From f8489cf667a0e5831b84c033e1fcd6a18337d4ed Mon Sep 17 00:00:00 2001 From: Joanne Chung Date: Fri, 5 May 2023 18:41:29 +0800 Subject: [PATCH] Validate checkInstallConstraints() installer package name installerPackageName is set when creating PackageInstaller instance. The value is get by context.getPackageName(). But it is possible the application can modify the value by reflection to bypass the security check to access the API. This change will verify it and throws the SecurityException if the name doesn't match. The change here doesn't update the javadoc part, it will be added in the follow up changes. Bug: 280721965 Test: atest InstallConstraintsTest Test: manual. Set fake installerPackageName will throw exception Change-Id: I168e695cf12971f3d770de0f3c9189222bb1707c --- .../java/com/android/server/pm/PackageInstallerService.java | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/services/core/java/com/android/server/pm/PackageInstallerService.java b/services/core/java/com/android/server/pm/PackageInstallerService.java index f358ce796fcfa..b849786cb842b 100644 --- a/services/core/java/com/android/server/pm/PackageInstallerService.java +++ b/services/core/java/com/android/server/pm/PackageInstallerService.java @@ -1317,6 +1317,11 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements final var snapshot = mPm.snapshotComputer(); final int callingUid = Binder.getCallingUid(); + final var callingPackageName = snapshot.getNameForUid(callingUid); + if (!TextUtils.equals(callingPackageName, installerPackageName)) { + throw new SecurityException("The installerPackageName set by the caller doesn't match " + + "the caller's own package name."); + } if (!PackageManagerServiceUtils.isSystemOrRootOrShell(callingUid)) { for (var packageName : packageNames) { var ps = snapshot.getPackageStateInternal(packageName);