Merge "Check that only allowed installers can perform a non-staged APEX update" into sc-dev
This commit is contained in:
@@ -653,13 +653,20 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (params.isStaged && !isCalledBySystemOrShell(callingUid)) {
|
if (params.isStaged && !isCalledBySystemOrShell(callingUid)) {
|
||||||
if (mBypassNextStagedInstallerCheck) {
|
if (!mBypassNextStagedInstallerCheck
|
||||||
mBypassNextStagedInstallerCheck = false;
|
&& !isStagedInstallerAllowed(requestedInstallerPackageName)) {
|
||||||
} else if (!isStagedInstallerAllowed(requestedInstallerPackageName)) {
|
|
||||||
throw new SecurityException("Installer not allowed to commit staged install");
|
throw new SecurityException("Installer not allowed to commit staged install");
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
if (isApex && !isCalledBySystemOrShell(callingUid)) {
|
||||||
|
if (!mBypassNextStagedInstallerCheck
|
||||||
|
&& !isStagedInstallerAllowed(requestedInstallerPackageName)) {
|
||||||
|
throw new SecurityException(
|
||||||
|
"Installer not allowed to commit non-staged APEX install");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
mBypassNextStagedInstallerCheck = false;
|
||||||
if (!params.isMultiPackage) {
|
if (!params.isMultiPackage) {
|
||||||
// Only system components can circumvent runtime permissions when installing.
|
// Only system components can circumvent runtime permissions when installing.
|
||||||
if ((params.installFlags & PackageManager.INSTALL_GRANT_RUNTIME_PERMISSIONS) != 0
|
if ((params.installFlags & PackageManager.INSTALL_GRANT_RUNTIME_PERMISSIONS) != 0
|
||||||
|
|||||||
Reference in New Issue
Block a user