Fix a vulnerable query from sql injection
[platform/core/appfw/pkgmgr-info.git] / src / pkgmgrinfo_appinfo.c
index 4feacd5..1529a85 100644 (file)
@@ -52,9 +52,12 @@ static const char join_app_control[] =
 static const char join_metadata[] =
        " LEFT OUTER JOIN package_app_app_metadata"
        "  ON ai.app_id=package_app_app_metadata.app_id ";
+static const char join_appinfo_for_uid[] =
+       " LEFT OUTER JOIN package_app_info_for_uid"
+       " ON ai.app_id=package_app_info_for_uid.app_id ";
 
 static int _get_filtered_query(pkgmgrinfo_filter_x *filter,
-       const char *locale, char **query, GList **bind_params)
+       const char *locale, uid_t uid, char **query, GList **bind_params)
 {
        int joined = 0;
        size_t len = 0;
@@ -65,8 +68,8 @@ static int _get_filtered_query(pkgmgrinfo_filter_x *filter,
                        "(SELECT package FROM package_info WHERE package_disable='false')";
        GSList *list;
 
-       len += strlen(" WHERE 1=1");
        strncat(buf, " WHERE 1=1", MAX_QUERY_LEN - len - 1);
+       len += strlen(" WHERE 1=1");
 
        if (filter == NULL) {
                strncat(buf, query_pkg_disable, MAX_QUERY_LEN - len - 1);
@@ -75,17 +78,39 @@ static int _get_filtered_query(pkgmgrinfo_filter_x *filter,
        }
 
        for (list = filter->list; list; list = list->next) {
-               joined |= __get_filter_condition(list->data, &condition, bind_params);
+               joined |= __get_filter_condition(list->data, uid, &condition, bind_params);
                if (condition == NULL)
                        continue;
 
-               len += strlen(" AND ");
                strncat(buf, " AND ", MAX_QUERY_LEN - len - 1);
+               len += strlen(" AND ");
 
+               strncat(buf, condition, sizeof(buf) - len - 1);
                len += strlen(condition);
+               free(condition);
+               condition = NULL;
+       }
+
+       if (filter->list_metadata) {
+               strncat(buf, " AND (", MAX_QUERY_LEN - len - 1);
+               len += strlen(" AND (");
+       }
+       for (list = filter->list_metadata; list; list = list->next) {
+               joined |= __get_metadata_filter_condition(list->data,
+                               &condition, bind_params);
+               if (condition == NULL)
+                       continue;
                strncat(buf, condition, sizeof(buf) - len - 1);
+               len += strlen(condition);
                free(condition);
                condition = NULL;
+
+               strncat(buf, " OR ", MAX_QUERY_LEN - len - 1);
+               len += strlen(" OR ");
+       }
+       if (filter->list_metadata) {
+               strncat(buf, "1=0)", MAX_QUERY_LEN - len - 1);
+               len += strlen("1=0)");
        }
 
        if (joined & E_PMINFO_APPINFO_JOIN_LOCALIZED_INFO) {
@@ -105,9 +130,13 @@ static int _get_filtered_query(pkgmgrinfo_filter_x *filter,
                strncat(tmp_query, join_metadata, MAX_QUERY_LEN - len - 1);
                len += strlen(join_metadata);
        }
+       if (joined & E_PMINFO_APPINFO_JOIN_APPINFO_FOR_UID) {
+               strncat(tmp_query, join_appinfo_for_uid, MAX_QUERY_LEN - len - 1);
+               len += strlen(join_appinfo_for_uid);
+       }
        strncat(tmp_query, buf, MAX_QUERY_LEN - len - 1);
-
        len += strlen(buf);
+
        strncat(tmp_query, query_pkg_disable, MAX_QUERY_LEN - len - 1);
 
