Do not review removed permissions
Removed permissions don't participate in the permission model, hence we
should ignore them everywhere.
The problem was that if we set them as "review-required" other code gets
confused as an app that has been reviewed still has some permissions with
this flag set.
Test: 1. Installed legacy app that needs storage access (verified
permission flags)
2. reviewed permisisons (verified permission flags)
3. reset app (verified permission flags)
atest android.appsecurity.cts.PermissionsHostTest#testCompatDefault22 (while in isolated storage mode)
atest android.appsecurity.cts.PermissionsHostTest#testReviewPermissionWhenServiceIsBound (while in isolated storage mode)
Fixes: 120223984
Change-Id: I4b55cc4fb2e39b358fd3b6c5db600c5b3b927096
This commit is contained in:
@@ -18302,6 +18302,10 @@ public class PackageManagerService extends IPackageManager.Stub
|
||||
continue;
|
||||
}
|
||||
|
||||
if (bp.isRemoved()) {
|
||||
continue;
|
||||
}
|
||||
|
||||
// If shared user we just reset the state to which only this app contributed.
|
||||
if (ps.sharedUser != null) {
|
||||
boolean used = false;
|
||||
|
||||
@@ -189,6 +189,11 @@ public final class BasePermission {
|
||||
return (protectionLevel & PermissionInfo.PROTECTION_MASK_BASE)
|
||||
== PermissionInfo.PROTECTION_DANGEROUS;
|
||||
}
|
||||
|
||||
public boolean isRemoved() {
|
||||
return perm.info != null && (perm.info.flags & PermissionInfo.FLAG_REMOVED) != 0;
|
||||
}
|
||||
|
||||
public boolean isSignature() {
|
||||
return (protectionLevel & PermissionInfo.PROTECTION_MASK_BASE) ==
|
||||
PermissionInfo.PROTECTION_SIGNATURE;
|
||||
|
||||
@@ -799,6 +799,10 @@ public class PermissionManagerService {
|
||||
continue;
|
||||
}
|
||||
|
||||
if (bp.isRemoved()) {
|
||||
continue;
|
||||
}
|
||||
|
||||
// Limit ephemeral apps to ephemeral allowed permissions.
|
||||
if (pkg.applicationInfo.isInstantApp() && !bp.isInstant()) {
|
||||
if (DEBUG_PERMISSIONS) {
|
||||
|
||||
Reference in New Issue
Block a user