Merge "Prevent system reset staged installer bypass flag unexpactly" into rvc-dev am: 809bf93563

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/12106109

Change-Id: I1a84ce3d8e8d50136455162e6d01c8a594289b2d
This commit is contained in:
TreeHugger Robot
2020-07-09 16:48:32 +00:00
committed by Automerger Merge Worker

View File

@@ -589,13 +589,13 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements
} }
} }
if (params.isStaged && !isCalledBySystemOrShell(callingUid)) {
if (mBypassNextStagedInstallerCheck) { if (mBypassNextStagedInstallerCheck) {
mBypassNextStagedInstallerCheck = false; mBypassNextStagedInstallerCheck = false;
} else if (params.isStaged } else if (!isStagedInstallerAllowed(requestedInstallerPackageName)) {
&& !isCalledBySystemOrShell(callingUid)
&& !isWhitelistedStagedInstaller(requestedInstallerPackageName)) {
throw new SecurityException("Installer not allowed to commit staged install"); throw new SecurityException("Installer not allowed to commit staged install");
} }
}
if (!params.isMultiPackage) { if (!params.isMultiPackage) {
// Only system components can circumvent runtime permissions when installing. // Only system components can circumvent runtime permissions when installing.
@@ -725,7 +725,7 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements
|| callingUid == Process.SHELL_UID; || callingUid == Process.SHELL_UID;
} }
private boolean isWhitelistedStagedInstaller(String installerName) { private boolean isStagedInstallerAllowed(String installerName) {
return SystemConfig.getInstance().getWhitelistedStagedInstallers().contains(installerName); return SystemConfig.getInstance().getWhitelistedStagedInstallers().contains(installerName);
} }