        *query = strdup(tmp_query);
@@ -225,7 +254,7 @@ static int _appinfo_get_data_control(sqlite3 *db, const char *appid,
                GList **datacontrol)
 {
        static const char query_raw[] =
-               "SELECT providerid, access, type "
+               "SELECT providerid, access, type, trusted "
                "FROM package_app_data_control WHERE app_id=%Q";
        int ret;
        char *query;
@@ -257,6 +286,7 @@ static int _appinfo_get_data_control(sqlite3 *db, const char *appid,
                _save_column_str(stmt, idx++, &info->providerid);
                _save_column_str(stmt, idx++, &info->access);
                _save_column_str(stmt, idx++, &info->type);
+               _save_column_str(stmt, idx++, &info->trusted);
                *datacontrol = g_list_append(*datacontrol, info);
        }
 
@@ -397,35 +427,46 @@ static GList *__get_background_category(const char *value)
 
 }
 
-static void __get_splash_screen_display(sqlite3 *db, const char *appid, uid_t uid, char **value)
+static int __get_appinfo_for_uid(sqlite3 *db, application_x *info, uid_t uid)
 {
        static const char query_raw[] =
-               "SELECT is_splash_screen_enabled FROM package_app_info_for_uid "
-               "WHERE app_id='%s' AND uid='%d'";
+               "SELECT is_splash_screen_enabled, is_disabled "
+               "FROM package_app_info_for_uid WHERE app_id=%Q AND uid=%d";
        int ret;
        char *query;
+       char *is_disabled = NULL;
        sqlite3_stmt *stmt;
 
-       query = sqlite3_mprintf(query_raw, appid, uid);
+       query = sqlite3_mprintf(query_raw, info->appid, uid);
        if (query == NULL) {
                LOGE("out of memory");
-               return;
+               return PMINFO_R_ERROR;
        }
 
        ret = sqlite3_prepare_v2(db, query, strlen(query), &stmt, NULL);
        sqlite3_free(query);
        if (ret != SQLITE_OK) {
                LOGE("sqlite3_prepare_v2() failed: %s", sqlite3_errmsg(db));
-               return;
+               return PMINFO_R_ERROR;
        }
 
        while (sqlite3_step(stmt) == SQLITE_ROW) {
-               if (*value)
-                       free(*value);
-               _save_column_str(stmt, 0, value);
+               if (info->splash_screen_display)
+                       free(info->splash_screen_display);
+               _save_column_str(stmt, 0, &info->splash_screen_display);
+               if (strcasecmp(info->is_disabled, "false") == 0) {
+                       _save_column_str(stmt, 1, &is_disabled);
+                       if (strcasecmp(is_disabled, "true") == 0) {
+                               free(info->is_disabled);
+                               info->is_disabled = is_disabled;
+                       } else {
+                               free(is_disabled);
+                       }
+               }
        }
 
        sqlite3_finalize(stmt);
+       return PMINFO_R_OK;
 }
 
 static void __free_applications(gpointer data)
@@ -509,7 +550,7 @@ static int _appinfo_get_applications(uid_t db_uid, uid_t uid,
                "SELECT DISTINCT ai.app_id, ai.app_component, ai.app_exec, "
                "ai.app_nodisplay, ai.app_type, ai.app_onboot, "
                "ai.app_multiple, ai.app_autorestart, ai.app_taskmanage, "
-               "ai.app_enabled, ai.app_hwacceleration, ai.app_screenreader, "
+               "ai.app_hwacceleration, ai.app_screenreader, "
                "ai.app_mainapp, ai.app_recentimage, ai.app_launchcondition, "
                "ai.app_indicatordisplay, ai.app_portraitimg, "
                "ai.app_landscapeimg, ai.app_guestmodevisibility, "
@@ -523,7 +564,7 @@ static int _appinfo_get_applications(uid_t db_uid, uid_t uid,
                "ai.app_zip_mount_file, ai.component_type, ai.package, "
                "ai.app_external_path, ai.app_package_system, ai.app_removable, "
                "ai.app_package_installed_time, ai.app_support_mode, "
-               "ai.app_support_ambient";
+               "ai.app_support_ambient, ai.app_setup_appid";
        static const char query_label[] =
                ", COALESCE("
                "(SELECT app_label FROM package_app_localized_info WHERE ai.app_id=app_id AND app_locale=?), "
@@ -551,7 +592,7 @@ static int _appinfo_get_applications(uid_t db_uid, uid_t uid,
        if (dbpath == NULL)
                return PMINFO_R_ERROR;
 
