Merge "pm: Verify shared-user priv-app install location"

This commit is contained in:
TreeHugger Robot
2018-01-17 22:47:44 +00:00
committed by Android (Google) Code Review
2 changed files with 25 additions and 0 deletions

View File

@@ -10764,6 +10764,26 @@ Slog.e("TODD",
}
}
}
// Verify that packages sharing a user with a privileged app are marked as privileged.
if (!pkg.isPrivileged() && (pkg.mSharedUserId != null)) {
SharedUserSetting sharedUserSetting = null;
try {
sharedUserSetting = mSettings.getSharedUserLPw(pkg.mSharedUserId, 0, 0, false);
} catch (PackageManagerException ignore) {}
if (sharedUserSetting != null && sharedUserSetting.isPrivileged()) {
// Exempt SharedUsers signed with the platform key.
PackageSetting platformPkgSetting = mSettings.mPackages.get("android");
if ((platformPkgSetting.signatures.mSignatures != null) &&
(compareSignatures(platformPkgSetting.signatures.mSignatures,
pkg.mSigningDetails.signatures) != PackageManager.SIGNATURE_MATCH)) {
throw new PackageManagerException("Apps that share a user with a " +
"privileged app must themselves be marked as privileged. " +
pkg.packageName + " shares privileged user " +
pkg.mSharedUserId + ".");
}
}
}
}
}

View File

@@ -17,6 +17,7 @@
package com.android.server.pm;
import android.annotation.Nullable;
import android.content.pm.ApplicationInfo;
import android.content.pm.PackageParser;
import android.service.pm.PackageServiceDumpProto;
import android.util.ArraySet;
@@ -102,4 +103,8 @@ public final class SharedUserSetting extends SettingBase {
}
return pkgList;
}
public boolean isPrivileged() {
return (this.pkgPrivateFlags & ApplicationInfo.PRIVATE_FLAG_PRIVILEGED) != 0;
}
}