Revert fs-verity for all APKs

Due to the system health concern of cold app start time, revert the
change that applies fs-verity to all APKs.

There's an ongoing work to improve performance (b/233247259 for
dm-verity, but the idea is applicable to fs-verity, if works) and may
reduce the impact to an acceptable level. Once that lands, we can try to
re-enable again.

Bug: 249158715
Test: atest ChecksumsTest ApkVerityTest
      CtsAppSecurityHostTestCases:android.appsecurity.cts.ApkVerityInstallTest
Change-Id: I1ec7273bbb255745a1854ceb7af15bfa2738e265
This commit is contained in:
Victor Hsieh
2023-01-17 14:27:15 -08:00
parent d9e14d3a69
commit 76a3e5480b

View File

@@ -2325,7 +2325,6 @@ final class InstallPackageHelper {
@GuardedBy("mPm.mInstallLock")
private void executePostCommitStepsLIF(List<ReconciledPackage> reconciledPackages) {
final ArraySet<IncrementalStorage> incrementalStorages = new ArraySet<>();
final ArrayList<String> apkPaths = new ArrayList<>();
for (ReconciledPackage reconciledPkg : reconciledPackages) {
final InstallRequest installRequest = reconciledPkg.mInstallRequest;
final boolean instantApp = ((installRequest.getScanFlags() & SCAN_AS_INSTANT_APP) != 0);
@@ -2344,13 +2343,6 @@ final class InstallPackageHelper {
incrementalStorages.add(storage);
}
// Enabling fs-verity is a blocking operation. To reduce the impact to the install time,
// collect the files to later enable in a background thread.
apkPaths.add(pkg.getBaseApkPath());
if (pkg.getSplitCodePaths() != null) {
Collections.addAll(apkPaths, pkg.getSplitCodePaths());
}
// Hardcode previousAppId to 0 to disable any data migration (http://b/221088088)
mAppDataHelper.prepareAppDataPostCommitLIF(pkg, 0);
if (installRequest.isClearCodeCache()) {
@@ -2479,20 +2471,6 @@ final class InstallPackageHelper {
}
PackageManagerServiceUtils.waitForNativeBinariesExtractionForIncremental(
incrementalStorages);
mInjector.getBackgroundHandler().post(() -> {
for (String path : apkPaths) {
if (!VerityUtils.hasFsverity(path)) {
try {
VerityUtils.setUpFsverity(path);
} catch (IOException e) {
// There's nothing we can do if the setup failed. Since fs-verity is
// optional, just ignore the error for now.
Slog.e(TAG, "Failed to fully enable fs-verity to " + path);
}
}
}
});
}
Pair<Integer, String> verifyReplacingVersionCode(PackageInfoLite pkgLite,