-       ret = sqlite3_open_v2(dbpath, &db, SQLITE_OPEN_READONLY, NULL);
+       ret = __open_db(dbpath, &db, SQLITE_OPEN_READONLY);
        if (ret != SQLITE_OK) {
                _LOGE("failed to open db: %d", ret);
                free(dbpath);
@@ -574,7 +615,7 @@ static int _appinfo_get_applications(uid_t db_uid, uid_t uid,
 
        is_check_storage = __check_app_storage_status(filter);
 
-       ret = _get_filtered_query(filter, locale, &constraint, &bind_params);
+       ret = _get_filtered_query(filter, locale, uid, &constraint, &bind_params);
        if (ret != PMINFO_R_OK) {
                LOGE("Failed to get WHERE clause");
                goto catch;
@@ -624,7 +665,6 @@ static int _appinfo_get_applications(uid_t db_uid, uid_t uid,
                _save_column_str(stmt, idx++, &info->multiple);
                _save_column_str(stmt, idx++, &info->autorestart);
                _save_column_str(stmt, idx++, &info->taskmanage);
-               _save_column_str(stmt, idx++, &info->enabled);
                _save_column_str(stmt, idx++, &info->hwacceleration);
                _save_column_str(stmt, idx++, &info->screenreader);
                _save_column_str(stmt, idx++, &info->mainapp);
@@ -660,13 +700,20 @@ static int _appinfo_get_applications(uid_t db_uid, uid_t uid,
                _save_column_str(stmt, idx++, &info->package_installed_time);
                _save_column_str(stmt, idx++, &info->support_mode);
                _save_column_str(stmt, idx++, &info->support_ambient);
+               _save_column_str(stmt, idx++, &info->setup_appid);
 
                info->for_all_users =
-                       strdup((uid != GLOBAL_USER) ? "false" : "true");
-
-               if (db_uid == GLOBAL_USER)
-                       __get_splash_screen_display(db, info->appid, db_uid,
-                                       &info->splash_screen_display);
+                       strdup((db_uid != GLOBAL_USER) ? "false" : "true");
+
+               if (db_uid == GLOBAL_USER) {
+                       ret = __get_appinfo_for_uid(db, info, uid);
+                       if (ret != PMINFO_R_OK) {
+                               LOGI("Failed to get appinfo for given uid[%d]", (int)uid);
+                               pkgmgrinfo_basic_free_application(info);
+                               info = NULL;
+                               continue;
+                       }
+               }
 
                info->background_category = __get_background_category(
                                bg_category_str);
@@ -784,7 +831,7 @@ static int _pkgmgrinfo_get_appinfo(const char *appid, uid_t uid,
        ret = _appinfo_get_applications(uid, uid, locale, filter,
                        PMINFO_APPINFO_GET_ALL, list);
        if (!g_hash_table_size(list) && uid != GLOBAL_USER)
-               ret = _appinfo_get_applications(GLOBAL_USER, GLOBAL_USER, locale, filter,
+               ret = _appinfo_get_applications(GLOBAL_USER, uid, locale, filter,
                                PMINFO_APPINFO_GET_ALL, list);
 
        if (!g_hash_table_size(list)) {
@@ -1035,6 +1082,8 @@ static gpointer __copy_datacontrol(gconstpointer src, gpointer data)
                datacontrol->access = strdup(tmp->access);
        if (tmp->type)
                datacontrol->type = strdup(tmp->type);
+       if (tmp->trusted)
+               datacontrol->trusted = strdup(tmp->trusted);
 
