blob: 1627655f5064891afef7c19251611f1c159ed04a [file] [log] [blame]
Brian Carlstrom3e6251d2011-04-11 09:05:06 -07001/*
2 * Copyright (C) 2011 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16
17package com.android.keychain;
18
Fred Quintanafb2e18e2011-07-13 14:54:05 -070019import android.app.IntentService;
20import android.content.ContentValues;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070021import android.content.Context;
22import android.content.Intent;
Fred Quintanafb2e18e2011-07-13 14:54:05 -070023import android.content.pm.PackageManager;
Zoltan Szatmary-Ban3d25b312014-08-18 10:54:19 +010024import android.content.pm.ParceledListSlice;
Fred Quintanafb2e18e2011-07-13 14:54:05 -070025import android.database.Cursor;
26import android.database.DatabaseUtils;
27import android.database.sqlite.SQLiteDatabase;
28import android.database.sqlite.SQLiteOpenHelper;
Kenny Root6f1f03b2012-03-08 10:30:39 -080029import android.os.Binder;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070030import android.os.IBinder;
Kenny Root6f1f03b2012-03-08 10:30:39 -080031import android.os.Process;
Robin Lee93772c32014-09-02 14:53:50 +010032import android.os.UserHandle;
Julia Reynolds3fb74492014-06-30 16:54:50 -040033import android.os.UserManager;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070034import android.security.Credentials;
35import android.security.IKeyChainService;
Selim Gurun39e36e52012-02-14 10:50:42 -080036import android.security.KeyChain;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070037import android.security.KeyStore;
38import android.util.Log;
Zoltan Szatmary-Ban3d25b312014-08-18 10:54:19 +010039import com.android.internal.util.ParcelableString;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070040import java.io.ByteArrayInputStream;
Brian Carlstroma58db542011-05-11 23:02:20 -070041import java.io.IOException;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070042import java.security.cert.CertificateException;
Zoltan Szatmary-Ban3d25b312014-08-18 10:54:19 +010043import java.security.cert.CertificateEncodingException;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070044import java.security.cert.CertificateFactory;
45import java.security.cert.X509Certificate;
Zoltan Szatmary-Ban3d25b312014-08-18 10:54:19 +010046import java.util.Set;
47import java.util.List;
48import java.util.ArrayList;
49import java.util.Collections;
Fred Quintanafb2e18e2011-07-13 14:54:05 -070050
Kenny Root3048b6c2013-04-23 22:38:11 -070051import com.android.org.conscrypt.TrustedCertificateStore;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070052
Fred Quintanafb2e18e2011-07-13 14:54:05 -070053public class KeyChainService extends IntentService {
Selim Gurun39e36e52012-02-14 10:50:42 -080054
Fred Quintanafb2e18e2011-07-13 14:54:05 -070055 private static final String TAG = "KeyChain";
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070056
Fred Quintanafb2e18e2011-07-13 14:54:05 -070057 private static final String DATABASE_NAME = "grants.db";
58 private static final int DATABASE_VERSION = 1;
59 private static final String TABLE_GRANTS = "grants";
60 private static final String GRANTS_ALIAS = "alias";
61 private static final String GRANTS_GRANTEE_UID = "uid";
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070062
Fred Quintanafb2e18e2011-07-13 14:54:05 -070063 /** created in onCreate(), closed in onDestroy() */
64 public DatabaseHelper mDatabaseHelper;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070065
Fred Quintanafb2e18e2011-07-13 14:54:05 -070066 private static final String SELECTION_COUNT_OF_MATCHING_GRANTS =
67 "SELECT COUNT(*) FROM " + TABLE_GRANTS
68 + " WHERE " + GRANTS_GRANTEE_UID + "=? AND " + GRANTS_ALIAS + "=?";
69
70 private static final String SELECT_GRANTS_BY_UID_AND_ALIAS =
71 GRANTS_GRANTEE_UID + "=? AND " + GRANTS_ALIAS + "=?";
72
73 private static final String SELECTION_GRANTS_BY_UID = GRANTS_GRANTEE_UID + "=?";
74
Robin Leeba755b12016-02-24 15:27:43 +000075 private static final String SELECTION_GRANTS_BY_ALIAS = GRANTS_ALIAS + "=?";
76
Fred Quintanafb2e18e2011-07-13 14:54:05 -070077 public KeyChainService() {
