From f7e44ca988290551131b9895ab6dd7a2b20445e7 Mon Sep 17 00:00:00 2001 From: Suprabh Shukla Date: Wed, 3 Feb 2021 15:54:53 -0800 Subject: [PATCH] Relax restrictions on appop protection level Added appop to the set of protection flags that can be used without combining with a base protection of 'signature' or 'internal'. Test: Builds, boots. Bug: 179304245 Change-Id: Ifd7f925acdb560d966905f54603f68519311d9ad --- .../component/ParsedPermissionUtils.java | 19 ++++++++----------- 1 file changed, 8 insertions(+), 11 deletions(-) diff --git a/core/java/android/content/pm/parsing/component/ParsedPermissionUtils.java b/core/java/android/content/pm/parsing/component/ParsedPermissionUtils.java index cbd2c550a797f..9012b5ce2b1e5 100644 --- a/core/java/android/content/pm/parsing/component/ParsedPermissionUtils.java +++ b/core/java/android/content/pm/parsing/component/ParsedPermissionUtils.java @@ -108,17 +108,14 @@ public class ParsedPermissionUtils { permission.protectionLevel = PermissionInfo.fixProtectionLevel(permission.protectionLevel); - if (permission.getProtectionFlags() != 0) { - if ((permission.protectionLevel & PermissionInfo.PROTECTION_FLAG_INSTANT) == 0 - && (permission.protectionLevel & PermissionInfo.PROTECTION_FLAG_RUNTIME_ONLY) - == 0 - && (permission.protectionLevel & PermissionInfo.PROTECTION_MASK_BASE) - != PermissionInfo.PROTECTION_SIGNATURE - && (permission.protectionLevel & PermissionInfo.PROTECTION_MASK_BASE) - != PermissionInfo.PROTECTION_INTERNAL) { - return input.error(" protectionLevel specifies a non-instant flag " - + "but is not based on signature or internal type"); - } + final int otherProtectionFlags = permission.getProtectionFlags() + & ~(PermissionInfo.PROTECTION_FLAG_APPOP | PermissionInfo.PROTECTION_FLAG_INSTANT + | PermissionInfo.PROTECTION_FLAG_RUNTIME_ONLY); + if (otherProtectionFlags != 0 + && permission.getProtection() != PermissionInfo.PROTECTION_SIGNATURE + && permission.getProtection() != PermissionInfo.PROTECTION_INTERNAL) { + return input.error(" protectionLevel specifies a non-instant, non-appop," + + " non-runtimeOnly flag but is not based on signature or internal type"); } return ComponentParseUtils.parseAllMetaData(pkg, res, parser, tag, permission, input);