Fix static analysis issue
[platform/core/appfw/pkgmgr-info.git] / src / pkgmgrinfo_certinfo.c
index 6bd3ebb..3b346bc 100644 (file)
@@ -8,8 +8,6 @@
 #include <sqlite3.h>
 #include <glib.h>
 
-#include <db-util.h>
-
 #include "pkgmgr-info.h"
 #include "pkgmgrinfo_debug.h"
 #include "pkgmgrinfo_private.h"
@@ -41,676 +39,371 @@ typedef struct _pkgmgr_cert_x {
        int cert_id;
 } pkgmgr_cert_x;
 
-static int __cert_cb(void *data, int ncols, char **coltxt, char **colname)
+API int pkgmgrinfo_pkginfo_create_certinfo(pkgmgrinfo_certinfo_h *handle)
 {
-       pkgmgr_cert_x *info = (pkgmgr_cert_x *)data;
-       int i = 0;
-
-       for(i = 0; i < ncols; i++)
-       {
-               if (strcmp(colname[i], "author_signer_cert") == 0) {
-                       if (coltxt[i])
-                               info->cert_id = atoi(coltxt[i]);
-                       else
-                               info->cert_id = 0;
-               } else if (strcmp(colname[i], "package") == 0) {
-                       if (coltxt[i])
-                               info->pkgid= strdup(coltxt[i]);
-                       else
-                               info->pkgid = NULL;
-               } else
-                       continue;
-       }
-       return 0;
+       retvm_if(handle == NULL, PMINFO_R_EINVAL, "Argument supplied to hold return value is NULL\n");
+       pkgmgr_certinfo_x *certinfo = NULL;
+       certinfo = calloc(1, sizeof(pkgmgr_certinfo_x));
+       *handle = NULL;
+       retvm_if(certinfo == NULL, PMINFO_R_ERROR, "Malloc Failed\n");
+       *handle = (void *)certinfo;
+       return PMINFO_R_OK;
 }
 
-static int __certinfo_cb(void *data, int ncols, char **coltxt, char **colname)
+static int _pkginfo_compare_certinfo(sqlite3 *db, const char *l_pkgid,
+               const char *r_pkgid,
+               pkgmgrinfo_cert_compare_result_type_e *result)
 {
-       pkgmgr_certinfo_x *info = (pkgmgr_certinfo_x *)data;
-       int i = 0;
-       for(i = 0; i < ncols; i++)
-       {
-               if (strcmp(colname[i], "package") == 0) {
-                       if (coltxt[i])
-                               info->pkgid = strdup(coltxt[i]);
-                       else
-                               info->pkgid = NULL;
-               } else if (strcmp(colname[i], "author_signer_cert") == 0) {
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_AUTHOR_SIGNER_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_AUTHOR_SIGNER_CERT] = 0;
-               } else if (strcmp(colname[i], "author_im_cert") == 0) {
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_AUTHOR_INTERMEDIATE_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_AUTHOR_INTERMEDIATE_CERT] = 0;
-               } else if (strcmp(colname[i], "author_root_cert") == 0) {
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_AUTHOR_ROOT_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_AUTHOR_ROOT_CERT] = 0;
-               } else if (strcmp(colname[i], "dist_signer_cert") == 0 ){
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_DISTRIBUTOR_SIGNER_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_DISTRIBUTOR_SIGNER_CERT] = 0;
-               } else if (strcmp(colname[i], "dist_im_cert") == 0 ){
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_DISTRIBUTOR_INTERMEDIATE_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_DISTRIBUTOR_INTERMEDIATE_CERT] = 0;
-               } else if (strcmp(colname[i], "dist_root_cert") == 0 ){
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_DISTRIBUTOR_ROOT_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_DISTRIBUTOR_ROOT_CERT] = 0;
-               } else if (strcmp(colname[i], "dist2_signer_cert") == 0 ){
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_DISTRIBUTOR2_SIGNER_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_DISTRIBUTOR2_SIGNER_CERT] = 0;
-               } else if (strcmp(colname[i], "dist2_im_cert") == 0 ){
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_DISTRIBUTOR2_INTERMEDIATE_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_DISTRIBUTOR2_INTERMEDIATE_CERT] = 0;
-               } else if (strcmp(colname[i], "dist2_root_cert") == 0 ){
-                       if (coltxt[i])
-                               (info->cert_id)[PMINFO_DISTRIBUTOR2_ROOT_CERT] = atoi(coltxt[i]);
-                       else
-                               (info->cert_id)[PMINFO_DISTRIBUTOR2_ROOT_CERT] = 0;
-               } else if (strcmp(colname[i], "cert_info") == 0 ){
-                       if (coltxt[i])
-                               info->cert_value = strdup(coltxt[i]);
-                       else
-                               info->cert_value = NULL;
-               } else if (strcmp(colname[i], "for_all_users") == 0 ){
-                       if (coltxt[i])
-                               info->for_all_users = atoi(coltxt[i]);
-                       else
-                               info->for_all_users = 0;
-               } else
-                       continue;
-       }
-       return 0;
-}
+       static const char query[] =
+               "SELECT COALESCE(author_signer_cert, -1) FROM package_cert_info "
+               "WHERE package=?";
+       int ret;
+       sqlite3_stmt *stmt;
+       const char *pkgid[2];
+       int certid[2] = {-1, -1};
+       int i;
 
-static int __exec_certinfo_query(char *query, void *data)
-{
-       char *error_message = NULL;
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(cert_db), query, __certinfo_cb, data, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               sqlite3_free(error_message);
-               return -1;
-       }
-       sqlite3_free(error_message);
-       return 0;
-}
+       pkgid[0] = l_pkgid;
+       pkgid[1] = r_pkgid;
 
-static int __certindexinfo_cb(void *data, int ncols, char **coltxt, char **colname)
-{
-       pkgmgr_certindexinfo_x *info = (pkgmgr_certindexinfo_x *)data;
-       int i = 0;
-       for(i = 0; i < ncols; i++) {
-               if (strcmp(colname[i], "cert_id") == 0) {
-                       if (coltxt[i])
-                               info->cert_id = atoi(coltxt[i]);
-                       else
-                               info->cert_id = 0;
-               } else if (strcmp(colname[i], "cert_ref_count") == 0) {
-                       if (coltxt[i])
-                               info->cert_ref_count = atoi(coltxt[i]);
-                       else
-                               info->cert_ref_count = 0;
-               } else
-                       continue;
+       ret = sqlite3_prepare_v2(db, query, strlen(query), &stmt, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("prepare error: %s", sqlite3_errmsg(db));
+               return PMINFO_R_ERROR;
        }
-       return 0;
-}
 
