Merge "Only allow access to the dexopt commands from root or shell." into udc-dev am: 71498b565e

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/21510886

Change-Id: Ic8063becc3e867baf4951c0a5ca44e232a54a093
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Martin Stjernholm
2023-02-27 20:50:07 +00:00
committed by Automerger Merge Worker
2 changed files with 5 additions and 8 deletions

View File

@@ -6675,15 +6675,7 @@ public class PackageManagerService implements PackageSender, TestUtilityService
@Deprecated
public void legacyDumpProfiles(String packageName, boolean dumpClassesAndMethods)
throws LegacyDexoptDisabledException {
/* Only the shell, root, or the app user should be able to dump profiles. */
final int callingUid = Binder.getCallingUid();
final Computer snapshot = snapshotComputer();
final String[] callerPackageNames = snapshot.getPackagesForUid(callingUid);
if (!PackageManagerServiceUtils.isRootOrShell(callingUid)
&& !ArrayUtils.contains(callerPackageNames, packageName)) {
throw new SecurityException("dumpProfiles");
}
AndroidPackage pkg = snapshot.getPackage(packageName);
if (pkg == null) {
throw new IllegalArgumentException("Unknown package: " + packageName);

View File

@@ -391,6 +391,11 @@ class PackageManagerShellCommand extends ShellCommand {
private int runLegacyDexoptCommand(@NonNull String cmd)
throws RemoteException, LegacyDexoptDisabledException {
Installer.checkLegacyDexoptDisabled();
if (!PackageManagerServiceUtils.isRootOrShell(Binder.getCallingUid())) {
throw new SecurityException("Dexopt shell commands need root or shell access");
}
switch (cmd) {
case "compile":
return runCompile();