78 super(KeyChainService.class.getSimpleName());
79 }
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070080
81 @Override public void onCreate() {
82 super.onCreate();
Fred Quintanafb2e18e2011-07-13 14:54:05 -070083 mDatabaseHelper = new DatabaseHelper(this);
84 }
85
86 @Override
87 public void onDestroy() {
88 super.onDestroy();
89 mDatabaseHelper.close();
90 mDatabaseHelper = null;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070091 }
92
93 private final IKeyChainService.Stub mIKeyChainService = new IKeyChainService.Stub() {
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070094 private final KeyStore mKeyStore = KeyStore.getInstance();
Brian Carlstroma58db542011-05-11 23:02:20 -070095 private final TrustedCertificateStore mTrustedCertificateStore
96 = new TrustedCertificateStore();
Brian Carlstrom3e6251d2011-04-11 09:05:06 -070097
Kenny Root6f1f03b2012-03-08 10:30:39 -080098 @Override
99 public String requestPrivateKey(String alias) {
100 checkArgs(alias);
101
102 final String keystoreAlias = Credentials.USER_PRIVATE_KEY + alias;
103 final int uid = Binder.getCallingUid();
104 if (!mKeyStore.grant(keystoreAlias, uid)) {
105 return null;
106 }
Robin Lee93772c32014-09-02 14:53:50 +0100107 final int userHandle = UserHandle.getUserId(uid);
108 final int systemUidForUser = UserHandle.getUid(userHandle, Process.SYSTEM_UID);
Kenny Root6f1f03b2012-03-08 10:30:39 -0800109
110 final StringBuilder sb = new StringBuilder();
Robin Lee93772c32014-09-02 14:53:50 +0100111 sb.append(systemUidForUser);
Kenny Root6f1f03b2012-03-08 10:30:39 -0800112 sb.append('_');
113 sb.append(keystoreAlias);
114
115 return sb.toString();
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700116 }
117
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700118 @Override public byte[] getCertificate(String alias) {
Kenny Root6f1f03b2012-03-08 10:30:39 -0800119 checkArgs(alias);
120 return mKeyStore.get(Credentials.USER_CERTIFICATE + alias);
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700121 }
122
Rubin Xu8714f062016-03-23 12:37:10 +0000123 @Override public byte[] getCaCertificates(String alias) {
124 checkArgs(alias);
125 return mKeyStore.get(Credentials.CA_CERTIFICATE + alias);
126 }
127
Kenny Root6f1f03b2012-03-08 10:30:39 -0800128 private void checkArgs(String alias) {
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700129 if (alias == null) {
130 throw new NullPointerException("alias == null");
131 }
Kenny Root4ff22962013-02-14 10:17:06 -0800132 if (!mKeyStore.isUnlocked()) {
Nick Kralevichc8b04632012-05-21 15:13:07 -0700133 throw new IllegalStateException("keystore is "
134 + mKeyStore.state().toString());
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700135 }
Nick Kralevichc8b04632012-05-21 15:13:07 -0700136
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700137 final int callingUid = getCallingUid();
138 if (!hasGrantInternal(mDatabaseHelper.getReadableDatabase(), callingUid, alias)) {
139 throw new IllegalStateException("uid " + callingUid
140 + " doesn't have permission to access the requested alias");
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700141 }
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700142 }
143
Brian Carlstroma58db542011-05-11 23:02:20 -0700144 @Override public void installCaCertificate(byte[] caCertificate) {
Brian Carlstrom43f5b772011-06-27 02:27:16 -0700145 checkCertInstallerOrSystemCaller();
Julia Reynolds3fb74492014-06-30 16:54:50 -0400146 checkUserRestriction();
Brian Carlstroma58db542011-05-11 23:02:20 -0700147 try {
148 synchronized (mTrustedCertificateStore) {
149 mTrustedCertificateStore.installCertificate(parseCertificate(caCertificate));
150 }
151 } catch (IOException e) {
152 throw new IllegalStateException(e);
153 } catch (CertificateException e) {
154 throw new IllegalStateException(e);
155 }
Selim Gurun39e36e52012-02-14 10:50:42 -0800156 broadcastStorageChange();
Brian Carlstroma58db542011-05-11 23:02:20 -0700157 }
Brian Carlstrom5aeadd92011-05-17 00:40:33 -0700158
Rubin Xu8714f062016-03-23 12:37:10 +0000159 /**
160 * Install a key pair to the keystore.