-static int __exec_certindexinfo_query(char *query, void *data)
-{
-       char *error_message = NULL;
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(cert_db), query, __certindexinfo_cb, data, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               sqlite3_free(error_message);
-               return -1;
+       for (i = 0; i < 2; i++) {
+               ret = sqlite3_bind_text(stmt, 1, pkgid[i], -1, SQLITE_STATIC);
+               if (ret != SQLITE_OK) {
+                       _LOGE("bind error: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
+               }
+
+               ret = sqlite3_step(stmt);
+               if (ret == SQLITE_ROW) {
+                       _save_column_int(stmt, 0, &certid[i]);
+               } else if (ret != SQLITE_DONE) {
+                       _LOGE("step error: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
+               }
+
+               sqlite3_reset(stmt);
+               sqlite3_clear_bindings(stmt);
        }
-       sqlite3_free(error_message);
-       return 0;
+
+       if (certid[0] == -1 && certid[1] == -1)
+               *result = PMINFO_CERT_COMPARE_BOTH_NO_CERT;
+       else if (certid[0] == -1)
+               *result = PMINFO_CERT_COMPARE_LHS_NO_CERT;
+       else if (certid[1] == -1)
+               *result = PMINFO_CERT_COMPARE_RHS_NO_CERT;
+       else if (certid[0] == certid[1])
+               *result = PMINFO_CERT_COMPARE_MATCH;
+       else
+               *result = PMINFO_CERT_COMPARE_MISMATCH;
+
+       sqlite3_finalize(stmt);
+       return PMINFO_R_OK;
 }
 
-static int __delete_certinfo(const char *pkgid, uid_t uid)
+API int pkgmgrinfo_pkginfo_compare_usr_pkg_cert_info(const char *lhs_package_id,
+               const char *rhs_package_id, uid_t uid,
+               pkgmgrinfo_cert_compare_result_type_e *compare_result)
 {
-       int ret = -1;
-       int i = 0;
-       int j = 0;
-       int c = 0;
-       int unique_id[MAX_CERT_TYPE] = {0, 0, 0, 0, 0, 0, 0, 0, 0};
-       char *error_message = NULL;
-       char query[MAX_QUERY_LEN] = {'\0'};
-       pkgmgr_certinfo_x *certinfo = NULL;
-       pkgmgr_certindexinfo_x *indexinfo = NULL;
-       certinfo = calloc(1, sizeof(pkgmgr_certinfo_x));
-       retvm_if(certinfo == NULL, PMINFO_R_ERROR, "Malloc Failed\n");
-       indexinfo = calloc(1, sizeof(pkgmgr_certindexinfo_x));
-       if (indexinfo == NULL) {
-               _LOGE("Out of Memory!!!");
-               ret = PMINFO_R_ERROR;
-               goto err;
-       }
+       int ret;
+       sqlite3 *db;
+       char *dbpath;
 
-       __open_cert_db(uid, false);
-       /*populate certinfo from DB*/
-       snprintf(query, MAX_QUERY_LEN, "select * from package_cert_info where package='%s' ", pkgid);
-       ret = __exec_certinfo_query(query, (void *)certinfo);
-       if (ret == -1) {
-               _LOGE("Package Cert Info DB Information retrieval failed\n");
-               ret = PMINFO_R_ERROR;
-               goto err;
-       }
-       /*Update cert index table*/
-       for (i = 0; i < MAX_CERT_TYPE; i++) {
-               if ((certinfo->cert_id)[i]) {
-                       for (j = 0; j < MAX_CERT_TYPE; j++) {
-                               if ((certinfo->cert_id)[i] == unique_id[j]) {
-                                       /*Ref count has already been updated. Just continue*/
-                                       break;
-                               }
-                       }
-                       if (j == MAX_CERT_TYPE)
-                               unique_id[c++] = (certinfo->cert_id)[i];
-                       else
-                               continue;
-                       memset(query, '\0', MAX_QUERY_LEN);
-                       snprintf(query, MAX_QUERY_LEN, "select * from package_cert_index_info where cert_id=%d ", (certinfo->cert_id)[i]);
-                       ret = __exec_certindexinfo_query(query, (void *)indexinfo);
-                       if (ret == -1) {
-                               _LOGE("Cert Info DB Information retrieval failed\n");
-                               ret = PMINFO_R_ERROR;
-                               goto err;
-                       }
-                       memset(query, '\0', MAX_QUERY_LEN);
-                       if (indexinfo->cert_ref_count > 1) {
-                               /*decrease ref count*/
-                               snprintf(query, MAX_QUERY_LEN, "update package_cert_index_info set cert_ref_count=%d where cert_id=%d ",
-                               indexinfo->cert_ref_count - 1, (certinfo->cert_id)[i]);
-                       } else {
-                               /*delete this certificate as ref count is 1 and it will become 0*/
-                               snprintf(query, MAX_QUERY_LEN, "delete from  package_cert_index_info where cert_id=%d ", (certinfo->cert_id)[i]);
-                       }
-                       if (SQLITE_OK !=
-                           sqlite3_exec(GET_DB(cert_db), query, NULL, NULL, &error_message)) {
-                               _LOGE("Don't execute query = %s error message = %s\n", query,
-                                      error_message);
-                               sqlite3_free(error_message);
-                               ret = PMINFO_R_ERROR;
-                               goto err;
-                       }
-               }
-       }
-       /*Now delete the entry from db*/
-       snprintf(query, MAX_QUERY_LEN, "delete from package_cert_info where package='%s'", pkgid);
-        if (SQLITE_OK !=
-            sqlite3_exec(GET_DB(cert_db), query, NULL, NULL, &error_message)) {
-                _LOGE("Don't execute query = %s error message = %s\n", query,
-                       error_message);
-               sqlite3_free(error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
-        }
-       ret = PMINFO_R_OK;
-err:
-       if (indexinfo) {
-               free(indexinfo);
-               indexinfo = NULL;
+       if (lhs_package_id == NULL || rhs_package_id == NULL ||
+                       compare_result == NULL) {
+               _LOGE("invalid parameter");
+               return PMINFO_R_EINVAL;
        }
-       if (certinfo->pkgid) {
-               free(certinfo->pkgid);
-               certinfo->pkgid = NULL;
+
+       /* open unified global cert db */
+       dbpath = getUserPkgCertDBPath();
+       if (dbpath == NULL)
+               return PMINFO_R_ERROR;
+
+       ret = __open_db(dbpath, &db, SQLITE_OPEN_READONLY);
+       if (ret != SQLITE_OK) {
+               _LOGE("failed to open db: %d", ret);
+               free(dbpath);
+               return PMINFO_R_ERROR;
        }
-       for (i = 0; i < MAX_CERT_TYPE; i++) {
-               if ((certinfo->cert_info)[i]) {
-                       free((certinfo->cert_info)[i]);
-                       (certinfo->cert_info)[i] = NULL;
-               }
+       free(dbpath);
+
+       if (_pkginfo_compare_certinfo(db, lhs_package_id, rhs_package_id,
+                               compare_result)) {
+               _LOGE("failed to compare certinfo");
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
        }
-       __close_cert_db();
-       free(certinfo);
-       certinfo = NULL;
-       return ret;
-}
 
