Merge "Allow update owner to access InstallConstraints APIs" into udc-dev am: 08d9484b49

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/23109997

Change-Id: I9e20ef1ac91a8731c883dd7fcb3d596f4d97fbcf
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Joanne Chung
2023-05-11 11:53:36 +00:00
committed by Automerger Merge Worker

View File

@@ -104,6 +104,7 @@ import com.android.server.SystemConfig;
import com.android.server.SystemService;
import com.android.server.SystemServiceManager;
import com.android.server.pm.parsing.PackageParser2;
import com.android.server.pm.pkg.PackageStateInternal;
import com.android.server.pm.utils.RequestThrottle;
import libcore.io.IoUtils;
@@ -1308,6 +1309,13 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements
}
}
private boolean isValidForInstallConstraints(PackageStateInternal ps,
String installerPackageName) {
return TextUtils.equals(ps.getInstallSource().mInstallerPackageName, installerPackageName)
|| TextUtils.equals(ps.getInstallSource().mUpdateOwnerPackageName,
installerPackageName);
}
private CompletableFuture<InstallConstraintsResult> checkInstallConstraintsInternal(
String installerPackageName, List<String> packageNames,
InstallConstraints constraints, long timeoutMillis) {
@@ -1324,8 +1332,7 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements
if (!PackageManagerServiceUtils.isSystemOrRootOrShell(callingUid)) {
for (var packageName : packageNames) {
var ps = snapshot.getPackageStateInternal(packageName);
if (ps == null || !TextUtils.equals(
ps.getInstallSource().mInstallerPackageName, installerPackageName)) {
if (ps == null || !isValidForInstallConstraints(ps, installerPackageName)) {
throw new SecurityException("Caller has no access to package " + packageName);
}
}