Java中執行shell筆記

轉載:https://www.cnblogs.com/jevan/p/3169617.htmlhtml

java中執行shell有好幾種方式:第一種(exec)方式一java

public static synchronized void runshell2()
{
   File superuser = new File("/system/bin/superuser");
 
   if (superuser.exists())
   {
      // return device to original state
      Process process;
      try
      {
         process = Runtime.getRuntime().exec("superuser");
         DataOutputStream os = new DataOutputStream(process.getOutputStream());
         os.writeBytes("mount -oremount,rw /dev/block/mtdblock3 /system\n");
         os.writeBytes("busybox cp /system/bin/superuser /system/bin/su\n");
         os.writeBytes("busybox chown 0:0 /system/bin/su\n");
         os.writeBytes("chmod 4755 /system/bin/su\n");
         os.writeBytes("rm /system/bin/superuser\n");
         os.writeBytes("/system/bin/monkey -v 100\n");
         os.writeBytes("exit\n");
         os.flush();
      } catch (Exception e)
      {
         // TODO Auto-generated catch block
         e.printStackTrace();
      }
   }
}

第一種(exec)方式二:android

  1. public static synchronized void runshell3()
  2. {
  3.    String cmd = "sendkey 3 2\n";
  4.    try
  5.    {
  6.       Process exeEcho = Runtime.getRuntime().exec("su");
  7.       exeEcho.getOutputStream().write(cmd.getBytes());
  8.       exeEcho.getOutputStream().flush();
  9.    } catch (IOException e)
  10.    {
  11.       //showMessage("Excute exception: " + e.getMessage());
  12.       e.printStackTrace();
  13.    }
  14. }

第二種方式一:shell

  1. public static synchronized void runShell() {
  2.    ProcessBuilder pb = new ProcessBuilder("/system/bin/sh");
  3.    // java.lang.ProcessBuilder: Creates operating system processes.
  4.    pb.directory(new File("/system/bin"));// 設置shell的當前目錄。
  5.    try {
  6.       Process proc = pb.start();
  7.       // 獲取輸入流,能夠經過它獲取SHELL的輸出。
  8.       BufferedReader in = new BufferedReader(new InputStreamReader(proc.getInputStream()));
  9.       BufferedReader err = new BufferedReader(new InputStreamReader(proc.getErrorStream()));
  10.       // 獲取輸出流,能夠經過它向SHELL發送命令。
  11.       PrintWriter out = new PrintWriter(new BufferedWriter(new OutputStreamWriter(proc.getOutputStream())), true);
  12.       out.println("pwd");
  13.       out.println("su root");// 執行這一句時會彈出對話框(如下程序要求授予最高權限...),要求用戶確認。
  14.       // out.println("cat /proc/version");
  15.       // out.println("monkey -v 500");
  16.       // out.println("cd /data/data");//這個目錄在系統中要求有root權限才能夠訪問的。
  17.       // out.println("ls -l");//這個命令若是能列出當前安裝的APK的數據文件存放目錄,就說明咱們有了ROOT權限。
  18.       out.println("exit");
  19.       // proc.waitFor();
  20.       String line;
  21.       while ((line = in.readLine()) != null) {
  22.          System.out.println(line); // 打印輸出結果
  23.       }
  24.       while ((line = err.readLine()) != null) {
  25.          System.out.println(line); // 打印錯誤輸出結果
  26.       }
  27.       in.close();
  28.       out.close();
  29.       proc.destroy();
  30.    } catch (Exception e) {
  31.       System.out.println("exception:" + e);
  32.    }
  33. }

第二種方式二:數組

  1. /**
  2.     * 執行一個shell命令,並返回字符串值
  3.     *
  4.     * @param cmd
  5.     * 命令名稱&參數組成的數組(例如:{"/system/bin/cat", "/proc/version"})
  6.     * @param workdirectory
  7.     * 命令執行路徑(例如:"system/bin/")
  8.     * @return 執行結果組成的字符串
  9.     * @throws IOException
  10.     */
  11.    public static synchronized String run(String[] cmd, String workdirectory) {
  12.       StringBuffer result = new StringBuffer();
  13.       try {
  14.          ProcessBuilder builder = new ProcessBuilder(cmd);
  15.  
  16.          InputStream in = null;
  17.          // 設置一個路徑(絕對路徑了就不必定須要)
  18.          if (workdirectory != null) {
  19.             // 設置工做目錄(同上)
  20.             builder.directory(new File(workdirectory));
  21.             // 合併標準錯誤和標準輸出
  22.             builder.redirectErrorStream(true);
  23.             // 啓動一個新進程
  24.             Process process = builder.start();
  25.  
  26.             // 讀取進程標準輸出流
  27.             in = process.getInputStream();
  28.             byte[] re = new byte[1024];
  29.             while (in.read(re) != -1) {
  30.                result = result.append(new String(re));
  31.             }
  32.          }
  33.          // 關閉輸入流
  34.          if (in != null) {
  35.             in.close();
  36.          }
  37.       } catch (Exception ex) {
  38.          ex.printStackTrace();
  39.       }
  40.       return result.toString();
  41.    }

