binder 架构设计

1.binder概述: binder实现跨进程通信,进程之间通信是不能直接通过全局变量实现数据传输,因为两个进程启动两个java虚拟机,binder只是封装进程通信的一套框架,实质还是android 底层利用linux特性实现虚拟设备映射一块公共区域的内存,实现不同java虚拟机访问公共区域
2.binder 流程图
3.binder 源码设计

先从ServiceManager 入口开始
public final class ServiceManager {
     * Returns a reference to a service with the given name.
     * @param name the name of the service to get
     * @return a reference to the service, or <code>null</code> if the service doesn't exist
    public static IBinder getService(String name) {
        try {
            IBinder service = sCache.get(name);
            if (service != null) {
                return service;
            } else {
                return Binder.allowBlocking(getIServiceManager().getService(name));
        } catch (RemoteException e) {
            Log.e(TAG, "error in getService", e);
        return null;

     * Place a new @a service called @a name into the service
     * manager.
     * @param name the name of the new service
     * @param service the service object
    public static void addService(String name, IBinder service) {
        try {
            getIServiceManager().addService(name, service, false);
        } catch (RemoteException e) {
            Log.e(TAG, "error in addService", e);

    private static IServiceManager getIServiceManager() {
        if (sServiceManager != null) {
            return sServiceManager;
        // Find the service manager
        sServiceManager = ServiceManagerNative
        return sServiceManager;

ServerManager是管理对系统各类服务的管理类,其中每个远程服务都继承binder,通过addService添加远程服务, getService能获取该服务的代理binder, BinderInternal.getContextObject()拿到的是一个java层BinderProxy代理,这个从native层去分析
public class BinderInternal {

     * Return the global "context object" of the system.  This is usually
     * an implementation of IServiceManager, which you can use to find
     * other services.
    public static final native IBinder getContextObject();
static jobject android_os_BinderInternal_getContextObject(JNIEnv* env, jobject clazz)
    sp<IBinder> b = ProcessState::self()->getContextObject(NULL); //获得Bpbinder指针
    return javaObjectForIBinder(env, b); //将BpBinder指针转换为java 层BinderProxy对象

jobject javaObjectForIBinder(JNIEnv* env, const sp<IBinder>& val)
    if (val == NULL) return NULL;
    if (val->checkSubclass(&gBinderOffsets)) {
        // One of our own!
        jobject object = static_cast<JavaBBinder*>(val.get())->object();
        LOGDEATH("objectForBinder %p: it's our own %p!\n", val.get(), object);
        return object;
    // For the rest of the function we will hold this lock, to serialize
    // looking/creation/destruction of Java proxies for native Binder proxies.
    AutoMutex _l(gProxyLock);
    // Someone else's...  do we know about it?
    jobject object = (jobject)val->findObject(&gBinderProxyOffsets);
    if (object != NULL) {
        jobject res = jniGetReferent(env, object);
        if (res != NULL) {
            ALOGV("objectForBinder %p: found existing %p!\n", val.get(), res);
            return res;
        LOGDEATH("Proxy object %p of IBinder %p no longer in working set!!!", object, val.get());
    object = env->NewObject(gBinderProxyOffsets.mClass, gBinderProxyOffsets.mConstructor); //通过反射创BinderProxy对象,gBinderProxyOffsets 结构体是BinderProxy类里面字段id,构造方法id存储,下面会介绍
    if (object != NULL) {
        LOGDEATH("objectForBinder %p: created new proxy %p !\n", val.get(), object);
        // The proxy holds a reference to the native object.
        env->SetLongField(object, gBinderProxyOffsets.mObject, (jlong)val.get());     //将BpBinder地址存储到BinderProxy
        // The native object needs to hold a weak reference back to the
        // proxy, so we can retrieve the same proxy if it is still active.
        jobject refObject = env->NewGlobalRef(
                env->GetObjectField(object, gBinderProxyOffsets.mSelf));
        val->attachObject(&gBinderProxyOffsets, refObject,
                jnienv_to_javavm(env), proxy_cleanup);
        // Also remember the death recipients registered on this proxy
        sp<DeathRecipientList> drl = new DeathRecipientList;
        env->SetLongField(object, gBinderProxyOffsets.mOrgue, reinterpret_cast<jlong>(drl.get()));
        // Note that a new object reference has been created.
    return object;

