Merge "Check if fuse enabled before mounting storage data and obb dirs" into rvc-dev am: bcc707d44c
Change-Id: I5951d1b5a33133e3485f530b7794867a1a90d297
This commit is contained in:
@@ -1653,7 +1653,9 @@ static void SpecializeCommon(JNIEnv* env, uid_t uid, gid_t gid, jintArray gids,
|
|||||||
uid, process_name, managed_nice_name, fail_fn);
|
uid, process_name, managed_nice_name, fail_fn);
|
||||||
isolateJitProfile(env, pkg_data_info_list, uid, process_name, managed_nice_name, fail_fn);
|
isolateJitProfile(env, pkg_data_info_list, uid, process_name, managed_nice_name, fail_fn);
|
||||||
}
|
}
|
||||||
if ((mount_external != MOUNT_EXTERNAL_INSTALLER) && mount_storage_dirs) {
|
if (mount_external != MOUNT_EXTERNAL_INSTALLER &&
|
||||||
|
mount_external != MOUNT_EXTERNAL_PASS_THROUGH &&
|
||||||
|
mount_storage_dirs) {
|
||||||
BindMountStorageDirs(env, pkg_data_info_list, uid, process_name, managed_nice_name, fail_fn);
|
BindMountStorageDirs(env, pkg_data_info_list, uid, process_name, managed_nice_name, fail_fn);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -220,6 +220,10 @@ class StorageManagerService extends IStorageManager.Stub
|
|||||||
|
|
||||||
private static final boolean ENABLE_ISOLATED_STORAGE = StorageManager.hasIsolatedStorage();
|
private static final boolean ENABLE_ISOLATED_STORAGE = StorageManager.hasIsolatedStorage();
|
||||||
|
|
||||||
|
// A system property to control if obb app data isolation is enabled in vold.
|
||||||
|
private static final String ANDROID_VOLD_APP_DATA_ISOLATION_ENABLED_PROPERTY =
|
||||||
|
"persist.sys.vold_app_data_isolation_enabled";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* If {@code 1}, enables the isolated storage feature. If {@code -1},
|
* If {@code 1}, enables the isolated storage feature. If {@code -1},
|
||||||
* disables the isolated storage feature. If {@code 0}, uses the default
|
* disables the isolated storage feature. If {@code 0}, uses the default
|
||||||
@@ -596,6 +600,8 @@ class StorageManagerService extends IStorageManager.Stub
|
|||||||
|
|
||||||
private final boolean mIsFuseEnabled;
|
private final boolean mIsFuseEnabled;
|
||||||
|
|
||||||
|
private final boolean mVoldAppDataIsolationEnabled;
|
||||||
|
|
||||||
@GuardedBy("mLock")
|
@GuardedBy("mLock")
|
||||||
private final Set<Integer> mUidsWithLegacyExternalStorage = new ArraySet<>();
|
private final Set<Integer> mUidsWithLegacyExternalStorage = new ArraySet<>();
|
||||||
// Not guarded by lock, always used on the ActivityManager thread
|
// Not guarded by lock, always used on the ActivityManager thread
|
||||||
@@ -1516,7 +1522,7 @@ class StorageManagerService extends IStorageManager.Stub
|
|||||||
if (vol.type == VolumeInfo.TYPE_EMULATED) {
|
if (vol.type == VolumeInfo.TYPE_EMULATED) {
|
||||||
if (newState != VolumeInfo.STATE_MOUNTED) {
|
if (newState != VolumeInfo.STATE_MOUNTED) {
|
||||||
mFuseMountedUser.remove(vol.getMountUserId());
|
mFuseMountedUser.remove(vol.getMountUserId());
|
||||||
} else {
|
} else if (mVoldAppDataIsolationEnabled){
|
||||||
final int userId = vol.getMountUserId();
|
final int userId = vol.getMountUserId();
|
||||||
mFuseMountedUser.add(userId);
|
mFuseMountedUser.add(userId);
|
||||||
// Async remount app storage so it won't block the main thread.
|
// Async remount app storage so it won't block the main thread.
