From 39bad6c991469de140ab71ac2edf72666f79a65d Mon Sep 17 00:00:00 2001 From: Khaled Abdelmohsen Date: Thu, 12 Mar 2020 20:18:51 +0000 Subject: [PATCH] Change source stamp verifier outcome Modify source stamp verifier to produce non-present stamps when receiving an error while reading the stamp file in an APK. Bug: 148005911 Test: atest FrameworksCoreTests:SourceStampVerifierTest Change-Id: I7682f51761e60b4236424cf2cdb6119f53259ab0 --- .../android/util/apk/SourceStampVerifier.java | 37 ++++++++++++------- 1 file changed, 23 insertions(+), 14 deletions(-) diff --git a/core/java/android/util/apk/SourceStampVerifier.java b/core/java/android/util/apk/SourceStampVerifier.java index 759c8649532bb..70e4a51bc07a8 100644 --- a/core/java/android/util/apk/SourceStampVerifier.java +++ b/core/java/android/util/apk/SourceStampVerifier.java @@ -82,25 +82,34 @@ public abstract class SourceStampVerifier { public static SourceStampVerificationResult verify(String apkFile) { try (RandomAccessFile apk = new RandomAccessFile(apkFile, "r")) { return verify(apk); - } catch (Exception e) { - // Any exception in the SourceStamp verification returns a non-verified SourceStamp - // outcome without affecting the outcome of any of the other signature schemes. - return SourceStampVerificationResult.notVerified(); + } catch (IOException e) { + // Any exception in reading the APK returns a non-present SourceStamp outcome + // without affecting the outcome of any of the other signature schemes. + return SourceStampVerificationResult.notPresent(); } } - private static SourceStampVerificationResult verify(RandomAccessFile apk) - throws IOException, SignatureNotFoundException { - byte[] sourceStampCertificateDigest = getSourceStampCertificateDigest(apk); - if (sourceStampCertificateDigest == null) { - // SourceStamp certificate hash file not found, which means that there is not - // SourceStamp present. + private static SourceStampVerificationResult verify(RandomAccessFile apk) { + byte[] sourceStampCertificateDigest; + try { + sourceStampCertificateDigest = getSourceStampCertificateDigest(apk); + if (sourceStampCertificateDigest == null) { + // SourceStamp certificate hash file not found, which means that there is not + // SourceStamp present. + return SourceStampVerificationResult.notPresent(); + } + } catch (IOException e) { return SourceStampVerificationResult.notPresent(); } - SignatureInfo signatureInfo = - ApkSigningBlockUtils.findSignature(apk, SOURCE_STAMP_BLOCK_ID); - Map apkContentDigests = getApkContentDigests(apk); - return verify(signatureInfo, apkContentDigests, sourceStampCertificateDigest); + + try { + SignatureInfo signatureInfo = + ApkSigningBlockUtils.findSignature(apk, SOURCE_STAMP_BLOCK_ID); + Map apkContentDigests = getApkContentDigests(apk); + return verify(signatureInfo, apkContentDigests, sourceStampCertificateDigest); + } catch (IOException | SignatureNotFoundException e) { + return SourceStampVerificationResult.notVerified(); + } } private static SourceStampVerificationResult verify(