Merge "Consider target path when verifyIdmap." into rvc-dev
This commit is contained in:
committed by
Android (Google) Code Review
commit
fa0f02a91c
@@ -22,6 +22,7 @@
|
|||||||
#include <ostream>
|
#include <ostream>
|
||||||
#include <vector>
|
#include <vector>
|
||||||
|
|
||||||
|
#include "Commands.h"
|
||||||
#include "android-base/stringprintf.h"
|
#include "android-base/stringprintf.h"
|
||||||
#include "idmap2/BinaryStreamVisitor.h"
|
#include "idmap2/BinaryStreamVisitor.h"
|
||||||
#include "idmap2/CommandLineOptions.h"
|
#include "idmap2/CommandLineOptions.h"
|
||||||
@@ -30,7 +31,6 @@
|
|||||||
#include "idmap2/Policies.h"
|
#include "idmap2/Policies.h"
|
||||||
#include "idmap2/PolicyUtils.h"
|
#include "idmap2/PolicyUtils.h"
|
||||||
#include "idmap2/SysTrace.h"
|
#include "idmap2/SysTrace.h"
|
||||||
#include "Commands.h"
|
|
||||||
|
|
||||||
using android::ApkAssets;
|
using android::ApkAssets;
|
||||||
using android::base::StringPrintf;
|
using android::base::StringPrintf;
|
||||||
|
|||||||
@@ -93,7 +93,8 @@ Status Idmap2Service::removeIdmap(const std::string& overlay_apk_path,
|
|||||||
return ok();
|
return ok();
|
||||||
}
|
}
|
||||||
|
|
||||||
Status Idmap2Service::verifyIdmap(const std::string& overlay_apk_path,
|
Status Idmap2Service::verifyIdmap(const std::string& target_apk_path,
|
||||||
|
const std::string& overlay_apk_path,
|
||||||
int32_t fulfilled_policies ATTRIBUTE_UNUSED,
|
int32_t fulfilled_policies ATTRIBUTE_UNUSED,
|
||||||
bool enforce_overlayable ATTRIBUTE_UNUSED,
|
bool enforce_overlayable ATTRIBUTE_UNUSED,
|
||||||
int32_t user_id ATTRIBUTE_UNUSED, bool* _aidl_return) {
|
int32_t user_id ATTRIBUTE_UNUSED, bool* _aidl_return) {
|
||||||
@@ -103,10 +104,15 @@ Status Idmap2Service::verifyIdmap(const std::string& overlay_apk_path,
|
|||||||
std::ifstream fin(idmap_path);
|
std::ifstream fin(idmap_path);
|
||||||
const std::unique_ptr<const IdmapHeader> header = IdmapHeader::FromBinaryStream(fin);
|
const std::unique_ptr<const IdmapHeader> header = IdmapHeader::FromBinaryStream(fin);
|
||||||
fin.close();
|
fin.close();
|
||||||
*_aidl_return = header && header->IsUpToDate();
|
if (!header) {
|
||||||
|
*_aidl_return = false;
|
||||||
|
return error("failed to parse idmap header");
|
||||||
|
}
|
||||||
|
|
||||||
|
*_aidl_return =
|
||||||
|
strcmp(header->GetTargetPath().data(), target_apk_path.data()) == 0 && header->IsUpToDate();
|
||||||
|
|
||||||
// TODO(b/119328308): Check that the set of fulfilled policies of the overlay has not changed
|
// TODO(b/119328308): Check that the set of fulfilled policies of the overlay has not changed
|
||||||
|
|
||||||
return ok();
|
return ok();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -37,7 +37,8 @@ class Idmap2Service : public BinderService<Idmap2Service>, public BnIdmap2 {
|
|||||||
binder::Status removeIdmap(const std::string& overlay_apk_path, int32_t user_id,
|
binder::Status removeIdmap(const std::string& overlay_apk_path, int32_t user_id,
|
||||||
bool* _aidl_return) override;
|
bool* _aidl_return) override;
|
||||||
|
|
||||||
binder::Status verifyIdmap(const std::string& overlay_apk_path, int32_t fulfilled_policies,
|
binder::Status verifyIdmap(const std::string& target_apk_path,
|
||||||
|
const std::string& overlay_apk_path, int32_t fulfilled_policies,
|
||||||
bool enforce_overlayable, int32_t user_id,
|
bool enforce_overlayable, int32_t user_id,
|
||||||
bool* _aidl_return) override;
|
bool* _aidl_return) override;
|
||||||
|
|
||||||
|
|||||||
@@ -22,8 +22,11 @@ package android.os;
|
|||||||
interface IIdmap2 {
|
interface IIdmap2 {
|
||||||
@utf8InCpp String getIdmapPath(@utf8InCpp String overlayApkPath, int userId);
|
@utf8InCpp String getIdmapPath(@utf8InCpp String overlayApkPath, int userId);
|
||||||
boolean removeIdmap(@utf8InCpp String overlayApkPath, int userId);
|
boolean removeIdmap(@utf8InCpp String overlayApkPath, int userId);
|
||||||
boolean verifyIdmap(@utf8InCpp String overlayApkPath, int fulfilledPolicies,
|
boolean verifyIdmap(@utf8InCpp String targetApkPath,
|
||||||
boolean enforceOverlayable, int userId);
|
@utf8InCpp String overlayApkPath,
|
||||||
|
int fulfilledPolicies,
|
||||||
|
boolean enforceOverlayable,
|
||||||
|
int userId);
|
||||||
@nullable @utf8InCpp String createIdmap(@utf8InCpp String targetApkPath,
|
@nullable @utf8InCpp String createIdmap(@utf8InCpp String targetApkPath,
|
||||||
@utf8InCpp String overlayApkPath,
|
@utf8InCpp String overlayApkPath,
|
||||||
int fulfilledPolicies,
|
int fulfilledPolicies,
|
||||||
|
|||||||
@@ -116,10 +116,11 @@ class IdmapDaemon {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
boolean verifyIdmap(String overlayPath, int policies, boolean enforce, int userId)
|
boolean verifyIdmap(String targetPath, String overlayPath, int policies, boolean enforce,
|
||||||
|
int userId)
|
||||||
throws Exception {
|
throws Exception {
|
||||||
try (Connection connection = connect()) {
|
try (Connection connection = connect()) {
|
||||||
return mService.verifyIdmap(overlayPath, policies, enforce, userId);
|
return mService.verifyIdmap(targetPath, overlayPath, policies, enforce, userId);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -75,7 +75,7 @@ class IdmapManager {
|
|||||||
try {
|
try {
|
||||||
int policies = calculateFulfilledPolicies(targetPackage, overlayPackage, userId);
|
int policies = calculateFulfilledPolicies(targetPackage, overlayPackage, userId);
|
||||||
boolean enforce = enforceOverlayable(overlayPackage);
|
boolean enforce = enforceOverlayable(overlayPackage);
|
||||||
if (mIdmapDaemon.verifyIdmap(overlayPath, policies, enforce, userId)) {
|
if (mIdmapDaemon.verifyIdmap(targetPath, overlayPath, policies, enforce, userId)) {
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
return mIdmapDaemon.createIdmap(targetPath, overlayPath, policies,
|
return mIdmapDaemon.createIdmap(targetPath, overlayPath, policies,
|
||||||
|
|||||||
Reference in New Issue
Block a user