筆記:app

今天使用第一種,發現瞭如下問題:ide

  1. /**
  2.  * 執行shell
  3.  *
  4.  * @return 0:成功,其它爲失敗。
  5.  */
  6. public static synchronized int runShellCmd() {
  7.    BufferedReader input = null;
  8.    PrintWriter output = null;
  9.    Process pro = null;
  10.    try {
  11.       pro = Runtime.getRuntime().exec("adb shell ");
  12.       input = new BufferedReader(new InputStreamReader(pro.getInputStream()));
  13.       pro.getOutputStream().write("pidof mediaserver\r\n".getBytes());
  14.       pro.getOutputStream().flush();
  15.       String line = input.readLine();
  16.       int pid = 0;
  17.       /**
  18.        * 按道理說直接執行命令打印是這樣的:
  19.        * root@android:/ # adb shell
  20.        * root@android:/ # pidof mediaserver
  21.        * 7114
  22.        * 也就是說第三行就應該是我取到的pid值,可是實際上倒是5行?
  23.        */
  24.       for (int i = 0; i < 6; i++) {
  25.          Log.e(TAG , i + " line is " + line);
  26.          pid = toInt(line, 0);
  27.          if (pid > 0)
  28.             break;
  29.          line = input.readLine();
  30.       }
  31.       Log.e(TAG, "pid:" + pid);
  32.       /**
  33.        * 實際打印以下:
  34.        * E/MainActivity( 7036): 0 line is pidof mediaserver
  35.        * E/MainActivity( 7036): 1 line is
  36.        * E/MainActivity( 7036): 2 line is root@android:/ # pidof mediaserver
  37.        * E/MainActivity( 7036): 3 line is
  38.        * E/MainActivity( 7036): 4 line is 6946
  39.        * E/MainActivity( 7036): pid:6946
  40.        * 爲何會多出2個空行??
  41.        */
  42.       if (pid == 0) {
  43.          throw new IOException("not find mediaserver process!");
  44.       }
  45.       String killCmd = String.format("kill -9 %d\r\n", pid);
  46.       /**
  47.        * 直接這麼使用不行的,不知道什麼緣由,執行結果死活不對。
  48.        */
  49.       pro.getOutputStream().write(killCmd.getBytes());
  50.       pro.getOutputStream().flush();
  51.  
  52.       /**
  53.        * 再一次這麼重開就ok了,誰能告訴我緣由?
  54.        */
  55.       pro.destroy();
  56.       pro = null;
  57.       pro = Runtime.getRuntime().exec("adb shell ");
  58.       pro.getOutputStream().write(killCmd.getBytes());
  59.       pro.getOutputStream().flush();
  60.  
  61.  
  62.    } catch (IOException ex) {
  63.       ex.printStackTrace();
  64.       return -1;
  65.    } finally {
  66.       try {
  67.          if (input != null) {
  68.             input.close();
  69.          }
  70.          if (output != null) {
  71.             output.close();
  72.          }
  73.       } catch (IOException e) {
  74.          e.printStackTrace();
  75.       }
  76.       if (pro != null) {
  77.          pro.destroy();
  78.          pro = null;
  79.       }
  80.    }
  81.    return 0;
  82. }