161 *
162 * @param privateKey The private key associated with the client certificate
163 * @param userCertificate The client certificate to be installed
164 * @param userCertificateChain The rest of the chain for the client certificate
165 * @param alias The alias under which the key pair is installed
166 * @return Whether the operation succeeded or not.
167 */
Bernhard Bauerd300fc52014-07-21 15:32:30 +0100168 @Override public boolean installKeyPair(byte[] privateKey, byte[] userCertificate,
Rubin Xu8714f062016-03-23 12:37:10 +0000169 byte[] userCertificateChain, String alias) {
Bernhard Bauerd300fc52014-07-21 15:32:30 +0100170 checkCertInstallerOrSystemCaller();
Robin Lee8847b122015-07-27 12:50:28 +0100171 if (!mKeyStore.isUnlocked()) {
172 Log.e(TAG, "Keystore is " + mKeyStore.state().toString() + ". Credentials cannot"
173 + " be installed until device is unlocked");
174 return false;
175 }
Robin Leeba755b12016-02-24 15:27:43 +0000176 if (!removeKeyPair(alias)) {
177 return false;
178 }
Bernhard Bauerd300fc52014-07-21 15:32:30 +0100179 if (!mKeyStore.importKey(Credentials.USER_PRIVATE_KEY + alias, privateKey, -1,
180 KeyStore.FLAG_ENCRYPTED)) {
181 Log.e(TAG, "Failed to import private key " + alias);
182 return false;
183 }
184 if (!mKeyStore.put(Credentials.USER_CERTIFICATE + alias, userCertificate, -1,
185 KeyStore.FLAG_ENCRYPTED)) {
186 Log.e(TAG, "Failed to import user certificate " + userCertificate);
Alex Klyubin44c777b2015-06-08 09:46:15 -0700187 if (!mKeyStore.delete(Credentials.USER_PRIVATE_KEY + alias)) {
Bernhard Bauerd300fc52014-07-21 15:32:30 +0100188 Log.e(TAG, "Failed to delete private key after certificate importing failed");
189 }
190 return false;
191 }
Rubin Xu8714f062016-03-23 12:37:10 +0000192 if (userCertificateChain != null && userCertificateChain.length > 0) {
193 if (!mKeyStore.put(Credentials.CA_CERTIFICATE + alias, userCertificateChain, -1,
194 KeyStore.FLAG_ENCRYPTED)) {
195 Log.e(TAG, "Failed to import certificate chain" + userCertificateChain);
196 if (!removeKeyPair(alias)) {
197 Log.e(TAG, "Failed to clean up key chain after certificate chain"
198 + " importing failed");
199 }
200 return false;
201 }
202 }
Bernhard Bauerd300fc52014-07-21 15:32:30 +0100203 broadcastStorageChange();
204 return true;
205 }
206
Robin Leef44a5192015-08-03 17:18:02 +0100207 @Override public boolean removeKeyPair(String alias) {
208 checkCertInstallerOrSystemCaller();
Robin Leeba755b12016-02-24 15:27:43 +0000209 if (!Credentials.deleteAllTypesForAlias(mKeyStore, alias)) {
210 return false;
211 }
212 removeGrantsForAlias(alias);
213 broadcastStorageChange();
214 return true;
Robin Leef44a5192015-08-03 17:18:02 +0100215 }
216
Brian Carlstrom5aeadd92011-05-17 00:40:33 -0700217 private X509Certificate parseCertificate(byte[] bytes) throws CertificateException {
218 CertificateFactory cf = CertificateFactory.getInstance("X.509");
219 return (X509Certificate) cf.generateCertificate(new ByteArrayInputStream(bytes));
220 }
221
Brian Carlstroma58db542011-05-11 23:02:20 -0700222 @Override public boolean reset() {
223 // only Settings should be able to reset
Brian Carlstrom43f5b772011-06-27 02:27:16 -0700224 checkSystemCaller();
Julia Reynolds3fb74492014-06-30 16:54:50 -0400225 checkUserRestriction();
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700226 removeAllGrants(mDatabaseHelper.getWritableDatabase());
