Merge "Only allow USER_OWNER to access PDB and change OEM unlock ability" into lmp-mr1-dev automerge: 36531b3

automerge: 3bc103b

* commit '3bc103b8dbcacf908e6512b805c89a399a460be9':
  Only allow USER_OWNER to access PDB and change OEM unlock ability
This commit is contained in:
Andres Morales
2014-11-05 18:05:14 +00:00
committed by android-build-merger

View File

@@ -72,7 +72,7 @@ public class PersistentDataBlockService extends SystemService {
private final String mDataBlockFile; private final String mDataBlockFile;
private final Object mLock = new Object(); private final Object mLock = new Object();
private int mAllowedAppId = -1; private int mAllowedUid = -1;
/* /*
* Separate lock for OEM unlock related operations as they can happen in parallel with regular * Separate lock for OEM unlock related operations as they can happen in parallel with regular
* block operations. * block operations.
@@ -86,11 +86,11 @@ public class PersistentDataBlockService extends SystemService {
mContext = context; mContext = context;
mDataBlockFile = SystemProperties.get(PERSISTENT_DATA_BLOCK_PROP); mDataBlockFile = SystemProperties.get(PERSISTENT_DATA_BLOCK_PROP);
mBlockDeviceSize = -1; // Load lazily mBlockDeviceSize = -1; // Load lazily
mAllowedAppId = getAllowedAppId(UserHandle.USER_OWNER); mAllowedUid = getAllowedUid(UserHandle.USER_OWNER);
} }
private int getAllowedAppId(int userHandle) { private int getAllowedUid(int userHandle) {
String allowedPackage = mContext.getResources() String allowedPackage = mContext.getResources()
.getString(R.string.config_persistentDataPackageName); .getString(R.string.config_persistentDataPackageName);
PackageManager pm = mContext.getPackageManager(); PackageManager pm = mContext.getPackageManager();
@@ -101,7 +101,7 @@ public class PersistentDataBlockService extends SystemService {
// not expected // not expected
Slog.e(TAG, "not able to find package " + allowedPackage, e); Slog.e(TAG, "not able to find package " + allowedPackage, e);
} }
return UserHandle.getAppId(allowedUid); return allowedUid;
} }
@Override @Override
@@ -116,11 +116,17 @@ public class PersistentDataBlockService extends SystemService {
} }
private void enforceUid(int callingUid) { private void enforceUid(int callingUid) {
if (UserHandle.getAppId(callingUid) != mAllowedAppId) { if (callingUid != mAllowedUid) {
throw new SecurityException("uid " + callingUid + " not allowed to access PST"); throw new SecurityException("uid " + callingUid + " not allowed to access PST");
} }
} }
private void enforceIsOwner() {
if (!Binder.getCallingUserHandle().isOwner()) {
throw new SecurityException("Only the Owner is allowed to change OEM unlock state");
}
}
private int getTotalDataSizeLocked(DataInputStream inputStream) throws IOException { private int getTotalDataSizeLocked(DataInputStream inputStream) throws IOException {
int totalDataSize; int totalDataSize;
int blockId = inputStream.readInt(); int blockId = inputStream.readInt();
@@ -249,6 +255,7 @@ public class PersistentDataBlockService extends SystemService {
return; return;
} }
enforceOemUnlockPermission(); enforceOemUnlockPermission();
enforceIsOwner();
FileOutputStream outputStream; FileOutputStream outputStream;
try { try {
outputStream = new FileOutputStream(new File(mDataBlockFile)); outputStream = new FileOutputStream(new File(mDataBlockFile));