我去看看源碼是怎麼樣的!函數

Runtime的exec最終調用的是ProcessManager,代碼以下所示:ui

  1. /**
  2.  * Executes the specified command and its arguments in a separate native
  3.  * process. The new process uses the environment provided in {@code envp}
  4.  * and the working directory specified by {@code directory}.
  5.  *
  6.  * @param progArray
  7.  * the array containing the program to execute as well as any
  8.  * arguments to the program.
  9.  * @param envp
  10.  * the array containing the environment to start the new process
  11.  * in.
  12.  * @param directory
  13.  * the directory in which to execute the program. If {@code null},
  14.  * execute if in the same directory as the parent process.
  15.  * @return the new {@code Process} object that represents the native
  16.  * process.
  17.  * @throws IOException
  18.  * if the requested program can not be executed.
  19.  * @throws SecurityException
  20.  * if the current {@code SecurityManager} disallows program
  21.  * execution.
  22.  * @see SecurityManager#checkExec
  23.  * @since Android 1.0
  24.  */
  25. public Process exec(String[] progArray, String[] envp, File directory) throws IOException {
  26.     // BEGIN android-changed: push responsibility for argument checking into ProcessManager
  27.     return ProcessManager.getInstance().exec(progArray, envp, directory, false);
  28.     // END android-changed
  29. }

ProcessManager的exec代碼以下:this

  1. /**
  2.  * Map from pid to Process. We keep weak references to the Process objects
  3.  * and clean up the entries when no more external references are left. The
  4.  * process objects themselves don't require much memory, but file
  5.  * descriptors (associated with stdin/out/err in this case) can be
  6.  * a scarce resource.
  7.  */
  8. private final Map<Integer, ProcessReference> processReferences
  9.         = new HashMap<Integer, ProcessReference>();
  10. /**
  11.  * Executes a process and returns an object representing it.
  12.  */
  13. Process exec(String[] taintedCommand, String[] taintedEnvironment, File workingDirectory,
  14.         boolean redirectErrorStream) throws IOException {
  15.     // Make sure we throw the same exceptions as the RI.
  16.     if (taintedCommand == null) {
  17.         throw new NullPointerException();
  18.     }
  19.     if (taintedCommand.length == 0) {
  20.         throw new IndexOutOfBoundsException();
  21.     }
  22.  
  23.     // Handle security and safety by copying mutable inputs and checking them.
  24.     String[] command = taintedCommand.clone();
  25.     String[] environment = taintedEnvironment != null ? taintedEnvironment.clone() : null;
  26.     SecurityManager securityManager = System.getSecurityManager();
  27.     if (securityManager != null) {
  28.         securityManager.checkExec(command[0]);//權限檢查
  29.     }
  30.     // Check we're not passing null Strings to the native exec.
  31.     for (String arg : command) {
  32.         if (arg == null) {
  33.             throw new NullPointerException();
  34.         }
  35.     }
  36.     // The environment is allowed to be null or empty, but no element may be null.
  37.     if (environment != null) {
  38.         for (String env : environment) {
  39.             if (env == null) {
  40.                 throw new NullPointerException();
  41.             }
  42.         }
  43.     }
  44.  
  45.     FileDescriptor in = new FileDescriptor();
  46.     FileDescriptor out = new FileDescriptor();
  47.     FileDescriptor err = new FileDescriptor();
  48.  
  49.     String workingPath = (workingDirectory == null)
  50.             ? null
  51.             : workingDirectory.getPath();
  52.  
  53.     // Ensure onExit() doesn't access the process map before we add our
  54.     // entry.
  55.     synchronized (processReferences) {
  56.         int pid;
  57.         try {
  58.            /**
  59.             * 調用exec函數
  60.             */
  61.             pid = exec(command, environment, workingPath, in, out, err, redirectErrorStream);
  62.         } catch (IOException e) {
  63.             IOException wrapper = new IOException("Error running exec()."
  64.                     + " Command: " + Arrays.toString(command)
  65.                     + " Working Directory: " + workingDirectory
  66.                     + " Environment: " + Arrays.toString(environment));
  67.             wrapper.initCause(e);
  68.             throw wrapper;
  69.         }
  70.         /**
  71.          * 新建一個進程實現。
  72.          */
  73.         ProcessImpl process = new ProcessImpl(pid, in, out, err);
  74.         /**
  75.          * 建立一個進程引用。
  76.          */
  77.         ProcessReference processReference
  78.                 = new ProcessReference(process, referenceQueue);
  79.  
  80.         /**
  81.          * 加入到全局進程引用map中。
  82.          */
  83.         processReferences.put(pid, processReference);
  84.  
  85.         /*
  86.          * This will wake up the child monitor thread in case there
  87.          * weren't previously any children to wait on.
  88.          */
  89.         processReferences.notifyAll();
  90.  
  91.         return process;
  92.     }
  93. }

