已开启
fd_test_1 #874
已开启
xhz-sz创建于 17 天前
xhz-sz
xhz-sz
17 天前

IssueNo: https://gitcode.com/openharmony/ability_ability_base/issues/1228

Description:

稳定性自检:

自检项 自检结果
涉及跨进程调用的相关操作需要抛至主线程或加锁防止并发
成员变量进行赋值或创建需要排查并发
谨慎在lambda表达式中使用引用捕获
谨慎在未经拷贝的情况下使用外部传入的string、C字符串
map\vector\list\set等stl模板类使用时需要排查并发
谨慎考虑加锁范围
在IPC通信中谨慎使用同步通信方式
禁止传递this指针至其他模块或线程(特别是eventhandler任务)
禁止将外部传入的裸指针在内部直接构造智能指针
禁止多个独立创建的智能指针管理同一地址
禁止在析构函数中抛异步任务
禁止js对象在非js线程(例如在IPC线程)创建、使用或销毁
禁止在对外接口中未经判空直接使用外部传入的指针
禁止接口返回局部变量引用
禁止在信号函数中加锁
禁止在关键流程(SA启动、应用启动等主流程)执行耗时的操作
禁止将同一个cpp编译在不同的so中

安全编码自检:

自检项 自检结果
裸指针避免通过隐式转换构造为sptr
json对象在取值之前必须先判断类型,避免类型不匹配
序列化时必须对传入的数组大小进行校验,避免出现超大数组
避免使用未明确位宽的整型,选择使用int8_t、uint8_t等类型
外部传入的路径要做规范化校验,对路径中的.、..、../等特殊字符严格校验
指针变量、表示资源描述符的变量、bool变量必须赋初值
readParcelable获取的对象使用前需要判空
分配和释放内存的函数需要成对出现
申请内存后异常退出前需要及时进行内存释放
内存申请前必须对内存大小进行合法性校验
内存分配后必须判断是否成功
禁止使用realloc、alloca函数
禁止打印文件路径、口令等敏感信息,如有需要,使用private修饰
禁止打印内存地址
整数之间运算时必须严格检查,确保不会出现溢出、反转、除0
禁止对有符号整数进行位操作符运算
禁止对指针进行逻辑或位运算
循环次数如果收外部数据控制,需要检验其合法性
禁止使用内存操作类危险函数,需要使用安全函数
谨慎使用不可重入函数
必须检查安全函数的返回值,并进行正确处理
禁止仅通过TokenType类型判断绕过权限校验

TDD Result:

XTS Result:

是否已执行L0用例

likedislike
合并受阻
xhz-szxhz-sz
17 天前 修改了pull request 的描述
openharmony_ciopenharmony_ci成员
17 天前 添加了label:waiting_on_author
openharmony_ci
openharmony_ci成员
17 天前 评论:

感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接


Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.

likedislike
openharmony_ciopenharmony_ci成员
17 天前 添加了label:dco检查成功
xhz-sz
xhz-sz5 天前进行代码检视1
interfaces/kits/native/want/include/want_fd_scope.h
@@ -0,0 +1,3 @@
1+/*
2+ * Copyright (c) 2026 Huawei Device Co., Ltd.
3+ * Licensed under the Apache License, Version 2.0 (the "License");
4+ * you may not use this file except in compliance with the License.
xhz-sz
xhz-sz5 天前评论:

/*

  • Copyright (c) 2026 Huawei Device Co., Ltd.
  • Licensed under the Apache License, Version 2.0 (the "License");
  • you may not use this file except in compliance with the License.
  • You may obtain a copy of the License at
  • http://www.apache.org/licenses/LICENSE-2.0
    
  • Unless required by applicable law or agreed to in writing, software
  • distributed under the License is distributed on an "AS IS" BASIS,
  • WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  • See the License for the specific language governing permissions and
  • limitations under the License.
    */
    #ifndef OHOS_ABILITY_BASE_WANT_FD_SCOPE_H
    #define OHOS_ABILITY_BASE_WANT_FD_SCOPE_H

