mirror of
https://github.com/Divested-Mobile/DivestOS-Build.git
synced 2025-01-21 12:51:18 -05:00
59bf3b75c7
https://review.lineageos.org/c/LineageOS/android_frameworks_base/+/353117 https://review.lineageos.org/q/topic:Q_asb_2023-03 https://review.lineageos.org/q/topic:Q_asb_2023-04 https://review.lineageos.org/q/topic:Q_asb_2023-05 https://review.lineageos.org/q/topic:Q_asb_2023-06 https://review.lineageos.org/q/topic:Q_asb_2023-07 https://review.lineageos.org/q/topic:Q_asb_2023-08 accounted for via patches: https://review.lineageos.org/c/LineageOS/android_system_ca-certificates/+/376560 https://review.lineageos.org/c/LineageOS/android_system_ca-certificates/+/376561 https://review.lineageos.org/c/LineageOS/android_system_ca-certificates/+/376562 https://review.lineageos.org/q/topic:Q_asb_2023-09 https://review.lineageos.org/q/topic:Q_asb_2023-10 https://review.lineageos.org/q/topic:Q_asb_2023-11 accounted for via patches: https://review.lineageos.org/c/LineageOS/android_system_ca-certificates/+/376563 accounted for via manifest change: https://review.lineageos.org/c/LineageOS/android_external_webp/+/376568 https://review.lineageos.org/q/topic:Q_asb_2023-12 https://review.lineageos.org/q/topic:Q_asb_2024-01 https://review.lineageos.org/q/topic:Q_asb_2024-02 https://review.lineageos.org/q/topic:Q_asb_2024-03 Signed-off-by: Tavi <tavi@divested.dev>
103 lines
5.5 KiB
Diff
103 lines
5.5 KiB
Diff
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
|
From: Daniel Micay <danielmicay@gmail.com>
|
|
Date: Fri, 21 Jul 2017 08:42:55 -0400
|
|
Subject: [PATCH] support new special runtime permissions
|
|
|
|
These are treated as a runtime permission even for legacy apps. They
|
|
need to be granted by default for all apps to maintain compatibility.
|
|
---
|
|
.../server/pm/PackageManagerService.java | 3 ++-
|
|
.../permission/PermissionManagerService.java | 23 +++++++++++++++----
|
|
2 files changed, 20 insertions(+), 6 deletions(-)
|
|
|
|
diff --git a/services/core/java/com/android/server/pm/PackageManagerService.java b/services/core/java/com/android/server/pm/PackageManagerService.java
|
|
index d27b5ad0d646..32b022455451 100644
|
|
--- a/services/core/java/com/android/server/pm/PackageManagerService.java
|
|
+++ b/services/core/java/com/android/server/pm/PackageManagerService.java
|
|
@@ -20218,7 +20218,8 @@ public class PackageManagerService extends IPackageManager.Stub
|
|
}
|
|
|
|
// If this permission was granted by default, make sure it is.
|
|
- if ((oldFlags & FLAG_PERMISSION_GRANTED_BY_DEFAULT) != 0) {
|
|
+ if ((oldFlags & FLAG_PERMISSION_GRANTED_BY_DEFAULT) != 0
|
|
+ || PermissionManagerService.isSpecialRuntimePermission(bp.getName())) {
|
|
mPermissionManager.grantRuntimePermission(permName, packageName, false,
|
|
Process.SYSTEM_UID, userId, delayingPermCallback);
|
|
// Allow app op later as we are holding mPackages
|
|
diff --git a/services/core/java/com/android/server/pm/permission/PermissionManagerService.java b/services/core/java/com/android/server/pm/permission/PermissionManagerService.java
|
|
index 2fcdec7c92d6..65646aef6c9e 100644
|
|
--- a/services/core/java/com/android/server/pm/permission/PermissionManagerService.java
|
|
+++ b/services/core/java/com/android/server/pm/permission/PermissionManagerService.java
|
|
@@ -1023,6 +1023,10 @@ public class PermissionManagerService {
|
|
}
|
|
}
|
|
|
|
+ public static boolean isSpecialRuntimePermission(final String permission) {
|
|
+ return false;
|
|
+ }
|
|
+
|
|
/**
|
|
* Restore the permission state for a package.
|
|
*
|
|
@@ -1322,6 +1326,14 @@ public class PermissionManagerService {
|
|
}
|
|
}
|
|
}
|
|
+
|
|
+ if (isSpecialRuntimePermission(bp.name) &&
|
|
+ origPermissions.getRuntimePermissionState(bp.name, userId) == null) {
|
|
+ if (permissionsState.grantRuntimePermission(bp, userId)
|
|
+ != PERMISSION_OPERATION_FAILURE) {
|
|
+ wasChanged = true;
|
|
+ }
|
|
+ }
|
|
} else {
|
|
if (permState == null) {
|
|
// New permission
|
|
@@ -1455,7 +1467,7 @@ public class PermissionManagerService {
|
|
wasChanged = true;
|
|
}
|
|
}
|
|
- } else {
|
|
+ } else {
|
|
if (!permissionsState.hasRuntimePermission(bp.name, userId)
|
|
&& permissionsState.grantRuntimePermission(bp,
|
|
userId) != PERMISSION_OPERATION_FAILURE) {
|
|
@@ -2233,7 +2245,7 @@ public class PermissionManagerService {
|
|
&& (grantedPermissions == null
|
|
|| ArrayUtils.contains(grantedPermissions, permission))) {
|
|
final int flags = permissionsState.getPermissionFlags(permission, userId);
|
|
- if (supportsRuntimePermissions) {
|
|
+ if (supportsRuntimePermissions || isSpecialRuntimePermission(bp.name)) {
|
|
// Installer cannot change immutable permissions.
|
|
if ((flags & immutableFlags) == 0) {
|
|
grantRuntimePermission(permission, pkg.packageName, false, callingUid,
|
|
@@ -2292,7 +2304,7 @@ public class PermissionManagerService {
|
|
// to keep the review required permission flag per user while an
|
|
// install permission's state is shared across all users.
|
|
if (pkg.applicationInfo.targetSdkVersion < Build.VERSION_CODES.M
|
|
- && bp.isRuntime()) {
|
|
+ && bp.isRuntime() && !isSpecialRuntimePermission(bp.name)) {
|
|
return;
|
|
}
|
|
|
|
@@ -2344,7 +2356,8 @@ public class PermissionManagerService {
|
|
+ permName + " for package " + packageName);
|
|
}
|
|
|
|
- if (pkg.applicationInfo.targetSdkVersion < Build.VERSION_CODES.M) {
|
|
+ if (pkg.applicationInfo.targetSdkVersion < Build.VERSION_CODES.M
|
|
+ && !isSpecialRuntimePermission(permName)) {
|
|
Slog.w(TAG, "Cannot grant runtime permission to a legacy app");
|
|
return;
|
|
}
|
|
@@ -2431,7 +2444,7 @@ public class PermissionManagerService {
|
|
// to keep the review required permission flag per user while an
|
|
// install permission's state is shared across all users.
|
|
if (pkg.applicationInfo.targetSdkVersion < Build.VERSION_CODES.M
|
|
- && bp.isRuntime()) {
|
|
+ && bp.isRuntime() && !isSpecialRuntimePermission(permName)) {
|
|
return;
|
|
}
|
|
|