Merge "Consider target path when verifyIdmap." into rvc-dev

This commit is contained in:
Ryan Mitchell
2020-03-30 15:45:47 +00:00
committed by Android (Google) Code Review
6 changed files with 21 additions and 10 deletions

View File

@@ -22,6 +22,7 @@
#include <ostream> #include <ostream>
#include <vector> #include <vector>
#include "Commands.h"
#include "android-base/stringprintf.h" #include "android-base/stringprintf.h"
#include "idmap2/BinaryStreamVisitor.h" #include "idmap2/BinaryStreamVisitor.h"
#include "idmap2/CommandLineOptions.h" #include "idmap2/CommandLineOptions.h"
@@ -30,7 +31,6 @@
#include "idmap2/Policies.h" #include "idmap2/Policies.h"
#include "idmap2/PolicyUtils.h" #include "idmap2/PolicyUtils.h"
#include "idmap2/SysTrace.h" #include "idmap2/SysTrace.h"
#include "Commands.h"
using android::ApkAssets; using android::ApkAssets;
using android::base::StringPrintf; using android::base::StringPrintf;

View File

@@ -93,7 +93,8 @@ Status Idmap2Service::removeIdmap(const std::string& overlay_apk_path,
return ok(); return ok();
} }
Status Idmap2Service::verifyIdmap(const std::string& overlay_apk_path, Status Idmap2Service::verifyIdmap(const std::string& target_apk_path,
const std::string& overlay_apk_path,
int32_t fulfilled_policies ATTRIBUTE_UNUSED, int32_t fulfilled_policies ATTRIBUTE_UNUSED,
bool enforce_overlayable ATTRIBUTE_UNUSED, bool enforce_overlayable ATTRIBUTE_UNUSED,
int32_t user_id ATTRIBUTE_UNUSED, bool* _aidl_return) { int32_t user_id ATTRIBUTE_UNUSED, bool* _aidl_return) {
@@ -103,10 +104,15 @@ Status Idmap2Service::verifyIdmap(const std::string& overlay_apk_path,
std::ifstream fin(idmap_path); std::ifstream fin(idmap_path);
const std::unique_ptr<const IdmapHeader> header = IdmapHeader::FromBinaryStream(fin); const std::unique_ptr<const IdmapHeader> header = IdmapHeader::FromBinaryStream(fin);
fin.close(); fin.close();
*_aidl_return = header && header->IsUpToDate(); if (!header) {
*_aidl_return = false;
return error("failed to parse idmap header");
}
*_aidl_return =
strcmp(header->GetTargetPath().data(), target_apk_path.data()) == 0 && header->IsUpToDate();
// TODO(b/119328308): Check that the set of fulfilled policies of the overlay has not changed // TODO(b/119328308): Check that the set of fulfilled policies of the overlay has not changed
return ok(); return ok();
} }

View File

@@ -37,7 +37,8 @@ class Idmap2Service : public BinderService<Idmap2Service>, public BnIdmap2 {
binder::Status removeIdmap(const std::string& overlay_apk_path, int32_t user_id, binder::Status removeIdmap(const std::string& overlay_apk_path, int32_t user_id,
bool* _aidl_return) override; bool* _aidl_return) override;
binder::Status verifyIdmap(const std::string& overlay_apk_path, int32_t fulfilled_policies, binder::Status verifyIdmap(const std::string& target_apk_path,
const std::string& overlay_apk_path, int32_t fulfilled_policies,
bool enforce_overlayable, int32_t user_id, bool enforce_overlayable, int32_t user_id,
bool* _aidl_return) override; bool* _aidl_return) override;

View File

@@ -22,8 +22,11 @@ package android.os;
interface IIdmap2 { interface IIdmap2 {
@utf8InCpp String getIdmapPath(@utf8InCpp String overlayApkPath, int userId); @utf8InCpp String getIdmapPath(@utf8InCpp String overlayApkPath, int userId);
boolean removeIdmap(@utf8InCpp String overlayApkPath, int userId); boolean removeIdmap(@utf8InCpp String overlayApkPath, int userId);
boolean verifyIdmap(@utf8InCpp String overlayApkPath, int fulfilledPolicies, boolean verifyIdmap(@utf8InCpp String targetApkPath,
boolean enforceOverlayable, int userId); @utf8InCpp String overlayApkPath,
int fulfilledPolicies,
boolean enforceOverlayable,
int userId);
@nullable @utf8InCpp String createIdmap(@utf8InCpp String targetApkPath, @nullable @utf8InCpp String createIdmap(@utf8InCpp String targetApkPath,
@utf8InCpp String overlayApkPath, @utf8InCpp String overlayApkPath,
int fulfilledPolicies, int fulfilledPolicies,

View File

@@ -116,10 +116,11 @@ class IdmapDaemon {
} }
} }
boolean verifyIdmap(String overlayPath, int policies, boolean enforce, int userId) boolean verifyIdmap(String targetPath, String overlayPath, int policies, boolean enforce,
int userId)
throws Exception { throws Exception {
try (Connection connection = connect()) { try (Connection connection = connect()) {
return mService.verifyIdmap(overlayPath, policies, enforce, userId); return mService.verifyIdmap(targetPath, overlayPath, policies, enforce, userId);
} }
} }

View File

@@ -75,7 +75,7 @@ class IdmapManager {
try { try {
int policies = calculateFulfilledPolicies(targetPackage, overlayPackage, userId); int policies = calculateFulfilledPolicies(targetPackage, overlayPackage, userId);
boolean enforce = enforceOverlayable(overlayPackage); boolean enforce = enforceOverlayable(overlayPackage);
if (mIdmapDaemon.verifyIdmap(overlayPath, policies, enforce, userId)) { if (mIdmapDaemon.verifyIdmap(targetPath, overlayPath, policies, enforce, userId)) {
return true; return true;
} }
return mIdmapDaemon.createIdmap(targetPath, overlayPath, policies, return mIdmapDaemon.createIdmap(targetPath, overlayPath, policies,