summaryrefslogtreecommitdiff
path: root/src/com/android/nfc/cardemulation/AidRoutingManager.java
blob: 38e0af74acee677831c0b8e7366e6d02b6d49712 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
/*
 * Copyright (C) 2013 The Android Open Source Project
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *      http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */
package com.android.nfc.cardemulation;

import android.os.SystemProperties;
import android.util.Log;
import android.util.SparseArray;
import android.util.proto.ProtoOutputStream;

import com.android.nfc.NfcService;
import com.android.nfc.NfcStatsLog;

import java.io.FileDescriptor;
import java.io.PrintWriter;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.HashMap;
import java.util.HashSet;
import java.util.Map;
import java.util.Set;

public class AidRoutingManager {

    static final String TAG = "AidRoutingManager";

    static final boolean DBG = SystemProperties.getBoolean("persist.nfc.debug_enabled", false);

    static final int ROUTE_HOST = 0x00;

    // Every routing table entry is matched exact
    static final int AID_MATCHING_EXACT_ONLY = 0x00;
    // Every routing table entry can be matched either exact or prefix
    static final int AID_MATCHING_EXACT_OR_PREFIX = 0x01;
    // Every routing table entry is matched as a prefix
    static final int AID_MATCHING_PREFIX_ONLY = 0x02;
    // Every routing table entry can be matched either exact or prefix or subset only
    static final int AID_MATCHING_EXACT_OR_SUBSET_OR_PREFIX = 0x03;

    int mDefaultIsoDepRoute;
    //Let mDefaultRoute as default aid route
    int mDefaultRoute;

    int mMaxAidRoutingTableSize;

    final byte[] mOffHostRouteUicc;
    final byte[] mOffHostRouteEse;
    // Used for backward compatibility in case application doesn't specify the
    // SE
    final int mDefaultOffHostRoute;

    // How the NFC controller can match AIDs in the routing table;
    // see AID_MATCHING constants
    final int mAidMatchingSupport;

    final Object mLock = new Object();

    // mAidRoutingTable contains the current routing table. The index is the route ID.
    // The route can include routes to a eSE/UICC.
    SparseArray<Set<String>> mAidRoutingTable =
            new SparseArray<Set<String>>();

    // Easy look-up what the route is for a certain AID
    HashMap<String, Integer> mRouteForAid = new HashMap<String, Integer>();

    private native int doGetDefaultRouteDestination();
    private native int doGetDefaultOffHostRouteDestination();
    private native byte[] doGetOffHostUiccDestination();
    private native byte[] doGetOffHostEseDestination();
    private native int doGetAidMatchingMode();
    private native int doGetDefaultIsoDepRouteDestination();

    final class AidEntry {
        boolean isOnHost;
        String offHostSE;
        int route;
        int aidInfo;
        int power;
    }

    public AidRoutingManager() {
        mDefaultRoute = doGetDefaultRouteDestination();
        if (DBG)
            Log.d(TAG, "mDefaultRoute=0x" + Integer.toHexString(mDefaultRoute));
        mDefaultOffHostRoute = doGetDefaultOffHostRouteDestination();
        if (DBG)
            Log.d(TAG, "mDefaultOffHostRoute=0x" + Integer.toHexString(mDefaultOffHostRoute));
        mOffHostRouteUicc = doGetOffHostUiccDestination();
        if (DBG)
            Log.d(TAG, "mOffHostRouteUicc=" + Arrays.toString(mOffHostRouteUicc));
        mOffHostRouteEse = doGetOffHostEseDestination();
        if (DBG)
          Log.d(TAG, "mOffHostRouteEse=" + Arrays.toString(mOffHostRouteEse));
        mAidMatchingSupport = doGetAidMatchingMode();
        if (DBG) Log.d(TAG, "mAidMatchingSupport=0x" + Integer.toHexString(mAidMatchingSupport));

        mDefaultIsoDepRoute = doGetDefaultIsoDepRouteDestination();
        if (DBG) Log.d(TAG, "mDefaultIsoDepRoute=0x" + Integer.toHexString(mDefaultIsoDepRoute));
    }

    public boolean supportsAidPrefixRouting() {
        return mAidMatchingSupport == AID_MATCHING_EXACT_OR_PREFIX ||
                mAidMatchingSupport == AID_MATCHING_PREFIX_ONLY ||
                 mAidMatchingSupport == AID_MATCHING_EXACT_OR_SUBSET_OR_PREFIX;
    }

