Merge "TEMP add more logging for SecurityExceptions in PermissionChecker"

This commit is contained in:
Nate Myren
2021-09-13 16:11:58 +00:00
committed by Android (Google) Code Review
2 changed files with 39 additions and 9 deletions

View File

@@ -4562,8 +4562,9 @@ public class AppOpsService extends IAppOpsService.Stub {
}
if (pkgUid != Process.INVALID_UID) {
if (pkgUid != UserHandle.getAppId(uid)) {
String otherUidMessage = DEBUG ? " but it is really " + pkgUid : " but it is not";
throw new SecurityException("Specified package " + packageName + " under uid "
//TODO 195339480: replace true with debug
String otherUidMessage = true ? " but it is really " + pkgUid : " but it is not";
throw new SecurityException("Specified package \"" + packageName + "\" under uid "
+ UserHandle.getAppId(uid) + otherUidMessage);
}
return new PackageVerificationResult(RestrictionBypass.UNRESTRICTED,
@@ -4618,8 +4619,9 @@ public class AppOpsService extends IAppOpsService.Stub {
}
if (pkgUid != uid) {
String otherUidMessage = DEBUG ? " but it is really " + pkgUid : " but it is not";
throw new SecurityException("Specified package " + packageName + " under uid " + uid
//TODO 195339480: replace true with debug
String otherUidMessage = true ? " but it is really " + pkgUid : " but it is not";
throw new SecurityException("Specified package \"" + packageName + "\" under uid " + uid
+ otherUidMessage);
}

View File

@@ -6131,9 +6131,23 @@ public class PermissionManagerService extends IPermissionManager.Stub {
proxyAttributionFlags, proxiedAttributionFlags, attributionChainId);
}
} else {
startedOpResult = appOpsManager.startProxyOpNoThrow(startedOp,
resolvedAttributionSource, message, skipProxyOperation,
proxyAttributionFlags, proxiedAttributionFlags, attributionChainId);
try {
startedOpResult = appOpsManager.startProxyOpNoThrow(startedOp,
resolvedAttributionSource, message, skipProxyOperation,
proxyAttributionFlags, proxiedAttributionFlags, attributionChainId);
} catch (SecurityException e) {
//TODO 195339480: remove
String msg = "Security exception for op " + startedOp + " with source "
+ attributionSource.getUid() + ":"
+ attributionSource.getPackageName() + ", "
+ attributionSource.getNextUid() + ":"
+ attributionSource.getNextPackageName();
if (attributionSource.getNext() != null) {
AttributionSource next = attributionSource.getNext();
msg = msg + ", " + next.getNextPackageName() + ":" + next.getNextUid();
}
throw new SecurityException(msg + ":" + e.getMessage());
}
}
return Math.max(checkedOpResult, startedOpResult);
} else {
@@ -6180,8 +6194,22 @@ public class PermissionManagerService extends IPermissionManager.Stub {
message, skipProxyOperation);
}
} else {
notedOpResult = appOpsManager.noteProxyOpNoThrow(notedOp,
resolvedAttributionSource, message, skipProxyOperation);
try {
notedOpResult = appOpsManager.noteProxyOpNoThrow(notedOp,
resolvedAttributionSource, message, skipProxyOperation);
} catch (SecurityException e) {
//TODO 195339480: remove
String msg = "Security exception for op " + notedOp + " with source "
+ attributionSource.getUid() + ":"
+ attributionSource.getPackageName() + ", "
+ attributionSource.getNextUid() + ":"
+ attributionSource.getNextPackageName();
if (attributionSource.getNext() != null) {
AttributionSource next = attributionSource.getNext();
msg = msg + ", " + next.getNextPackageName() + ":" + next.getNextUid();
}
throw new SecurityException(msg + ":" + e.getMessage());
}
}
return Math.max(checkedOpResult, notedOpResult);
}