Merge "Revert "Add API to allow apps with location permission to access data blobs."" into sc-dev
This commit is contained in:
committed by
Android (Google) Code Review
commit
252eef4aa9
@@ -258,8 +258,7 @@ public class BlobStoreManager {
|
|||||||
public @NonNull ParcelFileDescriptor openBlob(@NonNull BlobHandle blobHandle)
|
public @NonNull ParcelFileDescriptor openBlob(@NonNull BlobHandle blobHandle)
|
||||||
throws IOException {
|
throws IOException {
|
||||||
try {
|
try {
|
||||||
return mService.openBlob(blobHandle, mContext.getOpPackageName(),
|
return mService.openBlob(blobHandle, mContext.getOpPackageName());
|
||||||
mContext.getAttributionTag());
|
|
||||||
} catch (ParcelableException e) {
|
} catch (ParcelableException e) {
|
||||||
e.maybeRethrow(IOException.class);
|
e.maybeRethrow(IOException.class);
|
||||||
throw new RuntimeException(e);
|
throw new RuntimeException(e);
|
||||||
@@ -316,7 +315,7 @@ public class BlobStoreManager {
|
|||||||
@CurrentTimeMillisLong long leaseExpiryTimeMillis) throws IOException {
|
@CurrentTimeMillisLong long leaseExpiryTimeMillis) throws IOException {
|
||||||
try {
|
try {
|
||||||
mService.acquireLease(blobHandle, descriptionResId, null, leaseExpiryTimeMillis,
|
mService.acquireLease(blobHandle, descriptionResId, null, leaseExpiryTimeMillis,
|
||||||
mContext.getOpPackageName(), mContext.getAttributionTag());
|
mContext.getOpPackageName());
|
||||||
} catch (ParcelableException e) {
|
} catch (ParcelableException e) {
|
||||||
e.maybeRethrow(IOException.class);
|
e.maybeRethrow(IOException.class);
|
||||||
e.maybeRethrow(LimitExceededException.class);
|
e.maybeRethrow(LimitExceededException.class);
|
||||||
@@ -379,7 +378,7 @@ public class BlobStoreManager {
|
|||||||
@CurrentTimeMillisLong long leaseExpiryTimeMillis) throws IOException {
|
@CurrentTimeMillisLong long leaseExpiryTimeMillis) throws IOException {
|
||||||
try {
|
try {
|
||||||
mService.acquireLease(blobHandle, INVALID_RES_ID, description, leaseExpiryTimeMillis,
|
mService.acquireLease(blobHandle, INVALID_RES_ID, description, leaseExpiryTimeMillis,
|
||||||
mContext.getOpPackageName(), mContext.getAttributionTag());
|
mContext.getOpPackageName());
|
||||||
} catch (ParcelableException e) {
|
} catch (ParcelableException e) {
|
||||||
e.maybeRethrow(IOException.class);
|
e.maybeRethrow(IOException.class);
|
||||||
e.maybeRethrow(LimitExceededException.class);
|
e.maybeRethrow(LimitExceededException.class);
|
||||||
@@ -498,8 +497,7 @@ public class BlobStoreManager {
|
|||||||
*/
|
*/
|
||||||
public void releaseLease(@NonNull BlobHandle blobHandle) throws IOException {
|
public void releaseLease(@NonNull BlobHandle blobHandle) throws IOException {
|
||||||
try {
|
try {
|
||||||
mService.releaseLease(blobHandle, mContext.getOpPackageName(),
|
mService.releaseLease(blobHandle, mContext.getOpPackageName());
|
||||||
mContext.getAttributionTag());
|
|
||||||
} catch (ParcelableException e) {
|
} catch (ParcelableException e) {
|
||||||
e.maybeRethrow(IOException.class);
|
e.maybeRethrow(IOException.class);
|
||||||
throw new RuntimeException(e);
|
throw new RuntimeException(e);
|
||||||
@@ -604,8 +602,7 @@ public class BlobStoreManager {
|
|||||||
@Nullable
|
@Nullable
|
||||||
public LeaseInfo getLeaseInfo(@NonNull BlobHandle blobHandle) throws IOException {
|
public LeaseInfo getLeaseInfo(@NonNull BlobHandle blobHandle) throws IOException {
|
||||||
try {
|
try {
|
||||||
return mService.getLeaseInfo(blobHandle, mContext.getOpPackageName(),
|
return mService.getLeaseInfo(blobHandle, mContext.getOpPackageName());
|
||||||
mContext.getAttributionTag());
|
|
||||||
} catch (ParcelableException e) {
|
} catch (ParcelableException e) {
|
||||||
e.maybeRethrow(IOException.class);
|
e.maybeRethrow(IOException.class);
|
||||||
throw new RuntimeException(e);
|
throw new RuntimeException(e);
|
||||||
@@ -899,64 +896,6 @@ public class BlobStoreManager {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* Allow apps with location permission to access this blob data once it is committed using
|
|
||||||
* a {@link BlobHandle} representing the blob.
|
|
||||||
*
|
|
||||||
* <p> This needs to be called before committing the blob using
|
|
||||||
* {@link #commit(Executor, Consumer)}.
|
|
||||||
*
|
|
||||||
* Note that if a caller allows access to the blob using this API in addition to other APIs
|
|
||||||
* like {@link #allowPackageAccess(String, byte[])}, then apps satisfying any one of these
|
|
||||||
* access conditions will be allowed to access the blob.
