Merge pull request #27 from Andrea-lyz/pr/fix-gpay-include-unique-id
fix(interception): strip INCLUDE_UNIQUE_ID instead of rejecting when permission missing
This commit is contained in:
+15
-6
@@ -434,8 +434,8 @@ class KeyMintSecurityLevelInterceptor(
|
|||||||
SystemLogger.debug(
|
SystemLogger.debug(
|
||||||
"Handling generateKey ${keyDescriptor.alias}, attestKey=${attestationKey?.alias}"
|
"Handling generateKey ${keyDescriptor.alias}, attestKey=${attestationKey?.alias}"
|
||||||
)
|
)
|
||||||
val params = data.createTypedArray(KeyParameter.CREATOR)!!
|
var params = data.createTypedArray(KeyParameter.CREATOR)!!
|
||||||
val parsedParams = KeyMintAttestation(params)
|
var parsedParams = KeyMintAttestation(params)
|
||||||
val isAttestKeyRequest = parsedParams.isAttestKey()
|
val isAttestKeyRequest = parsedParams.isAttestKey()
|
||||||
|
|
||||||
if (ConfigurationManager.shouldSkipUid(callingUid)
|
if (ConfigurationManager.shouldSkipUid(callingUid)
|
||||||
@@ -477,8 +477,16 @@ class KeyMintSecurityLevelInterceptor(
|
|||||||
return InterceptorUtils.createErrorReply(KEYMINT_CANNOT_ATTEST_IDS)
|
return InterceptorUtils.createErrorReply(KEYMINT_CANNOT_ATTEST_IDS)
|
||||||
}
|
}
|
||||||
|
|
||||||
// AOSP security_level.rs:478-485: INCLUDE_UNIQUE_ID requires
|
// INCLUDE_UNIQUE_ID requires SELinux gen_unique_id OR
|
||||||
// SELinux gen_unique_id OR Android REQUEST_UNIQUE_ID_ATTESTATION
|
// android.permission.REQUEST_UNIQUE_ID_ATTESTATION (AOSP
|
||||||
|
// security_level.rs:478-485). AOSP returns PERMISSION_DENIED
|
||||||
|
// when neither is held — but doing so breaks Google Wallet
|
||||||
|
// card binding (Wallet's generateKey carries the tag without
|
||||||
|
// holding the permission, and Play Integrity also fails when
|
||||||
|
// unique_id ends up in the attestation). Silently strip the
|
||||||
|
// tag so the key generates normally and the resulting
|
||||||
|
// attestation simply omits the unique_id field. This mirrors
|
||||||
|
// the pre-PR157 behavior where the tag had no effect.
|
||||||
if (params.any { it.tag == Tag.INCLUDE_UNIQUE_ID }) {
|
if (params.any { it.tag == Tag.INCLUDE_UNIQUE_ID }) {
|
||||||
val hasSELinux = ConfigurationManager.checkSELinuxPermission(
|
val hasSELinux = ConfigurationManager.checkSELinuxPermission(
|
||||||
callingPid, "keystore_key", "gen_unique_id",
|
callingPid, "keystore_key", "gen_unique_id",
|
||||||
@@ -487,8 +495,9 @@ class KeyMintSecurityLevelInterceptor(
|
|||||||
callingUid, "android.permission.REQUEST_UNIQUE_ID_ATTESTATION",
|
callingUid, "android.permission.REQUEST_UNIQUE_ID_ATTESTATION",
|
||||||
)
|
)
|
||||||
if (!hasSELinux && !hasAndroid) {
|
if (!hasSELinux && !hasAndroid) {
|
||||||
SystemLogger.warning("[TX_ID: $txId] Rejecting INCLUDE_UNIQUE_ID for uid=$callingUid pid=$callingPid")
|
SystemLogger.debug("[TX_ID: $txId] Stripping INCLUDE_UNIQUE_ID for uid=$callingUid pid=$callingPid (no permission)")
|
||||||
return InterceptorUtils.createServiceSpecificErrorReply(RESPONSE_PERMISSION_DENIED)
|
params = params.filter { it.tag != Tag.INCLUDE_UNIQUE_ID }.toTypedArray()
|
||||||
|
parsedParams = KeyMintAttestation(params)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user