Do not review removed permissions

Removed permissions don't participate in the permission model, hence we
should ignore them everywhere.

The problem was that if we set them as "review-required" other code gets
confused as an app that has been reviewed still has some permissions with
this flag set.

Test: 1. Installed legacy app that needs storage access (verified
         permission flags)
      2. reviewed permisisons (verified permission flags)
      3. reset app (verified permission flags)
      atest android.appsecurity.cts.PermissionsHostTest#testCompatDefault22 (while in isolated storage mode)
      atest android.appsecurity.cts.PermissionsHostTest#testReviewPermissionWhenServiceIsBound (while in isolated storage mode)
Fixes: 120223984
Change-Id: I4b55cc4fb2e39b358fd3b6c5db600c5b3b927096
This commit is contained in:
Philip P. Moltmann
2018-12-07 16:57:38 -08:00
parent 3159fa2df8
commit c6bdbec499
3 changed files with 13 additions and 0 deletions

View File

@@ -18302,6 +18302,10 @@ public class PackageManagerService extends IPackageManager.Stub
continue;
}
if (bp.isRemoved()) {
continue;
}
// If shared user we just reset the state to which only this app contributed.
if (ps.sharedUser != null) {
boolean used = false;

View File

@@ -189,6 +189,11 @@ public final class BasePermission {
return (protectionLevel & PermissionInfo.PROTECTION_MASK_BASE)
== PermissionInfo.PROTECTION_DANGEROUS;
}
public boolean isRemoved() {
return perm.info != null && (perm.info.flags & PermissionInfo.FLAG_REMOVED) != 0;
}
public boolean isSignature() {
return (protectionLevel & PermissionInfo.PROTECTION_MASK_BASE) ==
PermissionInfo.PROTECTION_SIGNATURE;

View File

@@ -799,6 +799,10 @@ public class PermissionManagerService {
continue;
}
if (bp.isRemoved()) {
continue;
}
// Limit ephemeral apps to ephemeral allowed permissions.
if (pkg.applicationInfo.isInstantApp() && !bp.isInstant()) {
if (DEBUG_PERMISSIONS) {