Derive boot and vendor patch levels from system prop when system=prop
TrickyAddon fetches Pixel bulletin dates for boot/vendor but system=prop resolves to the real device prop, creating a cross-component date mismatch on non-Pixel devices. Force all three through the same prop resolution path.
This commit is contained in:
@@ -112,6 +112,7 @@ object AttestationBuilder {
|
|||||||
}
|
}
|
||||||
|
|
||||||
val bootPatch = AndroidDeviceUtils.getBootPatchLevelLong(uid)
|
val bootPatch = AndroidDeviceUtils.getBootPatchLevelLong(uid)
|
||||||
|
SystemLogger.info("Attestation patch levels for uid=$uid: os=$osPatch, vendor=$vendorPatch, boot=$bootPatch")
|
||||||
properties[AttestationConstants.TAG_BOOT_PATCHLEVEL] =
|
properties[AttestationConstants.TAG_BOOT_PATCHLEVEL] =
|
||||||
if (bootPatch != DO_NOT_REPORT) {
|
if (bootPatch != DO_NOT_REPORT) {
|
||||||
DERTaggedObject(
|
DERTaggedObject(
|
||||||
|
|||||||
@@ -253,7 +253,14 @@ object ConfigurationManager {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Parse global and per-package configurations.
|
// Parse global and per-package configurations.
|
||||||
val newGlobalLevel = parseLines(contextLines[""])
|
var newGlobalLevel = parseLines(contextLines[""])
|
||||||
|
// TrickyAddon writes Pixel bulletin dates for boot/vendor but system=prop
|
||||||
|
// resolves to the real device prop — force boot/vendor through the same path
|
||||||
|
// to prevent cross-component date mismatches on non-Pixel devices.
|
||||||
|
if (newGlobalLevel?.system.equals("prop", ignoreCase = true)) {
|
||||||
|
SystemLogger.info("system=prop: forcing boot/vendor to derive from device props (were: boot=${newGlobalLevel?.boot}, vendor=${newGlobalLevel?.vendor})")
|
||||||
|
newGlobalLevel = newGlobalLevel?.copy(boot = "prop", vendor = "prop")
|
||||||
|
}
|
||||||
contextLines.remove("") // Remove global context to iterate over packages next
|
contextLines.remove("") // Remove global context to iterate over packages next
|
||||||
|
|
||||||
for ((pkg, lines) in contextLines) {
|
for ((pkg, lines) in contextLines) {
|
||||||
|
|||||||
@@ -239,11 +239,12 @@ object AndroidDeviceUtils {
|
|||||||
val resolvedValue = resolveDateKeywords(value)
|
val resolvedValue = resolveDateKeywords(value)
|
||||||
|
|
||||||
return when {
|
return when {
|
||||||
// "device_default" indicates falling back to the system property.
|
|
||||||
resolvedValue.equals("device_default", ignoreCase = true) -> null
|
resolvedValue.equals("device_default", ignoreCase = true) -> null
|
||||||
// "no" indicates this value should not be reported.
|
// Resolve from live system prop — matches what detectors see via getprop,
|
||||||
|
// even when PIF has spoofed ro.build.version.security_patch via resetprop
|
||||||
|
resolvedValue.equals("prop", ignoreCase = true) ->
|
||||||
|
parsePatchLevelValue(SystemProperties.get("ro.build.version.security_patch", ""), isLong)
|
||||||
resolvedValue.equals("no", ignoreCase = true) -> DO_NOT_REPORT
|
resolvedValue.equals("no", ignoreCase = true) -> DO_NOT_REPORT
|
||||||
// Otherwise, parse the resolved date string.
|
|
||||||
else -> parsePatchLevelValue(resolvedValue, isLong)
|
else -> parsePatchLevelValue(resolvedValue, isLong)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user