|
|
||||||
*
|
|
||||||
* @param permissionName the name of the location permission that needs to be granted
|
|
||||||
* for the app. This can be either one of
|
|
||||||
* {@link android.Manifest.permission#ACCESS_FINE_LOCATION} or
|
|
||||||
* {@link android.Manifest.permission#ACCESS_COARSE_LOCATION}.
|
|
||||||
*
|
|
||||||
* @throws IOException when there is an I/O error while changing the access.
|
|
||||||
* @throws SecurityException when the caller is not the owner of the session.
|
|
||||||
* @throws IllegalStateException when the caller tries to change access for a blob which is
|
|
||||||
* already committed.
|
|
||||||
*/
|
|
||||||
public void allowPackagesWithLocationPermission(@NonNull String permissionName)
|
|
||||||
throws IOException {
|
|
||||||
try {
|
|
||||||
mSession.allowPackagesWithLocationPermission(permissionName);
|
|
||||||
} catch (ParcelableException e) {
|
|
||||||
e.maybeRethrow(IOException.class);
|
|
||||||
throw new RuntimeException(e);
|
|
||||||
} catch (RemoteException e) {
|
|
||||||
throw e.rethrowFromSystemServer();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Returns {@code true} if access has been allowed for apps with location permission by
|
|
||||||
* using {@link #allowPackagesWithLocationPermission(String)}.
|
|
||||||
*
|
|
||||||
* @param permissionName the name of the location permission that needs to be granted
|
|
||||||
* for the app. This can be either one of
|
|
||||||
* {@link android.Manifest.permission#ACCESS_FINE_LOCATION} or
|
|
||||||
* {@link android.Manifest.permission#ACCESS_COARSE_LOCATION}.
|
|
||||||
*
|
|
||||||
* @throws IOException when there is an I/O error while getting the access type.
|
|
||||||
* @throws IllegalStateException when the caller tries to get access type from a session
|
|
||||||
* which is closed or abandoned.
|
|
||||||
*/
|
|
||||||
public boolean arePackagesWithLocationPermissionAllowed(@NonNull String permissionName)
|
|
||||||
throws IOException {
|
|
||||||
try {
|
|
||||||
return mSession.arePackagesWithLocationPermissionAllowed(permissionName);
|
|
||||||
} catch (ParcelableException e) {
|
|
||||||
e.maybeRethrow(IOException.class);
|
|
||||||
throw new RuntimeException(e);
|
|
||||||
} catch (RemoteException e) {
|
|
||||||
throw e.rethrowFromSystemServer();
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Commit the file that was written so far to this session to the blob store maintained by
|
* Commit the file that was written so far to this session to the blob store maintained by
|
||||||
* the system.
|
* the system.
|
||||||
|
|||||||
@@ -25,13 +25,12 @@ import android.os.RemoteCallback;
|
|||||||
interface IBlobStoreManager {
|
interface IBlobStoreManager {
|
||||||
long createSession(in BlobHandle handle, in String packageName);
|
long createSession(in BlobHandle handle, in String packageName);
|
||||||
IBlobStoreSession openSession(long sessionId, in String packageName);
|
IBlobStoreSession openSession(long sessionId, in String packageName);
|
||||||
ParcelFileDescriptor openBlob(in BlobHandle handle, in String packageName,
|
ParcelFileDescriptor openBlob(in BlobHandle handle, in String packageName);
|
||||||
in String attributionTag);
|
|
||||||
void abandonSession(long sessionId, in String packageName);
|
void abandonSession(long sessionId, in String packageName);
|
||||||
|
|
||||||
void acquireLease(in BlobHandle handle, int descriptionResId, in CharSequence description,
|
void acquireLease(in BlobHandle handle, int descriptionResId, in CharSequence description,
|
||||||
long leaseTimeoutMillis, in String packageName, in String attributionTag);
|
long leaseTimeoutMillis, in String packageName);
|
||||||
void releaseLease(in BlobHandle handle, in String packageName, in String attributionTag);
|
void releaseLease(in BlobHandle handle, in String packageName);
|
||||||
long getRemainingLeaseQuotaBytes(String packageName);
|
long getRemainingLeaseQuotaBytes(String packageName);
|
||||||
|
|
||||||
void waitForIdle(in RemoteCallback callback);
|
void waitForIdle(in RemoteCallback callback);
|
||||||
@@ -40,6 +39,5 @@ interface IBlobStoreManager {
|
|||||||
void deleteBlob(long blobId);
|
void deleteBlob(long blobId);
|
||||||
|
|
||||||
List<BlobHandle> getLeasedBlobs(in String packageName);
|
List<BlobHandle> getLeasedBlobs(in String packageName);
