diff options
| author | 2023-07-18 04:10:21 +0000 | |
|---|---|---|
| committer | 2023-07-18 04:10:21 +0000 | |
| commit | 9ffd42185bc5fa6dd0a5b493221def38736f180e (patch) | |
| tree | af0ab7949935be3529091a0d436c0107af7bfece | |
| parent | b9064cdc483213199f78babc810e313568d9ccef (diff) | |
| parent | 72cc4403af2d449e8f49064cbba7b56081425d67 (diff) | |
Merge "Remove obsolete comment from FileIntegrityService" into main am: a3cd5a9e90 am: 35ed783c43 am: 0f579212fa am: 5d90c239e3 am: 72cc4403af
Original change: https://android-review.googlesource.com/c/platform/frameworks/base/+/2661275
Change-Id: Id24425602bdf67c73b33a9c04ffcf5429c98372e
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
| -rw-r--r-- | services/core/java/com/android/server/security/FileIntegrityService.java | 6 |
1 files changed, 0 insertions, 6 deletions
diff --git a/services/core/java/com/android/server/security/FileIntegrityService.java b/services/core/java/com/android/server/security/FileIntegrityService.java index 5ae697315ed1..95296210be80 100644 --- a/services/core/java/com/android/server/security/FileIntegrityService.java +++ b/services/core/java/com/android/server/security/FileIntegrityService.java @@ -184,13 +184,7 @@ public class FileIntegrityService extends SystemService { } private void loadAllCertificates() { - // A better alternative to load certificates would be to read from .fs-verity kernel - // keyring, which fsverity_init loads to during earlier boot time from the same sources - // below. But since the read operation from keyring is not provided in kernel, we need to - // duplicate the same loading logic here. - // Load certificates trusted by the device manufacturer. - // NB: Directories need to be synced with system/security/fsverity_init/fsverity_init.cpp. final String relativeDir = "etc/security/fsverity"; loadCertificatesFromDirectory(Environment.getRootDirectory().toPath() .resolve(relativeDir)); |