Merge "Change source stamp verifier outcome" into rvc-dev

This commit is contained in:
Khaled Abdelmohsen
2020-03-13 19:01:28 +00:00
committed by Android (Google) Code Review

View File

@@ -82,25 +82,34 @@ public abstract class SourceStampVerifier {
public static SourceStampVerificationResult verify(String apkFile) { public static SourceStampVerificationResult verify(String apkFile) {
try (RandomAccessFile apk = new RandomAccessFile(apkFile, "r")) { try (RandomAccessFile apk = new RandomAccessFile(apkFile, "r")) {
return verify(apk); return verify(apk);
} catch (Exception e) { } catch (IOException e) {
// Any exception in the SourceStamp verification returns a non-verified SourceStamp // Any exception in reading the APK returns a non-present SourceStamp outcome
// outcome without affecting the outcome of any of the other signature schemes. // without affecting the outcome of any of the other signature schemes.
return SourceStampVerificationResult.notVerified(); return SourceStampVerificationResult.notPresent();
} }
} }
private static SourceStampVerificationResult verify(RandomAccessFile apk) private static SourceStampVerificationResult verify(RandomAccessFile apk) {
throws IOException, SignatureNotFoundException { byte[] sourceStampCertificateDigest;
byte[] sourceStampCertificateDigest = getSourceStampCertificateDigest(apk); try {
if (sourceStampCertificateDigest == null) { sourceStampCertificateDigest = getSourceStampCertificateDigest(apk);
// SourceStamp certificate hash file not found, which means that there is not if (sourceStampCertificateDigest == null) {
// SourceStamp present. // SourceStamp certificate hash file not found, which means that there is not
// SourceStamp present.
return SourceStampVerificationResult.notPresent();
}
} catch (IOException e) {
return SourceStampVerificationResult.notPresent(); return SourceStampVerificationResult.notPresent();
} }
SignatureInfo signatureInfo =
ApkSigningBlockUtils.findSignature(apk, SOURCE_STAMP_BLOCK_ID); try {
Map<Integer, byte[]> apkContentDigests = getApkContentDigests(apk); SignatureInfo signatureInfo =
return verify(signatureInfo, apkContentDigests, sourceStampCertificateDigest); ApkSigningBlockUtils.findSignature(apk, SOURCE_STAMP_BLOCK_ID);
Map<Integer, byte[]> apkContentDigests = getApkContentDigests(apk);
return verify(signatureInfo, apkContentDigests, sourceStampCertificateDigest);
} catch (IOException | SignatureNotFoundException e) {
return SourceStampVerificationResult.notVerified();
}
} }
private static SourceStampVerificationResult verify( private static SourceStampVerificationResult verify(