|
||||||
LeaseInfo getLeaseInfo(in BlobHandle blobHandle, in String packageName,
|
LeaseInfo getLeaseInfo(in BlobHandle blobHandle, in String packageName);
|
||||||
in String attributionTag);
|
|
||||||
}
|
}
|
||||||
@@ -26,12 +26,10 @@ interface IBlobStoreSession {
|
|||||||
void allowPackageAccess(in String packageName, in byte[] certificate);
|
void allowPackageAccess(in String packageName, in byte[] certificate);
|
||||||
void allowSameSignatureAccess();
|
void allowSameSignatureAccess();
|
||||||
void allowPublicAccess();
|
void allowPublicAccess();
|
||||||
void allowPackagesWithLocationPermission(in String permissionName);
|
|
||||||
|
|
||||||
boolean isPackageAccessAllowed(in String packageName, in byte[] certificate);
|
boolean isPackageAccessAllowed(in String packageName, in byte[] certificate);
|
||||||
boolean isSameSignatureAccessAllowed();
|
boolean isSameSignatureAccessAllowed();
|
||||||
boolean isPublicAccessAllowed();
|
boolean isPublicAccessAllowed();
|
||||||
boolean arePackagesWithLocationPermissionAllowed(in String permissionName);
|
|
||||||
|
|
||||||
long getSize();
|
long getSize();
|
||||||
void close();
|
void close();
|
||||||
|
|||||||
@@ -38,7 +38,6 @@ public final class XmlTags {
|
|||||||
public static final String ATTR_TYPE = "t";
|
public static final String ATTR_TYPE = "t";
|
||||||
public static final String TAG_ALLOWED_PACKAGE = "wl";
|
public static final String TAG_ALLOWED_PACKAGE = "wl";
|
||||||
public static final String ATTR_CERTIFICATE = "ct";
|
public static final String ATTR_CERTIFICATE = "ct";
|
||||||
public static final String TAG_ALLOWED_PERMISSION = "ap";
|
|
||||||
|
|
||||||
// For BlobHandle
|
// For BlobHandle
|
||||||
public static final String TAG_BLOB_HANDLE = "bh";
|
public static final String TAG_BLOB_HANDLE = "bh";
|
||||||
@@ -56,7 +55,4 @@ public final class XmlTags {
|
|||||||
public static final String TAG_LEASEE = "l";
|
public static final String TAG_LEASEE = "l";
|
||||||
public static final String ATTR_DESCRIPTION_RES_NAME = "rn";
|
public static final String ATTR_DESCRIPTION_RES_NAME = "rn";
|
||||||
public static final String ATTR_DESCRIPTION = "d";
|
public static final String ATTR_DESCRIPTION = "d";
|
||||||
|
|
||||||
// Generic
|
|
||||||
public static final String ATTR_VALUE = "val";
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -15,30 +15,19 @@
|
|||||||
*/
|
*/
|
||||||
package com.android.server.blob;
|
package com.android.server.blob;
|
||||||
|
|
||||||
import static android.Manifest.permission.ACCESS_COARSE_LOCATION;
|
|
||||||
import static android.Manifest.permission.ACCESS_FINE_LOCATION;
|
|
||||||
import static android.app.blob.XmlTags.ATTR_CERTIFICATE;
|
import static android.app.blob.XmlTags.ATTR_CERTIFICATE;
|
||||||
import static android.app.blob.XmlTags.ATTR_PACKAGE;
|
import static android.app.blob.XmlTags.ATTR_PACKAGE;
|
||||||
import static android.app.blob.XmlTags.ATTR_TYPE;
|
import static android.app.blob.XmlTags.ATTR_TYPE;
|
||||||
import static android.app.blob.XmlTags.ATTR_VALUE;
|
|
||||||
import static android.app.blob.XmlTags.TAG_ALLOWED_PACKAGE;
|
import static android.app.blob.XmlTags.TAG_ALLOWED_PACKAGE;
|
||||||
import static android.app.blob.XmlTags.TAG_ALLOWED_PERMISSION;
|
|
||||||
|
|
||||||
import static com.android.server.blob.BlobStoreConfig.TAG;
|
|
||||||
|
|
||||||
import android.annotation.IntDef;
|
import android.annotation.IntDef;
|
||||||
import android.annotation.NonNull;
|
import android.annotation.NonNull;
|
||||||
import android.annotation.Nullable;
|
|
||||||
import android.app.AppOpsManager;
|
|
||||||
import android.content.Context;
|
import android.content.Context;
|
||||||
import android.content.pm.PackageManager;
|
import android.content.pm.PackageManager;
|
||||||
import android.os.UserHandle;
|
|
||||||
import android.permission.PermissionManager;
|
|
||||||
import android.util.ArraySet;
|
import android.util.ArraySet;
|
||||||
import android.util.Base64;
|
import android.util.Base64;
|
||||||
import android.util.DebugUtils;
|
import android.util.DebugUtils;
|
||||||
import android.util.IndentingPrintWriter;
|
import android.util.IndentingPrintWriter;
|
||||||
import android.util.Slog;
|
|
||||||
|
|
||||||
import com.android.internal.util.XmlUtils;
|
import com.android.internal.util.XmlUtils;
|
||||||
|
