diff options
3 files changed, 10 insertions, 3 deletions
diff --git a/core/java/android/content/pm/ApplicationInfo.java b/core/java/android/content/pm/ApplicationInfo.java index 2978058b2848..9f46996269d3 100644 --- a/core/java/android/content/pm/ApplicationInfo.java +++ b/core/java/android/content/pm/ApplicationInfo.java @@ -1947,6 +1947,11 @@ public class ApplicationInfo extends PackageItemInfo implements Parcelable { return (privateFlags & ApplicationInfo.PRIVATE_FLAG_PRODUCT_SERVICES) != 0; } + /** @hide */ + public boolean isCodeIntegrityPreferred() { + return (privateFlags & PRIVATE_FLAG_PREFER_CODE_INTEGRITY) != 0; + } + /** * Returns whether or not this application was installed as a virtual preload. */ diff --git a/services/core/java/com/android/server/am/ProcessList.java b/services/core/java/com/android/server/am/ProcessList.java index d133deaf4b8e..26a0b599407f 100644 --- a/services/core/java/com/android/server/am/ProcessList.java +++ b/services/core/java/com/android/server/am/ProcessList.java @@ -1362,7 +1362,7 @@ public final class ProcessList { mService.mNativeDebuggingApp = null; } - if ((app.info.privateFlags & ApplicationInfo.PRIVATE_FLAG_PREFER_CODE_INTEGRITY) != 0 + if (app.info.isCodeIntegrityPreferred() || (app.info.isPrivilegedApp() && DexManager.isPackageSelectedToRunOob(app.pkgList.mPkgList.keySet()))) { runtimeFlags |= Zygote.ONLY_USE_SYSTEM_OAT_FILES; diff --git a/services/core/java/com/android/server/pm/PackageDexOptimizer.java b/services/core/java/com/android/server/pm/PackageDexOptimizer.java index f9e31aed1174..db7e99d952a9 100644 --- a/services/core/java/com/android/server/pm/PackageDexOptimizer.java +++ b/services/core/java/com/android/server/pm/PackageDexOptimizer.java @@ -509,8 +509,10 @@ public class PackageDexOptimizer { boolean isUsedByOtherApps) { int flags = info.flags; boolean vmSafeMode = (flags & ApplicationInfo.FLAG_VM_SAFE_MODE) != 0; - // When a priv app is configured to run out of box, only verify it. - if (info.isPrivilegedApp() && DexManager.isPackageSelectedToRunOob(info.packageName)) { + // When an app or priv app is configured to run out of box, only verify it. + if (info.isCodeIntegrityPreferred() + || (info.isPrivilegedApp() + && DexManager.isPackageSelectedToRunOob(info.packageName))) { return "verify"; } if (vmSafeMode) { |