static struct binderproxy_offsets_t
    // Class state.
    jclass mClass;  // android/os/BinderProxy
    jmethodID mConstructor; // "<init>", "()V"
    jmethodID mSendDeathNotice; // sendDeathNotice", "(Landroid/os/IBinder$DeathRecipient;)V"
    // Object state.
    jfieldID mObject; //"mObject", "J" //存储的
    jfieldID mSelf;// "mSelf", "Ljava/lang/ref/WeakReference;"
    jfieldID mOrgue;// "()Ljava/lang/String;"
} gBinderProxyOffsets;
const char* const kBinderProxyPathName = "android/os/BinderProxy";
static int int_register_android_os_BinderProxy(JNIEnv* env)
    jclass clazz = FindClassOrDie(env, "java/lang/Error");
    gErrorOffsets.mClass = MakeGlobalRefOrDie(env, clazz);
    clazz = FindClassOrDie(env, kBinderProxyPathName);
    gBinderProxyOffsets.mClass = MakeGlobalRefOrDie(env, clazz);
    gBinderProxyOffsets.mConstructor = GetMethodIDOrDie(env, clazz, "<init>", "()V");
    gBinderProxyOffsets.mSendDeathNotice = GetStaticMethodIDOrDie(env, clazz, "sendDeathNotice",
    gBinderProxyOffsets.mObject = GetFieldIDOrDie(env, clazz, "mObject", "J");
    gBinderProxyOffsets.mSelf = GetFieldIDOrDie(env, clazz, "mSelf",
    gBinderProxyOffsets.mOrgue = GetFieldIDOrDie(env, clazz, "mOrgue", "J");
    clazz = FindClassOrDie(env, "java/lang/Class");
    gClassOffsets.mGetName = GetMethodIDOrDie(env, clazz, "getName", "()Ljava/lang/String;");
    return RegisterMethodsOrDie(
        env, kBinderProxyPathName,
        gBinderProxyMethods, NELEM(gBinderProxyMethods));
通过上面介绍,从BpBinde指针r到BinderProxy对象有一定的了解,上面只说了ProcessState::self()->getContextObject(NULL);返回 BpBinder指针,接下来从源码去分析
sp<ProcessState> ProcessState::self()
    Mutex::Autolock _l(gProcessMutex);
    if (gProcess != NULL) {
        return gProcess;
    gProcess = new ProcessState("/dev/binder");
    return gProcess;
ProcessState::ProcessState(const char *driver)
    : mDriverName(String8(driver))
    , mDriverFD(open_driver(driver))
    , mVMStart(MAP_FAILED)
    , mThreadCountDecrement(PTHREAD_COND_INITIALIZER)
    , mExecutingThreadsCount(0)
    , mStarvationStartTimeMs(0)
    , mManagesContexts(false)
    , mBinderContextCheckFunc(NULL)
    , mBinderContextUserData(NULL)
    , mThreadPoolStarted(false)
    , mThreadPoolSeq(1)
    if (mDriverFD >= 0) {
        // mmap the binder, providing a chunk of virtual address space to receive transactions.
        mVMStart = mmap(0, BINDER_VM_SIZE, PROT_READ, MAP_PRIVATE | MAP_NORESERVE, mDriverFD, 0);
        if (mVMStart == MAP_FAILED) {
            // *sigh*
            ALOGE("Using /dev/binder failed: unable to mmap transaction memory.\n");
            mDriverFD = -1;
    LOG_ALWAYS_FATAL_IF(mDriverFD < 0, "Binder driver could not be opened.  Terminating.");

sp<IBinder> ProcessState::getContextObject(const sp<IBinder>& /*caller*/)
    return getStrongProxyForHandle(0); //返回BpBinder指针,0对应是serviceManager的binder,
sp<IBinder> ProcessState::getStrongProxyForHandle(int32_t handle)
    sp<IBinder> result;
    AutoMutex _l(mLock);
    handle_entry* e = lookupHandleLocked(handle);
    if (e != NULL) {
        // We need to create a new BpBinder if there isn't currently one, OR we
        // are unable to acquire a weak reference on this current one.  See comment
        // in getWeakProxyForHandle() for more info about this.
        IBinder* b = e->binder;
        if (b == NULL || !e->refs->attemptIncWeak(this)) {
            if (handle == 0) {
                // Special case for context manager...
                // The context manager is the only object for which we create
                // a BpBinder proxy without already holding a reference.
                // Perform a dummy transaction to ensure the context manager
                // is registered before we create the first local reference
                // to it (which will occur when creating the BpBinder).
                // If a local reference is created for the BpBinder when the
                // context manager is not present, the driver will fail to
                // provide a reference to the context manager, but the
                // driver API does not return status.
                // Note that this is not race-free if the context manager
                // dies while this code runs.
                // TODO: add a driver API to wait for context manager, or
                // stop special casing handle 0 for context manager and add
                // a driver API to get a handle to the context manager with
                // proper reference counting.
                Parcel data;
                status_t status = IPCThreadState::self()->transact(
                        0, IBinder::PING_TRANSACTION, data, NULL, 0);
                if (status == DEAD_OBJECT)
                   return NULL;
            b = new BpBinder(handle); //得到的BpBinder指针
            e->binder = b;
            if (b) e->refs = b->getWeakRefs();
            result = b;
        } else {
            // This little bit of nastyness is to allow us to add a primary
            // reference to the remote proxy when this team doesn't have one
            // but another team is sending the handle to us.
    return result;
   private static IServiceManager getIServiceManager() {
        if (sServiceManager != null) {
            return sServiceManager;
        // Find the service manager
        sServiceManager = ServiceManagerNative
        return sServiceManager;