|
||||||
@@ -64,27 +53,21 @@ class BlobAccessMode {
|
|||||||
ACCESS_TYPE_PUBLIC,
|
ACCESS_TYPE_PUBLIC,
|
||||||
ACCESS_TYPE_SAME_SIGNATURE,
|
ACCESS_TYPE_SAME_SIGNATURE,
|
||||||
ACCESS_TYPE_ALLOWLIST,
|
ACCESS_TYPE_ALLOWLIST,
|
||||||
ACCESS_TYPE_LOCATION_PERMISSION,
|
|
||||||
})
|
})
|
||||||
@interface AccessType {}
|
@interface AccessType {}
|
||||||
public static final int ACCESS_TYPE_PRIVATE = 1 << 0;
|
public static final int ACCESS_TYPE_PRIVATE = 1 << 0;
|
||||||
public static final int ACCESS_TYPE_PUBLIC = 1 << 1;
|
public static final int ACCESS_TYPE_PUBLIC = 1 << 1;
|
||||||
public static final int ACCESS_TYPE_SAME_SIGNATURE = 1 << 2;
|
public static final int ACCESS_TYPE_SAME_SIGNATURE = 1 << 2;
|
||||||
public static final int ACCESS_TYPE_ALLOWLIST = 1 << 3;
|
public static final int ACCESS_TYPE_ALLOWLIST = 1 << 3;
|
||||||
public static final int ACCESS_TYPE_LOCATION_PERMISSION = 1 << 4;
|
|
||||||
|
|
||||||
private int mAccessType = ACCESS_TYPE_PRIVATE;
|
private int mAccessType = ACCESS_TYPE_PRIVATE;
|
||||||
|
|
||||||
private final ArraySet<PackageIdentifier> mAllowedPackages = new ArraySet<>();
|
private final ArraySet<PackageIdentifier> mAllowedPackages = new ArraySet<>();
|
||||||
private final ArraySet<String> mAllowedPermissions = new ArraySet<>();
|
|
||||||
|
|
||||||
void allow(BlobAccessMode other) {
|
void allow(BlobAccessMode other) {
|
||||||
if ((other.mAccessType & ACCESS_TYPE_ALLOWLIST) != 0) {
|
if ((other.mAccessType & ACCESS_TYPE_ALLOWLIST) != 0) {
|
||||||
mAllowedPackages.addAll(other.mAllowedPackages);
|
mAllowedPackages.addAll(other.mAllowedPackages);
|
||||||
}
|
}
|
||||||
if ((other.mAccessType & ACCESS_TYPE_LOCATION_PERMISSION) != 0) {
|
|
||||||
mAllowedPermissions.addAll(other.mAllowedPermissions);
|
|
||||||
}
|
|
||||||
mAccessType |= other.mAccessType;
|
mAccessType |= other.mAccessType;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -101,11 +84,6 @@ class BlobAccessMode {
|
|||||||
mAllowedPackages.add(PackageIdentifier.create(packageName, certificate));
|
mAllowedPackages.add(PackageIdentifier.create(packageName, certificate));
|
||||||
}
|
}
|
||||||
|
|
||||||
void allowPackagesWithLocationPermission(@NonNull String permissionName) {
|
|
||||||
mAccessType |= ACCESS_TYPE_LOCATION_PERMISSION;
|
|
||||||
mAllowedPermissions.add(permissionName);
|
|
||||||
}
|
|
||||||
|
|
||||||
boolean isPublicAccessAllowed() {
|
boolean isPublicAccessAllowed() {
|
||||||
return (mAccessType & ACCESS_TYPE_PUBLIC) != 0;
|
return (mAccessType & ACCESS_TYPE_PUBLIC) != 0;
|
||||||
}
|
}
|
||||||
@@ -121,15 +99,8 @@ class BlobAccessMode {
|
|||||||
return mAllowedPackages.contains(PackageIdentifier.create(packageName, certificate));
|
return mAllowedPackages.contains(PackageIdentifier.create(packageName, certificate));
|
||||||
}
|
}
|
||||||
|
|
||||||
boolean arePackagesWithLocationPermissionAllowed(@NonNull String permissionName) {
|
boolean isAccessAllowedForCaller(Context context,
|
||||||
if ((mAccessType & ACCESS_TYPE_LOCATION_PERMISSION) == 0) {
|
@NonNull String callingPackage, @NonNull String committerPackage) {
|
||||||
return false;
|
|
||||||
}
|
|
||||||
return mAllowedPermissions.contains(permissionName);
|
|
||||||
}
|
|
||||||
|
|
||||||
boolean isAccessAllowedForCaller(Context context, @NonNull String callingPackage,
|
|
||||||
@NonNull String committerPackage, int callingUid, @Nullable String attributionTag) {
|
|
||||||
if ((mAccessType & ACCESS_TYPE_PUBLIC) != 0) {
|
if ((mAccessType & ACCESS_TYPE_PUBLIC) != 0) {
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
@@ -153,37 +124,9 @@ class BlobAccessMode {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if ((mAccessType & ACCESS_TYPE_LOCATION_PERMISSION) != 0) {
|
|
||||||
final AppOpsManager appOpsManager = context.getSystemService(AppOpsManager.class);
|
|
||||||
for (int i = 0; i < mAllowedPermissions.size(); ++i) {
|
|
||||||
final String permission = mAllowedPermissions.valueAt(i);
|
|
||||||
if (PermissionManager.checkPackageNamePermission(permission, callingPackage,
|
|
||||||
UserHandle.getUserId(callingUid)) != PackageManager.PERMISSION_GRANTED) {
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
// TODO: Add appropriate message
|
|
||||||
if (appOpsManager.noteOpNoThrow(getAppOp(permission), callingUid, callingPackage,
|
|
||||||