Brian Carlstroma58db542011-05-11 23:02:20 -0700227 boolean ok = true;
Brian Carlstroma58db542011-05-11 23:02:20 -0700228 synchronized (mTrustedCertificateStore) {
229 // delete user-installed CA certs
230 for (String alias : mTrustedCertificateStore.aliases()) {
231 if (TrustedCertificateStore.isUser(alias)) {
Brian Carlstrom43f5b772011-06-27 02:27:16 -0700232 if (!deleteCertificateEntry(alias)) {
Brian Carlstroma58db542011-05-11 23:02:20 -0700233 ok = false;
234 }
235 }
236 }
Brian Carlstroma58db542011-05-11 23:02:20 -0700237 }
Selim Gurun39e36e52012-02-14 10:50:42 -0800238 broadcastStorageChange();
239 return ok;
Brian Carlstroma58db542011-05-11 23:02:20 -0700240 }
Brian Carlstrom43f5b772011-06-27 02:27:16 -0700241
242 @Override public boolean deleteCaCertificate(String alias) {
243 // only Settings should be able to delete
244 checkSystemCaller();
Julia Reynolds3fb74492014-06-30 16:54:50 -0400245 checkUserRestriction();
Selim Gurun39e36e52012-02-14 10:50:42 -0800246 boolean ok = true;
247 synchronized (mTrustedCertificateStore) {
248 ok = deleteCertificateEntry(alias);
249 }
250 broadcastStorageChange();
251 return ok;
Brian Carlstrom43f5b772011-06-27 02:27:16 -0700252 }
253
254 private boolean deleteCertificateEntry(String alias) {
255 try {
256 mTrustedCertificateStore.deleteCertificateEntry(alias);
257 return true;
258 } catch (IOException e) {
259 Log.w(TAG, "Problem removing CA certificate " + alias, e);
260 return false;
261 } catch (CertificateException e) {
262 Log.w(TAG, "Problem removing CA certificate " + alias, e);
263 return false;
264 }
265 }
266
267 private void checkCertInstallerOrSystemCaller() {
268 String actual = checkCaller("com.android.certinstaller");
269 if (actual == null) {
270 return;
271 }
272 checkSystemCaller();
273 }
274 private void checkSystemCaller() {
275 String actual = checkCaller("android.uid.system:1000");
276 if (actual != null) {
277 throw new IllegalStateException(actual);
278 }
279 }
Julia Reynolds3fb74492014-06-30 16:54:50 -0400280 private void checkUserRestriction() {
281 UserManager um = (UserManager) getSystemService(USER_SERVICE);
282 if (um.hasUserRestriction(UserManager.DISALLOW_CONFIG_CREDENTIALS)) {
283 throw new SecurityException("User cannot modify credentials");
284 }
285 }
Brian Carlstrom43f5b772011-06-27 02:27:16 -0700286 /**
287 * Returns null if actually caller is expected, otherwise return bad package to report
288 */
289 private String checkCaller(String expectedPackage) {
290 String actualPackage = getPackageManager().getNameForUid(getCallingUid());
291 return (!expectedPackage.equals(actualPackage)) ? actualPackage : null;
292 }
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700293
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700294 @Override public boolean hasGrant(int uid, String alias) {
295 checkSystemCaller();
296 return hasGrantInternal(mDatabaseHelper.getReadableDatabase(), uid, alias);
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700297 }
298
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700299 @Override public void setGrant(int uid, String alias, boolean value) {
300 checkSystemCaller();
301 setGrantInternal(mDatabaseHelper.getWritableDatabase(), uid, alias, value);
Selim Gurun39e36e52012-02-14 10:50:42 -0800302 broadcastStorageChange();
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700303 }
Zoltan Szatmary-Ban3d25b312014-08-18 10:54:19 +0100304
