - if (length <= maxData) { - mAdbConnection.sendPacket(AdbProtocol.generateWrite(mLocalId, mRemoteId, bytes, offset, length)); - offset = offset + length; - length = 0; - } else { // if (length > maxData) { - mAdbConnection.sendPacket(AdbProtocol.generateWrite(mLocalId, mRemoteId, bytes, offset, maxData)); - offset = offset + maxData; - length = length - maxData; - } + if (mIsClosed) throw new IOException("Stream closed"); + // Keep consuming OKAY and sending WRTE atomic with close(). A + // concurrent close must never put WRTE on the wire after CLSE. + mTransport.sendPacket( + AdbProtocol.generateWrite(mLocalId, mRemoteId, bytes, offset, count)); } } @@ -252,7 +307,7 @@ public class AdbStream implements Closeable { if (mIsClosed) { throw new IOException("Stream closed"); } - mAdbConnection.flushPacket(); + mTransport.flushPacket(); } /** @@ -271,7 +326,7 @@ public class AdbStream implements Closeable { notifyClose(false); } - mAdbConnection.sendPacket(AdbProtocol.generateClose(mLocalId, mRemoteId)); + mTransport.sendPacket(AdbProtocol.generateClose(mLocalId, mRemoteId)); } /** @@ -291,12 +346,10 @@ public class AdbStream implements Closeable { */ public int available() throws IOException { synchronized (this) { - if (mIsClosed) { - throw new IOException("Stream closed."); - } if (mReadBuffer.hasRemaining()) { return mReadBuffer.remaining(); } + if (mIsClosed) return 0; byte[] data = mReadQueue.peek(); return data == null ? 0 : data.length; } diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AndroidPubkey.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AndroidPubkey.java index 6aa12aa..91227b3 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AndroidPubkey.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/AndroidPubkey.java @@ -3,25 +3,18 @@ package io.github.muntashirakon.adb; import androidx.annotation.NonNull; -import androidx.annotation.Nullable; import androidx.annotation.VisibleForTesting; import org.bouncycastle.util.encoders.Base64; +import java.io.ByteArrayOutputStream; import java.math.BigInteger; import java.nio.ByteBuffer; import java.nio.ByteOrder; -import java.security.GeneralSecurityException; +import java.nio.charset.StandardCharsets; import java.security.InvalidKeyException; -import java.security.KeyFactory; -import java.security.NoSuchAlgorithmException; -import java.security.PrivateKey; import java.security.interfaces.RSAPublicKey; -import java.security.spec.InvalidKeySpecException; -import java.security.spec.RSAPublicKeySpec; -import java.util.Objects; - -import javax.crypto.Cipher; +import java.util.Locale; final class AndroidPubkey { /** @@ -39,61 +32,6 @@ final class AndroidPubkey { */ public static final int ANDROID_PUBKEY_MODULUS_SIZE_WORDS = ANDROID_PUBKEY_MODULUS_SIZE / 4; - /** - * The RSA signature padding as an int array. - */ - private static final int[] SIGNATURE_PADDING_AS_INT = new int[]{ - 0x00, 0x01, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00, - 0x30, 0x21, 0x30, 0x09, 0x06, 0x05, 0x2b, 0x0e, 0x03, 0x02, 0x1a, 0x05, 0x00, - 0x04, 0x14 - }; - - /** - * The RSA signature padding as a byte array - */ - private static final byte[] RSA_SHA_PKCS1_SIGNATURE_PADDING; - - static { - RSA_SHA_PKCS1_SIGNATURE_PADDING = new byte[SIGNATURE_PADDING_AS_INT.length]; - - for (int i = 0; i < RSA_SHA_PKCS1_SIGNATURE_PADDING.length; i++) - RSA_SHA_PKCS1_SIGNATURE_PADDING[i] = (byte) SIGNATURE_PADDING_AS_INT[i]; - } - - /** - * Signs the ADB SHA1 payload with the private key of this object. - * - * @param privateKey Private key to sign with - * @param payload SHA1 payload to sign - * @return Signed SHA1 payload - * @throws GeneralSecurityException If signing fails - */ - // Taken from adb_auth_sign - @NonNull - public static byte[] adbAuthSign(@NonNull PrivateKey privateKey, byte[] payload) - throws GeneralSecurityException { - Cipher c = Cipher.getInstance("RSA/ECB/NoPadding"); - c.init(Cipher.ENCRYPT_MODE, privateKey); - c.update(RSA_SHA_PKCS1_SIGNATURE_PADDING); - return c.doFinal(payload); - } - /** * Converts a standard RSAPublicKey object to the special ADB format. Available since 4.2.2. * @@ -105,21 +43,24 @@ final class AndroidPubkey { public static byte[] encodeWithName(@NonNull RSAPublicKey publicKey, @NonNull String name) throws InvalidKeyException { int pkeySize = 4 * (int) Math.ceil(ANDROID_PUBKEY_ENCODED_SIZE / 3.0); - try (ByteArrayNoThrowOutputStream bos = new ByteArrayNoThrowOutputStream(pkeySize + name.length() + 2)) { - bos.write(Base64.encode(encode(publicKey))); - bos.write(getUserInfo(name)); - return bos.toByteArray(); - } + ByteArrayOutputStream out = new ByteArrayOutputStream(pkeySize + name.length() + 2); + byte[] encoded = Base64.encode(encode(publicKey)); + out.write(encoded, 0, encoded.length); + byte[] userInfo = getUserInfo(name); + out.write(userInfo, 0, userInfo.length); + return out.toByteArray(); } // Taken from get_user_info except that a custom name is used instead of host@user @VisibleForTesting @NonNull static byte[] getUserInfo(@NonNull String name) { - return StringCompat.getBytes(String.format(" %s\u0000", name), "UTF-8"); + return String.format(Locale.ROOT, " %s\u0000", name) + .getBytes(StandardCharsets.UTF_8); } - // https://android.googlesource.com/platform/system/core/+/e797a5c75afc17024d0f0f488c130128fcd704e2/libcrypto_utils/android_pubkey.cpp + // AOSP platform/system/core commit e797a5c7, + // libcrypto_utils/android_pubkey.cpp: // typedef struct RSAPublicKey { // uint32_t modulus_size_words; // Modulus length. This must be ANDROID_PUBKEY_MODULUS_SIZE. // uint32_t n0inv; // Precomputed montgomery parameter: -1 / n[0] mod 2^32 @@ -128,46 +69,6 @@ final class AndroidPubkey { // uint32_t exponent; // RSA modulus: 3 or 65537 // } RSAPublicKey; - /** - * Allocates a new {@link RSAPublicKey} object, decodes a public RSA key stored in Android's custom binary format, - * and sets the key parameters. The resulting key can be used with the standard Java cryptography API to perform - * public operations. - * - * @param androidPubkey Public RSA key in Android's custom binary format. The size of the key must be at least - * {@link #ANDROID_PUBKEY_ENCODED_SIZE} - * @return {@link RSAPublicKey} object - */ - @NonNull - public static RSAPublicKey decode(@NonNull byte[] androidPubkey) - throws InvalidKeyException, NoSuchAlgorithmException, InvalidKeySpecException { - BigInteger n; - BigInteger e; - - // Check size is large enough and the modulus size is correct. - if (androidPubkey.length < ANDROID_PUBKEY_ENCODED_SIZE) { - throw new InvalidKeyException("Invalid key length"); - } - ByteBuffer keyStruct = ByteBuffer.wrap(androidPubkey).order(ByteOrder.LITTLE_ENDIAN); - int modulusSize = keyStruct.getInt(); - if (modulusSize != ANDROID_PUBKEY_MODULUS_SIZE_WORDS) { - throw new InvalidKeyException("Invalid modulus length."); - } - - // Convert the modulus to big-endian byte order as expected by BN_bin2bn. - byte[] modulus = new byte[ANDROID_PUBKEY_MODULUS_SIZE]; - keyStruct.position(8); - keyStruct.get(modulus); - n = new BigInteger(1, swapEndianness(modulus)); - - // Read the exponent. - keyStruct.position(520); - e = BigInteger.valueOf(keyStruct.getInt()); - - KeyFactory keyFactory = KeyFactory.getInstance("RSA"); - RSAPublicKeySpec publicKeySpec = new RSAPublicKeySpec(n, e); - return (RSAPublicKey) keyFactory.generatePublic(publicKeySpec); - } - /** * Encodes the given key in the Android RSA public key binary format. * @@ -180,8 +81,13 @@ final class AndroidPubkey { BigInteger n0inv; BigInteger rr; - if (publicKey.getModulus().toByteArray().length < ANDROID_PUBKEY_MODULUS_SIZE) { - throw new InvalidKeyException("Invalid key length " + publicKey.getModulus().toByteArray().length); + if (publicKey.getModulus().bitLength() != ANDROID_PUBKEY_MODULUS_SIZE * 8) { + throw new InvalidKeyException("ADB requires an RSA-2048 key"); + } + BigInteger exponent = publicKey.getPublicExponent(); + if (!BigInteger.valueOf(3).equals(exponent) + && !BigInteger.valueOf(65537).equals(exponent)) { + throw new InvalidKeyException("ADB RSA exponent must be 3 or 65537"); } ByteBuffer keyStruct = ByteBuffer.allocate(ANDROID_PUBKEY_ENCODED_SIZE).order(ByteOrder.LITTLE_ENDIAN); @@ -196,12 +102,13 @@ final class AndroidPubkey { keyStruct.putInt(n0inv.intValue()); // n0inv // Store the modulus. - keyStruct.put(Objects.requireNonNull(BigEndianToLittleEndianPadded(ANDROID_PUBKEY_MODULUS_SIZE, publicKey.getModulus()))); + keyStruct.put(bigEndianToLittleEndianPadded( + ANDROID_PUBKEY_MODULUS_SIZE, publicKey.getModulus())); // Compute and store rr = (2^(rsa_size)) ^ 2 mod N. rr = BigInteger.ZERO.setBit(ANDROID_PUBKEY_MODULUS_SIZE * 8); // rr = 2^(rsa_size) rr = rr.modPow(BigInteger.valueOf(2), publicKey.getModulus()); // rr = rr^2 mod N - keyStruct.put(Objects.requireNonNull(BigEndianToLittleEndianPadded(ANDROID_PUBKEY_MODULUS_SIZE, rr))); + keyStruct.put(bigEndianToLittleEndianPadded(ANDROID_PUBKEY_MODULUS_SIZE, rr)); // Store the exponent. keyStruct.putInt(publicKey.getPublicExponent().intValue()); // exponent @@ -209,24 +116,24 @@ final class AndroidPubkey { return keyStruct.array(); } - @Nullable - private static byte[] BigEndianToLittleEndianPadded(int len, @NonNull BigInteger in) { + private static byte[] bigEndianToLittleEndianPadded(int len, @NonNull BigInteger in) + throws InvalidKeyException { byte[] out = new byte[len]; byte[] bytes = swapEndianness(in.toByteArray()); // Convert big endian -> little endian - int num_bytes = bytes.length; - if (len < num_bytes) { - if (!fitsInBytes(bytes, num_bytes, len)) { - return null; + int numBytes = bytes.length; + if (len < numBytes) { + if (!fitsInBytes(bytes, numBytes, len)) { + throw new InvalidKeyException("RSA value does not fit ADB key structure"); } - num_bytes = len; + numBytes = len; } - System.arraycopy(bytes, 0, out, 0, num_bytes); + System.arraycopy(bytes, 0, out, 0, numBytes); return out; } - static boolean fitsInBytes(@NonNull byte[] bytes, int num_bytes, int len) { + static boolean fitsInBytes(@NonNull byte[] bytes, int numBytes, int len) { byte mask = 0; - for (int i = len; i < num_bytes; i++) { + for (int i = len; i < numBytes; i++) { mask |= bytes[i]; } return mask == 0; diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/ByteArrayNoThrowOutputStream.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/ByteArrayNoThrowOutputStream.java deleted file mode 100644 index 55cc1bf..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/ByteArrayNoThrowOutputStream.java +++ /dev/null @@ -1,24 +0,0 @@ -// SPDX-License-Identifier: GPL-3.0-or-later OR Apache-2.0 - -package io.github.muntashirakon.adb; - -import java.io.ByteArrayOutputStream; - -class ByteArrayNoThrowOutputStream extends ByteArrayOutputStream { - public ByteArrayNoThrowOutputStream() { - super(); - } - - public ByteArrayNoThrowOutputStream(int size) { - super(size); - } - - @Override - public void write(byte[] b) { - write(b, 0, b.length); - } - - @Override - public void close() { - } -} diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/KeyPair.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/KeyPair.java index 4574d8b..6323934 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/KeyPair.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/KeyPair.java @@ -6,8 +6,6 @@ import java.security.PrivateKey; import java.security.PublicKey; import java.security.cert.Certificate; -import javax.security.auth.DestroyFailedException; - final class KeyPair { private final PrivateKey mPrivateKey; private final Certificate mCertificate; @@ -28,11 +26,4 @@ final class KeyPair { public Certificate getCertificate() { return mCertificate; } - - public void destroy() throws DestroyFailedException { - try { - mPrivateKey.destroy(); - } catch (NoSuchMethodError ignore) { - } - } } diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/LocalServices.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/LocalServices.java deleted file mode 100644 index 523bce3..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/LocalServices.java +++ /dev/null @@ -1,271 +0,0 @@ -// SPDX-License-Identifier: GPL-3.0-or-later OR Apache-2.0 - -package io.github.muntashirakon.adb; - -import android.text.TextUtils; - -import androidx.annotation.IntDef; -import androidx.annotation.NonNull; - -import java.lang.annotation.Retention; -import java.lang.annotation.RetentionPolicy; -import java.util.Objects; - - -/** - * Local services extracted from the ADB client - * for easy access. - */ -public class LocalServices { - static final int SERVICE_FIRST = 1; - - public static final int SHELL = 1; - /** - * Remount the device's filesystem in read-write mode, instead of read-only. This is usually necessary before - * performing an {@link #SYNC} request. This request may not succeed on certain builds which do not allow that. - *

- * This essentially executes {@code /system/bin/remount} command. Additional arguments such as {@code -R} can be - * passed too. - */ - public static final int REMOUNT = 2; - public static final int FILE = 3; - public static final int TCP_CONNECT = 4; - public static final int LOCAL_UNIX_SOCKET = 5; - public static final int LOCAL_UNIX_SOCKET_RESERVED = 6; - public static final int LOCAL_UNIX_SOCKET_ABSTRACT = 7; - public static final int LOCAL_UNIX_SOCKET_FILE_SYSTEM = 8; - /** - * Receive snapshots of the framebuffer. It requires sufficient privileges (or the connection is closed immediately) - * but works as follows: - *

- * After an {@link AdbStream} is opened, ADB daemon sends a 16-byte binary structure containing the following fields - * (little-endian format): - *

-     * uint32_t depth;     // framebuffer depth = 16
-     * uint32_t size;      // framebuffer size in bytes = 2 * width * height
-     * uint32_t width;     // framebuffer width in pixels
-     * uint32_t height;    // framebuffer height in pixels
-     * 