-static int __validate_cb(void *data, int ncols, char **coltxt, char **colname)
-{
-       int *p = (int*)data;
-       *p = atoi(coltxt[0]);
-       return 0;
+       sqlite3_close_v2(db);
+
+       return PMINFO_R_OK;
 }
 
-static int __maxid_cb(void *data, int ncols, char **coltxt, char **colname)
+API int pkgmgrinfo_pkginfo_compare_pkg_cert_info(const char *lhs_package_id, const char *rhs_package_id, pkgmgrinfo_cert_compare_result_type_e *compare_result)
 {
-       int *p = (int*)data;
-       if (coltxt[0])
-               *p = atoi(coltxt[0]);
-       return 0;
+       return pkgmgrinfo_pkginfo_compare_usr_pkg_cert_info(lhs_package_id, rhs_package_id, _getuid(), compare_result);
 }
 
-API int pkgmgrinfo_pkginfo_compare_usr_pkg_cert_info(const char *lhs_package_id, const char *rhs_package_id, uid_t uid, pkgmgrinfo_cert_compare_result_type_e *compare_result)
+static int _pkginfo_get_pkgid_from_appid(uid_t uid, const char *appid,
+               char **pkgid)
 {
-       int ret = PMINFO_R_OK;
-       char query[MAX_QUERY_LEN] = {'\0'};
-       char *error_message = NULL;
-       sqlite3_stmt *stmt = NULL;
-       char *lhs_certinfo = NULL;
-       char *rhs_certinfo = NULL;
-       int lcert;
-       int rcert;
-       int exist;
-       int i;
-       int is_global = 0;
-       *compare_result = PMINFO_CERT_COMPARE_ERROR;
-
-       retvm_if(lhs_package_id == NULL, PMINFO_R_EINVAL, "lhs package ID is NULL");
-       retvm_if(rhs_package_id == NULL, PMINFO_R_EINVAL, "rhs package ID is NULL");
-       retvm_if(compare_result == NULL, PMINFO_R_EINVAL, "Argument supplied to hold return value is NULL");
+       static const char query[] =
+               "SELECT package FROM package_app_info WHERE app_id=?";
+       int ret;
+       sqlite3 *db;
+       char *dbpath;
+       sqlite3_stmt *stmt;
+
+       dbpath = getUserPkgParserDBPathUID(uid);
+       if (dbpath == NULL)
+               return PMINFO_R_ERROR;
 
-       ret = __open_cert_db(uid, true);
-       if (ret != 0) {
-               ret = PMINFO_R_ERROR;
-               goto err;
-       }
-       _check_create_cert_db(GET_DB(cert_db));
-       snprintf(query, MAX_QUERY_LEN, "select exists(select * from package_cert_info where package='%s')", lhs_package_id);
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(cert_db), query, __validate_cb, (void *)&exist, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
+       ret = __open_db(dbpath, &db, SQLITE_OPEN_READONLY);
+       if (ret != SQLITE_OK) {
+               _LOGE("failed to open db: %d", ret);
+               free(dbpath);
+               return PMINFO_R_ERROR;
        }
-       lcert = exist;
+       free(dbpath);
 
-       snprintf(query, MAX_QUERY_LEN, "select exists(select * from package_cert_info where package='%s')", rhs_package_id);
-       if (SQLITE_OK !=
-               sqlite3_exec(GET_DB(cert_db), query, __validate_cb, (void *)&exist, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                          error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
-       }
-       rcert = exist;
-
-       if (uid == GLOBAL_USER || uid == ROOT_UID) {
-               snprintf(query, MAX_QUERY_LEN, "select cert_info from package_cert_index_info where cert_id=(select author_signer_cert from package_cert_info where package=?)");
-               is_global = 1;
-       } else
-               snprintf(query, MAX_QUERY_LEN, "select cert_info from package_cert_index_info where cert_id=(select author_signer_cert from package_cert_info where package=?) and for_all_users=(select for_all_users from package_cert_info where package=?)");
-       if (SQLITE_OK != sqlite3_prepare_v2(GET_DB(cert_db), query, strlen(query), &stmt, NULL)) {
-               _LOGE("sqlite3_prepare_v2 error: %s", sqlite3_errmsg(GET_DB(cert_db)));
-               ret = PMINFO_R_ERROR;
-               goto err;
+       ret = sqlite3_prepare_v2(db, query, strlen(query), &stmt, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("prepare error: %s", sqlite3_errmsg(db));
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
        }
 
-       for (i = 1; i <= 2 - is_global; i++) {
-               if (SQLITE_OK != sqlite3_bind_text(stmt, i, lhs_package_id, -1, SQLITE_STATIC)) {
-                       _LOGE("sqlite3_bind_text error: %s", sqlite3_errmsg(GET_DB(cert_db)));
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
+       ret = sqlite3_bind_text(stmt, 1, appid, -1, SQLITE_STATIC);
+       if (ret != SQLITE_OK) {
+               _LOGE("bind error: %s", sqlite3_errmsg(db));
+               sqlite3_finalize(stmt);
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
        }
-       if (SQLITE_ROW != sqlite3_step(stmt) || sqlite3_column_text(stmt, 0) == NULL) {
-               _LOGE("sqlite3_step error: %s", sqlite3_errmsg(GET_DB(cert_db)));
+
+       ret = sqlite3_step(stmt);
+       if (ret == SQLITE_ROW) {
+               _save_column_str(stmt, 0, pkgid);
+               ret = PMINFO_R_OK;
+       } else if (ret == SQLITE_DONE) {
+               _LOGI("cannot find pkgid of app %s for uid %d", appid, (int)uid);
+               ret = PMINFO_R_ENOENT;
+       } else {
+               _LOGE("step error: %s", sqlite3_errmsg(db));
                ret = PMINFO_R_ERROR;
-               goto err;
        }
 
-       lhs_certinfo = strdup((const char *)sqlite3_column_text(stmt, 0));
-       sqlite3_reset(stmt);
-       sqlite3_clear_bindings(stmt);
+       sqlite3_finalize(stmt);
+       sqlite3_close_v2(db);
 