305 private ParceledListSlice<ParcelableString> makeAliasesParcelableSynchronised(
306 Set<String> aliasSet) {
307 List<ParcelableString> aliases = new ArrayList<ParcelableString>(aliasSet.size());
308 for (String alias : aliasSet) {
309 ParcelableString parcelableString = new ParcelableString();
310 parcelableString.string = alias;
311 aliases.add(parcelableString);
312 }
313 return new ParceledListSlice<ParcelableString>(aliases);
314 }
315
316 @Override
317 public ParceledListSlice<ParcelableString> getUserCaAliases() {
318 synchronized (mTrustedCertificateStore) {
319 Set<String> aliasSet = mTrustedCertificateStore.userAliases();
320 return makeAliasesParcelableSynchronised(aliasSet);
321 }
322 }
323
324 @Override
325 public ParceledListSlice<ParcelableString> getSystemCaAliases() {
326 synchronized (mTrustedCertificateStore) {
327 Set<String> aliasSet = mTrustedCertificateStore.allSystemAliases();
328 return makeAliasesParcelableSynchronised(aliasSet);
329 }
330 }
331
332 @Override
333 public boolean containsCaAlias(String alias) {
334 return mTrustedCertificateStore.containsAlias(alias);
335 }
336
337 @Override
338 public byte[] getEncodedCaCertificate(String alias, boolean includeDeletedSystem) {
339 synchronized (mTrustedCertificateStore) {
340 X509Certificate certificate = (X509Certificate) mTrustedCertificateStore
341 .getCertificate(alias, includeDeletedSystem);
342 if (certificate == null) {
343 Log.w(TAG, "Could not find CA certificate " + alias);
344 return null;
345 }
346 try {
347 return certificate.getEncoded();
348 } catch (CertificateEncodingException e) {
349 Log.w(TAG, "Error while encoding CA certificate " + alias);
350 return null;
351 }
352 }
353 }
354
355 @Override
356 public List<String> getCaCertificateChainAliases(String rootAlias,
357 boolean includeDeletedSystem) {
358 synchronized (mTrustedCertificateStore) {
359 X509Certificate root = (X509Certificate) mTrustedCertificateStore.getCertificate(
360 rootAlias, includeDeletedSystem);
361 try {
362 List<X509Certificate> chain = mTrustedCertificateStore.getCertificateChain(
363 root);
364 List<String> aliases = new ArrayList<String>(chain.size());
365 final int n = chain.size();
366 for (int i = 0; i < n; ++i) {
367 String alias = mTrustedCertificateStore.getCertificateAlias(chain.get(i),
368 true);
369 if (alias != null) {
370 aliases.add(alias);
371 }
372 }
373 return aliases;
374 } catch (CertificateException e) {
375 Log.w(TAG, "Error retrieving cert chain for root " + rootAlias);
376 return Collections.emptyList();
377 }
378 }
379 }
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700380 };
381
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700382 private boolean hasGrantInternal(final SQLiteDatabase db, final int uid, final String alias) {
383 final long numMatches = DatabaseUtils.longForQuery(db, SELECTION_COUNT_OF_MATCHING_GRANTS,
384 new String[]{String.valueOf(uid), alias});
385 return numMatches > 0;
386 }
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700387
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700388 private void setGrantInternal(final SQLiteDatabase db,
389 final int uid, final String alias, final boolean value) {
390 if (value) {
391 if (!hasGrantInternal(db, uid, alias)) {
392 final ContentValues values = new ContentValues();
393 values.put(GRANTS_ALIAS, alias);
394 values.put(GRANTS_GRANTEE_UID, uid);