- * After that, each time a snapshot is wanted, one byte should be sent through the channel, which will trigger the - * daemon to send {@code size} bytes of framebuffer data. - */ - public static final int FRAMEBUFFER = 9; - /** - * Connects to the JDWP thread running in the VM of process PID (specified as an argument). - */ - public static final int CONNECT_JDWP = 10; - /** - * Receive the list of JDWP PIDs periodically. The format of the returned data is the following (in order): - *
    - *
  1. {@code hex4}: The length of all content as a 4-char hexadecimal string i.e. {@code %04zx}. - *
  2. {@code content}: A series of ASCII lines of the following format: - *
    -     *  <pid> "\n"
    -     *  
    - *
- * This service is used by DDMS to know which debuggable processes are running on the device/emulator. - *

- * Note that there is no single-shot service to retrieve the list only once. - */ - public static final int TRACK_JDWP = 11; - public static final int SYNC = 12; - /** - * Reverse socket connections from the device running ADB daemon to this client. This should not be used if both - * the ADB daemon and the client are in the same device. - *

- * It takes an additional argument called {@code forward-command}. It can be one of the following: - *

    - *
  • {@code list-forward}: List all forwarded connections from the device - * This returns something that looks like the following: - *
      - *
    1. {@code hex4}: The length of the payload, as 4 hexadecimal chars i.e. {@code %04zx}. - *
    2. {@code payload}: A series of lines of the following format: - *
      -     *     host " " <local> " " <remote> "\n"
      -     *     
      - * Where <local> is the device-specific endpoint (e.g. {@code tcp:9000}), and <remote> is the - * client-specific endpoint. - *
    - *
  • forward:; - *
  • forward:norebind:; - *
  • killforward-all - *
  • killforward: - *
- */ - public static final int REVERSE = 13; - /** - * Backup some or all packages installed in the device. For this to work, {@code allowBackup=true} must be present - * in the application section of the AndroidManifest.xml of the app. - *

- * It takes additional arguments which can be one of the following: - *

    - *
  • List of packages (as array) - *
  • {@code -all} - *
  • {@code -shared} - *
- * Output is a stream which is in zlib format with 24 bytes at the front (if unencrypted). - */ - public static final int BACKUP = 14; - /** - * Restore a backup. Input is a stream which is in zlib format with 24 bytes at the front (if unencrypted). - */ - public static final int RESTORE = 15; - - static final int SERVICE_LAST = 15; - - @IntDef({ - SHELL, - REMOUNT, - FILE, - TCP_CONNECT, - LOCAL_UNIX_SOCKET, - LOCAL_UNIX_SOCKET_RESERVED, - LOCAL_UNIX_SOCKET_ABSTRACT, - LOCAL_UNIX_SOCKET_FILE_SYSTEM, - FRAMEBUFFER, - CONNECT_JDWP, - TRACK_JDWP, - SYNC, - REVERSE, - BACKUP, - RESTORE, - }) - @Retention(RetentionPolicy.SOURCE) - public @interface Services { - } - - @NonNull - static String getServiceName(@Services int service) { - switch (service) { - case SHELL: - return "shell:"; - case CONNECT_JDWP: - return "jdwp:"; - case FILE: - return "dev:"; - case FRAMEBUFFER: - return "framebuffer:"; - case LOCAL_UNIX_SOCKET: - return "local:"; - case LOCAL_UNIX_SOCKET_ABSTRACT: - return "localabstract:"; - case LOCAL_UNIX_SOCKET_FILE_SYSTEM: - return "localfilesystem:"; - case LOCAL_UNIX_SOCKET_RESERVED: - return "localreserved:"; - case REMOUNT: - return "remount:"; - case REVERSE: - return "reverse:"; - case SYNC: - return "sync:"; - case TCP_CONNECT: - return "tcp:"; - case TRACK_JDWP: - return "track-jdwp"; - case BACKUP: - return "backup:"; - case RESTORE: - return "restore:"; - default: - throw new IllegalArgumentException("Invalid service: " + service); - } - } - - @NonNull - static String getDestination(@Services int service, @NonNull String... args) { - String serviceName = getServiceName(service); - StringBuilder destination = new StringBuilder(serviceName); - switch (service) { - case SHELL: - for (String arg : args) { - if (arg.contains("\"")) { - throw new IllegalArgumentException("Arguments for inline shell cannot contain double" + - " quotations."); - } - if (arg.contains(" ")) { - destination.append("\"").append(Objects.requireNonNull(arg)).append("\""); - } else destination.append(Objects.requireNonNull(arg)); - } - break; - case FILE: - if (args.length == 0) { - throw new IllegalArgumentException("File name must be specified."); - } else if (args.length != 1) { - throw new IllegalArgumentException("Service expects exactly one argument, " + args.length - + " supplied."); - } - destination.append(Objects.requireNonNull(args[0])); - break; - case TCP_CONNECT: - if (args.length == 0) { - throw new IllegalArgumentException("Port number must be specified."); - } else if (args.length == 1) { - destination.append(args[0]); - } else if (args.length == 2) { - destination.append(Objects.requireNonNull(args[0])) - .append(':') - .append(Objects.requireNonNull(args[1])); - } else { - throw new IllegalArgumentException("Invalid number of arguments supplied."); - } - break; - case LOCAL_UNIX_SOCKET: - case LOCAL_UNIX_SOCKET_ABSTRACT: - case LOCAL_UNIX_SOCKET_FILE_SYSTEM: - case LOCAL_UNIX_SOCKET_RESERVED: - if (args.length == 0) { - throw new IllegalArgumentException("Path must be specified."); - } else if (args.length != 1) { - throw new IllegalArgumentException("Service expects exactly one argument, " + args.length - + " supplied."); - } - destination.append(Objects.requireNonNull(args[0])); - break; - case CONNECT_JDWP: - if (args.length == 0) { - throw new IllegalArgumentException("PID must be specified."); - } else if (args.length != 1) { - throw new IllegalArgumentException("Service expects exactly one argument, " + args.length - + " supplied."); - } - destination.append(Objects.requireNonNull(args[0])); - break; - case REVERSE: - if (args.length == 0) { - throw new IllegalArgumentException("Forward command must be specified."); - } else if (args.length != 1) { - throw new IllegalArgumentException("Service expects exactly one argument, " + args.length - + " supplied."); - } - if (args[0] == null) { - throw new IllegalArgumentException("Forward command is empty"); - } - if ("list-forward".equals(args[0]) || "killforward-all".equals(args[0])) { - destination.append(args[0]); - } else if (args[0].startsWith("forward:") || args[0].startsWith("killforward:")) { - destination.append(args[0]); - } else { - throw new IllegalArgumentException("Invalid forward command."); - } - break; - case BACKUP: - if (args.length == 0) { - throw new IllegalArgumentException("At least one package must be specified or use -shared/-all."); - } - case REMOUNT: - // Additional arguments for the commands - destination.append(TextUtils.join(" ", args)); - break; - case RESTORE: - case FRAMEBUFFER: - case SYNC: - case TRACK_JDWP: - if (args.length != 0) { - throw new IllegalArgumentException("Service expects no arguments."); - } - break; - } - return destination.toString(); - } -} diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PRNGFixes.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PRNGFixes.java deleted file mode 100644 index fe6343f..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PRNGFixes.java +++ /dev/null @@ -1,319 +0,0 @@ -// SPDX-License-Identifier: MIT AND (GPL-3.0-or-later OR Apache-2.0) - -package io.github.muntashirakon.adb; - -import android.os.Build; -import android.os.Process; -import android.util.Log; - -import androidx.annotation.GuardedBy; - -import java.io.ByteArrayOutputStream; -import java.io.DataInputStream; -import java.io.DataOutputStream; -import java.io.File; -import java.io.FileInputStream; -import java.io.FileOutputStream; -import java.io.IOException; -import java.io.OutputStream; -import java.io.UnsupportedEncodingException; -import java.security.NoSuchAlgorithmException; -import java.security.Provider; -import java.security.SecureRandom; -import java.security.SecureRandomSpi; -import java.security.Security; - -/** - * Fixes for the output of the default PRNG having low entropy. - *

- * The fixes need to be applied via {@link #apply()} before any use of Java - * Cryptography Architecture primitives. A good place to invoke them is in the - * application's {@code onCreate}. - */ -// Copyright 2013 Google Inc. -public final class PRNGFixes { - private static final byte[] BUILD_FINGERPRINT_AND_DEVICE_SERIAL = getBuildFingerprintAndDeviceSerial(); - - /** - * Hidden constructor to prevent instantiation. - */ - private PRNGFixes() { - } - - /** - * Applies all fixes. - * - * @throws SecurityException if a fix is needed but could not be applied. - */ - public static void apply() { - applyOpenSSLFix(); - installLinuxPRNGSecureRandom(); - } - - /** - * Applies the fix for OpenSSL PRNG having low entropy. Does nothing if the - * fix is not needed. - * - * @throws SecurityException if the fix is needed but could not be applied. - */ - private static void applyOpenSSLFix() throws SecurityException { - if ((Build.VERSION.SDK_INT < Build.VERSION_CODES.JELLY_BEAN) - || (Build.VERSION.SDK_INT > Build.VERSION_CODES.JELLY_BEAN_MR2)) { - // No need to apply the fix - return; - } - - try { - // Mix in the device- and invocation-specific seed. - Class.forName("org.apache.harmony.xnet.provider.jsse.NativeCrypto") - .getMethod("RAND_seed", byte[].class) - .invoke(null, generateSeed()); - - // Mix output of Linux PRNG into OpenSSL's PRNG - int bytesRead = (Integer) Class.forName("org.apache.harmony.xnet.provider.jsse.NativeCrypto") - .getMethod("RAND_load_file", String.class, long.class) - .invoke(null, "/dev/urandom", 1024); - if (bytesRead != 1024) { - throw new IOException("Unexpected number of bytes read from Linux PRNG: " + bytesRead); - } - } catch (Exception e) { - throw new SecurityException("Failed to seed OpenSSL PRNG", e); - } - } - - /** - * Installs a Linux PRNG-backed {@code SecureRandom} implementation as the - * default. Does nothing if the implementation is already the default or if - * there is not need to install the implementation. - * - * @throws SecurityException if the fix is needed but could not be applied. - */ - private static void installLinuxPRNGSecureRandom() - throws SecurityException { - if (Build.VERSION.SDK_INT > Build.VERSION_CODES.JELLY_BEAN_MR2) { - // No need to apply the fix - return; - } - - // Install a Linux PRNG-based SecureRandom implementation as the - // default, if not yet installed. - Provider[] secureRandomProviders = Security.getProviders("SecureRandom.SHA1PRNG"); - if ((secureRandomProviders == null) - || (secureRandomProviders.length < 1) - || (!LinuxPRNGSecureRandomProvider.class.equals(secureRandomProviders[0].getClass()))) { - Security.insertProviderAt(new LinuxPRNGSecureRandomProvider(), 1); - } - - // Assert that new SecureRandom() and - // SecureRandom.getInstance("SHA1PRNG") return a SecureRandom backed - // by the Linux PRNG-based SecureRandom implementation. - SecureRandom rng1 = new SecureRandom(); - if (!LinuxPRNGSecureRandomProvider.class.equals(rng1.getProvider().getClass())) { - throw new SecurityException("new SecureRandom() backed by wrong Provider: " - + rng1.getProvider().getClass()); - } - - SecureRandom rng2; - try { - rng2 = SecureRandom.getInstance("SHA1PRNG"); - } catch (NoSuchAlgorithmException e) { - throw new SecurityException("SHA1PRNG not available", e); - } - if (!LinuxPRNGSecureRandomProvider.class.equals( - rng2.getProvider().getClass())) { - throw new SecurityException("SecureRandom.getInstance(\"SHA1PRNG\") backed by wrong provider: " - + rng2.getProvider().getClass()); - } - } - - /** - * {@code Provider} of {@code SecureRandom} engines which pass through - * all requests to the Linux PRNG. - */ - private static class LinuxPRNGSecureRandomProvider extends Provider { - - public LinuxPRNGSecureRandomProvider() { - super("LinuxPRNG", 1.0, "A Linux-specific random number provider that uses /dev/urandom"); - // Although /dev/urandom is not a SHA-1 PRNG, some apps - // explicitly request a SHA1PRNG SecureRandom and we thus need to - // prevent them from getting the default implementation whose output - // may have low entropy. - put("SecureRandom.SHA1PRNG", LinuxPRNGSecureRandom.class.getName()); - put("SecureRandom.SHA1PRNG ImplementedIn", "Software"); - } - } - - /** - * {@link SecureRandomSpi} which passes all requests to the Linux PRNG - * ({@code /dev/urandom}). - */ - public static class LinuxPRNGSecureRandom extends SecureRandomSpi { - - /* - * IMPLEMENTATION NOTE: Requests to generate bytes and to mix in a seed - * are passed through to the Linux PRNG (/dev/urandom). Instances of - * this class seed themselves by mixing in the current time, PID, UID, - * build fingerprint, and hardware serial number (where available) into - * Linux PRNG. - * - * Concurrency: Read requests to the underlying Linux PRNG are - * serialized (on sLock) to ensure that multiple threads do not get - * duplicated PRNG output. - */ - - private static final File URANDOM_FILE = new File("/dev/urandom"); - - private static final Object sLock = new Object(); - - /** - * Input stream for reading from Linux PRNG or {@code null} if not yet - * opened. - */ - @GuardedBy("sLock") - private static DataInputStream sUrandomIn; - - /** - * Output stream for writing to Linux PRNG or {@code null} if not yet - * opened. - */ - @GuardedBy("sLock") - private static OutputStream sUrandomOut; - - /** - * Whether this engine instance has been seeded. This is needed because - * each instance needs to seed itself if the client does not explicitly - * seed it. - */ - private boolean mSeeded; - - @Override - protected void engineSetSeed(byte[] bytes) { - try { - OutputStream out; - synchronized (sLock) { - out = getUrandomOutputStream(); - } - out.write(bytes); - out.flush(); - } catch (IOException e) { - // On a small fraction of devices /dev/urandom is not writable. - // Log and ignore. - Log.w(PRNGFixes.class.getSimpleName(), - "Failed to mix seed into " + URANDOM_FILE); - } finally { - mSeeded = true; - } - } - - @Override - protected void engineNextBytes(byte[] bytes) { - if (!mSeeded) { - // Mix in the device- and invocation-specific seed. - engineSetSeed(generateSeed()); - } - - try { - DataInputStream in; - synchronized (sLock) { - in = getUrandomInputStream(); - } - synchronized (in) { - in.readFully(bytes); - } - } catch (IOException e) { - throw new SecurityException( - "Failed to read from " + URANDOM_FILE, e); - } - } - - @Override - protected byte[] engineGenerateSeed(int size) { - byte[] seed = new byte[size]; - engineNextBytes(seed); - return seed; - } - - private DataInputStream getUrandomInputStream() { - synchronized (sLock) { - if (sUrandomIn == null) { - // NOTE: Consider inserting a BufferedInputStream between - // DataInputStream and FileInputStream if you need higher - // PRNG output performance and can live with future PRNG - // output being pulled into this process prematurely. - try { - sUrandomIn = new DataInputStream( - new FileInputStream(URANDOM_FILE)); - } catch (IOException e) { - throw new SecurityException("Failed to open " - + URANDOM_FILE + " for reading", e); - } - } - return sUrandomIn; - } - } - - private OutputStream getUrandomOutputStream() throws IOException { - synchronized (sLock) { - if (sUrandomOut == null) { - sUrandomOut = new FileOutputStream(URANDOM_FILE); - } - return sUrandomOut; - } - } - } - - /** - * Generates a device- and invocation-specific seed to be mixed into the - * Linux PRNG. - */ - private static byte[] generateSeed() { - try { - ByteArrayOutputStream seedBuffer = new ByteArrayOutputStream(); - DataOutputStream seedBufferOut = - new DataOutputStream(seedBuffer); - seedBufferOut.writeLong(System.currentTimeMillis()); - seedBufferOut.writeLong(System.nanoTime()); - seedBufferOut.writeInt(Process.myPid()); - if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.BASE_1_1) { - seedBufferOut.writeInt(Process.myUid()); - } - seedBufferOut.write(BUILD_FINGERPRINT_AND_DEVICE_SERIAL); - seedBufferOut.close(); - return seedBuffer.toByteArray(); - } catch (IOException e) { - throw new SecurityException("Failed to generate seed", e); - } - } - - /** - * Gets the hardware serial number of this device. - * - * @return serial number or {@code null} if not available. - */ - private static String getDeviceSerialNumber() { - // We're using the Reflection API because Build.SERIAL is only available - // since API Level 9 (Gingerbread, Android 2.3). - try { - return (String) Build.class.getField("SERIAL").get(null); - } catch (Exception ignored) { - return null; - } - } - - private static byte[] getBuildFingerprintAndDeviceSerial() { - StringBuilder result = new StringBuilder(); - String fingerprint = Build.FINGERPRINT; - if (fingerprint != null) { - result.append(fingerprint); - } - String serial = getDeviceSerialNumber(); - if (serial != null) { - result.append(serial); - } - try { - return result.toString().getBytes("UTF-8"); - } catch (UnsupportedEncodingException e) { - throw new RuntimeException("UTF-8 encoding not supported"); - } - } -} \ No newline at end of file diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PairingAuthCtx.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PairingAuthCtx.java index a329c29..412355c 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PairingAuthCtx.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PairingAuthCtx.java @@ -2,11 +2,8 @@ package io.github.muntashirakon.adb; -import android.os.Build; - import androidx.annotation.NonNull; import androidx.annotation.Nullable; -import androidx.annotation.RequiresApi; import androidx.annotation.VisibleForTesting; import org.bouncycastle.crypto.InvalidCipherTextException; @@ -21,6 +18,7 @@ import org.bouncycastle.crypto.params.KeyParameter; import java.nio.ByteBuffer; import java.nio.ByteOrder; +import java.nio.charset.StandardCharsets; import java.util.Arrays; import javax.security.auth.Destroyable; @@ -28,16 +26,18 @@ import javax.security.auth.Destroyable; import io.github.muntashirakon.crypto.spake2.Spake2Context; import io.github.muntashirakon.crypto.spake2.Spake2Role; -@RequiresApi(Build.VERSION_CODES.GINGERBREAD) class PairingAuthCtx implements Destroyable { // The following values are taken from the following source and are subjected to change // https://github.com/aosp-mirror/platform_system_core/blob/android-11.0.0_r1/adb/pairing_auth/pairing_auth.cpp - private static final byte[] CLIENT_NAME = StringCompat.getBytes("adb pair client\u0000", "UTF-8"); - private static final byte[] SERVER_NAME = StringCompat.getBytes("adb pair server\u0000", "UTF-8"); + private static final byte[] CLIENT_NAME = + "adb pair client\u0000".getBytes(StandardCharsets.UTF_8); + private static final byte[] SERVER_NAME = + "adb pair server\u0000".getBytes(StandardCharsets.UTF_8); // The following values are taken from the following source and are subjected to change // https://github.com/aosp-mirror/platform_system_core/blob/android-11.0.0_r1/adb/pairing_auth/aes_128_gcm.cpp - private static final byte[] INFO = StringCompat.getBytes("adb pairing_auth aes-128-gcm key", "UTF-8"); + private static final byte[] INFO = + "adb pairing_auth aes-128-gcm key".getBytes(StandardCharsets.UTF_8); private static final int HKDF_KEY_LENGTH = 128 / 8; public static final int GCM_IV_LENGTH = 12; // in bytes @@ -83,10 +83,14 @@ class PairingAuthCtx implements Destroyable { if (mIsDestroyed) return false; byte[] keyMaterial = mSpake2Ctx.processMessage(theirMsg); if (keyMaterial == null) return false; - HKDFBytesGenerator hkdf = new HKDFBytesGenerator(new SHA256Digest()); - hkdf.init(new HKDFParameters(keyMaterial, null, INFO)); - hkdf.generateBytes(mSecretKey, 0, mSecretKey.length); - return true; + try { + HKDFBytesGenerator hkdf = new HKDFBytesGenerator(new SHA256Digest()); + hkdf.init(new HKDFParameters(keyMaterial, null, INFO)); + hkdf.generateBytes(mSecretKey, 0, mSecretKey.length); + return true; + } finally { + Arrays.fill(keyMaterial, (byte) 0); + } } @Nullable @@ -108,7 +112,9 @@ class PairingAuthCtx implements Destroyable { @Override public void destroy() { + if (mIsDestroyed) return; mIsDestroyed = true; + Arrays.fill(mMsg, (byte) 0); Arrays.fill(mSecretKey, (byte) 0); mSpake2Ctx.destroy(); } diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PairingConnectionCtx.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PairingConnectionCtx.java index 732a08e..b009e66 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PairingConnectionCtx.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/PairingConnectionCtx.java @@ -2,19 +2,18 @@ package io.github.muntashirakon.adb; -import android.annotation.SuppressLint; -import android.os.Build; import android.util.Log; import androidx.annotation.NonNull; import androidx.annotation.Nullable; -import androidx.annotation.RequiresApi; + +import org.conscrypt.Conscrypt; import java.io.Closeable; import java.io.DataInputStream; import java.io.DataOutputStream; import java.io.IOException; -import java.lang.reflect.Method; +import java.net.InetSocketAddress; import java.net.Socket; import java.nio.ByteBuffer; import java.nio.ByteOrder; @@ -28,18 +27,17 @@ import java.util.Arrays; import java.util.Objects; import javax.net.ssl.SSLContext; -import javax.net.ssl.SSLException; -import javax.net.ssl.SSLServerSocket; import javax.net.ssl.SSLSocket; -// https://github.com/aosp-mirror/platform_system_core/blob/android-11.0.0_r1/adb/pairing_connection/pairing_connection.cpp +// AOSP android-11.0.0_r1 adb/pairing_connection/pairing_connection.cpp. // Also based on Shizuku's implementation -@RequiresApi(Build.VERSION_CODES.GINGERBREAD) public final class PairingConnectionCtx implements Closeable { - public static final String TAG = PairingConnectionCtx.class.getSimpleName(); + public static final String TAG = "scrcpy-android"; public static final String EXPORTED_KEY_LABEL = "adb-label\u0000"; public static final int EXPORT_KEY_SIZE = 64; + private static final int CONNECT_TIMEOUT_MS = 10_000; + private static final int IO_TIMEOUT_MS = 15_000; private enum State { Ready, @@ -48,29 +46,29 @@ public final class PairingConnectionCtx implements Closeable { Stopped } - enum Role { - Client, - Server, - } - private final String mHost; private final int mPort; private final byte[] mPswd; private final PeerInfo mPeerInfo; private final SSLContext mSslContext; - private final Role mRole = Role.Client; - private DataInputStream mInputStream; private DataOutputStream mOutputStream; private PairingAuthCtx mPairingAuthCtx; + private Socket mSocket; private State mState = State.Ready; public PairingConnectionCtx(@NonNull String host, int port, @NonNull byte[] pswd, @NonNull KeyPair keyPair, @NonNull String deviceName) throws NoSuchAlgorithmException, KeyManagementException, InvalidKeyException { this.mHost = Objects.requireNonNull(host); + if (host.isEmpty()) throw new IllegalArgumentException("host is empty"); + if (port < 1 || port > 65535) throw new IllegalArgumentException("port is invalid"); + Objects.requireNonNull(pswd); + if (pswd.length == 0 || pswd.length > 1024) { + throw new IllegalArgumentException("password length is invalid"); + } this.mPort = port; - this.mPswd = Objects.requireNonNull(pswd); + this.mPswd = pswd.clone(); this.mPeerInfo = new PeerInfo(PeerInfo.ADB_RSA_PUB_KEY, AndroidPubkey.encodeWithName((RSAPublicKey) keyPair.getPublicKey(), Objects.requireNonNull(deviceName))); this.mSslContext = SslUtils.getSslContext(keyPair); @@ -121,17 +119,19 @@ public final class PairingConnectionCtx implements Closeable { } private void setupTlsConnection() throws IOException { - Socket socket; - if (mRole == Role.Server) { - SSLServerSocket sslServerSocket = (SSLServerSocket) mSslContext.getServerSocketFactory().createServerSocket(mPort); - socket = sslServerSocket.accept(); - // TODO: Write automated test scripts after removing Conscrypt dependency. - } else { // role == Role.Client - socket = new Socket(mHost, mPort); + Socket socket = new Socket(); + try { + socket.connect(new InetSocketAddress(mHost, mPort), CONNECT_TIMEOUT_MS); + socket.setSoTimeout(IO_TIMEOUT_MS); + socket.setTcpNoDelay(true); + } catch (IOException e) { + try { socket.close(); } catch (IOException ignored) {} + throw e; } - socket.setTcpNoDelay(true); + mSocket = socket; - // We use custom SSLContext to allow any SSL certificates + // The PAKE below authenticates the pairing code and binds it to this + // TLS channel through exported key material. SSLSocket sslSocket = (SSLSocket) mSslContext.getSocketFactory().createSocket(socket, mHost, mPort, true); sslSocket.startHandshake(); Log.d(TAG, "Handshake succeeded."); @@ -141,41 +141,22 @@ public final class PairingConnectionCtx implements Closeable { // To ensure the connection is not stolen while we do the PAKE, append the exported key material from the // tls connection to the password. - byte[] keyMaterial = exportKeyingMaterial(sslSocket, EXPORT_KEY_SIZE); + byte[] keyMaterial = Conscrypt.exportKeyingMaterial( + sslSocket, EXPORTED_KEY_LABEL, null, EXPORT_KEY_SIZE); byte[] passwordBytes = new byte[mPswd.length + keyMaterial.length]; - System.arraycopy(mPswd, 0, passwordBytes, 0, mPswd.length); - System.arraycopy(keyMaterial, 0, passwordBytes, mPswd.length, keyMaterial.length); - - PairingAuthCtx pairingAuthCtx = PairingAuthCtx.createAlice(passwordBytes); - if (pairingAuthCtx == null) { - throw new IOException("Unable to create PairingAuthCtx."); - } - this.mPairingAuthCtx = pairingAuthCtx; - } - - @SuppressLint("PrivateApi") // Conscrypt is a stable private API - private byte[] exportKeyingMaterial(SSLSocket sslSocket, int length) throws SSLException { - // Conscrypt#exportKeyingMaterial(SSLSocket socket, String label, byte[] context, int length): byte[] - // throws SSLException + PairingAuthCtx pairingAuthCtx; try { - Class conscryptClass; - if (SslUtils.isCustomConscrypt()) { - conscryptClass = Class.forName("org.conscrypt.Conscrypt"); - } else if (Build.VERSION.SDK_INT < Build.VERSION_CODES.Q) { - // Although support for conscrypt has been added in Android 5.0 (Lollipop), - // TLS1.3 isn't supported until Android 9 (Pie). - throw new SSLException("TLSv1.3 isn't supported on your platform. Use custom Conscrypt library instead."); - } else { - conscryptClass = Class.forName("com.android.org.conscrypt.Conscrypt"); + System.arraycopy(mPswd, 0, passwordBytes, 0, mPswd.length); + System.arraycopy(keyMaterial, 0, passwordBytes, mPswd.length, keyMaterial.length); + pairingAuthCtx = PairingAuthCtx.createAlice(passwordBytes); + if (pairingAuthCtx == null) { + throw new IOException("Unable to create PairingAuthCtx."); } - Method exportKeyingMaterial = conscryptClass.getMethod("exportKeyingMaterial", SSLSocket.class, - String.class, byte[].class, int.class); - return (byte[]) exportKeyingMaterial.invoke(null, sslSocket, EXPORTED_KEY_LABEL, null, length); - } catch (SSLException e) { - throw e; - } catch (Throwable th) { - throw new SSLException(th); + } finally { + Arrays.fill(keyMaterial, (byte) 0); + Arrays.fill(passwordBytes, (byte) 0); } + this.mPairingAuthCtx = pairingAuthCtx; } private void writeHeader(@NonNull PairingPacketHeader header, @NonNull byte[] payload) throws IOException { @@ -269,31 +250,50 @@ public final class PairingConnectionCtx implements Closeable { } PeerInfo theirPeerInfo = PeerInfo.readFrom(ByteBuffer.wrap(decryptedMsg)); - Log.d(TAG, theirPeerInfo.toString()); + Log.d(TAG, "Received peer info type=" + theirPeerInfo.type); + if (theirPeerInfo.type != PeerInfo.ADB_DEVICE_GUID) { + Log.e(TAG, "Pairing peer did not send a device GUID"); + return false; + } + if (theirPeerInfo.data[0] == 0) { + Log.e(TAG, "Pairing peer sent an empty device GUID"); + return false; + } return true; } @Override public void close() { Arrays.fill(mPswd, (byte) 0); - try { - mInputStream.close(); - } catch (IOException ignore) { + if (mInputStream != null) { + try { + mInputStream.close(); + } catch (IOException ignore) { + } } - try { - mOutputStream.close(); - } catch (IOException ignore) { + if (mOutputStream != null) { + try { + mOutputStream.close(); + } catch (IOException ignore) { + } } - if (mState != State.Ready) { + if (mSocket != null) { + try { + mSocket.close(); + } catch (IOException ignore) { + } + } + if (mPairingAuthCtx != null) { mPairingAuthCtx.destroy(); } + mState = State.Stopped; } private static class PeerInfo { public static final int MAX_PEER_INFO_SIZE = 1 << 13; public static final byte ADB_RSA_PUB_KEY = 0; - public static final byte ADB_DEVICE_GUID = 0; + public static final byte ADB_DEVICE_GUID = 1; @NonNull public static PeerInfo readFrom(@NonNull ByteBuffer buffer) { @@ -314,15 +314,6 @@ public final class PairingConnectionCtx implements Closeable { public void writeTo(@NonNull ByteBuffer buffer) { buffer.put(type).put(data); } - - @NonNull - @Override - public String toString() { - return "PeerInfo{" + - "type=" + type + - ", data=" + Arrays.toString(data) + - '}'; - } } private static class PairingPacketHeader { @@ -370,15 +361,5 @@ public final class PairingConnectionCtx implements Closeable { public void writeTo(@NonNull ByteBuffer buffer) { buffer.put(version).put(type).putInt(payloadSize); } - - @NonNull - @Override - public String toString() { - return "PairingPacketHeader{" + - "version=" + version + - ", type=" + type + - ", payloadSize=" + payloadSize + - '}'; - } } } diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/SslUtils.