-       for (i = 1; i <= 2 - is_global; i++) {
-               if (SQLITE_OK != sqlite3_bind_text(stmt, i, rhs_package_id, -1, SQLITE_STATIC)) {
-                       _LOGE("sqlite3_bind_text error: %s", sqlite3_errmsg(GET_DB(cert_db)));
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
-       }
-       if (SQLITE_ROW != sqlite3_step(stmt) || sqlite3_column_text(stmt, 0) == NULL) {
-               _LOGE("sqlite3_step error: %s", sqlite3_errmsg(GET_DB(cert_db)));
-               ret = PMINFO_R_ERROR;
-               goto err;
+       return ret;
+}
+
+API int pkgmgrinfo_pkginfo_compare_usr_app_cert_info(const char *lhs_app_id,
+               const char *rhs_app_id, uid_t uid,
+               pkgmgrinfo_cert_compare_result_type_e *compare_result)
+{
+       int ret;
+       char *l_pkgid = NULL;
+       char *r_pkgid = NULL;
+
+       if (lhs_app_id == NULL || rhs_app_id == NULL ||
+                       compare_result == NULL) {
+               _LOGE("invalid parameter");
+               return PMINFO_R_EINVAL;
        }
 
-       rhs_certinfo = strdup((const char *)sqlite3_column_text(stmt, 0));
+       ret = _pkginfo_get_pkgid_from_appid(uid, lhs_app_id, &l_pkgid);
+       if (ret == PMINFO_R_ENOENT && uid != GLOBAL_USER)
+               ret = _pkginfo_get_pkgid_from_appid(GLOBAL_USER, lhs_app_id,
+                               &l_pkgid);
 
-       if ((lcert == 0) || (rcert == 0)) {
-               if ((lcert == 0) && (rcert == 0))
-                       *compare_result = PMINFO_CERT_COMPARE_BOTH_NO_CERT;
-               else if (lcert == 0)
-                       *compare_result = PMINFO_CERT_COMPARE_LHS_NO_CERT;
-               else if (rcert == 0)
-                       *compare_result = PMINFO_CERT_COMPARE_RHS_NO_CERT;
-       } else {
-               if (lhs_certinfo && rhs_certinfo && !strcmp(lhs_certinfo, rhs_certinfo))
-                       *compare_result = PMINFO_CERT_COMPARE_MATCH;
-               else
-                       *compare_result = PMINFO_CERT_COMPARE_MISMATCH;
+       if (ret != PMINFO_R_OK)
+               return ret;
+
+       ret = _pkginfo_get_pkgid_from_appid(uid, rhs_app_id, &r_pkgid);
+       if (ret == PMINFO_R_ENOENT && uid != GLOBAL_USER)
+               ret = _pkginfo_get_pkgid_from_appid(GLOBAL_USER, rhs_app_id,
+                               &r_pkgid);
+
+       if (ret != PMINFO_R_OK) {
+               free(l_pkgid);
+               return ret;
        }
 
-err:
-       if (stmt)
-               sqlite3_finalize(stmt);
-       if (lhs_certinfo)
-               free(lhs_certinfo);
-       if (rhs_certinfo)
-               free(rhs_certinfo);
-       sqlite3_free(error_message);
-       __close_cert_db();
+       ret = pkgmgrinfo_pkginfo_compare_usr_pkg_cert_info(l_pkgid, r_pkgid,
+                       uid, compare_result);
+
+       free(l_pkgid);
+       free(r_pkgid);
 
        return ret;
 }
 
-API int pkgmgrinfo_pkginfo_compare_pkg_cert_info(const char *lhs_package_id, const char *rhs_package_id, pkgmgrinfo_cert_compare_result_type_e *compare_result)
+API int pkgmgrinfo_pkginfo_compare_app_cert_info(const char *lhs_app_id,
+               const char *rhs_app_id,
+               pkgmgrinfo_cert_compare_result_type_e *compare_result)
 {
-       return pkgmgrinfo_pkginfo_compare_usr_pkg_cert_info(lhs_package_id, rhs_package_id, GLOBAL_USER, compare_result);
+       return pkgmgrinfo_pkginfo_compare_usr_app_cert_info(lhs_app_id,
+                       rhs_app_id, _getuid(), compare_result);
 }
 
-API int pkgmgrinfo_pkginfo_compare_app_cert_info(const char *lhs_app_id, const char *rhs_app_id, pkgmgrinfo_cert_compare_result_type_e *compare_result)
+static int _pkginfo_get_cert(sqlite3 *db, int cert_id[],
+               char *cert_info[])
 {
-       int ret = PMINFO_R_OK;
-       char query[MAX_QUERY_LEN] = {'\0'};
-       char *error_message = NULL;
-       pkgmgr_cert_x *info;
-       int exist;
-       char *lpkgid = NULL;
-       char *rpkgid = NULL;
-       const char* user_pkg_parser = getUserPkgParserDBPath();
-
-       retvm_if(lhs_app_id == NULL, PMINFO_R_EINVAL, "lhs app ID is NULL");
-       retvm_if(rhs_app_id == NULL, PMINFO_R_EINVAL, "rhs app ID is NULL");
-       retvm_if(compare_result == NULL, PMINFO_R_EINVAL, "Argument supplied to hold return value is NULL");
-
-       info = (pkgmgr_cert_x *)calloc(1, sizeof(pkgmgr_cert_x));
-       retvm_if(info == NULL, PMINFO_R_ERROR, "Out of Memory!!!");
-
-       ret = db_util_open_with_options(user_pkg_parser, &GET_DB(manifest_db),
-                                       SQLITE_OPEN_READONLY, NULL);
-       if (ret != SQLITE_OK) {
-               _LOGE("connect db [%s] failed!\n", user_pkg_parser);
-               ret = PMINFO_R_ERROR;
-               goto err;
-       }
+       static const char query[] =
+               "SELECT cert_info FROM package_cert_index_info WHERE cert_id=?";
+       int ret;
+       sqlite3_stmt *stmt;
+       int i;
 
-       snprintf(query, MAX_QUERY_LEN, "select exists(select * from package_app_info where app_id='%s')", lhs_app_id);
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(manifest_db), query, __validate_cb, (void *)&exist, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
+       ret = sqlite3_prepare_v2(db, query, strlen(query), &stmt, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("prepare failed: %s", sqlite3_errmsg(db));
+               return PMINFO_R_ERROR;
        }
 
-       if (exist == 0) {
-               lpkgid = NULL;
-       } else {
-               snprintf(query, MAX_QUERY_LEN, "select package from package_app_info where app_id='%s' ", lhs_app_id);
-               if (SQLITE_OK !=
-                       sqlite3_exec(GET_DB(manifest_db), query, __cert_cb, (void *)info, &error_message)) {
-                       _LOGE("Don't execute query = %s error message = %s\n", query,
-                                  error_message);
-                       ret = PMINFO_R_ERROR;
-                       goto err;
+       for (i = 0; i < MAX_CERT_TYPE; i++) {
+               ret = sqlite3_bind_int(stmt, 1, cert_id[i]);
+               if (ret != SQLITE_OK) {
+                       sqlite3_finalize(stmt);
+                       _LOGE("bind failed: %s", sqlite3_errmsg(db));
+                       return PMINFO_R_ERROR;
                }
-               lpkgid = strdup(info->pkgid);
-               if (lpkgid == NULL) {
-                       _LOGE("Out of Memory\n");
-                       ret = PMINFO_R_ERROR;
-                       goto err;
+
+               ret = sqlite3_step(stmt);
+               if (ret == SQLITE_DONE) {
+                       sqlite3_reset(stmt);
+                       sqlite3_clear_bindings(stmt);
+                       continue;
+               } else if (ret != SQLITE_ROW) {
+                       _LOGE("step failed: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
                }
-               free(info->pkgid);
-               info->pkgid = NULL;
-       }
 
