4 ms·
Just a quick look, but this is the PackageManager.java file: https://android.googlesource.com/platform/frameworks/base/+/master/core/java/android/content/pm/Pa
by sandervenema 10y ago
Just a quick look, but this is the PackageManager.java file:
https://android.googlesource.com/platform/frameworks/base/+/master/core/java/android/content/pm/PackageManager.java https://android.googlesource.com/platform/frameworks/base/+/...
for the Android base framework. It has the checkSignatures() abstract definition and some other stuff that seems to be the API you talk about. Now this is all abstract, so some other party (maybe phone manufacturer, possibly others) must implement these methods to conform to the API. Could Google (or some other party) not just override the abstract implementation?
I find it hard to believe this is something only the phone manufacturer would have access to, not Google itself, given that Google has created the entire operating system basically, and is pulling more and more stuff from the AOSP into their proprietary apps (like Play services).
- zigzigzag 10y agoThe subclass would have to be in the same process as the package manager (the system server) so it being abstract doesn't matter much. Android doesn't rely so much on root vs non-root: it uses SELinux and lots of capability based security. Root is still there of course but out of the box, even the parts under remote OEM control don't run as root. If the OEM wants to change the basic rules of the system they must push a system update and get the user to agree to it. Of course a firmware update can change anything but outside of that I'm not convinced Google can just replace software at will.