RESTRICT AUTOMERGE: Revoke permissions defined in a to-be removed package.
Bug: 67319274 Test: run cts-dev --module CtsPermissionTestCases --test android.permission.cts.RemovePermissionTest#permissionShouldBeRevokedIfRemoved Change-Id: I69edee8ed044cc2a8cdb01515f7996b004209c81
This commit is contained in:
@@ -512,6 +512,8 @@ public class PackageManagerService extends IPackageManager.Stub {
|
|||||||
/** Special library name that skips shared libraries check during compilation. */
|
/** Special library name that skips shared libraries check during compilation. */
|
||||||
private static final String SKIP_SHARED_LIBRARY_CHECK = "&";
|
private static final String SKIP_SHARED_LIBRARY_CHECK = "&";
|
||||||
|
|
||||||
|
private static final int PROTECTION_MASK_BASE = 0xf;
|
||||||
|
|
||||||
final ServiceThread mHandlerThread;
|
final ServiceThread mHandlerThread;
|
||||||
|
|
||||||
final PackageHandler mHandler;
|
final PackageHandler mHandler;
|
||||||
@@ -4226,6 +4228,11 @@ public class PackageManagerService extends IPackageManager.Stub {
|
|||||||
|
|
||||||
@Override
|
@Override
|
||||||
public void revokeRuntimePermission(String packageName, String name, int userId) {
|
public void revokeRuntimePermission(String packageName, String name, int userId) {
|
||||||
|
revokeRuntimePermission(packageName, name, userId, mSettings.getPermission(name));
|
||||||
|
}
|
||||||
|
|
||||||
|
private void revokeRuntimePermission(String packageName, String name, int userId,
|
||||||
|
BasePermission bp) {
|
||||||
if (!sUserManager.exists(userId)) {
|
if (!sUserManager.exists(userId)) {
|
||||||
Log.e(TAG, "No such user:" + userId);
|
Log.e(TAG, "No such user:" + userId);
|
||||||
return;
|
return;
|
||||||
@@ -4246,8 +4253,6 @@ public class PackageManagerService extends IPackageManager.Stub {
|
|||||||
if (pkg == null) {
|
if (pkg == null) {
|
||||||
throw new IllegalArgumentException("Unknown package: " + packageName);
|
throw new IllegalArgumentException("Unknown package: " + packageName);
|
||||||
}
|
}
|
||||||
|
|
||||||
final BasePermission bp = mSettings.mPermissions.get(name);
|
|
||||||
if (bp == null) {
|
if (bp == null) {
|
||||||
throw new IllegalArgumentException("Unknown permission: " + name);
|
throw new IllegalArgumentException("Unknown permission: " + name);
|
||||||
}
|
}
|
||||||
@@ -4364,7 +4369,8 @@ public class PackageManagerService extends IPackageManager.Stub {
|
|||||||
oldPermissionGroupName, "to", newPermissionGroupName);
|
oldPermissionGroupName, "to", newPermissionGroupName);
|
||||||
|
|
||||||
try {
|
try {
|
||||||
revokeRuntimePermission(packageName, permissionName, userId);
|
revokeRuntimePermission(packageName, permissionName, userId,
|
||||||
|
mSettings.getPermission(permissionName));
|
||||||
} catch (IllegalArgumentException e) {
|
} catch (IllegalArgumentException e) {
|
||||||
Slog.e(TAG, "Could not revoke " + permissionName + " from "
|
Slog.e(TAG, "Could not revoke " + permissionName + " from "
|
||||||
+ packageName, e);
|
+ packageName, e);
|
||||||
@@ -9827,7 +9833,10 @@ public class PackageManagerService extends IPackageManager.Stub {
|
|||||||
if (DEBUG_REMOVE) Log.d(TAG, " Activities: " + r);
|
if (DEBUG_REMOVE) Log.d(TAG, " Activities: " + r);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
final ArrayList<String> allPackageNames = new ArrayList<>(mPackages.keySet());
|
||||||
|
|
||||||
N = pkg.permissions.size();
|
N = pkg.permissions.size();
|
||||||
|
List<BasePermission> bps = new ArrayList<BasePermission>(N);
|
||||||
r = null;
|
r = null;
|
||||||