本地exec的原型:

  1. /**
  2.  * Executes a native process. Fills in in, out, and err and returns the
  3.  * new process ID upon success.
  4.  */
  5. static native int exec(String[] command, String[] environment,
  6.         String workingDirectory, FileDescriptor in, FileDescriptor out,
  7.         FileDescriptor err, boolean redirectErrorStream) throws IOException;

對應的native文件爲:

  1. //Android 4.0.3在
  2. ./libcore/luni/src/main/native/java_lang_ProcessManager.cpp
  3. //Android 2.2在
  4. ./dalvik/libcore/luni-kernel/src/main/native/java_lang_ProcessManager.cpp
  5. //源碼爲:
  6. /**
  7.  * Converts Java String[] to char** and delegates to executeProcess().
  8.  */
  9. static pid_t java_lang_ProcessManager_exec(
  10.         JNIEnv* env, jclass clazz, jobjectArray javaCommands,
  11.         jobjectArray javaEnvironment, jstring javaWorkingDirectory,
  12.         jobject inDescriptor, jobject outDescriptor, jobject errDescriptor,
  13.         jboolean redirectErrorStream) {
  14.  
  15.     // Copy commands into char*[].
  16.     char** commands = convertStrings(env, javaCommands);
  17.  
  18.     // Extract working directory string.
  19.     const char* workingDirectory = NULL;
  20.     if (javaWorkingDirectory != NULL) {
  21.         workingDirectory = env->GetStringUTFChars(javaWorkingDirectory, NULL);
  22.     }
  23.  
  24.     // Convert environment array.
  25.     char** environment = convertStrings(env, javaEnvironment);
  26.  
  27.     //關鍵就這一行.
  28.     pid_t result = executeProcess(
  29.             env, commands, environment, workingDirectory,
  30.             inDescriptor, outDescriptor, errDescriptor, redirectErrorStream);
  31.  
  32.     // Temporarily clear exception so we can clean up.
  33.     jthrowable exception = env->ExceptionOccurred();
  34.     env->ExceptionClear();
  35.  
  36.     freeStrings(env, javaEnvironment, environment);
  37.  
  38.     // Clean up working directory string.
  39.     if (javaWorkingDirectory != NULL) {
  40.         env->ReleaseStringUTFChars(javaWorkingDirectory, workingDirectory);
  41.     }
  42.  
  43.     freeStrings(env, javaCommands, commands);
  44.  
  45.     // Re-throw exception if present.
  46.     if (exception != NULL) {
  47.         if (env->Throw(exception) < 0) {
  48.             LOGE("Error rethrowing exception!");
  49.         }
  50.     }
  51.  
  52.     return result;
  53. }