    public boolean supportsAidSubsetRouting() {
        return mAidMatchingSupport == AID_MATCHING_EXACT_OR_SUBSET_OR_PREFIX;
    }

    public int calculateAidRouteSize(HashMap<String, AidEntry> routeCache) {
        // TAG + ROUTE + LENGTH_BYTE + POWER
        int AID_HDR_LENGTH = 0x04;
        int routeTableSize = 0x00;
        for(Map.Entry<String, AidEntry> aidEntry : routeCache.entrySet()) {
            String aid = aidEntry.getKey();
            // removing prefix length
            if(aid.endsWith("*")) {
                routeTableSize += ((aid.length() - 0x01) / 0x02) + AID_HDR_LENGTH;
            } else {
                routeTableSize += (aid.length() / 0x02)+ AID_HDR_LENGTH;
            }
        }
        if (DBG) Log.d(TAG, "calculateAidRouteSize: " + routeTableSize);
        return routeTableSize;
    }

    private void clearNfcRoutingTableLocked() {
        for (Map.Entry<String, Integer> aidEntry : mRouteForAid.entrySet())  {
            String aid = aidEntry.getKey();
            if (aid.endsWith("*")) {
                if (mAidMatchingSupport == AID_MATCHING_EXACT_ONLY) {
                    Log.e(TAG, "Device does not support prefix AIDs but AID [" + aid
                            + "] is registered");
                } else if (mAidMatchingSupport == AID_MATCHING_PREFIX_ONLY) {
                    if (DBG) Log.d(TAG, "Unrouting prefix AID " + aid);
                    // Cut off '*' since controller anyway treats all AIDs as a prefix
                    aid = aid.substring(0, aid.length() - 1);
                } else if (mAidMatchingSupport == AID_MATCHING_EXACT_OR_PREFIX ||
                    mAidMatchingSupport == AID_MATCHING_EXACT_OR_SUBSET_OR_PREFIX) {
                    aid = aid.substring(0, aid.length() - 1);
                    if (DBG) Log.d(TAG, "Unrouting prefix AID " + aid);
                }
            }  else if (aid.endsWith("#")) {
                if (mAidMatchingSupport == AID_MATCHING_EXACT_ONLY) {
                    Log.e(TAG, "Device does not support subset AIDs but AID [" + aid
                            + "] is registered");
                } else if (mAidMatchingSupport == AID_MATCHING_PREFIX_ONLY ||
                    mAidMatchingSupport == AID_MATCHING_EXACT_OR_PREFIX) {
                    Log.e(TAG, "Device does not support subset AIDs but AID [" + aid
                            + "] is registered");
                } else if (mAidMatchingSupport == AID_MATCHING_EXACT_OR_SUBSET_OR_PREFIX) {
                    if (DBG) Log.d(TAG, "Unrouting subset AID " + aid);
                    aid = aid.substring(0, aid.length() - 1);
                }
            } else {
                if (DBG) Log.d(TAG, "Unrouting exact AID " + aid);
            }

            NfcService.getInstance().unrouteAids(aid);
        }
        if (NfcService.getInstance().getNciVersion() >= NfcService.getInstance().NCI_VERSION_2_0) {
            // unRoute EmptyAid
            NfcService.getInstance().unrouteAids("");
        }
    }

    private int getRouteForSecureElement(String se) {
        if (se == null || se.length() <= 3) {
            return 0;
        }
        try {
            if (se.startsWith("eSE") && mOffHostRouteEse != null) {
                int index = Integer.parseInt(se.substring(3));
                if (mOffHostRouteEse.length >= index && index > 0) {
                    return mOffHostRouteEse[index - 1] & 0xFF;
                }
            } else if (se.startsWith("SIM") && mOffHostRouteUicc != null) {
                int index = Integer.parseInt(se.substring(3));
                if (mOffHostRouteUicc.length >= index && index > 0) {
                    return mOffHostRouteUicc[index - 1] & 0xFF;
                }
            }
            if (mOffHostRouteEse == null && mOffHostRouteUicc == null)
              return mDefaultOffHostRoute;
        } catch (NumberFormatException e) { }
        return 0;
    }

    public boolean configureRouting(HashMap<String, AidEntry> aidMap, boolean force) {
        boolean aidRouteResolved = false;
        HashMap<String, AidEntry> aidRoutingTableCache = new HashMap<String, AidEntry>(aidMap.size());
        ArrayList<Integer> seList = new ArrayList<Integer>();
        mDefaultRoute = doGetDefaultRouteDestination();
        seList.add(mDefaultRoute);
        if (mDefaultRoute != ROUTE_HOST) {
            seList.add(ROUTE_HOST);
        }