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/SslUtils.java index aea4e6f..0e5db6b 100644 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/SslUtils.java +++ b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/SslUtils.java @@ -2,19 +2,21 @@ package io.github.muntashirakon.adb; -import android.annotation.SuppressLint; -import android.os.Build; - import androidx.annotation.NonNull; +import org.conscrypt.Conscrypt; + +import java.math.BigInteger; import java.net.Socket; import java.security.KeyManagementException; import java.security.NoSuchAlgorithmException; import java.security.Principal; import java.security.PrivateKey; -import java.security.Provider; import java.security.SecureRandom; +import java.security.cert.CertificateException; import java.security.cert.X509Certificate; +import java.security.interfaces.RSAPublicKey; +import java.util.Objects; import javax.net.ssl.KeyManager; import javax.net.ssl.SSLContext; @@ -22,45 +24,25 @@ import javax.net.ssl.X509ExtendedKeyManager; import javax.net.ssl.X509TrustManager; final class SslUtils { - private static boolean customConscrypt = false; - private static SSLContext sslContext; - - public static boolean isCustomConscrypt() { - return customConscrypt; - } + private SslUtils() {} - @SuppressLint("TrulyRandom") // The users are already instructed to fix this issue @NonNull - public static SSLContext getSslContext(KeyPair keyPair) throws NoSuchAlgorithmException, KeyManagementException { - if (sslContext != null) { - return sslContext; - } - try { - Class providerClass = Class.forName("org.conscrypt.OpenSSLProvider"); - Provider openSslProvder = (Provider) providerClass.getDeclaredConstructor().newInstance(); - sslContext = SSLContext.getInstance("TLSv1.3", openSslProvder); - customConscrypt = true; - } catch (NoSuchAlgorithmException e) { - throw e; - } catch (Throwable e) { - if (Build.VERSION.SDK_INT < Build.VERSION_CODES.Q) { - // Custom error message to inform user that they should use custom Conscrypt library. - throw new NoSuchAlgorithmException("TLSv1.3 isn't supported on your platform. Use custom Conscrypt library instead."); - } - sslContext = SSLContext.getInstance("TLSv1.3"); - customConscrypt = false; + static SSLContext getSslContext(KeyPair keyPair) + throws NoSuchAlgorithmException, KeyManagementException { + Objects.requireNonNull(keyPair); + if (!Conscrypt.isAvailable()) { + throw new NoSuchAlgorithmException("bundled Conscrypt is unavailable"); } - System.out.println("Using " + (customConscrypt ? "custom" : "default") + " TLSv1.3 provider..."); - sslContext.init(new KeyManager[]{getKeyManager(keyPair)}, - new X509TrustManager[]{getAllAcceptingTrustManager()}, - new SecureRandom()); - return sslContext; + SSLContext context = SSLContext.getInstance("TLSv1.3", Conscrypt.newProvider()); + context.init(new KeyManager[]{getKeyManager(keyPair)}, + new X509TrustManager[]{getAdbTrustManager()}, new SecureRandom()); + return context; } @NonNull private static KeyManager getKeyManager(KeyPair keyPair) { return new X509ExtendedKeyManager() { - private final String mAlias = "key"; + private static final String ALIAS = "key"; @Override public String[] getClientAliases(String keyType, Principal[] issuers) { @@ -70,7 +52,7 @@ final class SslUtils { @Override public String chooseClientAlias(String[] keyTypes, Principal[] issuers, Socket socket) { for (String keyType : keyTypes) { - if (keyType.equals("RSA")) return mAlias; + if ("RSA".equals(keyType)) return ALIAS; } return null; } @@ -87,32 +69,45 @@ final class SslUtils { @Override public X509Certificate[] getCertificateChain(String alias) { - if (this.mAlias.equals(alias)) { - return new X509Certificate[]{(X509Certificate) keyPair.getCertificate()}; - } - return null; + if (!ALIAS.equals(alias)) return null; + return new X509Certificate[]{(X509Certificate) keyPair.getCertificate()}; } @Override public PrivateKey getPrivateKey(String alias) { - if (this.mAlias.equals(alias)) { - return keyPair.getPrivateKey(); - } - return null; + return ALIAS.equals(alias) ? keyPair.getPrivateKey() : null; } }; } - @SuppressLint("TrustAllX509TrustManager") // Accept all certificates + // ADB does not give the client a stable target certificate to verify. + // The pairing server generates a new key for each pairing operation and + // adbd generates a separate process-scoped key. Pairing authenticates the + // six-digit-code exchange; later TLS connections authenticate this client + // to adbd, but not adbd to this client. Reject malformed certificates and + // keep TLS mandatory without pretending that an ephemeral key is an + // identity pin. @NonNull - private static X509TrustManager getAllAcceptingTrustManager() { + private static X509TrustManager getAdbTrustManager() { return new X509TrustManager() { @Override - public void checkClientTrusted(X509Certificate[] chain, String authType) { + public void checkClientTrusted(X509Certificate[] chain, String authType) + throws CertificateException { + throw new CertificateException("ADB TLS context is client-only"); } @Override - public void checkServerTrusted(X509Certificate[] chain, String authType) { + public void checkServerTrusted(X509Certificate[] chain, String authType) + throws CertificateException { + if (chain == null || chain.length == 0) { + throw new CertificateException("ADB peer presented no certificate"); + } + if (!(chain[0].getPublicKey() instanceof RSAPublicKey key) + || key.getModulus().bitLength() != 2048 + || (!BigInteger.valueOf(3).equals(key.getPublicExponent()) + && !BigInteger.valueOf(65537).equals(key.getPublicExponent()))) { + throw new CertificateException("ADB peer certificate is not RSA-2048"); + } } @Override diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/StringCompat.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/StringCompat.java deleted file mode 100644 index 1e05eee..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/StringCompat.java +++ /dev/null @@ -1,26 +0,0 @@ -// SPDX-License-Identifier: GPL-3.0-or-later OR Apache-2.0 - -package io.github.muntashirakon.adb; - -import android.os.Build; - -import androidx.annotation.NonNull; - -import java.io.UnsupportedEncodingException; -import java.nio.charset.Charset; -import java.nio.charset.IllegalCharsetNameException; - -final class StringCompat { - @NonNull - public static byte[] getBytes(@NonNull String text, @NonNull String charsetName) { - if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.GINGERBREAD) { - return text.getBytes(Charset.forName(charsetName)); - } - try { - return text.getBytes(charsetName); - } catch (UnsupportedEncodingException e) { - throw (IllegalCharsetNameException) new IllegalCharsetNameException("Illegal charset " + charsetName) - .initCause(e); - } - } -} diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/AdbMdns.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/AdbMdns.java deleted file mode 100644 index 6b424cb..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/AdbMdns.java +++ /dev/null @@ -1,193 +0,0 @@ -// SPDX-License-Identifier: GPL-3.0-or-later OR Apache-2.0 - -package io.github.muntashirakon.adb.android; - -import android.content.Context; -import android.net.nsd.NsdManager; -import android.net.nsd.NsdServiceInfo; -import android.os.Build; - -import androidx.annotation.NonNull; -import androidx.annotation.Nullable; -import androidx.annotation.RequiresApi; -import androidx.annotation.StringDef; - -import java.io.IOException; -import java.lang.annotation.Retention; -import java.lang.annotation.RetentionPolicy; -import java.net.InetAddress; -import java.net.InetSocketAddress; -import java.net.NetworkInterface; -import java.net.ServerSocket; -import java.net.SocketException; -import java.util.Collections; -import java.util.Objects; - -/** - * Automatic discovery of ADB daemons. - */ -// Copyright 2020 南宫雪珊 -// Copyright 2022 Muntashir Al-Islam -// Based on https://android.googlesource.com/platform/packages/modules/adb/+/eddd2d3a386a83f5d1e14f87a318adef4c2f1a9d/adb_mdns.cpp -@RequiresApi(Build.VERSION_CODES.JELLY_BEAN) -public class AdbMdns { - public static final String SERVICE_TYPE_ADB = "adb"; - public static final String SERVICE_TYPE_TLS_PAIRING = "adb-tls-pairing"; - public static final String SERVICE_TYPE_TLS_CONNECT = "adb-tls-connect"; - - @StringDef({ - SERVICE_TYPE_ADB, - SERVICE_TYPE_TLS_PAIRING, - SERVICE_TYPE_TLS_CONNECT, - }) - @Retention(RetentionPolicy.SOURCE) - public @interface ServiceType { - } - - public interface OnAdbDaemonDiscoveredListener { - void onPortChanged(@Nullable InetAddress hostAddress, int port); - } - - @NonNull - private final Context mContext; - @NonNull - private final String mServiceType; - @NonNull - private final OnAdbDaemonDiscoveredListener mAdbDaemonDiscoveredListener; - private final NsdManager.DiscoveryListener mDiscoveryListener; - private final NsdManager mNsdManager; - - private boolean mRegistered; - private boolean mRunning; - @Nullable - private String mServiceName; - - public AdbMdns(@NonNull Context context, @ServiceType @NonNull String serviceType, - @NonNull OnAdbDaemonDiscoveredListener portChangeListener) { - mContext = Objects.requireNonNull(context); - mServiceType = String.format("_%s._tcp", Objects.requireNonNull(serviceType)); - mAdbDaemonDiscoveredListener = Objects.requireNonNull(portChangeListener); - mNsdManager = (NsdManager) context.getSystemService(Context.NSD_SERVICE); - mDiscoveryListener = new DiscoveryListener(this); - } - - public void start() { - if (mRunning) return; - mRunning = true; - if (!mRegistered) { - mNsdManager.discoverServices(mServiceType, NsdManager.PROTOCOL_DNS_SD, mDiscoveryListener); - } - } - - public void stop() { - if (!mRunning) return; - mRunning = false; - if (mRegistered) { - mNsdManager.stopServiceDiscovery(mDiscoveryListener); - } - } - - public boolean isRunning() { - return mRunning; - } - - private void onDiscoveryStart() { - mRegistered = true; - } - - private void onDiscoverStop() { - mRegistered = false; - } - - private void onServiceFound(NsdServiceInfo serviceInfo) { - mNsdManager.resolveService(serviceInfo, new ResolveListener(this)); - } - - private void onServiceLost(NsdServiceInfo serviceInfo) { - if (mServiceName != null && mServiceName.equals(serviceInfo.getServiceName())) { - mAdbDaemonDiscoveredListener.onPortChanged(serviceInfo.getHost(), -1); - } - } - - private void onServiceResolved(NsdServiceInfo serviceInfo) { - if (!mRunning) return; - try { - for (NetworkInterface networkInterface : Collections.list(NetworkInterface.getNetworkInterfaces())) { - for (InetAddress inetAddress : Collections.list(networkInterface.getInetAddresses())) { - String inetHost = inetAddress.getHostAddress(); - if (Objects.equals(inetHost, serviceInfo.getHost().getHostAddress()) - && isPortAvailable(serviceInfo.getPort())) { - mServiceName = serviceInfo.getServiceName(); - mAdbDaemonDiscoveredListener.onPortChanged(serviceInfo.getHost(), serviceInfo.getPort()); - } - } - } - } catch (SocketException e) { - e.printStackTrace(); - } - } - - private boolean isPortAvailable(int port) { - try (ServerSocket socket = new ServerSocket()) { - socket.bind(new InetSocketAddress(AndroidUtils.getHostIpAddress(mContext), port), 1); - return false; - } catch (IOException e) { - return true; - } - } - - private static class DiscoveryListener implements NsdManager.DiscoveryListener { - @NonNull - private final AdbMdns mAdbMdns; - - private DiscoveryListener(@NonNull AdbMdns adbMdns) { - mAdbMdns = adbMdns; - } - - @Override - public void onDiscoveryStarted(String serviceType) { - mAdbMdns.onDiscoveryStart(); - } - - @Override - public void onStartDiscoveryFailed(String serviceType, int errorCode) { - } - - @Override - public void onDiscoveryStopped(String serviceType) { - mAdbMdns.onDiscoverStop(); - } - - @Override - public void onStopDiscoveryFailed(String serviceType, int errorCode) { - } - - @Override - public void onServiceFound(NsdServiceInfo serviceInfo) { - mAdbMdns.onServiceFound(serviceInfo); - } - - @Override - public void onServiceLost(NsdServiceInfo serviceInfo) { - mAdbMdns.onServiceLost(serviceInfo); - } - } - - private static class ResolveListener implements NsdManager.ResolveListener { - @NonNull - private final AdbMdns mAdbMdns; - - private ResolveListener(@NonNull AdbMdns adbMdns) { - mAdbMdns = adbMdns; - } - - @Override - public void onResolveFailed(NsdServiceInfo serviceInfo, int errorCode) { - } - - @Override - public void onServiceResolved(NsdServiceInfo serviceInfo) { - mAdbMdns.onServiceResolved(serviceInfo); - } - } -} diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/AndroidUtils.java b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/AndroidUtils.java deleted file mode 100644 index bb679d2..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/AndroidUtils.java +++ /dev/null @@ -1,58 +0,0 @@ -// SPDX-License-Identifier: GPL-3.0-or-later OR Apache-2.0 - -package io.github.muntashirakon.adb.android; - -import android.annotation.SuppressLint; -import android.content.Context; -import android.os.Build; -import android.provider.Settings; - -import androidx.annotation.NonNull; - -import java.net.InetAddress; -import java.net.UnknownHostException; - -public class AndroidUtils { - // https://github.com/firebase/firebase-android-sdk/blob/7d86138304a6573cbe2c61b66b247e930fa05767/firebase-crashlytics/src/main/java/com/google/firebase/crashlytics/internal/common/CommonUtils.java#L402 - private static final String GOLDFISH = "goldfish"; - private static final String RANCHU = "ranchu"; - private static final String SDK = "sdk"; - - public static boolean isEmulator(@NonNull Context context) { - if (Build.PRODUCT.contains(SDK)) { - return true; - } - if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.FROYO - && (Build.HARDWARE.contains(GOLDFISH) || Build.HARDWARE.contains(RANCHU))) { - return true; - } - if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.CUPCAKE) { - @SuppressLint("HardwareIds") - String androidId = Settings.Secure.getString(context.getContentResolver(), Settings.Secure.ANDROID_ID); - return androidId == null; - } - return false; - } - - - @NonNull - public static String getHostIpAddress(@NonNull Context context) { - if (AndroidUtils.isEmulator(context)) { - return "10.0.2.2"; - } - String ipAddress; - if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.KITKAT) { - ipAddress = InetAddress.getLoopbackAddress().getHostAddress(); - } else { - try { - ipAddress = InetAddress.getLocalHost().getHostAddress(); - } catch (UnknownHostException e) { - ipAddress = null; - } - } - if (ipAddress == null || ipAddress.equals("::1")) { - return "127.0.0.1"; - } - return ipAddress; - } -} diff --git a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/package.html b/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/package.html deleted file mode 100644 index 704dd26..0000000 --- a/vendor/libadb-android/libadb/src/main/java/io/github/muntashirakon/adb/android/package.html +++ /dev/null @@ -1 +0,0 @@ -