attributionTag, null /* message */) == AppOpsManager.MODE_ALLOWED) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
private static String getAppOp(String permission) {
|
|
||||||
switch (permission) {
|
|
||||||
case ACCESS_FINE_LOCATION:
|
|
||||||
return AppOpsManager.OPSTR_FINE_LOCATION;
|
|
||||||
case ACCESS_COARSE_LOCATION:
|
|
||||||
return AppOpsManager.OPSTR_COARSE_LOCATION;
|
|
||||||
default:
|
|
||||||
Slog.w(TAG, "Unknown permission found: " + permission);
|
|
||||||
return null;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
int getAccessType() {
|
int getAccessType() {
|
||||||
return mAccessType;
|
return mAccessType;
|
||||||
}
|
}
|
||||||
@@ -205,16 +148,6 @@ class BlobAccessMode {
|
|||||||
}
|
}
|
||||||
fout.decreaseIndent();
|
fout.decreaseIndent();
|
||||||
}
|
}
|
||||||
fout.print("Allowed permissions:");
|
|
||||||
if (mAllowedPermissions.isEmpty()) {
|
|
||||||
fout.println(" (Empty)");
|
|
||||||
} else {
|
|
||||||
fout.increaseIndent();
|
|
||||||
for (int i = 0, count = mAllowedPermissions.size(); i < count; ++i) {
|
|
||||||
fout.println(mAllowedPermissions.valueAt(i).toString());
|
|
||||||
}
|
|
||||||
fout.decreaseIndent();
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
void writeToXml(@NonNull XmlSerializer out) throws IOException {
|
void writeToXml(@NonNull XmlSerializer out) throws IOException {
|
||||||
@@ -226,12 +159,6 @@ class BlobAccessMode {
|
|||||||
XmlUtils.writeByteArrayAttribute(out, ATTR_CERTIFICATE, packageIdentifier.certificate);
|
XmlUtils.writeByteArrayAttribute(out, ATTR_CERTIFICATE, packageIdentifier.certificate);
|
||||||
out.endTag(null, TAG_ALLOWED_PACKAGE);
|
out.endTag(null, TAG_ALLOWED_PACKAGE);
|
||||||
}
|
}
|
||||||
for (int i = 0, count = mAllowedPermissions.size(); i < count; ++i) {
|
|
||||||
out.startTag(null, TAG_ALLOWED_PERMISSION);
|
|
||||||
final String permission = mAllowedPermissions.valueAt(i);
|
|
||||||
XmlUtils.writeStringAttribute(out, ATTR_VALUE, permission);
|
|
||||||
out.endTag(null, TAG_ALLOWED_PERMISSION);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
@NonNull
|
@NonNull
|
||||||
@@ -249,10 +176,6 @@ class BlobAccessMode {
|
|||||||
final byte[] certificate = XmlUtils.readByteArrayAttribute(in, ATTR_CERTIFICATE);
|
final byte[] certificate = XmlUtils.readByteArrayAttribute(in, ATTR_CERTIFICATE);
|
||||||
blobAccessMode.allowPackageAccess(packageName, certificate);
|
blobAccessMode.allowPackageAccess(packageName, certificate);
|
||||||
}
|
}
|
||||||
if (TAG_ALLOWED_PERMISSION.equals(in.getName())) {
|
|
||||||
final String permission = XmlUtils.readStringAttribute(in, ATTR_VALUE);
|
|
||||||
blobAccessMode.allowPackagesWithLocationPermission(permission);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
return blobAccessMode;
|
return blobAccessMode;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -263,8 +263,7 @@ class BlobMetadata {
|
|||||||
return getBlobFile().length();
|
return getBlobFile().length();
|
||||||
}
|
}
|
||||||
|
|
||||||
boolean isAccessAllowedForCaller(@NonNull String callingPackage, int callingUid,
|
boolean isAccessAllowedForCaller(@NonNull String callingPackage, int callingUid) {
|
||||||
@Nullable String attributionTag) {
|
|
||||||
// Don't allow the blob to be accessed after it's expiry time has passed.
|
// Don't allow the blob to be accessed after it's expiry time has passed.
|
||||||
if (getBlobHandle().isExpired()) {
|
if (getBlobHandle().isExpired()) {
|
||||||
return false;
|
return false;
|
||||||
@@ -293,7 +292,7 @@ class BlobMetadata {
|
|||||||
// Check if the caller is allowed access as per the access mode specified
|
// Check if the caller is allowed access as per the access mode specified
|
||||||
// by the committer.
|
// by the committer.
|
||||||
if (committer.blobAccessMode.isAccessAllowedForCaller(mContext,
|
if (committer.blobAccessMode.isAccessAllowedForCaller(mContext,
|
||||||
callingPackage, committer.packageName, callingUid, attributionTag)) {
|
callingPackage, committer.packageName)) {
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -316,7 +315,7 @@ class BlobMetadata {
|
|||||||
// Check if the caller is allowed access as per the access mode specified
|
// Check if the caller is allowed access as per the access mode specified
|
||||||
// by the committer.
|
// by the committer.