        return datacontrol;
 }
@@ -1110,8 +1159,6 @@ static int _appinfo_copy_appinfo(application_x **application, application_x *dat
                app_info->multiple = strdup(data->multiple);
        if (data->taskmanage != NULL)
                app_info->taskmanage = strdup(data->taskmanage);
-       if (data->enabled != NULL)
-               app_info->enabled = strdup(data->enabled);
        if (data->type != NULL)
                app_info->type = strdup(data->type);
        if (data->categories != NULL)
@@ -1299,9 +1346,10 @@ static int _appinfo_get_filtered_foreach_appinfo(uid_t uid,
                return PMINFO_R_ERROR;
        }
 
-       if (__check_disable_filter_exist(filter) == false)
+       if (__check_disable_filter_exist(filter) == false) {
                pkgmgrinfo_appinfo_filter_add_bool(filter,
                                PMINFO_APPINFO_PROP_APP_DISABLE, false);
+       }
 
        ret = _appinfo_get_applications(uid, uid, locale, filter, flag, list);
        if (ret == PMINFO_R_OK && uid != GLOBAL_USER)
@@ -1359,15 +1407,6 @@ API int pkgmgrinfo_appinfo_get_usr_list(pkgmgrinfo_pkginfo_h handle,
                return PMINFO_R_ERROR;
        }
 
-       if (uid == GLOBAL_USER) {
-               if (pkgmgrinfo_appinfo_filter_add_int(filter,
-                                       PMINFO_APPINFO_PROP_APP_DISABLE_FOR_USER,
-                                       (int)getuid())) {
-                       pkgmgrinfo_appinfo_filter_destroy(filter);
-                       return PMINFO_R_ERROR;
-               }
-       }
-
        comp_str = __appcomponent_str(component);
 
        if (comp_str) {
@@ -1415,13 +1454,10 @@ API int pkgmgrinfo_appinfo_get_usr_installed_list_full(
                return PMINFO_R_ERROR;
        }
 
-       if (uid == GLOBAL_USER) {
-               if (pkgmgrinfo_appinfo_filter_add_int(filter,
-                                       PMINFO_APPINFO_PROP_APP_DISABLE_FOR_USER,
-                                       (int)getuid())) {
-                       pkgmgrinfo_appinfo_filter_destroy(filter);
-                       return PMINFO_R_ERROR;
-               }
+       if (pkgmgrinfo_appinfo_filter_add_bool(filter,
+                       PMINFO_APPINFO_PROP_APP_CHECK_STORAGE, false)) {
+               pkgmgrinfo_appinfo_filter_destroy(filter);
+               return PMINFO_R_ERROR;
        }
 
        ret = _appinfo_get_filtered_foreach_appinfo(uid, filter, flag, app_func,
@@ -1439,20 +1475,6 @@ API int pkgmgrinfo_appinfo_get_installed_list_full(
                        _getuid(), flag, user_data);
 }
 
-API int pkgmgrinfo_appinfo_get_usr_install_list(pkgmgrinfo_app_list_cb app_func,
-               uid_t uid, void *user_data)
-{
-       return pkgmgrinfo_appinfo_get_usr_installed_list_full(app_func,
-                       uid, PMINFO_APPINFO_GET_ALL, user_data);
-}
-
-API int pkgmgrinfo_appinfo_get_install_list(pkgmgrinfo_app_list_cb app_func,
-               void *user_data)
-{
-       return pkgmgrinfo_appinfo_get_usr_installed_list_full(app_func,
-                       _getuid(), PMINFO_APPINFO_GET_ALL, user_data);
-}
-
 API int pkgmgrinfo_appinfo_get_usr_installed_list(
                pkgmgrinfo_app_list_cb app_func, uid_t uid, void *user_data)
 {
@@ -1621,7 +1643,7 @@ static char *_get_localed_label(const char *appid, const char *locale, uid_t uid
                goto err;
        }
 