        SparseArray<Set<String>> aidRoutingTable = new SparseArray<Set<String>>(aidMap.size());
        HashMap<String, Integer> routeForAid = new HashMap<String, Integer>(aidMap.size());
        HashMap<String, Integer> infoForAid = new HashMap<String, Integer>(aidMap.size());
        // Then, populate internal data structures first
        for (Map.Entry<String, AidEntry> aidEntry : aidMap.entrySet())  {
            int route = ROUTE_HOST;
            if (!aidEntry.getValue().isOnHost) {
                String offHostSE = aidEntry.getValue().offHostSE;
                if (offHostSE == null) {
                    route = mDefaultOffHostRoute;
                } else {
                    route = getRouteForSecureElement(offHostSE);
                    if (route == 0) {
                        Log.e(TAG, "Invalid Off host Aid Entry " + offHostSE);
                        continue;
                    }
                }
            }
            if (!seList.contains(route))
                seList.add(route);
            aidEntry.getValue().route = route;
            int aidType = aidEntry.getValue().aidInfo;
            String aid = aidEntry.getKey();
            Set<String> entries =
                    aidRoutingTable.get(route, new HashSet<String>());
            entries.add(aid);
            aidRoutingTable.put(route, entries);
            routeForAid.put(aid, route);
            infoForAid.put(aid, aidType);
        }

        synchronized (mLock) {
            if (routeForAid.equals(mRouteForAid) && !force) {
                if (DBG) Log.d(TAG, "Routing table unchanged, not updating");
                return false;
            }

            // Otherwise, update internal structures and commit new routing
            clearNfcRoutingTableLocked();
            mRouteForAid = routeForAid;
            mAidRoutingTable = aidRoutingTable;

            mMaxAidRoutingTableSize = NfcService.getInstance().getAidRoutingTableSize();
            if (DBG) Log.d(TAG, "mMaxAidRoutingTableSize: " + mMaxAidRoutingTableSize);

            //calculate AidRoutingTableSize for existing route destination
            for(int index = 0; index < seList.size(); index ++) {
              mDefaultRoute = seList.get(index);
              if(index != 0)
                if (DBG) Log.d(TAG, "AidRoutingTable is full, try to switch mDefaultRoute to 0x" + Integer.toHexString(mDefaultRoute));

              aidRoutingTableCache.clear();

              if (mAidMatchingSupport == AID_MATCHING_PREFIX_ONLY) {
                  /* If a non-default route registers an exact AID which is shorter
                   * than this exact AID, this will create a problem with controllers
                   * that treat every AID in the routing table as a prefix.
                   * For example, if App A registers F0000000041010 as an exact AID,
                   * and App B registers F000000004 as an exact AID, and App B is not
                   * the default route, the following would be added to the routing table:
                   * F000000004 -> non-default destination
                   * However, because in this mode, the controller treats every routing table
                   * entry as a prefix, it means F0000000041010 would suddenly go to the non-default
                   * destination too, whereas it should have gone to the default.
                   *
                   * The only way to prevent this is to add the longer AIDs of the
                   * default route at the top of the table, so they will be matched first.
                   */
                  Set<String> defaultRouteAids = mAidRoutingTable.get(mDefaultRoute);
                  if (defaultRouteAids != null) {
                      for (String defaultRouteAid : defaultRouteAids) {
                          // Check whether there are any shorted AIDs routed to non-default
                          // TODO this is O(N^2) run-time complexity...
                          for (Map.Entry<String, Integer> aidEntry : mRouteForAid.entrySet()) {
                              String aid = aidEntry.getKey();
                              int route = aidEntry.getValue();
                              if (defaultRouteAid.startsWith(aid) && route != mDefaultRoute) {
                                  if (DBG) Log.d(TAG, "Adding AID " + defaultRouteAid + " for default " +
                                          "route, because a conflicting shorter AID will be " +
                                          "added to the routing table");
                                    aidRoutingTableCache.put(defaultRouteAid, aidMap.get(defaultRouteAid));
                              }
                          }
                      }
                  }
              }

