Revert "Revert "Enable low target sdk install block by default""
This reverts commit db0fc499b1.
Reason for revert: All issues fixed that required the original revert
Change-Id: I1f5e29cd2d033c9cdbfef602597e4b74aaa7a272
This commit is contained in:
committed by
Android (Google) Code Review
parent
db0fc499b1
commit
08d73f2f36
@@ -1134,22 +1134,22 @@ final class InstallPackageHelper {
|
||||
// behavior.
|
||||
if (DeviceConfig.getBoolean(DeviceConfig.NAMESPACE_PACKAGE_MANAGER_SERVICE,
|
||||
"MinInstallableTargetSdk__install_block_enabled",
|
||||
false)) {
|
||||
true)) {
|
||||
int minInstallableTargetSdk =
|
||||
DeviceConfig.getInt(DeviceConfig.NAMESPACE_PACKAGE_MANAGER_SERVICE,
|
||||
"MinInstallableTargetSdk__min_installable_target_sdk",
|
||||
0);
|
||||
PackageManagerService.MIN_INSTALLABLE_TARGET_SDK);
|
||||
|
||||
// Determine if enforcement is in strict mode
|
||||
boolean strictMode = false;
|
||||
|
||||
if (DeviceConfig.getBoolean(DeviceConfig.NAMESPACE_PACKAGE_MANAGER_SERVICE,
|
||||
"MinInstallableTargetSdk__install_block_strict_mode_enabled",
|
||||
false)) {
|
||||
true)) {
|
||||
if (parsedPackage.getTargetSdkVersion()
|
||||
< DeviceConfig.getInt(DeviceConfig.NAMESPACE_PACKAGE_MANAGER_SERVICE,
|
||||
"MinInstallableTargetSdk__strict_mode_target_sdk",
|
||||
0)) {
|
||||
PackageManagerService.MIN_INSTALLABLE_TARGET_SDK)) {
|
||||
strictMode = true;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -557,6 +557,14 @@ public class PackageManagerService implements PackageSender, TestUtilityService
|
||||
// How many required verifiers can be on the system.
|
||||
private static final int REQUIRED_VERIFIERS_MAX_COUNT = 2;
|
||||
|
||||
/**
|
||||
* Specifies the minimum target SDK version an apk must specify in order to be installed
|
||||
* on the system. This improves security and privacy by blocking low
|
||||
* target sdk apps as malware can target older sdk versions to avoid
|
||||
* the enforcement of new API behavior.
|
||||
*/
|
||||
public static final int MIN_INSTALLABLE_TARGET_SDK = Build.VERSION_CODES.M;
|
||||
|
||||
// Compilation reasons.
|
||||
// TODO(b/260124949): Clean this up with the legacy dexopt code.
|
||||
public static final int REASON_FIRST_BOOT = 0;
|
||||
|
||||
Reference in New Issue
Block a user