-       if (sqlite3_open_v2(parser_db, &db, SQLITE_OPEN_READONLY, NULL) != SQLITE_OK) {
+       if (__open_db(parser_db, &db, SQLITE_OPEN_READONLY) != SQLITE_OK) {
                _LOGE("DB open fail\n");
                free(parser_db);
                goto err;
@@ -2231,7 +2253,8 @@ API int pkgmgrinfo_appinfo_get_installed_time(pkgmgrinfo_appinfo_h handle, int *
        return PMINFO_R_OK;
 }
 
-API int pkgmgrinfo_appinfo_usr_get_datacontrol_info(const char *providerid, const char *type, uid_t uid, char **appid, char **access)
+API int pkgmgrinfo_appinfo_usr_get_datacontrol_info(const char *providerid,
+               const char *type, uid_t uid, char **appid, char **access)
 {
        retvm_if(providerid == NULL, PMINFO_R_EINVAL, "Argument supplied is NULL\n");
        retvm_if(type == NULL, PMINFO_R_EINVAL, "Argument supplied is NULL\n");
@@ -2270,9 +2293,11 @@ catch:
        return ret;
 }
 
-API int pkgmgrinfo_appinfo_get_datacontrol_info(const char *providerid, const char *type, char **appid, char **access)
+API int pkgmgrinfo_appinfo_get_datacontrol_info(const char *providerid,
+               const char *type, char **appid, char **access)
 {
-       return pkgmgrinfo_appinfo_usr_get_datacontrol_info(providerid, type, _getuid(), appid, access);
+       return pkgmgrinfo_appinfo_usr_get_datacontrol_info(providerid,
+                       type, _getuid(), appid, access);
 }
 
 API int pkgmgrinfo_appinfo_usr_get_datacontrol_appid(const char *providerid, uid_t uid, char **appid)
@@ -2316,6 +2341,52 @@ API int pkgmgrinfo_appinfo_get_datacontrol_appid(const char *providerid, char **
        return pkgmgrinfo_appinfo_usr_get_datacontrol_appid(providerid, _getuid(), appid);
 }
 
+API int pkgmgrinfo_appinfo_usr_get_datacontrol_trusted_info(const char *providerid,
+               const char *type, uid_t uid, char **appid, bool *is_trusted)
+{
+       retvm_if(providerid == NULL, PMINFO_R_EINVAL, "Argument supplied is NULL\n");
+       retvm_if(appid == NULL, PMINFO_R_EINVAL, "Argument supplied to hold return value is NULL\n");
+
+       int ret = PMINFO_R_OK;
+       char *query = NULL;
+       sqlite3_stmt *stmt = NULL;
+
+       /*open db*/
+       ret = __open_manifest_db(uid, true);
+       retvm_if(ret != SQLITE_OK, ret = PMINFO_R_ERROR, "connect db [%s] failed!", MANIFEST_DB);
+
+       /*Start constructing query*/
+       query = sqlite3_mprintf("SELECT app_id, trusted FROM package_app_data_control WHERE providerid=%Q AND type=%Q", providerid, type);
+       tryvm_if(query == NULL, ret = PMINFO_R_ERROR, "Out of memory");
+
+       /*prepare query*/
+       ret = sqlite3_prepare_v2(GET_DB(manifest_db), query, strlen(query), &stmt, NULL);
+       tryvm_if(ret != PMINFO_R_OK, ret = PMINFO_R_ERROR, "sqlite3_prepare_v2 failed[%s]\n", query);
+
+       /*step query*/
+       ret = sqlite3_step(stmt);
+       tryvm_if((ret != SQLITE_ROW) || (ret == SQLITE_DONE), ret = PMINFO_R_ERROR, "No records found");
+
+       _save_column_str(stmt, 0, appid);
+       *is_trusted = _get_bool_value((char *)sqlite3_column_text(stmt, 1));
+
+       ret = PMINFO_R_OK;
+
+catch:
+       sqlite3_free(query);
+       sqlite3_finalize(stmt);
+       __close_manifest_db();
+       return ret;
+}
+
+API int pkgmgrinfo_appinfo_get_datacontrol_trsuted_info(const char *providerid,
+               const char *type, char **appid, bool *is_trusted)
+{
+       return pkgmgrinfo_appinfo_usr_get_datacontrol_trusted_info(providerid,
+                       type, _getuid(), appid, is_trusted);
+}
+
+
 API int pkgmgrinfo_appinfo_get_support_mode(pkgmgrinfo_appinfo_h  handle, int *support_mode)
 {
        retvm_if(handle == NULL, PMINFO_R_EINVAL, "appinfo handle is NULL");
@@ -2552,10 +2623,10 @@ API int pkgmgrinfo_appinfo_is_enabled(pkgmgrinfo_appinfo_h  handle, bool *enable
        retvm_if(enabled == NULL, PMINFO_R_EINVAL, "Argument supplied to hold return value is NULL");
        pkgmgr_appinfo_x *info = (pkgmgr_appinfo_x *)handle;
 