|
||||||
if (committer.blobAccessMode.isAccessAllowedForCaller(mContext,
|
if (committer.blobAccessMode.isAccessAllowedForCaller(mContext,
|
||||||
callingPackage, committer.packageName, callingUid, attributionTag)) {
|
callingPackage, committer.packageName)) {
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -397,11 +397,11 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private ParcelFileDescriptor openBlobInternal(BlobHandle blobHandle, int callingUid,
|
private ParcelFileDescriptor openBlobInternal(BlobHandle blobHandle, int callingUid,
|
||||||
String callingPackage, String attributionTag) throws IOException {
|
String callingPackage) throws IOException {
|
||||||
synchronized (mBlobsLock) {
|
synchronized (mBlobsLock) {
|
||||||
final BlobMetadata blobMetadata = mBlobsMap.get(blobHandle);
|
final BlobMetadata blobMetadata = mBlobsMap.get(blobHandle);
|
||||||
if (blobMetadata == null || !blobMetadata.isAccessAllowedForCaller(
|
if (blobMetadata == null || !blobMetadata.isAccessAllowedForCaller(
|
||||||
callingPackage, callingUid, attributionTag)) {
|
callingPackage, callingUid)) {
|
||||||
if (blobMetadata == null) {
|
if (blobMetadata == null) {
|
||||||
FrameworkStatsLog.write(FrameworkStatsLog.BLOB_OPENED, callingUid,
|
FrameworkStatsLog.write(FrameworkStatsLog.BLOB_OPENED, callingUid,
|
||||||
INVALID_BLOB_ID, INVALID_BLOB_SIZE,
|
INVALID_BLOB_ID, INVALID_BLOB_SIZE,
|
||||||
@@ -449,7 +449,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
|
|
||||||
private void acquireLeaseInternal(BlobHandle blobHandle, int descriptionResId,
|
private void acquireLeaseInternal(BlobHandle blobHandle, int descriptionResId,
|
||||||
CharSequence description, long leaseExpiryTimeMillis,
|
CharSequence description, long leaseExpiryTimeMillis,
|
||||||
int callingUid, String callingPackage, String attributionTag) {
|
int callingUid, String callingPackage) {
|
||||||
synchronized (mBlobsLock) {
|
synchronized (mBlobsLock) {
|
||||||
final int leasesCount = getLeasedBlobsCountLocked(callingUid, callingPackage);
|
final int leasesCount = getLeasedBlobsCountLocked(callingUid, callingPackage);
|
||||||
if (leasesCount >= getMaxLeasedBlobs()) {
|
if (leasesCount >= getMaxLeasedBlobs()) {
|
||||||
@@ -470,7 +470,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
|
|
||||||
final BlobMetadata blobMetadata = mBlobsMap.get(blobHandle);
|
final BlobMetadata blobMetadata = mBlobsMap.get(blobHandle);
|
||||||
if (blobMetadata == null || !blobMetadata.isAccessAllowedForCaller(
|
if (blobMetadata == null || !blobMetadata.isAccessAllowedForCaller(
|
||||||
callingPackage, callingUid, attributionTag)) {
|
callingPackage, callingUid)) {
|
||||||
if (blobMetadata == null) {
|
if (blobMetadata == null) {
|
||||||
FrameworkStatsLog.write(FrameworkStatsLog.BLOB_LEASED, callingUid,
|
FrameworkStatsLog.write(FrameworkStatsLog.BLOB_LEASED, callingUid,
|
||||||
INVALID_BLOB_ID, INVALID_BLOB_SIZE,
|
INVALID_BLOB_ID, INVALID_BLOB_SIZE,
|
||||||
@@ -521,11 +521,11 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private void releaseLeaseInternal(BlobHandle blobHandle, int callingUid,
|
private void releaseLeaseInternal(BlobHandle blobHandle, int callingUid,
|
||||||
String callingPackage, String attributionTag) {
|
String callingPackage) {
|
||||||
synchronized (mBlobsLock) {
|
synchronized (mBlobsLock) {
|
||||||
final BlobMetadata blobMetadata = mBlobsMap.get(blobHandle);
|
final BlobMetadata blobMetadata = mBlobsMap.get(blobHandle);
|
||||||
if (blobMetadata == null || !blobMetadata.isAccessAllowedForCaller(
|
if (blobMetadata == null || !blobMetadata.isAccessAllowedForCaller(
|
||||||
callingPackage, callingUid, attributionTag)) {
|
callingPackage, callingUid)) {
|
||||||
throw new SecurityException("Caller not allowed to access " + blobHandle
|
throw new SecurityException("Caller not allowed to access " + blobHandle
|
||||||
+ "; callingUid=" + callingUid + ", callingPackage=" + callingPackage);
|
+ "; callingUid=" + callingUid + ", callingPackage=" + callingPackage);
|
||||||
}
|
}
|
||||||
@@ -632,11 +632,11 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private LeaseInfo getLeaseInfoInternal(BlobHandle blobHandle,
|
private LeaseInfo getLeaseInfoInternal(BlobHandle blobHandle,
|
||||||
int callingUid, @NonNull String callingPackage, String attributionTag) {
|
int callingUid, @NonNull String callingPackage) {
|
||||||
synchronized (mBlobsLock) {
|
synchronized (mBlobsLock) {
|
||||||
final BlobMetadata blobMetadata = mBlobsMap.get(blobHandle);
|
final BlobMetadata blobMetadata = mBlobsMap.get(blobHandle);
|
||||||
if (blobMetadata == null || !blobMetadata.isAccessAllowedForCaller(
|
if (blobMetadata == null || !blobMetadata.isAccessAllowedForCaller(
|
||||||
callingPackage, callingUid, attributionTag)) {
|
callingPackage, callingUid)) {
|
||||||