              // Add AID entries for all non-default routes
              for (int i = 0; i < mAidRoutingTable.size(); i++) {
                  int route = mAidRoutingTable.keyAt(i);
                  if (route != mDefaultRoute) {
                      Set<String> aidsForRoute = mAidRoutingTable.get(route);
                      for (String aid : aidsForRoute) {
                          if (aid.endsWith("*")) {
                              if (mAidMatchingSupport == AID_MATCHING_EXACT_ONLY) {
                                  Log.e(TAG, "This device does not support prefix AIDs.");
                              } else if (mAidMatchingSupport == AID_MATCHING_PREFIX_ONLY) {
                                  if (DBG) Log.d(TAG, "Routing prefix AID " + aid + " to route "
                                          + Integer.toString(route));
                                  // Cut off '*' since controller anyway treats all AIDs as a prefix
                                    aidRoutingTableCache.put(aid.substring(0,aid.length() - 1), aidMap.get(aid));
                              } else if (mAidMatchingSupport == AID_MATCHING_EXACT_OR_PREFIX ||
                                mAidMatchingSupport == AID_MATCHING_EXACT_OR_SUBSET_OR_PREFIX) {
                                  if (DBG) Log.d(TAG, "Routing prefix AID " + aid + " to route "
                                          + Integer.toString(route));
                                  aidRoutingTableCache.put(aid.substring(0,aid.length() - 1), aidMap.get(aid));
                              }
                          } else if (aid.endsWith("#")) {
                              if (mAidMatchingSupport == AID_MATCHING_EXACT_ONLY) {
                                  Log.e(TAG, "Device does not support subset AIDs but AID [" + aid
                                          + "] is registered");
                              } else if (mAidMatchingSupport == AID_MATCHING_PREFIX_ONLY ||
                                  mAidMatchingSupport == AID_MATCHING_EXACT_OR_PREFIX) {
                                  Log.e(TAG, "Device does not support subset AIDs but AID [" + aid
                                          + "] is registered");
                              } else if (mAidMatchingSupport == AID_MATCHING_EXACT_OR_SUBSET_OR_PREFIX) {
                                  if (DBG) Log.d(TAG, "Routing subset AID " + aid + " to route "
                                          + Integer.toString(route));
                                  aidRoutingTableCache.put(aid.substring(0,aid.length() - 1), aidMap.get(aid));
                              }
                         } else {
                              if (DBG) Log.d(TAG, "Routing exact AID " + aid + " to route "
                                      + Integer.toString(route));
                                aidRoutingTableCache.put(aid, aidMap.get(aid));
                          }
                        }
                 }
              }

              // register default route in below cases:
              // 1. mDefaultRoute is different with mDefaultIsoDepRoute
              // 2. mDefaultRoute and mDefaultIsoDepRoute all equal to ROUTE_HOST
              //    , which is used for screen off HCE scenarios
              if (mDefaultRoute != mDefaultIsoDepRoute || mDefaultIsoDepRoute == ROUTE_HOST) {
                  if (NfcService.getInstance().getNciVersion()
                          >= NfcService.getInstance().NCI_VERSION_2_0) {
                      String emptyAid = "";
                      AidEntry entry = new AidEntry();
                      int default_route_power_state;
                      entry.route = mDefaultRoute;
                      if (mDefaultRoute == ROUTE_HOST) {
                          entry.isOnHost = true;
                          default_route_power_state = RegisteredAidCache.POWER_STATE_SWITCH_ON
                                  | RegisteredAidCache.POWER_STATE_SCREEN_ON_LOCKED;
                          Set<String> aidsForDefaultRoute = mAidRoutingTable.get(mDefaultRoute);
                          if (aidsForDefaultRoute != null) {
                              for (String aid : aidsForDefaultRoute) {
                                  default_route_power_state |= aidMap.get(aid).power;
                              }
                          }
                      } else {
                          entry.isOnHost = false;
                          default_route_power_state = RegisteredAidCache.POWER_STATE_ALL;
                      }
                      entry.aidInfo = RegisteredAidCache.AID_ROUTE_QUAL_PREFIX;
                      entry.power = default_route_power_state;

                      aidRoutingTableCache.put(emptyAid, entry);
                      if (DBG) Log.d(TAG, "Add emptyAid into AidRoutingTable");
                  }
              }

