Validate checkInstallConstraints() installer package name

installerPackageName is set when creating PackageInstaller instance.
The value is get by context.getPackageName(). But it is possible the
application can modify the value by reflection to bypass the security
check to access the API. This change will verify it and throws the
SecurityException if the name doesn't match.

The change here doesn't update the javadoc part, it will be added in
the follow up changes.

Bug: 280721965
Test: atest InstallConstraintsTest
Test: manual. Set fake installerPackageName will throw exception
Change-Id: I168e695cf12971f3d770de0f3c9189222bb1707c
This commit is contained in:
Joanne Chung
2023-05-05 18:41:29 +08:00
parent 6b44c7bb9a
commit f8489cf667

View File

@@ -1317,6 +1317,11 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements
final var snapshot = mPm.snapshotComputer();
final int callingUid = Binder.getCallingUid();
final var callingPackageName = snapshot.getNameForUid(callingUid);
if (!TextUtils.equals(callingPackageName, installerPackageName)) {
throw new SecurityException("The installerPackageName set by the caller doesn't match "
+ "the caller's own package name.");
}
if (!PackageManagerServiceUtils.isSystemOrRootOrShell(callingUid)) {
for (var packageName : packageNames) {
var ps = snapshot.getPackageStateInternal(packageName);