-       snprintf(query, MAX_QUERY_LEN, "select exists(select * from package_app_info where app_id='%s')", rhs_app_id);
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(manifest_db), query, __validate_cb, (void *)&exist, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
+               _save_column_str(stmt, 0, &cert_info[i]);
+               sqlite3_reset(stmt);
+               sqlite3_clear_bindings(stmt);
        }
 
-       if (exist == 0) {
-               rpkgid = NULL;
-       } else {
-               snprintf(query, MAX_QUERY_LEN, "select package from package_app_info where app_id='%s' ", rhs_app_id);
-               if (SQLITE_OK !=
-                       sqlite3_exec(GET_DB(manifest_db), query, __cert_cb, (void *)info, &error_message)) {
-                       _LOGE("Don't execute query = %s error message = %s\n", query,
-                                  error_message);
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
-               rpkgid = strdup(info->pkgid);
-               if (rpkgid == NULL) {
-                       _LOGE("Out of Memory\n");
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
-               free(info->pkgid);
-               info->pkgid = NULL;
-       }
-       ret = pkgmgrinfo_pkginfo_compare_pkg_cert_info(lpkgid, rpkgid, compare_result);
- err:
-       if (error_message)
-               sqlite3_free(error_message);
-       __close_manifest_db();
-       if (info) {
-               if (info->pkgid) {
-                       free(info->pkgid);
-                       info->pkgid = NULL;
-               }
-               free(info);
-               info = NULL;
-       }
-       if (lpkgid) {
-               free(lpkgid);
-               lpkgid = NULL;
-       }
-       if (rpkgid) {
-               free(rpkgid);
-               rpkgid = NULL;
-       }
-       return ret;
+       sqlite3_finalize(stmt);
+
+       return PMINFO_R_OK;
 }
 
-API int pkgmgrinfo_pkginfo_compare_usr_app_cert_info(const char *lhs_app_id, const char *rhs_app_id, uid_t uid, pkgmgrinfo_cert_compare_result_type_e *compare_result)
+static int _pkginfo_get_certid(sqlite3 *db, const char *pkgid, int cert_id[])
 {
-       int ret = PMINFO_R_OK;
-       char query[MAX_QUERY_LEN] = {'\0'};
-       char *error_message = NULL;
-       pkgmgr_cert_x *info;
-       int exist;
-       char *lpkgid = NULL;
-       char *rpkgid = NULL;
-
-       retvm_if(lhs_app_id == NULL, PMINFO_R_EINVAL, "lhs app ID is NULL");
-       retvm_if(rhs_app_id == NULL, PMINFO_R_EINVAL, "rhs app ID is NULL");
-       retvm_if(compare_result == NULL, PMINFO_R_EINVAL, "Argument supplied to hold return value is NULL");
-
-       info = (pkgmgr_cert_x *)calloc(1, sizeof(pkgmgr_cert_x));
-       retvm_if(info == NULL, PMINFO_R_ERROR, "Out of Memory!!!");
-
-       ret = __open_manifest_db(uid, true);
+       static const char query[] =
+               "SELECT author_root_cert, author_im_cert, author_signer_cert, "
+               "dist_root_cert, dist_im_cert, dist_signer_cert, "
+               "dist2_root_cert, dist2_im_cert, dist2_signer_cert "
+               "FROM package_cert_info WHERE package=?";
+       int ret;
+       sqlite3_stmt *stmt;
+       int idx;
+
+       ret = sqlite3_prepare_v2(db, query, strlen(query), &stmt, NULL);
        if (ret != SQLITE_OK) {
-               _LOGE("connect db [%s] failed!\n", getUserPkgParserDBPathUID(uid));
-               ret = PMINFO_R_ERROR;
-               goto err;
+               _LOGE("prepare failed: %s", sqlite3_errmsg(db));
+               return PMINFO_R_ERROR;
        }
 
-       snprintf(query, MAX_QUERY_LEN, "select exists(select * from package_app_info where app_id='%s')", lhs_app_id);
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(manifest_db), query, __validate_cb, (void *)&exist, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
+       ret = sqlite3_bind_text(stmt, 1, pkgid, -1, SQLITE_STATIC);
+       if (ret != SQLITE_OK) {
+               _LOGE("bind failed: %s", sqlite3_errmsg(db));
+               sqlite3_finalize(stmt);
+               return PMINFO_R_ERROR;
        }
 
-       if (exist == 0) {
-               lpkgid = NULL;
-       } else {
-               snprintf(query, MAX_QUERY_LEN, "select package from package_app_info where app_id='%s' ", lhs_app_id);
-               if (SQLITE_OK !=
-                       sqlite3_exec(GET_DB(manifest_db), query, __cert_cb, (void *)info, &error_message)) {
-                       _LOGE("Don't execute query = %s error message = %s\n", query,
-                                  error_message);
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
-               lpkgid = strdup(info->pkgid);
-               if (lpkgid == NULL) {
-                       _LOGE("Out of Memory\n");
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
-               free(info->pkgid);
-               info->pkgid = NULL;
+       ret = sqlite3_step(stmt);
+       if (ret == SQLITE_DONE) {
+               sqlite3_finalize(stmt);
+               return PMINFO_R_ENOENT;
+       } else if (ret != SQLITE_ROW) {
+               _LOGE("step failed: %s", sqlite3_errmsg(db));
+               sqlite3_finalize(stmt);
+               return PMINFO_R_ERROR;
        }
 
-       snprintf(query, MAX_QUERY_LEN, "select exists(select * from package_app_info where app_id='%s')", rhs_app_id);
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(manifest_db), query, __validate_cb, (void *)&exist, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
-       }
+       idx = 0;
+       _save_column_int(stmt, idx++, &cert_id[PMINFO_AUTHOR_ROOT_CERT]);
+       _save_column_int(stmt, idx++,
+                       &cert_id[PMINFO_AUTHOR_INTERMEDIATE_CERT]);
+       _save_column_int(stmt, idx++, &cert_id[PMINFO_AUTHOR_SIGNER_CERT]);
+       _save_column_int(stmt, idx++, &cert_id[PMINFO_DISTRIBUTOR_ROOT_CERT]);
+       _save_column_int(stmt, idx++,
+                       &cert_id[PMINFO_DISTRIBUTOR_INTERMEDIATE_CERT]);
+       _save_column_int(stmt, idx++, &cert_id[PMINFO_DISTRIBUTOR_SIGNER_CERT]);
+       _save_column_int(stmt, idx++, &cert_id[PMINFO_DISTRIBUTOR2_ROOT_CERT]);
+       _save_column_int(stmt, idx++,
+                       &cert_id[PMINFO_DISTRIBUTOR2_INTERMEDIATE_CERT]);
+       _save_column_int(stmt, idx++,
+                       &cert_id[PMINFO_DISTRIBUTOR2_SIGNER_CERT]);
 