All Android dependencies are kept under this package for easy reference.

\ No newline at end of file diff --git a/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AdbProtocolTest.java b/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AdbProtocolTest.java new file mode 100644 index 0000000..2471c62 --- /dev/null +++ b/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AdbProtocolTest.java @@ -0,0 +1,113 @@ +// SPDX-License-Identifier: GPL-3.0-or-later OR Apache-2.0 + +package io.github.muntashirakon.adb; + +import static org.junit.Assert.assertArrayEquals; +import static org.junit.Assert.assertEquals; +import static org.junit.Assert.fail; + +import org.junit.Test; + +import java.io.ByteArrayInputStream; +import java.io.IOException; +import java.io.InputStream; +import java.io.StreamCorruptedException; +import java.nio.ByteBuffer; +import java.nio.ByteOrder; +import java.nio.charset.StandardCharsets; + +public class AdbProtocolTest { + + @Test + public void oversizedPayloadIsRejectedBeforeAllocation() throws Exception { + byte[] header = header(AdbProtocol.A_WRTE, 1, 1, + AdbProtocol.MAX_PAYLOAD_V1 + 1, 0); + try { + AdbProtocol.Message.parse(new ByteArrayInputStream(header), + AdbProtocol.A_VERSION_MIN, AdbProtocol.MAX_PAYLOAD_V1); + fail("oversized payload accepted"); + } catch (StreamCorruptedException expected) { + // expected + } + } + + @Test + public void zeroProgressHeaderReadFails() throws Exception { + InputStream input = zeroThen(new byte[AdbProtocol.ADB_HEADER_LENGTH]); + try { + AdbProtocol.Message.parse(input, AdbProtocol.A_VERSION_MIN, + AdbProtocol.MAX_PAYLOAD_V1); + fail("zero-progress input accepted"); + } catch (IOException expected) { + assertEquals("ADB input made no progress", expected.getMessage()); + } + } + + @Test + public void zeroProgressPayloadReadFails() throws Exception { + byte[] packet = AdbProtocol.generateWrite(1, 2, new byte[]{1}, 0, 1); + InputStream input = new InputStream() { + int offset; + @Override public int read() { return -1; } + @Override public int read(byte[] b, int off, int len) { + if (offset < AdbProtocol.ADB_HEADER_LENGTH) { + int n = Math.min(len, AdbProtocol.ADB_HEADER_LENGTH - offset); + System.arraycopy(packet, offset, b, off, n); + offset += n; + return n; + } + return 0; + } + }; + try { + AdbProtocol.Message.parse(input, AdbProtocol.A_VERSION_MIN, + AdbProtocol.MAX_PAYLOAD_V1); + fail("zero-progress payload accepted"); + } catch (IOException expected) { + assertEquals("ADB input made no progress", expected.getMessage()); + } + } + + @Test + public void openUsesUtf8ByteLength() throws Exception { + String destination = "shell:printf caf\u00e9"; + byte[] packet = AdbProtocol.generateOpen(7, destination); + AdbProtocol.Message message = AdbProtocol.Message.parse( + new ByteArrayInputStream(packet), AdbProtocol.A_VERSION_MIN, + AdbProtocol.MAX_PAYLOAD_V1); + byte[] expected = (destination + "\0").getBytes(StandardCharsets.UTF_8); + assertEquals(expected.length, message.dataLength); + assertArrayEquals(expected, message.payload); + } + + @Test(expected = IndexOutOfBoundsException.class) + public void invalidOutgoingRangeIsRejected() { + AdbProtocol.generateWrite(1, 2, new byte[4], 3, 2); + } + + private static byte[] header(int command, int arg0, int arg1, int length, int checksum) { + return ByteBuffer.allocate(AdbProtocol.ADB_HEADER_LENGTH) + .order(ByteOrder.LITTLE_ENDIAN) + .putInt(command).putInt(arg0).putInt(arg1).putInt(length) + .putInt(checksum).putInt(~command).array(); + } + + private static InputStream zeroThen(byte[] data) { + return new InputStream() { + boolean first = true; + int offset; + @Override public int read() { return -1; } + @Override public int read(byte[] b, int off, int len) { + if (first) { + first = false; + return 0; + } + if (offset == data.length) return -1; + int n = Math.min(len, data.length - offset); + System.arraycopy(data, offset, b, off, n); + offset += n; + return n; + } + }; + } +} diff --git a/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AdbStreamTest.java b/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AdbStreamTest.java new file mode 100644 index 0000000..a16cc47 --- /dev/null +++ b/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AdbStreamTest.java @@ -0,0 +1,186 @@ +// SPDX-License-Identifier: GPL-3.0-or-later OR Apache-2.0 + +package io.github.muntashirakon.adb; + +import static org.junit.Assert.assertEquals; +import static org.junit.Assert.assertFalse; +import static org.junit.Assert.assertTrue; +import static org.junit.Assert.fail; + +import org.junit.Test; + +import java.io.IOException; +import java.io.StreamCorruptedException; +import java.nio.ByteBuffer; +import java.nio.ByteOrder; +import java.util.ArrayList; +import java.util.Collections; +import java.util.List; +import java.util.concurrent.CountDownLatch; +import java.util.concurrent.TimeUnit; +import java.util.concurrent.atomic.AtomicReference; + +public class AdbStreamTest { + + private static class RecordingTransport implements AdbStream.Transport { + final int maxData; + final List packets = Collections.synchronizedList(new ArrayList<>()); + RecordingTransport(int maxData) { this.maxData = maxData; } + @Override public int getMaxData() { return maxData; } + @Override public void sendPacket(byte[] packet) throws IOException { packets.add(packet); } + @Override public void flushPacket() {} + } + + private static final class BlockingTransport extends RecordingTransport { + final CountDownLatch writeEntered = new CountDownLatch(1); + final CountDownLatch releaseWrite = new CountDownLatch(1); + + BlockingTransport() { + super(4); + } + + @Override public void sendPacket(byte[] packet) throws IOException { + if (command(packet) == AdbProtocol.A_WRTE) { + writeEntered.countDown(); + try { + if (!releaseWrite.await(1, TimeUnit.SECONDS)) { + throw new IOException("test write release timed out"); + } + } catch (InterruptedException e) { + Thread.currentThread().interrupt(); + throw new IOException(e); + } + } + super.sendPacket(packet); + } + } + + @Test + public void zeroLengthWriteDoesNotConsumeReady() throws Exception { + RecordingTransport transport = new RecordingTransport(4); + AdbStream stream = openStream(transport); + stream.write(new byte[0], 0, 0); + stream.write(new byte[]{7}, 0, 1); + assertEquals(1, transport.packets.size()); + assertEquals(1, payloadLength(transport.packets.get(0))); + } + + @Test + public void eachWritePacketWaitsForOkay() throws Exception { + RecordingTransport transport = new RecordingTransport(4); + AdbStream stream = openStream(transport); + AtomicReference failure = new AtomicReference<>(); + Thread writer = new Thread(() -> { + try { + stream.write(new byte[6], 0, 6); + } catch (Throwable t) { + failure.set(t); + } + }); + writer.start(); + waitForPackets(transport, 1); + assertTrue("writer sent all chunks without a second OKAY", writer.isAlive()); + assertEquals(4, payloadLength(transport.packets.get(0))); + stream.readyForWrite(); + writer.join(1_000); + assertFalse("writer did not finish after second OKAY", writer.isAlive()); + if (failure.get() != null) throw new AssertionError(failure.get()); + assertEquals(2, transport.packets.size()); + assertEquals(2, payloadLength(transport.packets.get(1))); + } + + @Test + public void readAcknowledgesOnlyAfterPacketIsConsumed() throws Exception { + RecordingTransport transport = new RecordingTransport(8); + AdbStream stream = openStream(transport); + transport.packets.clear(); + stream.addPayload(new byte[]{1, 2, 3, 4}); + + byte[] out = new byte[4]; + assertEquals(2, stream.read(out, 0, 2)); + assertEquals(0, transport.packets.size()); + try { + stream.addPayload(new byte[]{5}); + fail("peer bypassed ADB flow control"); + } catch (StreamCorruptedException expected) { + // expected + } + assertEquals(2, stream.read(out, 2, 2)); + assertEquals(1, transport.packets.size()); + assertEquals(AdbProtocol.A_OKAY, command(transport.packets.get(0))); + } + + @Test + public void remoteCloseDrainsBufferedPayload() throws Exception { + RecordingTransport transport = new RecordingTransport(8); + AdbStream stream = openStream(transport); + transport.packets.clear(); + stream.addPayload(new byte[]{1, 2, 3, 4}); + byte[] out = new byte[4]; + assertEquals(2, stream.read(out, 0, 2)); + stream.notifyClose(true); + assertEquals(2, stream.read(out, 2, 2)); + assertEquals(-1, stream.read(out, 0, out.length)); + assertEquals("CLSE must not be answered with OKAY", 0, transport.packets.size()); + } + + @Test + public void closeCannotPassAnInFlightWrite() throws Exception { + BlockingTransport transport = new BlockingTransport(); + AdbStream stream = openStream(transport); + AtomicReference failure = new AtomicReference<>(); + Thread writer = new Thread(() -> { + try { + stream.write(new byte[]{1}, 0, 1); + } catch (Throwable t) { + failure.compareAndSet(null, t); + } + }); + Thread closer = new Thread(() -> { + try { + stream.close(); + } catch (Throwable t) { + failure.compareAndSet(null, t); + } + }); + + writer.start(); + assertTrue(transport.writeEntered.await(1, TimeUnit.SECONDS)); + closer.start(); + assertTrue("close passed blocked WRTE", closer.isAlive()); + transport.releaseWrite.countDown(); + writer.join(1_000); + closer.join(1_000); + + assertFalse(writer.isAlive()); + assertFalse(closer.isAlive()); + if (failure.get() != null) throw new AssertionError(failure.get()); + assertEquals(2, transport.packets.size()); + assertEquals(AdbProtocol.A_WRTE, command(transport.packets.get(0))); + assertEquals(AdbProtocol.A_CLSE, command(transport.packets.get(1))); + } + + private static AdbStream openStream(RecordingTransport transport) throws Exception { + AdbStream stream = new AdbStream(transport, 1); + stream.updateRemoteId(2); + stream.readyForWrite(); + return stream; + } + + private static int command(byte[] packet) { + return ByteBuffer.wrap(packet).order(ByteOrder.LITTLE_ENDIAN).getInt(); + } + + private static int payloadLength(byte[] packet) { + return ByteBuffer.wrap(packet).order(ByteOrder.LITTLE_ENDIAN).getInt(12); + } + + private static void waitForPackets(RecordingTransport transport, int count) + throws InterruptedException { + long deadline = System.nanoTime() + 1_000_000_000L; + while (transport.packets.size() < count && System.nanoTime() < deadline) { + Thread.sleep(1); + } + assertEquals(count, transport.packets.size()); + } +} diff --git a/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AndroidPubkeyTest.java b/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AndroidPubkeyTest.java index 261edac..ffeceeb 100644 --- a/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AndroidPubkeyTest.java +++ b/vendor/libadb-android/libadb/src/test/java/io/github/muntashirakon/adb/AndroidPubkeyTest.java @@ -2,117 +2,83 @@ package io.github.muntashirakon.adb; -import org.bouncycastle.util.encoders.Base64; -import org.junit.Before; +import static org.junit.Assert.assertArrayEquals; +import static org.junit.Assert.assertEquals; +import static org.junit.Assert.assertThrows; + +import org.junit.BeforeClass; import org.junit.Test; import java.math.BigInteger; +import java.nio.ByteBuffer; +import java.nio.ByteOrder; +import java.nio.charset.StandardCharsets; import java.security.InvalidKeyException; -import java.security.NoSuchAlgorithmException; -import java.security.Signature; -import java.security.SignatureException; +import java.security.KeyFactory; +import java.security.KeyPair; +import java.security.KeyPairGenerator; import java.security.interfaces.RSAPublicKey; -import java.security.spec.InvalidKeySpecException; - -import static io.github.muntashirakon.adb.AndroidPubkey.ANDROID_PUBKEY_ENCODED_SIZE; -import static org.junit.Assert.assertArrayEquals; -import static org.junit.Assert.assertEquals; -import static org.junit.Assert.assertTrue; +import java.security.spec.RSAPublicKeySpec; +import java.util.Arrays; +import java.util.Base64; public class AndroidPubkeyTest { - private static final byte[] DIGEST = { - 0x31, 0x5f, 0x5b, (byte) 0xdb, 0x76, (byte) 0xd0, 0x78, (byte) 0xc4, 0x3b, (byte) 0x8a, (byte) 0xc0, - 0x06, 0x4e, 