合并受阻
start build


感谢提交 Pull Requests !此PR未通过DCO校验。
校验失败可能原因:
1. 未签署“DCO协议”(开发者原创声明协议),在线签署、查看签署状态。
2. Commits 中未包含 Signed-off-by信息,参考FAQ处理。
修复上述问题后,在PR的评论框输入“check dco” ,单击”评论”,系统将再次进行DCO校验。
当前检测到如下Commits的Signed-off-by邮箱未签署DCO协议:
Thanks for submitting a pull request. This pull request has not passed the DCO check.
Possible causes:
1. You have not signed the Developer Certificate of Origin (DCO). Sign the DCO and check DCO status.
2. The commits do not contain the Signed-off-by information. To resolve this issue, see FAQs.
After resolving the preceding issues, enter check dco in the comment box of this pull request and click Comment. The system will check DCO status again.
The Signed-off-by emails in the following commits have not signed the DCO:


首次触发
门禁构建开始,包含静态检查、代码编译和测试【x86_64_virt编译, ohos-host_mini_tdd编译, dayu200测试, dayu200编译, dayu200_tdd编译, hispark_taurus_LiteOS编译, dayu600_7885编译, master_inner_build编译, dayu600_7885测试, hispark_taurus_LiteOS测试, ohos-sdk编译, hispark_taurus_Linux编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/6a94f9ad64650f998bf9c5f9/runlist


代码门禁未通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/6a94f9ad64650f998bf9c5f9/runlist
静态检查:
| # | check type | result | report |
|---|---|---|---|
| 1 | codeCheck | noPass | >>> |
编译测试:
| # | Device | build result | package |
|---|---|---|---|
| 1 | hispark_taurus_LiteOS | pending | NA |
| 2 | hispark_taurus_Linux | pending | NA |
| 3 | ohos-sdk | pending | NA |
| 4 | dayu200 | pending | NA |
| 5 | dayu200_tdd | pending | NA |
| 6 | master_inner_build | pending | NA |
| 7 | ohos-host_mini_tdd | pending | NA |
| 8 | dayu600_7885 | pending | NA |
| 9 | x86_64_virt | pending | NA |


代码有更新,重置PR验证状态


感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接。
Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.


static-check


静态检查:
| # | check type | result | report |
|---|---|---|---|
| 1 | codeCheck | noPass | >>> |


感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接。
Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.


感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接。
Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.


感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接。
Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.


感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接。
Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.


感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接。
Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.


感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接。
Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.


static-check


静态检查:
| # | check type | result | report |
|---|---|---|---|
| 1 | codeCheck | noPass | >>> |


high modules/sandbox/normal/sandbox_core.cpp:842
问题:MountIPCGroup 仅拒绝 groupGid == 0,任意非 0 gid 都会创建 root:
证据:groupGid == 0 是唯一校验;对照组 MountAllGroup 的 DataGroup 源路径为系统生成的 dir+uuid,不含应用可选 gid。
建议:appspawn 作为最后执行者应做防御性校验:限定 groupGid 落在专用分配段(类似 isolated uid 段做法),或 neverallow 已知系统保留 gid。同时请 owner 确认 AMS/BMS 侧的 gid 分配机制是否存在白名单。


medium modules/sandbox/normal/sandbox_core.cpp:507
问题:EnsureDirWithMode 中 chmod/chown 失败仅打日志后 return 0。IPCGroup 目录权限为 01771(sticky+setgid),属主/属组错误意味着共享内存的组内互访边界被破坏,但挂载照常完成,应用无感知。
证据:失败分支只 LOGE 后落到 return 0,调用方 EnsureDirWithMode(...) != 0 的检查在该路径永远不触发。
建议:IPCGroup 场景下 chmod/chown 失败应返回错误并跳过该项挂载,或至少提供可观测的上报手段。


medium modules/sandbox/normal/sandbox_core.cpp:837
问题:atoi("3000000000") 溢出为截断值,atoi("-1") 可通过 != 0 检查后 cast 为 (gid_t)0xFFFFFFFF,两者都会创建错误属主的共享内存目录,与 F1 叠加会扩大攻击面。
证据:static_cast<gid_t>(atoi(groupGidItem->valuestring)) 无 errno 与范围检查。
建议:改用 strtol 并做 errno 与范围校验(0 < gid,字符串完全消费)。


low modules/sandbox/normal/sandbox_core.cpp:848
问题:EnsureDirWithMode 失败(mkdir 失败路径)时 continue,该项 IPC 组不挂载但整体 ret=0,应用启动成功,直到运行时通信失败才暴露。与数据非法(ret=-1 启动失败)的容错策略不一致。
证据:if (EnsureDirWithMode(...) != 0) { continue; } 不置 ret。
建议:建议区分环境错误与数据错误的日志级别,或确认该容错策略是有意设计并在注释中说明。


low test/unittest/app_spawn_standard_test/app_spawn_sandbox_normal_test/app_spawn_sandbox_core_test.cpp:545
问题:测试 10/11/15-18 真实创建 /mnt/sandbox/shm/100/group/* 且可能真实 bind mount(设备 root 下 DoAppSandboxMountOnce 非 stub 路径会成功),但仅 rmdir 一层且无 umount,重复执行残留挂载点与父目录。另外测试用硬编码 "IPCGroup" 字符串而非 MSG_EXT_NAME_IPC_GROUP 宏。
证据:MountIPCGroup_10/11 注释自述 mount will likely fail in test env,但设备 root 环境下路径可达时实际会成功。
建议:teardown 中 umount 沙箱内挂载点并递归清理父目录;字符串统一使用宏。


相关的Issue
https://gitcode.com/openharmony/startup_appspawn/issues/2143
原因(目的、解决的问题等)
提供跨应用通信功能
描述(做了什么,变更了什么)
提供跨应用通信功能
测试用例(新增、改动、可能影响的功能)