-       if (exist == 0) {
-               rpkgid = NULL;
-       } else {
-               snprintf(query, MAX_QUERY_LEN, "select package from package_app_info where app_id='%s' ", rhs_app_id);
-               if (SQLITE_OK !=
-                       sqlite3_exec(GET_DB(manifest_db), query, __cert_cb, (void *)info, &error_message)) {
-                       _LOGE("Don't execute query = %s error message = %s\n", query,
-                                  error_message);
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
-               rpkgid = strdup(info->pkgid);
-               if (rpkgid == NULL) {
-                       _LOGE("Out of Memory\n");
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
-               free(info->pkgid);
-               info->pkgid = NULL;
-       }
-       ret = pkgmgrinfo_pkginfo_compare_usr_pkg_cert_info(lpkgid, rpkgid, uid, compare_result);
- err:
-       if (error_message)
-               sqlite3_free(error_message);
-       __close_manifest_db();
-       if (info) {
-               if (info->pkgid) {
-                       free(info->pkgid);
-                       info->pkgid = NULL;
-               }
-               free(info);
-               info = NULL;
-       }
-       if (lpkgid) {
-               free(lpkgid);
-               lpkgid = NULL;
-       }
-       if (rpkgid) {
-               free(rpkgid);
-               rpkgid = NULL;
-       }
-       return ret;
-}
+       sqlite3_finalize(stmt);
 
-API int pkgmgrinfo_pkginfo_create_certinfo(pkgmgrinfo_certinfo_h *handle)
-{
-       retvm_if(handle == NULL, PMINFO_R_EINVAL, "Argument supplied to hold return value is NULL\n");
-       pkgmgr_certinfo_x *certinfo = NULL;
-       certinfo = calloc(1, sizeof(pkgmgr_certinfo_x));
-       *handle = NULL;
-       retvm_if(certinfo == NULL, PMINFO_R_ERROR, "Malloc Failed\n");
-       *handle = (void *)certinfo;
        return PMINFO_R_OK;
 }
 
-API int pkgmgrinfo_pkginfo_load_certinfo(const char *pkgid, pkgmgrinfo_certinfo_h handle, uid_t uid)
+static int _pkginfo_get_certinfo(const char *pkgid, pkgmgr_certinfo_x *info)
 {
-       retvm_if(pkgid == NULL, PMINFO_R_EINVAL, "package ID is NULL\n");
-       retvm_if(handle == NULL, PMINFO_R_EINVAL, "Certinfo handle is NULL\n");
-       pkgmgr_certinfo_x *certinfo = NULL;
-       char *error_message = NULL;
-       int ret = PMINFO_R_OK;
-       char query[MAX_QUERY_LEN] = {'\0'};
-       int exist = 0;
-       int i = 0;
+       int ret;
+       sqlite3 *db;
+       char *dbpath;
 
-       /*Open db.*/
-       ret = __open_cert_db(uid, true);
+       /* open unified global cert db */
+       dbpath = getUserPkgCertDBPath();
+       if (dbpath == NULL)
+               return PMINFO_R_ERROR;
+
+       ret = __open_db(dbpath, &db, SQLITE_OPEN_READONLY);
        if (ret != SQLITE_OK) {
-               _LOGE("connect db [%s] failed!\n");
-               ret = PMINFO_R_ERROR;
-               goto err;
-       }
-       _check_create_cert_db(GET_DB(cert_db));
-       /*validate pkgid*/
-       snprintf(query, MAX_QUERY_LEN, "select exists(select * from package_cert_info where package='%s')", pkgid);
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(cert_db), query, __validate_cb, (void *)&exist, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               sqlite3_free(error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
+               _LOGE("failed to open db: %d", ret);
+               free(dbpath);
+               return PMINFO_R_ERROR;
        }
-       if (exist == 0) {
-               _LOGE("Package for user[%d] is not found in DB\n", uid);
-               ret = PMINFO_R_ERROR;
-               goto err;
+       free(dbpath);
+
+       ret = _pkginfo_get_certid(db, pkgid, info->cert_id);
+       if (ret != PMINFO_R_OK) {
+               sqlite3_close_v2(db);
+               return ret;
        }
-       certinfo = (pkgmgr_certinfo_x *)handle;
-       /*populate certinfo from DB*/
-       snprintf(query, MAX_QUERY_LEN, "select * from package_cert_info where package='%s' ", pkgid);
-       ret = __exec_certinfo_query(query, (void *)certinfo);
-       if (ret == -1) {
-               _LOGE("Package Cert Info DB Information retrieval failed\n");
-               ret = PMINFO_R_ERROR;
-               goto err;
+
+       ret = _pkginfo_get_cert(db, info->cert_id, info->cert_info);
+       if (ret != PMINFO_R_OK) {
+               sqlite3_close_v2(db);
+               return ret;
        }
-       for (i = 0; i < MAX_CERT_TYPE; i++) {
-               memset(query, '\0', MAX_QUERY_LEN);
-               if (uid == GLOBAL_USER || uid == ROOT_UID)
-                       snprintf(query, MAX_QUERY_LEN, "select cert_info from package_cert_index_info where cert_id=%d", (certinfo->cert_id)[i]);
-               else
-                       snprintf(query, MAX_QUERY_LEN, "select cert_info from package_cert_index_info where cert_id=%d and for_all_users=%d", (certinfo->cert_id)[i], certinfo->for_all_users);
-               ret = __exec_certinfo_query(query, (void *)certinfo);
-               if (ret == -1) {
-                       _LOGE("Cert Info DB Information retrieval failed\n");
-                       ret = PMINFO_R_ERROR;
-                       goto err;
-               }
-               if (certinfo->cert_value) {
-                       (certinfo->cert_info)[i] = strdup(certinfo->cert_value);
-                       free(certinfo->cert_value);
-                       certinfo->cert_value = NULL;
-               }
+
+       sqlite3_close_v2(db);
+
+       return PMINFO_R_OK;
+}
+
+API int pkgmgrinfo_pkginfo_load_certinfo(const char *pkgid, pkgmgrinfo_certinfo_h handle, uid_t uid)
+{
+       int ret;
+       pkgmgr_certinfo_x *info = (pkgmgr_certinfo_x *)handle;
+
+       if (pkgid == NULL || handle == NULL) {
+               _LOGE("invalid parameter");
+               return PMINFO_R_EINVAL;
        }
-err:
-       __close_cert_db();
+
+       ret = _pkginfo_get_certinfo(pkgid, info);
+       if (ret != PMINFO_R_OK)
+               _LOGE("failed to get certinfo of %s ", pkgid);
+
        return ret;
 }
 