              // Register additional offhost AIDs when their support power states are
              // differernt from the default route entry
              if (mDefaultRoute != ROUTE_HOST) {
                  int default_route_power_state = RegisteredAidCache.POWER_STATE_ALL;
                  if (NfcService.getInstance().getNciVersion()
                          < NfcService.getInstance().NCI_VERSION_2_0) {
                      default_route_power_state =
                              RegisteredAidCache.POWER_STATE_ALL_NCI_VERSION_1_0;
                  }

                  Set<String> aidsForDefaultRoute = mAidRoutingTable.get(mDefaultRoute);
                  if (aidsForDefaultRoute != null) {
                      for (String aid : aidsForDefaultRoute) {
                          if (aidMap.get(aid).power != default_route_power_state) {
                              aidRoutingTableCache.put(aid, aidMap.get(aid));
                          }
                      }
                  }
              }

              if (calculateAidRouteSize(aidRoutingTableCache) <= mMaxAidRoutingTableSize) {
                  aidRouteResolved = true;
                  break;
              }
          }

          if(aidRouteResolved == true) {
              commit(aidRoutingTableCache);
          } else {
              NfcStatsLog.write(NfcStatsLog.NFC_ERROR_OCCURRED,
                      NfcStatsLog.NFC_ERROR_OCCURRED__TYPE__AID_OVERFLOW, 0, 0);
              Log.e(TAG, "RoutingTable unchanged because it's full, not updating");
          }
        }
        return true;
    }

    private void commit(HashMap<String, AidEntry> routeCache ) {

        if(routeCache != null) {

            for (Map.Entry<String, AidEntry> aidEntry : routeCache.entrySet())  {
                int route = aidEntry.getValue().route;
                int aidType = aidEntry.getValue().aidInfo;
                String aid = aidEntry.getKey();
                int power = aidEntry.getValue().power;
                if (DBG) {
                    Log.d(TAG, "commit aid:" + aid + ",route:" + route
                        + ",aidtype:" + aidType + ", power state:" + power);
                }

                NfcService.getInstance().routeAids(aid, route, aidType, power);
            }
        }

        // And finally commit the routing
        NfcService.getInstance().commitRouting();
    }

    /**
     * This notifies that the AID routing table in the controller
     * has been cleared (usually due to NFC being turned off).
     */
    public void onNfccRoutingTableCleared() {
        // The routing table in the controller was cleared
        // To stay in sync, clear our own tables.
        synchronized (mLock) {
            mAidRoutingTable.clear();
            mRouteForAid.clear();
        }
    }

    public void dump(FileDescriptor fd, PrintWriter pw, String[] args) {
        pw.println("Routing table:");
        pw.println("    Default route: " + ((mDefaultRoute == 0x00) ? "host" : "secure element"));
        synchronized (mLock) {
            for (int i = 0; i < mAidRoutingTable.size(); i++) {
                Set<String> aids = mAidRoutingTable.valueAt(i);
                pw.println("    Routed to 0x" + Integer.toHexString(mAidRoutingTable.keyAt(i)) + ":");
                for (String aid : aids) {
                    pw.println("        \"" + aid + "\"");
                }
            }
        }
    }

    /**
     * Dump debugging information as a AidRoutingManagerProto
     *
     * Note:
     * See proto definition in frameworks/base/core/proto/android/nfc/card_emulation.proto
     * When writing a nested message, must call {@link ProtoOutputStream#start(long)} before and
     * {@link ProtoOutputStream#end(long)} after.
     * Never reuse a proto field number. When removing a field, mark it as reserved.
     */
    void dumpDebug(ProtoOutputStream proto) {
        proto.write(AidRoutingManagerProto.DEFAULT_ROUTE, mDefaultRoute);
        synchronized (mLock) {
            for (int i = 0; i < mAidRoutingTable.size(); i++) {
                long token = proto.start(AidRoutingManagerProto.ROUTES);
                proto.write(AidRoutingManagerProto.Route.ID, mAidRoutingTable.keyAt(i));
                mAidRoutingTable.valueAt(i).forEach(aid -> {
                    proto.write(AidRoutingManagerProto.Route.AIDS, aid);
                });
                proto.end(token);
            }
        }
    }
}