Check that only allowed installers can perform a non-staged APEX update

Test: atest CtsStagedInstallHostTestCases
Test: atest GtsStagedInstallHostTestCases
Bug: 187864524
Bug: 189274479
Change-Id: Iab8bcc3892577582e9a50964ef87b89f575e5983
This commit is contained in:
Nikita Ioffe
2021-06-04 19:22:30 +01:00
parent 00630da0cf
commit fa42461aa1

View File

@@ -653,13 +653,20 @@ public class PackageInstallerService extends IPackageInstaller.Stub implements
}
if (params.isStaged && !isCalledBySystemOrShell(callingUid)) {
if (mBypassNextStagedInstallerCheck) {
mBypassNextStagedInstallerCheck = false;
} else if (!isStagedInstallerAllowed(requestedInstallerPackageName)) {
if (!mBypassNextStagedInstallerCheck
&& !isStagedInstallerAllowed(requestedInstallerPackageName)) {
throw new SecurityException("Installer not allowed to commit staged install");
}
}
if (isApex && !isCalledBySystemOrShell(callingUid)) {
if (!mBypassNextStagedInstallerCheck
&& !isStagedInstallerAllowed(requestedInstallerPackageName)) {
throw new SecurityException(
"Installer not allowed to commit non-staged APEX install");
}
}
mBypassNextStagedInstallerCheck = false;
if (!params.isMultiPackage) {
// Only system components can circumvent runtime permissions when installing.
if ((params.installFlags & PackageManager.INSTALL_GRANT_RUNTIME_PERMISSIONS) != 0