From 2cce3fd8abac6cfac55f8e8ae3f652110068f0c6 Mon Sep 17 00:00:00 2001 From: Nate Myren Date: Fri, 10 Sep 2021 11:08:45 -0700 Subject: [PATCH] TEMP add more logging for SecurityExceptions in PermissionChecker Bug: 195339480 Test: build Change-Id: I3bc45878f1d4dfcc58d787a4a14ebbcf1fd5a905 --- .../android/server/appop/AppOpsService.java | 10 +++-- .../permission/PermissionManagerService.java | 38 ++++++++++++++++--- 2 files changed, 39 insertions(+), 9 deletions(-) diff --git a/services/core/java/com/android/server/appop/AppOpsService.java b/services/core/java/com/android/server/appop/AppOpsService.java index cfd2978d7eebd..fe6a5a3de3308 100644 --- a/services/core/java/com/android/server/appop/AppOpsService.java +++ b/services/core/java/com/android/server/appop/AppOpsService.java @@ -4562,8 +4562,9 @@ public class AppOpsService extends IAppOpsService.Stub { } if (pkgUid != Process.INVALID_UID) { if (pkgUid != UserHandle.getAppId(uid)) { - String otherUidMessage = DEBUG ? " but it is really " + pkgUid : " but it is not"; - throw new SecurityException("Specified package " + packageName + " under uid " + //TODO 195339480: replace true with debug + String otherUidMessage = true ? " but it is really " + pkgUid : " but it is not"; + throw new SecurityException("Specified package \"" + packageName + "\" under uid " + UserHandle.getAppId(uid) + otherUidMessage); } return new PackageVerificationResult(RestrictionBypass.UNRESTRICTED, @@ -4618,8 +4619,9 @@ public class AppOpsService extends IAppOpsService.Stub { } if (pkgUid != uid) { - String otherUidMessage = DEBUG ? " but it is really " + pkgUid : " but it is not"; - throw new SecurityException("Specified package " + packageName + " under uid " + uid + //TODO 195339480: replace true with debug + String otherUidMessage = true ? " but it is really " + pkgUid : " but it is not"; + throw new SecurityException("Specified package \"" + packageName + "\" under uid " + uid + otherUidMessage); } diff --git a/services/core/java/com/android/server/pm/permission/PermissionManagerService.java b/services/core/java/com/android/server/pm/permission/PermissionManagerService.java index 74497f72ff211..32a69c14ad407 100644 --- a/services/core/java/com/android/server/pm/permission/PermissionManagerService.java +++ b/services/core/java/com/android/server/pm/permission/PermissionManagerService.java @@ -6120,9 +6120,23 @@ public class PermissionManagerService extends IPermissionManager.Stub { proxyAttributionFlags, proxiedAttributionFlags, attributionChainId); } } else { - startedOpResult = appOpsManager.startProxyOpNoThrow(startedOp, - resolvedAttributionSource, message, skipProxyOperation, - proxyAttributionFlags, proxiedAttributionFlags, attributionChainId); + try { + startedOpResult = appOpsManager.startProxyOpNoThrow(startedOp, + resolvedAttributionSource, message, skipProxyOperation, + proxyAttributionFlags, proxiedAttributionFlags, attributionChainId); + } catch (SecurityException e) { + //TODO 195339480: remove + String msg = "Security exception for op " + startedOp + " with source " + + attributionSource.getUid() + ":" + + attributionSource.getPackageName() + ", " + + attributionSource.getNextUid() + ":" + + attributionSource.getNextPackageName(); + if (attributionSource.getNext() != null) { + AttributionSource next = attributionSource.getNext(); + msg = msg + ", " + next.getNextPackageName() + ":" + next.getNextUid(); + } + throw new SecurityException(msg + ":" + e.getMessage()); + } } return Math.max(checkedOpResult, startedOpResult); } else { @@ -6169,8 +6183,22 @@ public class PermissionManagerService extends IPermissionManager.Stub { message, skipProxyOperation); } } else { - notedOpResult = appOpsManager.noteProxyOpNoThrow(notedOp, - resolvedAttributionSource, message, skipProxyOperation); + try { + notedOpResult = appOpsManager.noteProxyOpNoThrow(notedOp, + resolvedAttributionSource, message, skipProxyOperation); + } catch (SecurityException e) { + //TODO 195339480: remove + String msg = "Security exception for op " + notedOp + " with source " + + attributionSource.getUid() + ":" + + attributionSource.getPackageName() + ", " + + attributionSource.getNextUid() + ":" + + attributionSource.getNextPackageName(); + if (attributionSource.getNext() != null) { + AttributionSource next = attributionSource.getNext(); + msg = msg + ", " + next.getNextPackageName() + ":" + next.getNextUid(); + } + throw new SecurityException(msg + ":" + e.getMessage()); + } } return Math.max(checkedOpResult, notedOpResult); }