395 db.insert(TABLE_GRANTS, GRANTS_ALIAS, values);
396 }
397 } else {
398 db.delete(TABLE_GRANTS, SELECT_GRANTS_BY_UID_AND_ALIAS,
399 new String[]{String.valueOf(uid), alias});
400 }
401 }
402
Robin Leeba755b12016-02-24 15:27:43 +0000403 private void removeGrantsForAlias(String alias) {
404 final SQLiteDatabase db = mDatabaseHelper.getWritableDatabase();
405 db.delete(TABLE_GRANTS, SELECTION_GRANTS_BY_ALIAS, new String[] {alias});
406 }
407
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700408 private void removeAllGrants(final SQLiteDatabase db) {
409 db.delete(TABLE_GRANTS, null /* whereClause */, null /* whereArgs */);
410 }
411
412 private class DatabaseHelper extends SQLiteOpenHelper {
413 public DatabaseHelper(Context context) {
414 super(context, DATABASE_NAME, null /* CursorFactory */, DATABASE_VERSION);
415 }
416
417 @Override
418 public void onCreate(final SQLiteDatabase db) {
419 db.execSQL("CREATE TABLE " + TABLE_GRANTS + " ( "
420 + GRANTS_ALIAS + " STRING NOT NULL, "
421 + GRANTS_GRANTEE_UID + " INTEGER NOT NULL, "
422 + "UNIQUE (" + GRANTS_ALIAS + "," + GRANTS_GRANTEE_UID + "))");
423 }
424
425 @Override
426 public void onUpgrade(final SQLiteDatabase db, int oldVersion, final int newVersion) {
427 Log.e(TAG, "upgrade from version " + oldVersion + " to version " + newVersion);
428
429 if (oldVersion == 1) {
430 // the first upgrade step goes here
431 oldVersion++;
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700432 }
Brian Carlstrom7037b732011-06-30 15:04:49 -0700433 }
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700434 }
435
436 @Override public IBinder onBind(Intent intent) {
Brian Carlstrom7037b732011-06-30 15:04:49 -0700437 if (IKeyChainService.class.getName().equals(intent.getAction())) {
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700438 return mIKeyChainService;
439 }
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700440 return null;
441 }
Fred Quintanafb2e18e2011-07-13 14:54:05 -0700442
443 @Override
444 protected void onHandleIntent(final Intent intent) {
445 if (Intent.ACTION_PACKAGE_REMOVED.equals(intent.getAction())) {
446 purgeOldGrants();
447 }
448 }
449
450 private void purgeOldGrants() {
451 final PackageManager packageManager = getPackageManager();
452 final SQLiteDatabase db = mDatabaseHelper.getWritableDatabase();
453 Cursor cursor = null;
454 db.beginTransaction();
455 try {
456 cursor = db.query(TABLE_GRANTS,
457 new String[]{GRANTS_GRANTEE_UID}, null, null, GRANTS_GRANTEE_UID, null, null);
458 while (cursor.moveToNext()) {
459 final int uid = cursor.getInt(0);
460 final boolean packageExists = packageManager.getPackagesForUid(uid) != null;
461 if (packageExists) {
462 continue;
463 }
464 Log.d(TAG, "deleting grants for UID " + uid
465 + " because its package is no longer installed");
466 db.delete(TABLE_GRANTS, SELECTION_GRANTS_BY_UID,
467 new String[]{Integer.toString(uid)});
468 }
469 db.setTransactionSuccessful();
470 } finally {
471 if (cursor != null) {
472 cursor.close();
473 }
474 db.endTransaction();
475 }
476 }
Selim Gurun39e36e52012-02-14 10:50:42 -0800477
478 private void broadcastStorageChange() {
479 Intent intent = new Intent(KeyChain.ACTION_STORAGE_CHANGED);
Robin Lee1f00eaf2014-10-16 16:27:02 +0100480 sendBroadcastAsUser(intent, new UserHandle(UserHandle.myUserId()));
Selim Gurun39e36e52012-02-14 10:50:42 -0800481 }
482
Brian Carlstrom3e6251d2011-04-11 09:05:06 -0700483}