0x4a, 0x01, 0x64, 0x61, 0x2b, 0x1f, (byte) 0xce, 0x77, (byte) 0xc8, - 0x69, 0x34, 0x5b, (byte) 0xfc, (byte) 0x94, (byte) 0xc7, 0x58, (byte) 0x94, (byte) 0xed, (byte) 0xd3, - }; + private static RSAPublicKey publicKey; + + @BeforeClass + public static void generateKey() throws Exception { + KeyPairGenerator generator = KeyPairGenerator.getInstance("RSA"); + generator.initialize(2048); + KeyPair pair = generator.generateKeyPair(); + publicKey = (RSAPublicKey) pair.getPublic(); + } - private static final String[] KEYS = new String[] { - "20686253007643618731996444194404343867753606615063450617882673005393433941259733754887313620913867473991126076227684529071148116710971688307399269161393680066708223500416626973582453156074796463551655506880263757530692111705709492670974173865966567229986684076018218836054376260921024258822748029571012424062161309155451659011612585496480130049086533401220131725127467783734498206350584978609270260042864036755332689164701948323567009422782353582299103998793983781904622199786127904484293079447215050401933233201140660611995982950449318766441491470794461010754367235997277784582260919909111021889463573881293340673638258140979906632549357292907467007755298711750754693102503358563113321739768558800007075371722687735888311697725543005911629713945900921982291726988822299885412290333597947505237030964811359845572308590371290828162825800693816284267659154250460946638141531109051703958714241913036543711553816745407369784077289292046547482798618404863636910359464490602947766408857942988353632212055739706153132169632236839182513092231542800002960492871433639429992495815686493836203332828415821398124085709593551180637824827628263278195555177924931666478926276783820224389307415162160245683448074970045831874158357509710640316611667245663639463489328681291088128", - "20686253017157961681070131581867072824582833493615686581285202812978323130952408474782337908483014193592959801158288937338861941384391935424181886115887706116180211910326203195827988548568848400075560545658694754072288281934799100824960003665469676627306218542649151650279594335310005774745074102233566034401681058875954456976451246992673780060830565203755535989743862421541016487655599803066890290569271073410408457924901854658523004566584730402488976324736395344746149490673499453625232592526755899773745566599094231998380788633185151420348626744906833795805930985207848484533950617753433631247755579325235753032891647748010767177734536686383017861046451119520379951845678816861944386294035286574657104145896837994175074910881605806540878194352563352369751154950231748036893872855863146059482454816118277619882879924798566063675418426269661488345544005535393697052314311247263890598514707311723166476167962362723441242864747039873917888833291982018201334656703016344691467362831812856230943332947764107530472082685276225170871545829843748520918630697076657160036883930216256677113853170428981812392602195530517909206428574912517211805856768824444514391062511206137932417723915871095033856634183547083377240616484404928845477796622124210865489291636384376815872", - "20686253012016661596297187165295953810124840916410787780259125355974730724901079696472630368937851048257090320232652157100991308376039941481829068380105246658346925724672501337521327139011807932361821638555679532028068537874220234967686261347630150684757119393835764732734869517200772690364990583127671131537583714931243019173197423018607993303448083354399470192423616983206536107095715775647406269008431508946794838483788727203899942491271993309634327951609153908662621681729016801610515674359693917283475097384354342498810325041161909134028476434295385254073752420814778998269287749533881374904934126049438895801381045118590479396113271334390254276279559056023087328573647647215037607856427456918131285395255693120064580259556735556512377323876432429678739578757363573131334912599024688462135510569451655007983978712803921393726583392694890019375462303417604382964474778937531805444153682154861176782819373335110870826625829171651646773939431655533573703527937698849234129612444879578476798107659804571742743573317338460943463599693739087545180845307099319818906850017269705411337110447078163740825844263091960377332261204721538817750302929778362322626050195563553439929517852576974112801805532465084720065825179978157459297137449086759181900619029928059339008", - "20686253007164298102187579022292645782622950267376457918101697669358007301488761837295142744126519186355305488389221986154518328646591249427359811715893827299671450881507028164629286041250862175310771677831707558127385367785197803483575096787182004608184320944234595728063837868041235349956855438493602107933402900375680275580658634153323631657275297128293064166637994755918951415154912946597772260559048829851194391800720841779417294685741008056484437199267285946970880090812268047882017049497063496655486104722944355404468824860822958344153152666873208144779124031791189998000506056940151806004196000409215856732235270100083588540707679527939391873638758465419555753702157561970233144942307459852882991188472466621152506161477788274973160814417916904823923993324434775898693916605927490225550209649971721585529738473244554435841443463085919856039187050589485138795602302083255665055214846777613999233572727226441658259782563053572457091354281339853515214717324207788284184709742610276702868576013972404040386528578798398612655692848123956484300353770097737367273673338660759524265042605762204830694090505973135478745543215676846804149964034093456987246386704478034104616628251724608616498482846759154973645939865112578396682953063481438609050519636632406065408", - "20686253013631672077140860925430431681294767795873158523291037328668344494856968639956583809600800609243074268151952075506986744112173705954028708402476984870394191960873402354883924141967550191866699568842907604201375691789447875717904606519911990426542474202257873447575301056799275687300162520647747107269726474224871972583841770132600021392824170364479997596039740110453703092023353509635466916728572484548240377314945387893669640571134322168573530937553272534344026352868086607470719702834083444892288110107409203387500645304783564563250097472203694663921776055854765509655453678476671839476460047809572066383800073578102412448677588127686456580476332728179819886722353651757881477563060082645588924556499391555273484226830089405923826482032061727033691299171028963180078332147031372667760359558227049050997025606644301016548127476540817805335115255877601761512137427173611440130583277311855464175578764391247410560993954608789331880719073041849580910172771756479685430766451208229539612899065008167414362054168182076054905614418672686595489698195205424496943265168367449853961685536803353605862503830213266961051166928463688349071936538327772591282503905358730343548547940428875061176999789174879128250317383032697059739647594262479435287070553934024147200", - "20686253009137100677580536481772220019834185053674835675104805567705108100012120793382980473459675176967509777404926949610065001902175161695962003614967789069678586166752499518706455413722715678873250863436364658098942388406798677103189295795606470644008251449037179794502035845361840650187691172794383123040477163218916023150334807750836446866590977919532470017535348573419966872388934361829146368421225272657444717715086585757479506344335650280743058062849751597138313964046571213056448713724664410661632559255622391230727347897637119451531510420187884140761879388980580251574156491409434892603700316490405451728370661830847139541500680542314851537865497120978838526245028564455048339534705369938676962653936571813488824888264746297425445127522661324094850525422265769467214262342247384649233154604849204645241734493281272153516726661106475381716751539505876924878328383153759965309983960685978480476384651288642156631803739479287061925347068044278079778523599362177880625669615321469494541417207707795112792614703988712865352607326208856280054996813476487679520479619834119561518751799862129372840860158171276154958342280155058027979175914132253409673754984859885834350221155842157851019202903208837729538330893332631827655821675906374426442436139049029730560", - "20686253016517652578576226218037280304512998878967782081643030383762252648179296997011341926638803523834137938978407145354361840964277764429298580433833879753046327333287664442011756674514375099551151016760768951640623954608522240638785781825523830834849040469461889966736539399995075932019080426966535734677817177333374424187501199788948653236985818361084089703379091583995023155469499841274582203201561305334645372332402890018547968670807123139871175453983341212876440749594027233646858105401856148507349000386220939016569850622488928617382330345394648656509732599042249901506581310905883901959534984505897371121911753593182717796270161120916944128299041339386928147022131549318082428289605796149115464012497661997457808599992494790605129095762340900378198216634471902525669353909170959057894014738736417606036662468401786737193290238560507341770145447091177773612273526207707414967862580865925752359713241893890750323872352660127060159105979208005350694984418621693785977972962175850201555015110758212910334258690225997862373112062500145196188829278217998167244761059788293227986694796302184050693617864339940026112434075085598165880397454033611127221858601971082649842623914964304450321042940327685124173187185970331014916661615200988009485722532416914981120", - "20686253011995955629076325009649943801969349915799396834999938713706577453135666219827378331078791305568238767012603523685969479718725348248703275237034007216573140943056580311779171211523596323125369774697691841627573832408640321451759775024971845341190607371902257208390902094844221754727824487661732047560640579666147972731827393052406954025855636608759486135987631984582660021446965995410633211966029298815507401281475655895406689670177716825267171265721675030636564325187593177345954853929509007143136312590872799900706331444637303395615294877562776780224309357978460277807368192971699424316405430599226137562559166681593644350393134128404993203172540565405337112770214130741644001329050834501676799331704650166273747915134031416224513404401863940821611218604578118152404764705070475345051218888969396184751106112136786410948127273335981631264270134095884196287017029694382607779915472082121808328197672918175667411956374486872625493883365083931491511971634291156868483178497893682614629335075497305499292286022408321989969349011048118695523910315223143950295729792988112393289748804875597785632720969020601590483488192942403773245914283442681067607851920760864623779136461182039085569209069946423436337464957827499602113031939666405499335195577103935340800", - "20686253012905249420753123641394125581338490431246330974155061264735030723090537231131634982701543430151111947340098713400919665484501369074291449678715950324404084971416405468246859755401939519930479946881325066315343108805200689731279192503717023845106229875664749782703938485867918135872531314893451199777947488701264763722901060781624134818284452130770584902522697944415430677834037635796007590708428660357263597678671576847673995935030932886476827700205482688638424266106169588048237006500162050678096674641748475495896688241776715995439349517453160862577278522303148756730047750797909055062592477399585648804967165274624689461786686029846025735530763855449050156214748263389735761523970386426501083016336782069534800132132814441821194458883018197602204145921510758387553720734875367542620886529149295030141428678136073816645318546217907182935719212846985527885268490931042846941843895577575986868990275246964000930910996610476509616118972208655613370459666905798364207165929375677455372211850892032163428761255574831943581170173798962498310302619079810560252634395602186653677496588976269539691991643655645015285991996519815871201426765673211289585535433601874045698363351158020555486412212492888981581014428858434326634365544072244470887968780251830419712", - "20686253012482713944170510486006503495965426418624979215207888186336584311563125668176618892341461495958989530109497058836208707044168245279695940788984032479278397649608713044920405685548592937000089068732569152566103178304391968262275366634982743672579525342222333315935193825742608586653438687027252465742150192128141744663537027469859051411958033527779975309458836521627355592244019941914250716050720601976679339560457780808022948385738031590113665471354096086486875697653599495164469297979201195396357751415927806268197841979271997133417306549038027016271542831330284708665839765584145061136794149016409901583479427347126229617073748763355410944442711689578134558428523469322867841307165512505150561440558923516413487943512575228004609949233825559134736566257971598139983362643764003946061810478982678081113673133692828469537444314163454166205388851192666274080898281014667651235171324569407150427688362370268502748192144621240298284168580601438138025554803091157078261255439130748192811252524386962992249383432688422311292315445533782932932345446806388697895661377268890467142415746788623768632474596533761037877631922147784592888033960567149861018268485072235834034618474495971824025999049529331906554158125086921199432771280915863695896037886622831739136", - "20686253017596800673636777315187534270021266420333274774530680374903816600749071306262945801692120725976064051984138994058746162072937121793853747964627815552811045393684927849560459595356986505364881801969476935753890194193700810599429133930398705250755254836009280177917842707354484199908531777573893797187673907712955690758349411755815598103902935655017090298516565740392457105436565547185001255070561133895788176000782782281412093088710504721088727045238362229707513145743387163755472103144359822049806563915934557475036319622688517527471037575232699010534869068383647539493972360025529780544812641848222048512592585298352948703198597172454291713942776468719578698387846171669051363353131159533380505301214164797646016372174811126560901763198906646299690775898549445445030438862050154367175654798908548309949046431701706518418835907611144671153892500148829267345