Map SELINUX_LATEST_CHANGES to Build.CUR_DEVELOPMENT

The SELINUX_LATEST_CHANGES AppCompat flag should always put the app in
the SELinux domain targeting the current release. Fixing its target SDK
to CUR_DEVELOPMENT ensures that it always gets added to the latest
SELinux domain.

Bug: 193151214
Bug: 171572148
Test: atest CtsSelinuxTargetSdkCurrentTestCases
Test: atest CtsSelinuxTargetSdk30TestCases
Test: atest CtsSelinuxTargetSdk29TestCases
Test: atest CtsSelinuxTargetSdk28TestCases
Test: atest CtsSelinuxTargetSdk27TestCases
Test: atest CompatChangesSelinuxTest
Change-Id: I643a65e79e076518c27c31d05229ee509fa35ec5
This commit is contained in:
Bram Bonné
2021-07-09 09:30:33 +02:00
parent 8a415895de
commit 7ac9a05dbe
2 changed files with 6 additions and 4 deletions

View File

@@ -17,6 +17,7 @@
package com.android.server.pm;
import android.compat.annotation.ChangeId;
import android.compat.annotation.Disabled;
import android.compat.annotation.EnabledAfter;
import android.content.pm.ApplicationInfo;
import android.content.pm.PackageParser.SigningDetails;
@@ -79,13 +80,13 @@ public final class SELinuxMMAC {
/**
* Allows opt-in to the latest targetSdkVersion enforced changes without changing target SDK.
* Turning this change off for an app targeting the latest SDK or higher is a no-op.
* Turning this change on for an app targeting the latest SDK or higher is a no-op.
*
* <p>Has no effect for apps using shared user id.
*
* TODO(b/143539591): Update description with relevant SELINUX changes this opts in to.
*/
@EnabledAfter(targetSdkVersion = android.os.Build.VERSION_CODES.R)
@Disabled
@ChangeId
static final long SELINUX_LATEST_CHANGES = 143539591L;
@@ -364,7 +365,8 @@ public final class SELinuxMMAC {
}
final ApplicationInfo appInfo = pkg.toAppInfoWithoutState();
if (compatibility.isChangeEnabledInternal(SELINUX_LATEST_CHANGES, appInfo)) {
return Math.max(android.os.Build.VERSION_CODES.S, pkg.getTargetSdkVersion());
return Math.max(
android.os.Build.VERSION_CODES.CUR_DEVELOPMENT, pkg.getTargetSdkVersion());
} else if (compatibility.isChangeEnabledInternal(SELINUX_R_CHANGES, appInfo)) {
return Math.max(android.os.Build.VERSION_CODES.R, pkg.getTargetSdkVersion());
}

View File

@@ -44,7 +44,7 @@ import org.mockito.junit.MockitoJUnitRunner;
public class SELinuxMMACTest {
private static final String PACKAGE_NAME = "my.package";
private static final int LATEST_OPT_IN_VERSION = Build.VERSION_CODES.S;
private static final int LATEST_OPT_IN_VERSION = Build.VERSION_CODES.CUR_DEVELOPMENT;
private static final int R_OPT_IN_VERSION = Build.VERSION_CODES.R;
@Mock