throw new SecurityException("Caller not allowed to access " + blobHandle
|
throw new SecurityException("Caller not allowed to access " + blobHandle
|
||||||
+ "; callingUid=" + callingUid + ", callingPackage=" + callingPackage);
|
+ "; callingUid=" + callingUid + ", callingPackage=" + callingPackage);
|
||||||
}
|
}
|
||||||
@@ -1478,7 +1478,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
|
|
||||||
@Override
|
@Override
|
||||||
public ParcelFileDescriptor openBlob(@NonNull BlobHandle blobHandle,
|
public ParcelFileDescriptor openBlob(@NonNull BlobHandle blobHandle,
|
||||||
@NonNull String packageName, @Nullable String attributionTag) {
|
@NonNull String packageName) {
|
||||||
Objects.requireNonNull(blobHandle, "blobHandle must not be null");
|
Objects.requireNonNull(blobHandle, "blobHandle must not be null");
|
||||||
blobHandle.assertIsValid();
|
blobHandle.assertIsValid();
|
||||||
Objects.requireNonNull(packageName, "packageName must not be null");
|
Objects.requireNonNull(packageName, "packageName must not be null");
|
||||||
@@ -1493,7 +1493,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
return openBlobInternal(blobHandle, callingUid, packageName, attributionTag);
|
return openBlobInternal(blobHandle, callingUid, packageName);
|
||||||
} catch (IOException e) {
|
} catch (IOException e) {
|
||||||
throw ExceptionUtils.wrap(e);
|
throw ExceptionUtils.wrap(e);
|
||||||
}
|
}
|
||||||
@@ -1502,8 +1502,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
@Override
|
@Override
|
||||||
public void acquireLease(@NonNull BlobHandle blobHandle, @IdRes int descriptionResId,
|
public void acquireLease(@NonNull BlobHandle blobHandle, @IdRes int descriptionResId,
|
||||||
@Nullable CharSequence description,
|
@Nullable CharSequence description,
|
||||||
@CurrentTimeSecondsLong long leaseExpiryTimeMillis, @NonNull String packageName,
|
@CurrentTimeSecondsLong long leaseExpiryTimeMillis, @NonNull String packageName) {
|
||||||
@Nullable String attributionTag) {
|
|
||||||
Objects.requireNonNull(blobHandle, "blobHandle must not be null");
|
Objects.requireNonNull(blobHandle, "blobHandle must not be null");
|
||||||
blobHandle.assertIsValid();
|
blobHandle.assertIsValid();
|
||||||
Preconditions.checkArgument(
|
Preconditions.checkArgument(
|
||||||
@@ -1527,7 +1526,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
|
|
||||||
try {
|
try {
|
||||||
acquireLeaseInternal(blobHandle, descriptionResId, description,
|
acquireLeaseInternal(blobHandle, descriptionResId, description,
|
||||||
leaseExpiryTimeMillis, callingUid, packageName, attributionTag);
|
leaseExpiryTimeMillis, callingUid, packageName);
|
||||||
} catch (Resources.NotFoundException e) {
|
} catch (Resources.NotFoundException e) {
|
||||||
throw new IllegalArgumentException(e);
|
throw new IllegalArgumentException(e);
|
||||||
} catch (LimitExceededException e) {
|
} catch (LimitExceededException e) {
|
||||||
@@ -1536,8 +1535,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public void releaseLease(@NonNull BlobHandle blobHandle, @NonNull String packageName,
|
public void releaseLease(@NonNull BlobHandle blobHandle, @NonNull String packageName) {
|
||||||
@Nullable String attributionTag) {
|
|
||||||
Objects.requireNonNull(blobHandle, "blobHandle must not be null");
|
Objects.requireNonNull(blobHandle, "blobHandle must not be null");
|
||||||
blobHandle.assertIsValid();
|
blobHandle.assertIsValid();
|
||||||
Objects.requireNonNull(packageName, "packageName must not be null");
|
Objects.requireNonNull(packageName, "packageName must not be null");
|
||||||
@@ -1551,7 +1549,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
+ "callingUid=" + callingUid + ", callingPackage=" + packageName);
|
+ "callingUid=" + callingUid + ", callingPackage=" + packageName);
|
||||||
}
|
}
|
||||||
|
|
||||||
releaseLeaseInternal(blobHandle, callingUid, packageName, attributionTag);
|
releaseLeaseInternal(blobHandle, callingUid, packageName);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
@@ -1621,8 +1619,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
|
|
||||||
@Override
|
@Override
|
||||||
@Nullable
|
@Nullable
|
||||||
public LeaseInfo getLeaseInfo(@NonNull BlobHandle blobHandle, @NonNull String packageName,
|
public LeaseInfo getLeaseInfo(@NonNull BlobHandle blobHandle, @NonNull String packageName) {
|
||||||
@Nullable String attributionTag) {
|
|
||||||
Objects.requireNonNull(blobHandle, "blobHandle must not be null");
|
Objects.requireNonNull(blobHandle, "blobHandle must not be null");
|
||||||
blobHandle.assertIsValid();
|
blobHandle.assertIsValid();
|
||||||
Objects.requireNonNull(packageName, "packageName must not be null");
|
Objects.requireNonNull(packageName, "packageName must not be null");
|
||||||
@@ -1636,7 +1633,7 @@ public class BlobStoreManagerService extends SystemService {