643289528684512615681494813120785604119244868024564867462454807660897301092541915645564379781995052629376347977326432306238090292830317108743463398855319724461757906202501054760315093634564844367373695116166888912389471388175972952318344253589126281155102370809690828946212895190035082791906579557462335096539646297577735157137081490920968937162188359746613039900117481527765337456961996600639744", - "20686253021670819484641397455235988893189004357659986764689257803151409177614461364649970433006714126825319428176308950177181495096102292376641455488005607469636772210940591752734984815566464618433768320892209283008301650256134897180639126904431683668620836360770522622987413924299753298563911962706925772038987129402614215060442406183258855362002322270760435388491304782642695492897104954057313819686015892539037035024067606433686326406317580126032026561653107203711784714174553258867988922391584823277517348441610017887616725654033103467290522569906901516453939475371008093949281078143911461551090436073001946185740446013553585657161583955882953841177944465026376300855580949947151004864741065528954219420584830087663819106583270144309975996802314686009200802567965571029611087066652726123514794266804514760076981917095632831537957124002094177446121777714425501240501887464206036422959211832442482836841510124546833303416051006026030814775613976153585582885196096288806254708297796542938960077290086802302255719602193211623734787514863004972159363553648873516823809184020531994302661726715338441496144201492168521781315979852201195520642908900413827363866480500192561642524090584879553530477247358859671792789145550860764422409857398848511879706827894470738176", - "20686253007779418538146435611960103480111665071547886109640735401007273574064776615540701179896428377142052442567006099697162043246765708980976145988576633992791951978052644497415923662944617922884643981724695008383893280530637173581248946990739081903596261263913018197718895124329861431222284653233340024925156526473018621659579602661924631346612848404894851502528305401866261493226279256928046285934986381048052034850172444367408714525087992488005859355731486073285673373650699722735519641713322832229543168311432490222848569998028342925773025050691460124263527225809542829858215777298289860007795297848906118975152353977610454216097635614989263760656961019437297514661609993804271689676470502860376666591936653476564447284287948444996394814992534945211106658510902269472032893555816145339327183535542766040947125922850444024392962311389749647694036921114853739217072675694979896955780825486065012334086560739968331771161859717998929049806691359069902247801751447279973168812586166245092210343145733018596567430818598988422806423359671179738425327829924055793651209866185908863272645671672053161275134558190614726280574493595200071091284480123481958235975875823917688354274132904898857900963754501168982796149653431776796588769427548375743948019813104125739264", - "20686253007604876142864868042280524165402934179882610914697720762337073476216917389996124773136098970057364791099676488858171958566606397819353213332750920419342798801931043028447913975575839783079948872757605203684602892225855510703027538051098416020818203339920511893350539925823111193247570595010592164929661686244708062422421354240082899804498188803419141823510080225562148441961167143787065210061597742895645200944179873692681009532549500390826790962525777523907581122863044028963918723919775810059776782603566022001398041618219382359180430108215466147420894596600846280899658544993640061836655948799058416531930107797645597300743718230009291894571536654250713613225292199432580280761478601571747214473410393967212703089811962847476443829426705969655282817199293842112005075777464459419904700085996691611909093195963267420749267548377551222829489604133422219862110546274841495019087571956520965526972054781444561101065107965888687457231748284726446965643182772550915093919251096627310403665749159263278352617835127791887411059400056120654704697281677759462412423949563123799300922337337031434011248992699167653294572541741943792138821657961461481276538506021735660790599721725446180641231442745067805783335704101764512016456627263309212202141050291403882752", - "20686253007021608241689663659963106759118723298198840826493322751986448442693666027764988836450224647331743582291670090917210382327270531482163927227988223092974790331550687752773643667187876554181907548400902488924327949585152208488928230350565913895512207957249179245514039152326127203620938403901730645311641228704710362766137452100607502345181504058992226565546374405238584328644321921093037858527565125084661975400406032983072371091348426803460064043823708388520703550652014817583643133020229845020242944346824617584906011027684828450454972028242671768211013258545366598182329727396593002246615440504964904310838157610000834126195478113929502258505249404659889702740225008795785252745301900749237920017295319107372211580703483426556992675462580169514689033492702354908848878614127325367288349925054680142050382109615731173807465659057525671650993994596156034190434249834629081700288210478883667431390577000482807339023985920513954187158118910393481098591489866417654826052352494975210865965568210016302565250763960252121003586393653990260068738875254130452064019745948999144292814505789232823453267156783611177723108336077508126670001743428554516943943698961609321446420452826416665860184743437533100494614025619487465731926709595422582461864066896099279104", - "20686253017576328604397757628696916976575522581262455658158084545267679494101813744271361066833895727275999990362314163487589781714736086134535643149499659121815284171966664818069832388563106430729424843320170501399681992962816815405466327181883993596336326588913980995040153015039842498603793624311027080239766082382138185011127721145696561736552179519972972189860686192212873871541534333569298609110022068676249161087325016973188219381193106238748350352370017704856280849939084182123474167745313719296726857149643911426423892259144920430332447233445727394410596908871121943691683251347594543016832133353836309946329620336278195398229250583694331105065483574747460477844028959296763798522682650225035915279057821815082477316716472233093622430236186011224736996806782238285457943841178908716320629716681607442109914452439698030106201073955996654282803838012221802786122722463668921800632723654622027772616422218197375832565654227089919843040086396119306096757556190008760084017430688032081654953292207865443621116020116320243741976393955557450724420382106551748948637361361237424102598662130622446951212397620681130020351934387640468968673784832844072192051121879959906157803839174272822858710610565971349380572855080734703266039110827437002755727257645879394560", - "20686253015632194446964549752865306095675796992984280836459827244594988985728341929467828908174136317388413601759640625700697567744571888535192920357933899911995149737015137803918541787810386447480938150007979984323709223630514858926018913313903533635089468154621298339064447275675686499058206570127524798025633713627136893628055375633970109073821185460898039856680258335615963791682491988980277498832573429849348764105832237085843498643498195695163785310161310344120423648634988353729865581801558283805742288660458122510719188397548085580202887930607910533534516693933657267260780859925051022338611693920561790642016487656354781128170103744324893680564297782645461578140938361264816397758641997289612268599215669012143301913510494792757326575404821915282598318350394530566425173158364070432671579795603645149354325381596532039075427958043639242360621114659751231872073036120732181043105972973109788769983560711082730917065413254697951492111991932795350395291042777547404358191506284743875086602012076691203993957228415814341341317076567346863011063363884150995846166969589047317632929392743149362575140604429955129918452363340274074095953595228692113309367060073180152866610193934981631436082786314283160713802768267996895973676591655886961137949790395651064064", - "20686253008280076434063627792976585679258240901117771774848183680897991358808598372294247945349776781930725891159660642772324594460473591428092423907922733507827637130679002417108815594381100952950780741331843640801790721759935458380251498677194095462459535511544103447989319232932465020496572704531324890159727609395394440487675667733293698176844674240132373049476798001543842889891227651621801389443373039936389118507727414268889974019400734622787942381724850321036295849698333470872363731655908573604683885345765197680079122655638597424255830729241057473120238971524652052886581049260033714044170704671920548231649930751117900234527322744641536960791319040850129139290431448454658633022000433479483039128614980515014378005152986215764207972187867609137628051392176711451953239313092106278507175222152806081191880959633861865125667318317791167731714976299042173744637249086661016974783212613211649879521639713884566600223256092655930849081112415596892313717463722708665626233145587935660772625224236074541613317671527221358656944545879413948646453563296121659821042385880073296612404056486812912561838422746761742255638925665021058593318024264673057295116442867443437729038595456425369615349800800527803917805871133175616209136030135179809038417225106990301440", - "20686253024951658247963784256461033211161677366121981865435929241662537577939141826066423582382620272467025896961525533649529834951928815732696192031254242001310976196395313722735262686979806326419012885189967369774411212706004362512392149609842235706677304433133443952583032520610040362070455319152450494660815670160633796512952042902222316108338953442388922875611033294149441219453308994445197831263244239682760264737410367007220572112879442727200430192143800723337291968248880476611034380579121992553429999072019510264034072224367169076681647830266796198698184376443826044285160611787998026826563875013778342721603031807058331671932037301518976354062079082150728323092697138014541325857426045339923252246197903880065058351701199295574478678901159403090260453086693563410504667697340773698567005624143430980337698805702319491020156284314353992648718466728823214596123324888480179957675142649621354384527020551369805874882218433548180164260225089194029633825464003674135793863996433213944915953458051073341886199898474985986664620533716615542750212008869522238677744797202727258018045172140382145668069884754503189079041670422324774317816739968675502203964561699314302235308312748370659797007514871638586017968916729509284382607208921962626655481606857704866048", - "20686253015329051263633614301062841926780457793244333362445652976039258394085904409997569212036513569627020122416105184089156035648212037623378445311136404144169674742143343217136229368645245696403751711017904206141255246181738620208604563131352355142398183885029711993169895631312556797474335190203415666424731815815318567886625912492670817003495147968334343459502296653971351530810954197377406607923523701655523747303747572405902504136614192793569878303382172717914572317866962252666818690300625318696007782616025654101394182820792992039050797265658839910245551706198215350312385971886655288470117569599164586651540666084220530837687983855363703457438523945771377188384096611403701921732343378131772105605616111230060395767250296130321274230574922212950953525510434760474902956273375775869424140206127230345610638214846167903417131896656272090379493970136500706006844054279981738876197283239177788834113814444218385342970502089028750415245685729607184037765166339498069290010361131234888359345071611741250271620624165209355771772144843622884733754033577735187746521804131583913214093166309888724137377435858133185966519694264750031605141214041348529307409532348278522558737337691108243193690034235284716283236278857093221201219489501714217369972614111881593088", - }; - private static final String[] SIGNATURES = new String[] { - "8528503594670204436052357015928862792506358113369106777406225289021120755325204284915095461436534593726527514965930392069276752206673637292335104066658988404928981760593418142871524780306395774215697719603009673950459832507052700686367128506073190142373812763000304886902929199810111204681208295515597746727406521222365667866848729045254159801613868059972975579907523041955922782192361370263034597048555422592874100353115430271270939317456318510451811646267157137577724074073241955677595103004166831493027134464898153615411682508571271524917051485420113620183698439910489332188676948813054298376589190870205376721722", - "12714752653171379071902223518900086455469254778099176783756546057501252740388760646633111438554988457804110827172122185741643374376377476845818226306550070549540100924375173033053872725592206270543865057909506204686416217217175205975936864769675359443835464932866652953564668335772839380415278907842078521565813907913565738769303530371937587632865012931316702492771417680964122472313546679654313803229834342261250191743408149738051095079442654981806457495648490488615580878652623030639431127849097089635678230782461813874847730298433045763073635235796063186457060470168072867337516295219377274643254214166187741928195", - "13908999250565370485651189816621604309406838390888107327583648160922258563174890896666525571590573441122409145906761904814530942061844184451657972503856070661891327123507140696829535452282425270195643203742925435202847440053652045520143275171734902378485911971935113470515174453988792439225620093679659059409128896537294846575246782278559049832955440237015381818190544157681329515828756452798679892374749946754033759443639475313334060671371142984239868008118691626803951984815668325843801784709432199331447858105577423245817671538352849819889855177911611607915665983585833151320422174088007859931381348016319265461694", - "10663928803538142495874798753524371044109713444112476166920999738661408452717517594386747916849812868865845184227592286809206405151706316864404978033443369238163211298053129657897912511475878426734168668138448142684774180483848489762892194047712675443661602073836529221861198253894032646440612405989149292046072809162239075060183622012102135