From 6c28c614ef83dc8a39fc96cdfe3947104edee468 Mon Sep 17 00:00:00 2001 From: Joanne Chung Date: Tue, 9 May 2023 21:33:02 +0800 Subject: [PATCH] Allow update owner to access InstallConstraints APIs An app may not have an installer of record, but could have an update owner, the API should make it honour the update owner. Bug: 280724094 Test: atest InstallConstraintsTest Test: manual. Local comment out the installer name check and CTS test sets with para.setRequestUpdateOwnership(true) and run test. Change-Id: I4ed9c3802df581608766908d5385d5f8e1e925a8 --- .../android/server/pm/PackageInstallerService.java | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/services/core/java/com/android/server/pm/PackageInstallerService.java b/services/core/java/com/android/server/pm/PackageInstallerService.java index 1721f83538ff4..2403c4ae3454f 100644 --- a/services/core/java/com/android/server/pm/PackageInstallerService.java +++ b/services/core/java/com/android/server/pm/PackageInstallerService.java @@ -104,6 +104,7 @@ import com.android.server.SystemConfig; import com.android.server.SystemService; import com.android.server.SystemServiceManager; import com.android.server.pm.parsing.PackageParser2; +import com.android.server.pm.pkg.PackageStateInternal; import com.android.server.pm.utils.RequestThrottle; import libcore.io.IoUtils; @@ -1308,6 +1309,13 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements } } + private boolean isValidForInstallConstraints(PackageStateInternal ps, + String installerPackageName) { + return TextUtils.equals(ps.getInstallSource().mInstallerPackageName, installerPackageName) + || TextUtils.equals(ps.getInstallSource().mUpdateOwnerPackageName, + installerPackageName); + } + private CompletableFuture checkInstallConstraintsInternal( String installerPackageName, List packageNames, InstallConstraints constraints, long timeoutMillis) { @@ -1319,8 +1327,7 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements if (!PackageManagerServiceUtils.isSystemOrRootOrShell(callingUid)) { for (var packageName : packageNames) { var ps = snapshot.getPackageStateInternal(packageName); - if (ps == null || !TextUtils.equals( - ps.getInstallSource().mInstallerPackageName, installerPackageName)) { + if (ps == null || !isValidForInstallConstraints(ps, installerPackageName)) { throw new SecurityException("Caller has no access to package " + packageName); } }