|
||||||
@@ -1740,6 +1746,8 @@ class StorageManagerService extends IStorageManager.Stub
|
|||||||
// incorrect until #updateFusePropFromSettings where we set the correct value and reboot if
|
// incorrect until #updateFusePropFromSettings where we set the correct value and reboot if
|
||||||
// different
|
// different
|
||||||
mIsFuseEnabled = SystemProperties.getBoolean(PROP_FUSE, DEFAULT_FUSE_ENABLED);
|
mIsFuseEnabled = SystemProperties.getBoolean(PROP_FUSE, DEFAULT_FUSE_ENABLED);
|
||||||
|
mVoldAppDataIsolationEnabled = mIsFuseEnabled && SystemProperties.getBoolean(
|
||||||
|
ANDROID_VOLD_APP_DATA_ISOLATION_ENABLED_PROPERTY, false);
|
||||||
mContext = context;
|
mContext = context;
|
||||||
mResolver = mContext.getContentResolver();
|
mResolver = mContext.getContentResolver();
|
||||||
mCallbacks = new Callbacks(FgThread.get().getLooper());
|
mCallbacks = new Callbacks(FgThread.get().getLooper());
|
||||||
|
|||||||
@@ -154,6 +154,9 @@ public final class ProcessList {
|
|||||||
static final String ANDROID_VOLD_APP_DATA_ISOLATION_ENABLED_PROPERTY =
|
static final String ANDROID_VOLD_APP_DATA_ISOLATION_ENABLED_PROPERTY =
|
||||||
"persist.sys.vold_app_data_isolation_enabled";
|
"persist.sys.vold_app_data_isolation_enabled";
|
||||||
|
|
||||||
|
// A system property to control if fuse is enabled.
|
||||||
|
static final String ANDROID_FUSE_ENABLED = "persist.sys.fuse";
|
||||||
|
|
||||||
// The minimum time we allow between crashes, for us to consider this
|
// The minimum time we allow between crashes, for us to consider this
|
||||||
// application to be bad and stop and its services and reject broadcasts.
|
// application to be bad and stop and its services and reject broadcasts.
|
||||||
static final int MIN_CRASH_INTERVAL = 60 * 1000;
|
static final int MIN_CRASH_INTERVAL = 60 * 1000;
|
||||||
@@ -707,8 +710,13 @@ public final class ProcessList {
|
|||||||
// want some apps enabled while some apps disabled
|
// want some apps enabled while some apps disabled
|
||||||
mAppDataIsolationEnabled =
|
mAppDataIsolationEnabled =
|
||||||
SystemProperties.getBoolean(ANDROID_APP_DATA_ISOLATION_ENABLED_PROPERTY, true);
|
SystemProperties.getBoolean(ANDROID_APP_DATA_ISOLATION_ENABLED_PROPERTY, true);
|
||||||
mVoldAppDataIsolationEnabled = SystemProperties.getBoolean(
|
boolean fuseEnabled = SystemProperties.getBoolean(ANDROID_FUSE_ENABLED, false);
|
||||||
|
boolean voldAppDataIsolationEnabled = SystemProperties.getBoolean(
|
||||||
ANDROID_VOLD_APP_DATA_ISOLATION_ENABLED_PROPERTY, false);
|
ANDROID_VOLD_APP_DATA_ISOLATION_ENABLED_PROPERTY, false);
|
||||||
|
if (!fuseEnabled && voldAppDataIsolationEnabled) {
|
||||||
|
Slog.e(TAG, "Fuse is not enabled while vold app data isolation is enabled");
|
||||||
|
}
|
||||||
|
mVoldAppDataIsolationEnabled = fuseEnabled && voldAppDataIsolationEnabled;
|
||||||
mAppDataIsolationWhitelistedApps = new ArrayList<>(
|
mAppDataIsolationWhitelistedApps = new ArrayList<>(
|
||||||
SystemConfig.getInstance().getAppDataIsolationWhitelistedApps());
|
SystemConfig.getInstance().getAppDataIsolationWhitelistedApps());
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user