247005904791258725387249405763973030121585327387996523577075440922630211242753391888083653575027601995970547566022378966563679332453413606097684906558136475009659092263370997631008298982911150670427099551097448345541506637646597809408731612314781030427962298783217248914223806", - "2306715670154317872337078201496706067018016875073166641656805679181208518844313408613041429049277142712575268846333720788389889629069536193483907615434194600534988985015385608627085443890672124721486043133411014103460576453162713180941943637321699804181949641374502608547423908202551134802437475178385172142729079080049166263881079442027408091314096230581266354997604485294706409288693050419576182967429750806152579311940537301588263217818952406077159490924792302551188620989397020490518323111334752644091498632583425115828895844183618266417719447627326662269293970039782216019092059851746977085656284304341508057993", - "4659358238164596158948789743224240069711265838365302036573085292613329291682190238495190399519475812546652724862729777463345410534406299261146698284440785385833664987236353362536409224868061055771434659441519724477807214986173373107393432602854768393738777892796122503107069552589289874263521713955968508746406485296523435090470754765084421945615052354670619502660960366860227870952975168583254800217898305238191480303688181715819411899720342242163096384819366364486118817498794842558871973328704472113837172120537734616429530518033340109825721160272151409573547421252939751876457633571421692240302001467345028442601", - "4049477946498817875644423736582614129429104652925293903578491350187944109357140281079215461385310310227699148230226103813511093858314731577806298771933039828435988536582683795573155489962134767330360695808904080698959547160137535666545619466761042007784679323603927971926202759931895569401425552243257170909460081819203771507281795697451004296311404365704082156689073796657538886169509765942854790434677625126588993604623270447590077611239790400219558927531394967281599304514894414627660359455930701315462448554588404533268609540765516347343066315049932609011242206592126920115645749055638930724732121135122116141166", - "-15821074705595424775489985353461364659530670829708431022534131332700730014024858879661015439321392526031983716218847190089100850526695320564737549648506802838787532008475561270345163817098663400387502475397954072183343244145179711236049401253605959260401466676172293703977395461139502392520912345905534309764600115973777897708515531741002585035454835142666002006897210376288419070871163424306698312361191916347081600355010527694492360779722717717750770230108246572032092508371533877677011198486557314243866055301211143049322569030292978261520962920278653892612567676627225563117772597001334618978059073836056716669225", - "-3253944899977321876942783783337240903554123129096642235321635334925673112914508303442241100990114967311556077951307727781710343006400897352395067739623245112414217140757020483043902863652615234151122932808390646136142553799710067271445726854624819815642073592109754781288339958163810012173119634614599349819358363736874502076277367766337257137053470157924537552941473944009380652976471624978609651165801832875705879218057300556705292310854083054205343202526672473020368237867322973861758935442876895613369159646304355164238984667221571500917386264593984463607981687284420899772355044207890979293151892151717827509819", - "9499141240577043451589632252552399646757731315654129758760015349045571672430739028949896539759619921365912271793699639488523910752170974284878504952562109143512853537668435378131893436415070630973505762192641967189753052893201272349296728232365714025670987726850356205941217266924338273790152610590219162996666427392130736201968771225650743588893284231594006554226911151399044815787836234434162548055950690340366254107040568369155820242765188526434944719636880243193487042089094702078107054425645211148742327810444676596010608038011230808463633129576609253919361989917628880939682855954355300546341301909315104641292", - "2785829464159962785792464154214301170737801888846376572507071703868621757492888529934734721293299181626548638776917276845515937348930186241646686214395195802058604838439131193816292088810714374344194956806787815938869239553710725569223765884297868657637234129941827347968009169909865231403471928705479925843478070964175560548021424092972184851431376822977172730546215170545593072337665216944481311725273881895390870402865177526671062318915225337990250246626982564561668482752340309344623795724163702528068799345034816267947632414651344549931495044609876171529597903856776762161922406306755255424075670945233876468235", - "9693399573277126168117955145498856804911026370939734084616110928720966781810687706982467213763886301391323622148228097849029578280382356919106089289850794524605638208088414420886934380985144626389853251740087295754111363849778298354982244500232225340060817412736334732343104887783650252691586118114592726131559322014895783483438914376642606356658629244848851203222766693264106049037206515886724418160132270092812177670695280590828717742154134306911500638045109639882998686085462128237114003344000744142984004964727666767343836058943694299268149858387245532882552313792450703351859102940672866025492125862734810702868", - "2588026480762077299880435211630462130829042494172803139844752929165151314366576349692479708707902818325002447901174618910914735813021836209789642281992964413385413651230009333804422618970344994918374367306597128918353293939655079898804834272495466247472976936750289217893184038643984663442084787174472727556425006629985118671735361758704886890235923409705820370265894413685399080693702003337025366946813158285546498272869112876242928634530360165484359119404508056677189703714418493887546407516490045931543871651300601164453872612008839158278878642833640818155397129455955015836831802614094386547616288007668519396656", - "-11728748857916220938525563370642851174888323460551443012033711709118634455694860641893644284241538905301760022334170567702665954472646365780973999849934512640749241332019089471035867766088117990425231025030842560049003944730933840471815845647939175446669519176892871100667327144122288934729242175451319185176733723593770503584081246166626636645030357166311144861050296775574567995193508629237812544699293985433002148216129743645932049717574867996068064127541167278296952065930035012382421475825376778590937794554225647092055932998039404832926821724386093261449972691735490787917635072888523885575813644811005358833688", - "-15229937207665399077858745779056928142076482322535266981438711930746572914030457988461614013826308364893535928521195966837848031188929394769614489759198148009387852082467397161392193074580370561838070595801238055150547001898037272379177792186097373425590642040064504319592980875488946638406365056236476661594999049247103250079448049760186508271091630332833596279458697068078832218087075544964591498372812863039399793891647438843170406180128852474289724184601066049404074247449524559845321683147746932532594721096776453826585995068663187778354136614612407086729935627102933428001169544176494702260120088616177094122596", - "4423817485097350932424418489755694412699593088843423207118652642017753124828670168023683986663483348010821563740973349339039999652593572489226634061594354003970858509410018682617414793335864951696251946617385611984536476771260728219342233573060916777310319872368264904534560004743365113463062419519791519083814132572592001715626074081892878836026456243524878087931315541387440248693791684485700635565529131429893772243402800191002799200914843481323690852313588145236316661063827783308810378121509659713394573216583671878018935266378492137948180346291679018739284608191825337179228499660670255782455554732811032893595", - "14060727610797171065873730743344628826300688857981195853338897134682600312555998942680998373000530961057721631672534399458386502204866782136713687245588626842312961478612189645195715241803501047584717823837224418642078891142575255896720379626691373477223808040839453370799715426143237974402342331020941533125564932963228074818891707580296516262584451816695873169230235668081091425131622898726217356123668519420820803676318446901933688924722455581079574809688082011559628335681866023133655136379898615214209349346203435853293689318189116037465645474669519318589567809649024218325830547412938703120625760137723658167545", - "12143975642996547734993210479666904095397741261764866078090510262645460132290235986630376713004350672851651807054875332939956731775733959997351324143497076406076776154977723396094902338839439098161231984686885314849947129332117197645344151755344324038625202859604817402251985217489847067013287339738384296915967594310421751908244841803407747710371415190598155158739898568686373111717605879278384135851318969079281050507414909011506576169586220120054116056221990949404820925350166961128163192137909212020962545745326872002538950594091355414304183527270036601878504771221000529804769425263948649859429914831451793830447", - "7681905128991420738358979923777240433337546546660192093231163456029821861424188702648102462301544733499592591906609649350535414419477664467070025593525931603028515171360109575816154776046183332815807349628739221532165348992025144025203444717113795284728750784856862721905401143841702874481392901879089726940312479501647028937736816673686877284445430463537947530572199915087117895344271025474693120828230653492777168767540782277375513209223619007329449471451811372004116502977451480549159579358749540564515729677785198516083957467543681269622455949740687260144765977931043642705413831493101417185777391942989245676973", - "6324957736802947762698105017681228051594271495029008384509236777170014306498658302206164665097448703570931287007659305566350360036085316522653055137878512074480755437541173568670880476898182300821763522340043814781148109583375526242284492181946863678861291620814183269643728258345959383134128289995080908583694306703558113066837628145217885578776624299254179033312744171665733436458179725336656848290970572987456090589484353899143202322971998318634185334126489034866595781074592194167476225131764951162637607536439161513547138214421713349130949142742184752353531752780426054707814473818221353155710305120310324535073", - }; + @Test + public void encodeProducesTheAndroidRsaStructure() throws Exception { + byte[] encoded = AndroidPubkey.encode(publicKey); + assertEquals(AndroidPubkey.ANDROID_PUBKEY_ENCODED_SIZE, encoded.length); - private final RSAPublicKey[] mPublicKeys = new RSAPublicKey[20]; + ByteBuffer fields = ByteBuffer.wrap(encoded).order(ByteOrder.LITTLE_ENDIAN); + assertEquals(AndroidPubkey.ANDROID_PUBKEY_MODULUS_SIZE_WORDS, fields.getInt()); + long n0inv = Integer.toUnsignedLong(fields.getInt()); - @Before - public void setUp() throws NoSuchAlgorithmException, InvalidKeySpecException, InvalidKeyException { - for (int i = 0; i < 20; ++i) { - mPublicKeys[i] = AndroidPubkey.decode(new BigInteger(KEYS[i]).toByteArray()); - } + byte[] modulus = Arrays.copyOfRange(encoded, 8, 264); + assertEquals(publicKey.getModulus(), littleEndianInteger(modulus)); + long lowWord = publicKey.getModulus().longValue() & 0xffffffffL; + assertEquals(0xffffffffL, lowWord * n0inv & 0xffffffffL); + + byte[] rr = Arrays.copyOfRange(encoded, 264, 520); + BigInteger expectedRr = BigInteger.ONE.shiftLeft(4096).mod(publicKey.getModulus()); + assertEquals(expectedRr, littleEndianInteger(rr)); + assertEquals(65537, fields.getInt(520)); } @Test - public void decodeTest() throws NoSuchAlgorithmException, InvalidKeyException, SignatureException { - for (int i = 0; i < 20; ++i) { - Signature signature = Signature.getInstance("SHA256withRSA"); - signature.initVerify(mPublicKeys[i]); - signature.update(DIGEST); - assertTrue(signature.verify(new BigInteger(SIGNATURES[i]).toByteArray())); - } + public void encodeWithNameAppendsTheAdbIdentity() throws Exception { + byte[] key = AndroidPubkey.encode(publicKey); + byte[] expected = (Base64.getEncoder().encodeToString(key) + " test-device\0") + .getBytes(StandardCharsets.UTF_8); + assertArrayEquals(expected, AndroidPubkey.encodeWithName(publicKey, "test-device")); } @Test - public void encodeTest() throws InvalidKeyException { - for (int i = 0; i < 20; ++i) { - byte[] pubKey = AndroidPubkey.encode(mPublicKeys[i]); - assertEquals(ANDROID_PUBKEY_ENCODED_SIZE, pubKey.length); - assertArrayEquals(new BigInteger(KEYS[i]).toByteArray(), pubKey); - } + public void encodeRejectsUnsupportedKeys() throws Exception { + KeyPairGenerator shortGenerator = KeyPairGenerator.getInstance("RSA"); + shortGenerator.initialize(1024); + RSAPublicKey shortKey = (RSAPublicKey) shortGenerator.generateKeyPair().getPublic(); + assertThrows(InvalidKeyException.class, () -> AndroidPubkey.encode(shortKey)); + + RSAPublicKey wrongExponent = (RSAPublicKey) KeyFactory.getInstance("RSA") + .generatePublic(new RSAPublicKeySpec( + publicKey.getModulus(), BigInteger.valueOf(17))); + assertThrows(InvalidKeyException.class, () -> AndroidPubkey.encode(wrongExponent)); } - @Test - public void encodeWithNameTest() throws InvalidKeyException { - String name = "MyAwesomeApp"; - byte[] nameEncodedBytes = AndroidPubkey.getUserInfo(name); - int pkeyB64Size = 4 * (int) Math.ceil(ANDROID_PUBKEY_ENCODED_SIZE / 3.0); - int expectedLength = pkeyB64Size + nameEncodedBytes.length; - for (int i = 0; i < 20; ++i) { - byte[] expectedEncodedBytes = new byte[expectedLength]; - System.arraycopy(Base64.encode(new BigInteger(KEYS[i]).toByteArray()), 0, expectedEncodedBytes, 0, pkeyB64Size); - System.arraycopy(nameEncodedBytes, 0, expectedEncodedBytes, pkeyB64Size, nameEncodedBytes.length); - byte[] actualEncodedBytes = AndroidPubkey.encodeWithName(mPublicKeys[i], name); - assertEquals(expectedLength, actualEncodedBytes.length); - assertArrayEquals(expectedEncodedBytes, actualEncodedBytes); + private static BigInteger littleEndianInteger(byte[] bytes) { + byte[] reversed = new byte[bytes.length]; + for (int i = 0; i < bytes.length; i++) { + reversed[i] = bytes[bytes.length - i - 1]; } + return new BigInteger(1, reversed); } - } -- cgit v1.2.3