|
|||||||
+ "callingUid=" + callingUid + ", callingPackage=" + packageName);
|
+ "callingUid=" + callingUid + ", callingPackage=" + packageName);
|
||||||
}
|
}
|
||||||
|
|
||||||
return getLeaseInfoInternal(blobHandle, callingUid, packageName, attributionTag);
|
return getLeaseInfoInternal(blobHandle, callingUid, packageName);
|
||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
|
|||||||
@@ -15,8 +15,6 @@
|
|||||||
*/
|
*/
|
||||||
package com.android.server.blob;
|
package com.android.server.blob;
|
||||||
|
|
||||||
import static android.Manifest.permission.ACCESS_COARSE_LOCATION;
|
|
||||||
import static android.Manifest.permission.ACCESS_FINE_LOCATION;
|
|
||||||
import static android.app.blob.BlobStoreManager.COMMIT_RESULT_ERROR;
|
import static android.app.blob.BlobStoreManager.COMMIT_RESULT_ERROR;
|
||||||
import static android.app.blob.XmlTags.ATTR_CREATION_TIME_MS;
|
import static android.app.blob.XmlTags.ATTR_CREATION_TIME_MS;
|
||||||
import static android.app.blob.XmlTags.ATTR_ID;
|
import static android.app.blob.XmlTags.ATTR_ID;
|
||||||
@@ -367,21 +365,6 @@ class BlobStoreSession extends IBlobStoreSession.Stub {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
|
||||||
public void allowPackagesWithLocationPermission(@NonNull String permissionName) {
|
|
||||||
assertCallerIsOwner();
|
|
||||||
Preconditions.checkArgument(ACCESS_FINE_LOCATION.equals(permissionName)
|
|
||||||
|| ACCESS_COARSE_LOCATION.equals(permissionName),
|
|
||||||
"permissionName is unknown: " + permissionName);
|
|
||||||
synchronized (mSessionLock) {
|
|
||||||
if (mState != STATE_OPENED) {
|
|
||||||
throw new IllegalStateException("Not allowed to change access type in state: "
|
|
||||||
+ stateToString(mState));
|
|
||||||
}
|
|
||||||
mBlobAccessMode.allowPackagesWithLocationPermission(permissionName);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public boolean isPackageAccessAllowed(@NonNull String packageName,
|
public boolean isPackageAccessAllowed(@NonNull String packageName,
|
||||||
@NonNull byte[] certificate) {
|
@NonNull byte[] certificate) {
|
||||||
@@ -422,21 +405,6 @@ class BlobStoreSession extends IBlobStoreSession.Stub {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
|
||||||
public boolean arePackagesWithLocationPermissionAllowed(@NonNull String permissionName) {
|
|
||||||
assertCallerIsOwner();
|
|
||||||
Preconditions.checkArgument(ACCESS_FINE_LOCATION.equals(permissionName)
|
|
||||||
|| ACCESS_COARSE_LOCATION.equals(permissionName),
|
|
||||||
"permissionName is unknown: " + permissionName);
|
|
||||||
synchronized (mSessionLock) {
|
|
||||||
if (mState != STATE_OPENED) {
|
|
||||||
throw new IllegalStateException("Not allowed to change access type in state: "
|
|
||||||
+ stateToString(mState));
|
|
||||||
}
|
|
||||||
return mBlobAccessMode.arePackagesWithLocationPermissionAllowed(permissionName);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
public void close() {
|
public void close() {
|
||||||
closeSession(STATE_CLOSED, false /* sendCallback */);
|
closeSession(STATE_CLOSED, false /* sendCallback */);
|
||||||
|
|||||||
@@ -7905,10 +7905,8 @@ package android.app.blob {
|
|||||||
public static class BlobStoreManager.Session implements java.io.Closeable {
|
public static class BlobStoreManager.Session implements java.io.Closeable {
|
||||||
method public void abandon() throws java.io.IOException;
|
method public void abandon() throws java.io.IOException;
|
||||||
method public void allowPackageAccess(@NonNull String, @NonNull byte[]) throws java.io.IOException;
|
method public void allowPackageAccess(@NonNull String, @NonNull byte[]) throws java.io.IOException;
|
||||||
method public void allowPackagesWithLocationPermission(@NonNull String) throws java.io.IOException;
|
|
||||||
method public void allowPublicAccess() throws java.io.IOException;
|
method public void allowPublicAccess() throws java.io.IOException;
|
||||||
method public void allowSameSignatureAccess() throws java.io.IOException;
|
method public void allowSameSignatureAccess() throws java.io.IOException;
|
||||||
method public boolean arePackagesWithLocationPermissionAllowed(@NonNull String) throws java.io.IOException;
|
|
||||||
method public void close() throws java.io.IOException;
|
method public void close() throws java.io.IOException;
|
||||||
method public void commit(@NonNull java.util.concurrent.Executor, @NonNull java.util.function.Consumer<java.lang.Integer>) throws java.io.IOException;
|
method public void commit(@NonNull java.util.concurrent.Executor, @NonNull java.util.function.Consumer<java.lang.Integer>) throws java.io.IOException;
|
||||||
method public long getSize() throws java.io.IOException;
|
method public long getSize() throws java.io.IOException;
|
||||||
|
|||||||
Reference in New Issue
Block a user