Merge "Only allow access to the dexopt commands from root or shell." into udc-dev

This commit is contained in:
Martin Stjernholm
2023-02-27 20:44:36 +00:00
committed by Android (Google) Code Review
2 changed files with 5 additions and 8 deletions

View File

@@ -6675,15 +6675,7 @@ public class PackageManagerService implements PackageSender, TestUtilityService
@Deprecated
public void legacyDumpProfiles(String packageName, boolean dumpClassesAndMethods)
throws LegacyDexoptDisabledException {
/* Only the shell, root, or the app user should be able to dump profiles. */
final int callingUid = Binder.getCallingUid();
final Computer snapshot = snapshotComputer();
final String[] callerPackageNames = snapshot.getPackagesForUid(callingUid);
if (!PackageManagerServiceUtils.isRootOrShell(callingUid)
&& !ArrayUtils.contains(callerPackageNames, packageName)) {
throw new SecurityException("dumpProfiles");
}
AndroidPackage pkg = snapshot.getPackage(packageName);
if (pkg == null) {
throw new IllegalArgumentException("Unknown package: " + packageName);

View File

@@ -391,6 +391,11 @@ class PackageManagerShellCommand extends ShellCommand {
private int runLegacyDexoptCommand(@NonNull String cmd)
throws RemoteException, LegacyDexoptDisabledException {
Installer.checkLegacyDexoptDisabled();
if (!PackageManagerServiceUtils.isRootOrShell(Binder.getCallingUid())) {
throw new SecurityException("Dexopt shell commands need root or shell access");
}
switch (cmd) {
case "compile":
return runCompile();