#include "want.h"

namespace OHOS {
namespace AAFwk {

class WantFdScope final {
public:
explicit WantFdScope(Want &want) : want_(&want) {}
explicit WantFdScope(Want *want) : want_(want) {}
~WantFdScope()
{
if (want_ != nullptr) {
want_->CloseAllFd();
}
}
WantFdScope(const WantFdScope &) = delete;
WantFdScope &operator=(const WantFdScope &) = delete;
WantFdScope(WantFdScope &&other) noexcept : want_(other.want_)
{
other.want_ = nullptr;
}
WantFdScope &operator=(WantFdScope &&) = delete;

void Release() noexcept
{
    want_ = nullptr;
}

void Strip()
{
    if (want_ != nullptr) {
        want_->RemoveAllFd();
    }
}

private:
Want *want_;
};
} // namespace AAFwk
} // namespace OHOS

#endif // OHOS_ABILITY_BASE_WANT_FD_SCOPE_H

likedislike
xhz-sz
xhz-sz5 天前进行代码检视1
interfaces/kits/native/want/src/want.cpp
@@ -2316,6 +2316,16 @@ void Want::DupAllFd()
23162316 parameters_.DupAllFd();
23172317}
23182318 
2319+bool Want::AssignDup(const Want &src)
xhz-sz
xhz-sz5 天前评论:

bool Want::AssignDup(const Want &src)
{
operation_ = src.operation_;
bool ret = parameters_.AssignDup(src.GetParams());
ABILITYBASE_LOGI("Want::AssignDup result:%{public}d", ret);
return ret;
}

bool Want::DupCopy(const Want &src, Want &out)
{
return WantParams::DupCopy(src.GetParams(), out.parameters_);
}

likedislike
xhz-sz
xhz-sz5 天前进行代码检视1
interfaces/kits/native/want/src/want_params.cpp
@@ -1885,22 +1885,63 @@ void WantParams::RemoveAllFd()
18851885 fds_.clear();
18861886}
18871887 
1888+bool WantParams::TryDupAllFd()
xhz-sz
xhz-sz5 天前评论:

bool WantParams::TryDupAllFd()
{
ABILITYBASE_LOGI("TryDupAllFd called, fd count: %{public}zu", fds_.size());
std::vector<std::pair<std::string, int32_t>> staged;
for (const auto &it : fds_) {
if (it.second < 0) {
continue;
}
int32_t dupFd = dup(it.second);
if (dupFd < 0) {
ABILITYBASE_LOGE("dup fd failed, key: %{public}s oldFd:%{public}d", it.first.c_str(), it.second);
for (const auto &s : staged) {
close(s.second);
}
return false;
}
ABILITYBASE_LOGI("dup fd key:%{public}s oldFd:%{public}d newFd:%{public}d", it.first.c_str(), it.second, dupFd);
staged.emplace_back(it.first, dupFd);
}
for (const auto &s : staged) {
WantParams wp;
wp.SetParam(TYPE_PROPERTY, String::Box(FD));
wp.SetParam(VALUE_PROPERTY, Integer::Box(s.second));
sptrAAFwk::IWantParams pWantParams = AAFwk::WantParamWrapper::Box(wp);
params_[s.first] = pWantParams;
fds_[s.first] = s.second;
}
return true;
}

void WantParams::DupAllFd()
{
(void)TryDupAllFd();
}

bool WantParams::AssignDup(const WantParams &src)
{
if (this == &src) {
return TryDupAllFd();
}
*this = src;
if (!TryDupAllFd()) {
RemoveAllFd();
return false;
}
return true;
}

bool WantParams::DupCopy(const WantParams &src, WantParams &out)
{
if (&out == &src) {
return out.TryDupAllFd();
}
out = src;
if (!out.TryDupAllFd()) {
out.RemoveAllFd();
return false;
}
return true;
}

likedislike