@@ -769,189 +462,227 @@ API int pkgmgrinfo_set_cert_value(pkgmgrinfo_instcertinfo_h handle, pkgmgrinfo_i
        retvm_if(cert_type > PMINFO_SET_DISTRIBUTOR2_SIGNER_CERT, PMINFO_R_EINVAL, "Invalid certificate type\n");
        pkgmgr_instcertinfo_x *certinfo = NULL;
        certinfo = (pkgmgr_instcertinfo_x *)handle;
+       if (certinfo->cert_info[cert_type])
+               free(certinfo->cert_info[cert_type]);
        (certinfo->cert_info)[cert_type] = strdup(cert_value);
        return PMINFO_R_OK;
 }
 
-API int pkgmgrinfo_save_certinfo(const char *pkgid, pkgmgrinfo_instcertinfo_h handle, uid_t uid)
+static int _pkginfo_save_cert_info(sqlite3 *db, const char *pkgid,
+               char *cert_info[])
 {
-       retvm_if(pkgid == NULL, PMINFO_R_EINVAL, "package ID is NULL\n");
-       retvm_if(handle == NULL, PMINFO_R_EINVAL, "Certinfo handle is NULL\n");
-       char *error_message = NULL;
-       char query[MAX_QUERY_LEN] = {'\0'};
-       char vquery[MAX_QUERY_LEN] = {'\0'};
-       int i = 0;
-       int j = 0;
-       int c = 0;
-       int unique_id[MAX_CERT_TYPE] = {0, 0, 0, 0, 0, 0, 0, 0, 0};
-       int newid = 0;
-       int is_new = 0;
-       int exist = -1;
-       int ret = -1;
-       int maxid = 0;
-       int flag = 0;
-       pkgmgr_instcertinfo_x *info = (pkgmgr_instcertinfo_x *)handle;
-       pkgmgr_certindexinfo_x *indexinfo = NULL;
-       indexinfo = calloc(1, sizeof(pkgmgr_certindexinfo_x));
-       if (indexinfo == NULL) {
-               _LOGE("Out of Memory!!!");
+       static const char query_insert[] =
+               "INSERT INTO package_cert_info (package, package_count,"
+               " author_root_cert, author_im_cert, author_signer_cert,"
+               " dist_root_cert, dist_im_cert, dist_signer_cert,"
+               " dist2_root_cert, dist2_im_cert, dist2_signer_cert) "
+               "VALUES(?, 1,"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?),"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?),"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?),"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?),"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?),"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?),"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?),"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?),"
+               " (SELECT cert_id FROM package_cert_index_info"
+               "  WHERE cert_info=?))";
+       static const char query_update[] =
+               "UPDATE package_cert_info "
+               "SET package_count = package_count + 1 "
+               "WHERE package=?";
+       int ret;
+       sqlite3_stmt *stmt;
+       int i;
+       int idx;
+
+       ret = sqlite3_prepare_v2(db, query_insert, strlen(query_insert),
+                       &stmt, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("prepare error: %s", sqlite3_errmsg(db));
                return PMINFO_R_ERROR;
        }
-       info->pkgid = strdup(pkgid);
 
-       /*Open db.*/
-       ret =__open_cert_db(uid, false);
-       if (ret != 0) {
-               ret = PMINFO_R_ERROR;
-               _LOGE("Failed to open cert db \n");
-               goto err;
+       idx = 1;
+       ret = sqlite3_bind_text(stmt, idx++, pkgid, -1, SQLITE_STATIC);
+       if (ret != SQLITE_OK) {
+               _LOGE("bind failed: %s", sqlite3_errmsg(db));
+               sqlite3_finalize(stmt);
+               return PMINFO_R_ERROR;
        }
-       _check_create_cert_db(GET_DB(cert_db));
-       /*Begin Transaction*/
-       ret = sqlite3_exec(GET_DB(cert_db), "BEGIN EXCLUSIVE", NULL, NULL, NULL);
-       if (ret == -1) {
-               _LOGE("Failed to begin transaction %s\n");
-               ret = PMINFO_R_ERROR;
-               goto err;
+
+       for (i = 0; i < MAX_CERT_TYPE; i++) {
+               if (sqlite3_bind_text(stmt, idx++, cert_info[i], -1,
+                               SQLITE_STATIC)) {
+                       _LOGE("bind error: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
+               }
        }
 
