DNS in Binder process communication

Keywords: DNS Android SELinux

DNS in Binder process communication ----- servicemanager

Just as "DNS" in the Internet needs to be ready before browsing all kinds of web pages, so service manager needs to be in a normal state before someone uses Binder.

Next, we briefly introduce service manager.

1. When to start

Since someone needs to be ready before using Binder, it's natural to think that the init process will start when the init.rc is parsed after the Android system is powered on. It turns out that's true.

service servicemanager /system/bin/servicemanager
    class core
    user system
    group system
    onrestart restart healthd
    onrestart restart zygote
    onrestart restart media
    onrestart restart surfaceflinger
    onrestart restart drm

As can be seen from the above code, if the service manager encounters problems and restarts, healthd, zygote, media, surfacelinker and drm will also restart.

2. Where is the source code of servicemanager


3. What is the main responsibility after startup

int main(int argc, char **argv)
    struct binder_state *bs;

    bs = binder_open(128*1024);//Open Binder device
    if (!bs) {
        ALOGE("failed to open binder driver\n");
        return -1;

    if (binder_become_context_manager(bs)) {//Set yourself as Binder manager. Only one service manager is allowed for Android
        ALOGE("cannot become context manager (%s)\n", strerror(errno));
        return -1;

    selinux_enabled = is_selinux_enabled();
    sehandle = selinux_android_service_context_handle();

    if (selinux_enabled > 0) {
        if (sehandle == NULL) {
            ALOGE("SELinux: Failed to acquire sehandle. Aborting.\n");

        if (getcon(&service_manager_context) != 0) {
            ALOGE("SELinux: Failed to acquire service_manager context. Aborting.\n");

    union selinux_callback cb;
    cb.func_audit = audit_callback;
    selinux_set_callback(SELINUX_CB_AUDIT, cb);
    cb.func_log = selinux_log_callback;
    selinux_set_callback(SELINUX_CB_LOG, cb);

    binder_loop(bs, svcmgr_handler);//Enter loop loop and wait for user request

    return 0;

From the above code, the main function does the following:

1 > Open Binder device


struct binder_state *binder_open(size_t mapsize)
    struct binder_state *bs;
    struct binder_version vers;

    bs = malloc(sizeof(*bs));
    if (!bs) {
        errno = ENOMEM;
        return NULL;

    bs->fd = open("/dev/binder", O_RDWR);//Open Binder drive node
    if (bs->fd < 0) {
        fprintf(stderr,"binder: cannot open device (%s)\n",
        goto fail_open;

    if ((ioctl(bs->fd, BINDER_VERSION, &vers) == -1) ||
        (vers.protocol_version != BINDER_CURRENT_PROTOCOL_VERSION)) {
                "binder: kernel driver version (%d) differs from user space version (%d)\n",
                vers.protocol_version, BINDER_CURRENT_PROTOCOL_VERSION);
        goto fail_open;

    bs->mapsize = mapsize;
    bs->mapped = mmap(NULL, mapsize, PROT_READ, MAP_PRIVATE, bs->fd, 0);
    if (bs->mapped == MAP_FAILED) {
        fprintf(stderr,"binder: cannot map device (%s)\n",
        goto fail_map;

    return bs;

    return NULL;

2 > set yourself as Binder Butler


int binder_become_context_manager(struct binder_state *bs)
    return ioctl(bs->fd, BINDER_SET_CONTEXT_MGR, 0);

3 > enter the main cycle


void binder_loop(struct binder_state *bs, binder_handler func)
    int res;
    struct binder_write_read bwr;
    uint32_t readbuf[32];

    bwr.write_size = 0;
    bwr.write_consumed = 0;
    bwr.write_buffer = 0;

    readbuf[0] = BC_ENTER_LOOPER;
    binder_write(bs, readbuf, sizeof(uint32_t));//Write information to Binder

    for (;;) {
        bwr.read_size = sizeof(readbuf);
        bwr.read_consumed = 0;
        bwr.read_buffer = (uintptr_t) readbuf;

        res = ioctl(bs->fd, BINDER_WRITE_READ, &bwr);//Read message from Binder

        if (res < 0) {
            ALOGE("binder_loop: ioctl failed (%s)\n", strerror(errno));

        res = binder_parse(bs, 0, (uintptr_t) readbuf, bwr.read_consumed, func);//Process this message
        if (res == 0) {
            ALOGE("binder_loop: unexpected reply?!\n");
        if (res < 0) {
            ALOGE("binder_loop: io error %d %s\n", res, strerror(errno));

Posted by teongkia on Wed, 06 Nov 2019 14:01:59 -0800