Only allow the system or shell to delete oat artifacts

This also fixes the side channel information disclosure
of the package existence caused by the `pm delete-dexopt`
command.

Bug: 232415364
Test: atest PackageManagerTest
Change-Id: Ifed5d73234276fcb47d79ecb22fb6e7101d6b077
This commit is contained in:
Rhed Jao
2022-06-24 17:10:23 +08:00
parent bdfb8336a5
commit a8670dfd57

View File

@@ -6760,6 +6760,9 @@ public class PackageManagerService implements PackageSender, TestUtilityService
}
long deleteOatArtifactsOfPackage(@NonNull Computer snapshot, String packageName) {
PackageManagerServiceUtils.enforceSystemOrRootOrShell(
"Only the system or shell can delete oat artifacts");
PackageStateInternal packageState = snapshot.getPackageStateInternal(packageName);
if (packageState == null || packageState.getPkg() == null) {
return -1; // error code of deleteOptimizedFiles