public abstract class ServiceManagerNative extends Binder implements IServiceManager
 static public IServiceManager asInterface(IBinder obj)
        if (obj == null) {
            return null;
        IServiceManager in =
        if (in != null) {
            return in;
        return new ServiceManagerProxy(obj);


从以上看出,getIServiceManager 方法返回的是 ServiceManagerProxy 代理,,继续看开头介绍的getService方法,
public abstract class ServiceManagerNative extends Binder implements IServiceManager{
public static IBinder getService(String name) {
        try {
            IBinder service = sCache.get(name);
            if (service != null) {
                return service;
            } else {
                return Binder.allowBlocking(getIServiceManager().getService(name));
        } catch (RemoteException e) {
            Log.e(TAG, "error in getService", e);
        return null;


前面说了ServiceManager是一个binder管理池,系统其它服务都从ServiceManager都从这里注册服务,和获取服务,我们以为ActivityManagerService 为例,
public class ActivityManagerService extends IActivityManager.Stub
        implements Watchdog.Monitor, BatteryStatsImpl.BatteryCallback {
 public void setSystemProcess() {
        try {
            ServiceManager.addService(ProcessStats.SERVICE_NAME, mProcessStats);
            ServiceManager.addService("meminfo", new MemBinder(this));
            ServiceManager.addService("gfxinfo", new GraphicsBinder(this));
            ServiceManager.addService("dbinfo", new DbBinder(this));
            if (MONITOR_CPU_USAGE) {
                ServiceManager.addService("cpuinfo", new CpuBinder(this));
            ServiceManager.addService("permission", new PermissionController(this));
            ServiceManager.addService("processinfo", new ProcessInfoService(this));
            ApplicationInfo info = mContext.getPackageManager().getApplicationInfo(
                    "android", STOCK_PM_FLAGS | MATCH_SYSTEM_ONLY);
            mSystemThread.installSystemApplicationInfo(info, getClass().getClassLoader());
            synchronized (this) {
                ProcessRecord app = newProcessRecordLocked(info, info.processName, false, 0);
                app.persistent = true;
       = MY_PID;
                app.maxAdj = ProcessList.SYSTEM_ADJ;
                app.makeActive(mSystemThread.getApplicationThread(), mProcessStats);
                synchronized (mPidsSelfLocked) {
                    mPidsSelfLocked.put(, app);
                updateLruProcessLocked(app, false, null);
        } catch (PackageManager.NameNotFoundException e) {
            throw new RuntimeException(
                    "Unable to find android system package", e);
public class Instrumentation {
  try {
            int result = ActivityManager.getService() //获取ActivityMangerProxy
                .startActivity(whoThread, who.getBasePackageName(), intent,
                        token, target != null ? target.mEmbeddedID : null,
                        requestCode, 0, null, options);
            checkStartActivityResult(result, intent);
        } catch (RemoteException e) {
            throw new RuntimeException("Failure from system", e);



public class ActivityManager {
  public static IActivityManager getService() {
        return IActivityManagerSingleton.get();
 private static final Singleton<IActivityManager> IActivityManagerSingleton =
            new Singleton<IActivityManager>() {
                protected IActivityManager create() {
                    final IBinder b = ServiceManager.getService(Context.ACTIVITY_SERVICE); //获取ActivityManagerService对应的Binder,
                    final IActivityManager am = IActivityManager.Stub.asInterface(b); //得到ActivityManagerProxy对象
                    return am;



public final class ServiceManager {
     * Returns a reference to a service with the given name.
     * @param name the name of the service to get
     * @return a reference to the service, or <code>null</code> if the service doesn't exist
    public static IBinder getService(String name) {
        try {
            IBinder service = sCache.get(name);
            if (service != null) {
                return service;
            } else {
                return Binder.allowBlocking(getIServiceManager().getService(name)); 
        } catch (RemoteException e) {
            Log.e(TAG, "error in getService", e);
        return null;



class ServiceManagerProxy implements IServiceManager {


  public ServiceManagerProxy(IBinder remote) {
        mRemote = remote;

  public IBinder asBinder() {
        return mRemote;
    public IBinder getService(String name) throws RemoteException {
        Parcel data = Parcel.obtain();
        Parcel reply = Parcel.obtain();
        mRemote.transact(GET_SERVICE_TRANSACTION, data, reply, 0);//GET_SERVICE_TRANSACTION找到服务类对应方法唯一标识,data要传的数据,reply返回的数据
        IBinder binder = reply.readStrongBinder();//得到ActivityMangerService的Binder代理
        return binder;

