blob: 4bc617c65fe0c3b6ba5aa50e5df7ff3b05d2e709 [file] [log] [blame]
// Copyright 2022 The ChromiumOS Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
#include <init/process_killer/process_killer.h>
#include <sys/signal.h>
#include <memory>
#include <string>
#include <utility>
#include <vector>
#include <base/json/json_reader.h>
#include <base/logging.h>
#include <base/strings/string_split.h>
#include <base/strings/string_util.h>
#include <base/threading/platform_thread.h>
#include <base/time/time.h>
#include <init/process_killer/process.h>
#include <init/process_killer/process_manager.h>
namespace init {
namespace {
constexpr char const* kSessionMountRegexes[] = {
constexpr char const* kSystemMountRegexes[] = {"/var", "/home", "/usr/local",
constexpr char const* kSessionDeviceRegexes[] = {
constexpr char const* kSystemDeviceRegexes[] = {
constexpr char kMatchNothingRegex[] = "$^";
constexpr int kKillerIterations = 10;
constexpr base::TimeDelta kSleepInterval = base::Milliseconds(100);
re2::RE2 ConstructMountRegex(bool session,
bool shutdown,
const std::string& mount_filter) {
std::vector<std::string> mounts;
if (session) {
for (auto mount : kSessionMountRegexes) {
if (shutdown) {
for (auto mount : kSystemMountRegexes) {
if (mount_filter.size()) {
auto filter = base::JSONReader::ReadAndReturnValueWithError(mount_filter);
if (!filter.has_value()) {
LOG(ERROR) << "Could not parse the mount filter JSON list. Error: "
<< filter.error().message;
} else if (!filter->is_list()) {
LOG(ERROR) << "Invalid mount filter JSON, expecting path regex list.";
} else {
for (const auto& mount : filter->GetList()) {
if (auto* mount_str = mount.GetIfString();
mount_str && mount_str->size()) {
if (mounts.empty()) {
// Avoid empty regex which matches to any string, return
// `kMatchNothingRegex` instead.
return kMatchNothingRegex;
return re2::RE2("^(" + base::JoinString(mounts, "|") + ")");
re2::RE2 ConstructDeviceRegex(bool session, bool shutdown) {
std::vector<std::string> devices;
if (session) {
for (auto device : kSessionDeviceRegexes) {
if (shutdown) {
for (auto device : kSystemDeviceRegexes) {
if (devices.empty()) {
return kMatchNothingRegex;
return re2::RE2("(" + base::JoinString(devices, "|") + ")");
} // namespace
ProcessKiller::ProcessKiller(bool session,
bool shutdown,
const std::string& mount_filter)
: mount_regex_(ConstructMountRegex(session, shutdown, mount_filter)),
device_regex_(ConstructDeviceRegex(session, shutdown)),
pm_(std::make_unique<ProcessManager>(base::FilePath("/proc"))) {}
void ProcessKiller::LogProcesses() {
for (ActiveProcess& p : process_list_) {
p.LogProcess(mount_regex_, device_regex_);
void ProcessKiller::KillProcesses(bool files, bool devices) {
// First try sending SIGTERM.
for (int i = 0; i < kKillerIterations; i++) {
UpdateProcessList(files, devices);
if (process_list_.empty())
LOG(INFO) << "Sending SIGTERM";
for (ActiveProcess& p : process_list_) {
pm_->SendSignalToProcess(p, SIGTERM);
// If processes are still running, send SIGKILL.
for (int i = 0; i < kKillerIterations; i++) {
UpdateProcessList(files, devices);
if (process_list_.empty())
LOG(INFO) << "Sending SIGKILL";
for (ActiveProcess& p : process_list_) {
pm_->SendSignalToProcess(p, SIGKILL);
// Check processes still active and log.
UpdateProcessList(files, devices);
if (!process_list_.empty()) {
LOG(INFO) << "Processes still active:";
void ProcessKiller::UpdateProcessList(bool files, bool devices) {
process_list_ = pm_->GetProcessList(files, devices);
std::remove_if(process_list_.begin(), process_list_.end(),
[this, files, devices](const ActiveProcess& p) {
bool dont_kill_this_process = true;
// Kill processes with a file open that matches the mount
// regex.
if (files && p.HasFileOpenOnMount(mount_regex_))
dont_kill_this_process = false;
// Kill processes with a non-init mount namespace and a
// mount open that matches the device regex.
if (devices && !p.InInitMountNamespace() &&
dont_kill_this_process = false;
if (!dont_kill_this_process && p.GetPid() == 1) {
LOG(ERROR) << "Cowardly refusing to kill init";
return true;
return dont_kill_this_process;
} // namespace init