Merge "Log when enforceActor fails" into sc-dev

This commit is contained in:
Ryan Mitchell
2021-02-18 16:00:33 +00:00
committed by Android (Google) Code Review

View File

@@ -23,6 +23,7 @@ import android.net.Uri;
import android.os.Process; import android.os.Process;
import android.text.TextUtils; import android.text.TextUtils;
import android.util.Pair; import android.util.Pair;
import android.util.Slog;
import com.android.internal.annotations.VisibleForTesting; import com.android.internal.annotations.VisibleForTesting;
import com.android.internal.util.ArrayUtils; import com.android.internal.util.ArrayUtils;
@@ -42,9 +43,6 @@ import java.util.Map;
*/ */
public class OverlayActorEnforcer { public class OverlayActorEnforcer {
// By default, the reason is not logged to prevent leaks of why it failed
private static final boolean DEBUG_REASON = false;
private final PackageManagerHelper mPackageManager; private final PackageManagerHelper mPackageManager;
/** /**
@@ -85,17 +83,18 @@ public class OverlayActorEnforcer {
void enforceActor(@NonNull OverlayInfo overlayInfo, @NonNull String methodName, void enforceActor(@NonNull OverlayInfo overlayInfo, @NonNull String methodName,
int callingUid, int userId) throws SecurityException { int callingUid, int userId) throws SecurityException {
ActorState actorState = isAllowedActor(methodName, overlayInfo, callingUid, userId); final ActorState actorState = isAllowedActor(methodName, overlayInfo, callingUid, userId);
if (actorState == ActorState.ALLOWED) { if (actorState == ActorState.ALLOWED) {
return; return;
} }
String targetOverlayableName = overlayInfo.targetOverlayableName; final String targetOverlayableName = overlayInfo.targetOverlayableName;
throw new SecurityException("UID" + callingUid + " is not allowed to call " final String errorMessage = "UID" + callingUid + " is not allowed to call " + methodName
+ methodName + " for " + " for "
+ (TextUtils.isEmpty(targetOverlayableName) ? "" : (targetOverlayableName + " in ")) + (TextUtils.isEmpty(targetOverlayableName) ? "" : (targetOverlayableName + " in "))
+ overlayInfo.targetPackageName + (DEBUG_REASON ? (" because " + actorState) : "") + overlayInfo.targetPackageName + " for user " + userId;
); Slog.w(OverlayManagerService.TAG, errorMessage + " because " + actorState);
throw new SecurityException(errorMessage);
} }
/** /**