for (i=0; i<N; i++) {
|
for (i=0; i<N; i++) {
|
||||||
PackageParser.Permission p = pkg.permissions.get(i);
|
PackageParser.Permission p = pkg.permissions.get(i);
|
||||||
@@ -9836,6 +9845,10 @@ public class PackageManagerService extends IPackageManager.Stub {
|
|||||||
bp = mSettings.mPermissionTrees.get(p.info.name);
|
bp = mSettings.mPermissionTrees.get(p.info.name);
|
||||||
}
|
}
|
||||||
if (bp != null && bp.perm == p) {
|
if (bp != null && bp.perm == p) {
|
||||||
|
if (((p.info.protectionLevel & PROTECTION_MASK_BASE) &
|
||||||
|
PermissionInfo.PROTECTION_DANGEROUS) != 0) {
|
||||||
|
bps.add(bp);
|
||||||
|
}
|
||||||
bp.perm = null;
|
bp.perm = null;
|
||||||
if (DEBUG_REMOVE && chatty) {
|
if (DEBUG_REMOVE && chatty) {
|
||||||
if (r == null) {
|
if (r == null) {
|
||||||
@@ -9853,6 +9866,44 @@ public class PackageManagerService extends IPackageManager.Stub {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
AsyncTask.execute(() -> {
|
||||||
|
final int numRemovedPermissions = bps.size();
|
||||||
|
for (int permissionNum = 0; permissionNum < numRemovedPermissions; permissionNum++) {
|
||||||
|
final int[] userIds = sUserManager.getUserIds();
|
||||||
|
final int numUserIds = userIds.length;
|
||||||
|
|
||||||
|
final int numPackages = allPackageNames.size();
|
||||||
|
for (int packageNum = 0; packageNum < numPackages; packageNum++) {
|
||||||
|
final String packageName = allPackageNames.get(packageNum);
|
||||||
|
final PackageManagerInternal packageManagerInt =
|
||||||
|
LocalServices.getService(PackageManagerInternal.class);
|
||||||
|
final ApplicationInfo applicationInfo = packageManagerInt.getApplicationInfo(
|
||||||
|
packageName, UserHandle.USER_SYSTEM);
|
||||||
|
if (applicationInfo != null
|
||||||
|
&& applicationInfo.targetSdkVersion < Build.VERSION_CODES.M) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
for (int userIdNum = 0; userIdNum < numUserIds; userIdNum++) {
|
||||||
|
final int userId = userIds[userIdNum];
|
||||||
|
final String permissionName = bps.get(permissionNum).name;
|
||||||
|
if (checkPermission(permissionName, packageName,
|
||||||
|
userId) == PackageManager.PERMISSION_GRANTED) {
|
||||||
|
try {
|
||||||
|
revokeRuntimePermission(packageName,
|
||||||
|
permissionName,
|
||||||
|
userId,
|
||||||
|
bps.get(permissionNum));
|
||||||
|
} catch (IllegalArgumentException e) {
|
||||||
|
Slog.e(TAG, "Could not revoke " + permissionName + " from "
|
||||||
|
+ packageName, e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
if (r != null) {
|
if (r != null) {
|
||||||
if (DEBUG_REMOVE) Log.d(TAG, " Permissions: " + r);
|
if (DEBUG_REMOVE) Log.d(TAG, " Permissions: " + r);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -454,6 +454,17 @@ final class Settings {
|
|||||||
return mPackages.get(name);
|
return mPackages.get(name);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public BasePermission getPermission(@NonNull String permName) {
|
||||||
|
synchronized (mLock) {
|
||||||
|
return getPermissionLocked(permName);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
@GuardedBy("mLock")
|
||||||
|
BasePermission getPermissionLocked(@NonNull String permName) {
|
||||||
|
return mPermissions.get(permName);
|
||||||
|
}
|
||||||
|
|
||||||
void setInstallStatus(String pkgName, final int status) {
|
void setInstallStatus(String pkgName, final int status) {
|
||||||
PackageSetting p = mPackages.get(pkgName);
|
PackageSetting p = mPackages.get(pkgName);
|
||||||
if(p != null) {
|
if(p != null) {
|
||||||
|
|||||||
Reference in New Issue
Block a user