这里的 mRemote就是上面介绍的BinderProxy
final class BinderProxy implements IBinder {final class BinderProxy implements IBinder {
  public boolean transact(int code, Parcel data, Parcel reply, int flags) throws RemoteException {
        Binder.checkParcel(this, code, data, "Unreasonably large binder buffer");
        if (mWarnOnBlocking && ((flags & FLAG_ONEWAY) == 0)) {
            // For now, avoid spamming the log by disabling after we've logged
            // about this interface at least once
            mWarnOnBlocking = false;
            Log.w(Binder.TAG, "Outgoing transactions from this process must be FLAG_ONEWAY",
                    new Throwable());
        final boolean tracingEnabled = Binder.isTracingEnabled();
        if (tracingEnabled) {
            final Throwable tr = new Throwable();
            StackTraceElement stackTraceElement = tr.getStackTrace()[1];
                    stackTraceElement.getClassName() + "." + stackTraceElement.getMethodName());
        try {
            return transactNative(code, data, reply, flags); //调用naive方法
        } finally {
            if (tracingEnabled) {


static const JNINativeMethod gBinderProxyMethods[] = {
     /* name, signature, funcPtr */
    {"pingBinder",          "()Z", (void*)android_os_BinderProxy_pingBinder},
    {"isBinderAlive",       "()Z", (void*)android_os_BinderProxy_isBinderAlive},
    {"getInterfaceDescriptor", "()Ljava/lang/String;", (void*)android_os_BinderProxy_getInterfaceDescriptor},
    {"transactNative",      "(ILandroid/os/Parcel;Landroid/os/Parcel;I)Z", (void*)android_os_BinderProxy_transact},//对应native方法 android_os_BinderProxy_transact
    {"linkToDeath",         "(Landroid/os/IBinder$DeathRecipient;I)V", (void*)android_os_BinderProxy_linkToDeath},
    {"unlinkToDeath",       "(Landroid/os/IBinder$DeathRecipient;I)Z", (void*)android_os_BinderProxy_unlinkToDeath},
    {"destroy",             "()V", (void*)android_os_BinderProxy_destroy},

static jboolean android_os_BinderProxy_transact(JNIEnv* env, jobject obj,
        jint code, jobject dataObj, jobject replyObj, jint flags) // throws RemoteException
    if (dataObj == NULL) {
        jniThrowNullPointerException(env, NULL);
        return JNI_FALSE;
    Parcel* data = parcelForJavaObject(env, dataObj);
    if (data == NULL) {
        return JNI_FALSE;
    Parcel* reply = parcelForJavaObject(env, replyObj); //Java 层 Parcel 转native  Parcel ,与BinderProxy转BpBinder类似
    if (reply == NULL && replyObj != NULL) {
        return JNI_FALSE;
    IBinder* target = (IBinder*)
        env->GetLongField(obj, gBinderProxyOffsets.mObject); //BinderProxy 转BpBinder,上面介绍过BinderProxy里面存储的是BpBinder地址,这里直接拿到地址存储在IBinder指针,其实就是BpBinder指针,BpBinder继承了IBinder
    if (target == NULL) {
        jniThrowException(env, "java/lang/IllegalStateException", "Binder has been finalized!");
        return JNI_FALSE;
    ALOGV("Java code calling transact on %p in Java object %p with code %" PRId32 "\n",
            target, obj, code);

    bool time_binder_calls;
    int64_t start_millis;
    if (kEnableBinderSample) {
        // Only log the binder call duration for things on the Java-level main thread.
        // But if we don't
        time_binder_calls = should_time_binder_calls();
        if (time_binder_calls) {
            start_millis = uptimeMillis();
    //printf("Transact from Java code to %p sending: ", target); data->print();
    status_t err = target->transact(code, *data, reply, flags);
    //if (reply) printf("Transact from Java code to %p received: ", target); reply->print();
    if (kEnableBinderSample) {
        if (time_binder_calls) {
            conditionally_log_binder_call(start_millis, target, code);
    if (err == NO_ERROR) {
        return JNI_TRUE;
    } else if (err == UNKNOWN_TRANSACTION) {
        return JNI_FALSE;
    signalExceptionForError(env, obj, err, true /*canThrowRemoteException*/, data->dataSize());
    return JNI_FALSE;