看看executeProcess接口,其實源碼註釋寫的很清楚。

  1. /** Executes a command in a child process. */
  2. static pid_t executeProcess(JNIEnv* env, char** commands, char** environment,
  3.         const char* workingDirectory, jobject inDescriptor,
  4.         jobject outDescriptor, jobject errDescriptor,
  5.         jboolean redirectErrorStream) {
  6.     int i, result, error;
  7.  
  8.     // Create 4 pipes: stdin, stdout, stderr, and an exec() status pipe.
  9.     int pipes[PIPE_COUNT * 2] = { -1, -1, -1, -1, -1, -1, -1, -1 };
  10.     for (i = 0; i < PIPE_COUNT; i++) {
  11.         if (pipe(pipes + i * 2) == -1) {
  12.             jniThrowIOException(env, errno);
  13.             closePipes(pipes, -1);
  14.             return -1;
  15.         }
  16.     }
  17.     int stdinIn = pipes[0];
  18.     int stdinOut = pipes[1];
  19.     int stdoutIn = pipes[2];
  20.     int stdoutOut = pipes[3];
  21.     int stderrIn = pipes[4];
  22.     int stderrOut = pipes[5];
  23.     int statusIn = pipes[6];
  24.     int statusOut = pipes[7];
  25.  
  26.     pid_t childPid = fork();
  27.  
  28.     // If fork() failed...
  29.     if (childPid == -1) {
  30.         jniThrowIOException(env, errno);
  31.         closePipes(pipes, -1);
  32.         return -1;
  33.     }
  34.  
  35.     // If this is the child process...
  36.     if (childPid == 0) {
  37.         /*
  38.          * Note: We cannot malloc() or free() after this point!
  39.          * A no-longer-running thread may be holding on to the heap lock, and
  40.          * an attempt to malloc() or free() would result in deadlock.
  41.          */
  42.  
  43.         // Replace stdin, out, and err with pipes.
  44.         dup2(stdinIn, 0);
  45.         dup2(stdoutOut, 1);
  46.         if (redirectErrorStream) {
  47.             dup2(stdoutOut, 2);
  48.         } else {
  49.             dup2(stderrOut, 2);
  50.         }
  51.  
  52.         // Close all but statusOut. This saves some work in the next step.
  53.         closePipes(pipes, statusOut);
  54.  
  55.         // Make statusOut automatically close if execvp() succeeds.
  56.         fcntl(statusOut, F_SETFD, FD_CLOEXEC);
  57.  
  58.         // Close remaining open fds with the exception of statusOut.
  59.         closeNonStandardFds(statusOut);
  60.  
  61.         // Switch to working directory.
  62.         if (workingDirectory != NULL) {
  63.             if (chdir(workingDirectory) == -1) {
  64.                 goto execFailed;
  65.             }
  66.         }
  67.  
  68.         // Set up environment.
  69.         if (environment != NULL) {
  70.             environ = environment;
  71.         }
  72.  
  73.         // Execute process. By convention, the first argument in the arg array
  74.         // should be the command itself. In fact, I get segfaults when this
  75.         // isn't the case.
  76.         execvp(commands[0], commands);
  77.  
  78.         // If we got here, execvp() failed or the working dir was invalid.
  79.         execFailed:
  80.             error = errno;
  81.             write(statusOut, &error, sizeof(int));
  82.             close(statusOut);
  83.             exit(error);
  84.     }
  85.  
  86.     // This is the parent process.
  87.  
  88.     // Close child's pipe ends.
  89.     close(stdinIn);
  90.     close(stdoutOut);
  91.     close(stderrOut);
  92.     close(statusOut);
  93.  
  94.     // Check status pipe for an error code. If execvp() succeeds, the other
  95.     // end of the pipe should automatically close, in which case, we'll read
  96.     // nothing.
  97.     int count = read(statusIn, &result, sizeof(int));
  98.     close(statusIn);
  99.     if (count > 0) {
  100.         jniThrowIOException(env, result);
  101.  
  102.         close(stdoutIn);
  103.         close(stdinOut);
  104.         close(stderrIn);
  105.  
  106.         return -1;
  107.     }
  108.  
  109.     // Fill in file descriptor wrappers.
  110.     jniSetFileDescriptorOfFD(env, inDescriptor, stdoutIn);
  111.     jniSetFileDescriptorOfFD(env, outDescriptor, stdinOut);
  112.     jniSetFileDescriptorOfFD(env, errDescriptor, stderrIn);
  113.  
  114.     return childPid;
  115. }

至此,Runtime的exec就所有結束了。若是對下面的fork,execvp這2個函數不瞭解。建議看看APU。

 

最後來看看ProcessBuilder類的實現:

  1. /**
  2.  * Starts a new process based on the current state of this process builder.
  3.  *
  4.  * @return the new {@code Process} instance.
  5.  * @throws NullPointerException
  6.  * if any of the elements of {@link #command()} is {@code null}.
  7.  * @throws IndexOutOfBoundsException
  8.  * if {@link #command()} is empty.
  9.  * @throws SecurityException
  10.  * if {@link SecurityManager#checkExec(String)} doesn't allow
  11.  * process creation.
  12.  * @throws IOException
  13.  * if an I/O error happens.
  14.  */
  15. public Process start() throws IOException {
  16.     // BEGIN android-changed: push responsibility for argument checking into ProcessManager
  17.     String[] cmdArray = command.toArray(new String[command.size()]);
  18.     String[] envArray = new String[environment.size()];
  19.     int i = 0;
  20.     for (Map.Entry<String, String> entry : environment.entrySet()) {
  21.         envArray[i++] = entry.getKey() + "=" + entry.getValue(); //$NON-NLS-1$
  22.     }
  23.     //和Runtime.exec的同樣。
  24.     return ProcessManager.getInstance().exec(cmdArray, envArray, directory, redirectErrorStream);
  25.     // END android-changed
  26. }

殊路同歸!!!哈。

相關文章
相關標籤/搜索