-       if (info->app_info == NULL || info->app_info->enabled == NULL)
+       if (info->app_info == NULL || info->app_info->is_disabled == NULL)
                return PMINFO_R_ERROR;
 
-       *enabled = _get_bool_value(info->app_info->enabled);
+       *enabled = !_get_bool_value(info->app_info->is_disabled);
 
        return PMINFO_R_OK;
 }
@@ -2781,6 +2852,22 @@ API int pkgmgrinfo_appinfo_get_splash_screen_display(pkgmgrinfo_appinfo_h handle
        return PMINFO_R_OK;
 }
 
+API int pkgmgrinfo_appinfo_get_setup_appid(pkgmgrinfo_appinfo_h handle, char **setup_appid)
+{
+       pkgmgr_appinfo_x *info = (pkgmgr_appinfo_x *)handle;
+
+       if (info == NULL || setup_appid == NULL) {
+               _LOGE("Invalid parameter");
+               return PMINFO_R_EINVAL;
+       }
+
+       if (info->app_info == NULL || info->app_info->setup_appid == NULL)
+               return PMINFO_R_ERROR;
+
+       *setup_appid = info->app_info->setup_appid;
+       return PMINFO_R_OK;
+}
+
 API int pkgmgrinfo_appinfo_is_support_ambient(pkgmgrinfo_appinfo_h handle,
                bool *support_ambient)
 {
@@ -3063,23 +3150,30 @@ API int pkgmgrinfo_appinfo_metadata_filter_add(
                pkgmgrinfo_appinfo_metadata_filter_h handle,
                const char *key, const char *value)
 {
-       int ret;
-
-       ret = pkgmgrinfo_appinfo_filter_add_string(handle,
-                       PMINFO_APPINFO_PROP_APP_METADATA_KEY, key);
-       if (ret != PMINFO_R_OK)
-               return ret;
+       pkgmgrinfo_filter_x *filter = (pkgmgrinfo_filter_x *)handle;
+       pkgmgrinfo_metadata_node_x *node;
 
        /* value can be NULL.
         * In that case all apps with specified key should be displayed
         */
-       if (value && strlen(value)) {
-               ret = pkgmgrinfo_appinfo_filter_add_string(handle,
-                               PMINFO_APPINFO_PROP_APP_METADATA_VALUE, value);
-               if (ret != PMINFO_R_OK)
-                       return ret;
+       if (key == NULL) {
+               LOGE("invalid parameter");
+               return PMINFO_R_EINVAL;
+       }
+
+       node = calloc(1, sizeof(pkgmgrinfo_metadata_node_x));
+       if (node == NULL) {
+               LOGE("out of memory");
+               return PMINFO_R_ERROR;
        }
 
+       node->key = strdup(key);
+       if (value && strlen(value))
+               node->value = strdup(value);
+
+       filter->list_metadata = g_slist_append(filter->list_metadata,
+                       (gpointer)node);
+
        return PMINFO_R_OK;
 }