-       /*Check if request is to insert/update*/
-       snprintf(query, sizeof(query), "select exists(select * from package_cert_info where package='%s')", pkgid);
-       if (SQLITE_OK !=
-           sqlite3_exec(GET_DB(cert_db), query, __validate_cb, (void *)&exist, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", query,
-                      error_message);
-               sqlite3_free(error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
+       ret = sqlite3_step(stmt);
+       sqlite3_finalize(stmt);
+       if (ret == SQLITE_CONSTRAINT) {
+               ret = sqlite3_prepare_v2(db, query_update, strlen(query_update),
+                               &stmt, NULL);
+               if (ret != SQLITE_OK) {
+                       _LOGE("prepare error: %s", sqlite3_errmsg(db));
+                       return PMINFO_R_ERROR;
+               }
+
+               if (sqlite3_bind_text(stmt, 1, pkgid, -1, SQLITE_STATIC)) {
+                       _LOGE("bind error: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
+               }
+
+               ret = sqlite3_step(stmt);
+               sqlite3_finalize(stmt);
        }
-       if (exist) {
-               /*Update request.
-               We cant just issue update query directly. We need to manage index table also.
-               Hence it is better to delete and insert again in case of update*/
-               ret = __delete_certinfo(pkgid, uid);
-               if (ret < 0)
-                       _LOGE("Certificate Deletion Failed\n");
+
+       if (ret != SQLITE_DONE) {
+               _LOGE("step error: %s", sqlite3_errmsg(db));
+               return PMINFO_R_ERROR;
        }
-       for (i = 0; i < MAX_CERT_TYPE; i++) {
-               if ((info->cert_info)[i]) {
-                       for (j = 0; j < i; j++) {
-                               if ( (info->cert_info)[j]) {
-                                       if (strcmp((info->cert_info)[i], (info->cert_info)[j]) == 0) {
-                                               (info->cert_id)[i] = (info->cert_id)[j];
-                                               (info->is_new)[i] = 0;
-                                               (info->ref_count)[i] = (info->ref_count)[j];
-                                               break;
-                                       }
-                               }
-                       }
-                       if (j < i)
-                               continue;
-                       snprintf(query, sizeof(query), "select * from package_cert_index_info " \
-                               "where cert_info='%s'",(info->cert_info)[i]);
-                       ret = __exec_certindexinfo_query(query, (void *)indexinfo);
-                       if (ret == -1) {
-                               _LOGE("Cert Info DB Information retrieval failed\n");
-                               ret = PMINFO_R_ERROR;
-                               goto err;
-                       }
-                       if (indexinfo->cert_id == 0) {
-                               /*New certificate. Get newid*/
-                               snprintf(query, sizeof(query), "select MAX(cert_id) from package_cert_index_info ");
-                               if (SQLITE_OK !=
-                                   sqlite3_exec(GET_DB(cert_db), query, __maxid_cb, (void *)&newid, &error_message)) {
-                                       _LOGE("Don't execute query = %s error message = %s\n", query,
-                                              error_message);
-                                       sqlite3_free(error_message);
-                                       ret = PMINFO_R_ERROR;
-                                       goto err;
-                               }
-                               newid = newid + 1;
-                               if (flag == 0) {
-                                       maxid = newid;
-                                       flag = 1;
-                               }
-                               indexinfo->cert_id = maxid;
-                               indexinfo->cert_ref_count = 1;
-                               is_new = 1;
-                               maxid = maxid + 1;
-                       }
-                       (info->cert_id)[i] = indexinfo->cert_id;
-                       (info->is_new)[i] = is_new;
-                       (info->ref_count)[i] = indexinfo->cert_ref_count;
-                       indexinfo->cert_id = 0;
-                       indexinfo->cert_ref_count = 0;
-                       is_new = 0;
-               }
+
+       return PMINFO_R_OK;
+}
+
+static int _pkginfo_save_cert_index_info(sqlite3 *db, char *cert_info[])
+{
+       static const char query[] =
+               "INSERT OR REPLACE INTO package_cert_index_info "
+               "(cert_info, cert_id, cert_ref_count) "
+               "VALUES ( "
+               " ?, "
+               " (SELECT cert_id FROM package_cert_index_info "
+               "  WHERE cert_info=?), "
+               " COALESCE( "
+               "  ((SELECT cert_ref_count FROM package_cert_index_info "
+               "    WHERE cert_info=?) + 1), 1))";
+       int ret;
+       sqlite3_stmt *stmt;
+       int i;
+       int idx;
+
+       ret = sqlite3_prepare_v2(db, query, strlen(query), &stmt, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("prepare error: %s", sqlite3_errmsg(db));
+               return PMINFO_R_ERROR;
        }
-       /*insert*/
-       snprintf(vquery, sizeof(vquery),
-                 "insert into package_cert_info(package, author_root_cert, author_im_cert, author_signer_cert, dist_root_cert, " \
-                "dist_im_cert, dist_signer_cert, dist2_root_cert, dist2_im_cert, dist2_signer_cert) " \
-                "values('%s', %d, %d, %d, %d, %d, %d, %d, %d, %d)",\
-                 info->pkgid,(info->cert_id)[PMINFO_SET_AUTHOR_ROOT_CERT],(info->cert_id)[PMINFO_SET_AUTHOR_INTERMEDIATE_CERT],
-               (info->cert_id)[PMINFO_SET_AUTHOR_SIGNER_CERT], (info->cert_id)[PMINFO_SET_DISTRIBUTOR_ROOT_CERT],
-               (info->cert_id)[PMINFO_SET_DISTRIBUTOR_INTERMEDIATE_CERT], (info->cert_id)[PMINFO_SET_DISTRIBUTOR_SIGNER_CERT],
-               (info->cert_id)[PMINFO_SET_DISTRIBUTOR2_ROOT_CERT],(info->cert_id)[PMINFO_SET_DISTRIBUTOR2_INTERMEDIATE_CERT],
-               (info->cert_id)[PMINFO_SET_DISTRIBUTOR2_SIGNER_CERT]);
-        if (SQLITE_OK !=
-            sqlite3_exec(GET_DB(cert_db), vquery, NULL, NULL, &error_message)) {
-               _LOGE("Don't execute query = %s error message = %s\n", vquery,
-                      error_message);
-               sqlite3_free(error_message);
-               ret = PMINFO_R_ERROR;
-               goto err;
-        }
-       /*Update index table info*/
-       /*If cert_id exists and is repeated for current package, ref count should only be increased once*/
+
        for (i = 0; i < MAX_CERT_TYPE; i++) {
-               if ((info->cert_info)[i]) {
-                       if ((info->is_new)[i]) {
-                               snprintf(vquery, sizeof(vquery), "insert into package_cert_index_info(cert_info, cert_id, cert_ref_count) " \
-                               "values('%s', '%d', '%d') ", (info->cert_info)[i], (info->cert_id)[i], 1);
-                               unique_id[c++] = (info->cert_id)[i];
-                       } else {
-                               /*Update*/
-                               for (j = 0; j < MAX_CERT_TYPE; j++) {
-                                       if ((info->cert_id)[i] == unique_id[j]) {
-                                               /*Ref count has already been increased. Just continue*/
-                                               break;
-                                       }
-                               }
-                               if (j == MAX_CERT_TYPE)
-                                       unique_id[c++] = (info->cert_id)[i];
-                               else
-                                       continue;
-                               snprintf(vquery, sizeof(vquery), "update package_cert_index_info set cert_ref_count=%d " \
-                               "where cert_id=%d",  (info->ref_count)[i] + 1, (info->cert_id)[i]);
-                       }
-                       if (SQLITE_OK !=
-                           sqlite3_exec(GET_DB(cert_db), vquery, NULL, NULL, &error_message)) {
-                               _LOGE("Don't execute query = %s error message = %s\n", vquery,
-                                      error_message);
-                               sqlite3_free(error_message);
-                               ret = PMINFO_R_ERROR;
-                               goto err;
-                       }
+               if (cert_info[i] == NULL)
+                       continue;
+               idx = 1;
+               ret = sqlite3_bind_text(stmt, idx++, cert_info[i], -1, SQLITE_STATIC);
+               if (ret != SQLITE_OK) {
+                       _LOGE("bind failed: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
+               }
+               ret = sqlite3_bind_text(stmt, idx++, cert_info[i], -1, SQLITE_STATIC);
+               if (ret != SQLITE_OK) {
+                       _LOGE("bind failed: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
                }
+               ret = sqlite3_bind_text(stmt, idx++, cert_info[i], -1, SQLITE_STATIC);
+               if (ret != SQLITE_OK) {
+                       _LOGE("bind failed: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
+               }
+
+               ret = sqlite3_step(stmt);
+               if (ret != SQLITE_DONE) {
+                       _LOGE("step failed: %s", sqlite3_errmsg(db));
+                       sqlite3_finalize(stmt);
+                       return PMINFO_R_ERROR;
+               }
+
+               sqlite3_reset(stmt);
+               sqlite3_clear_bindings(stmt);
        }
-       /*Commit transaction*/
-       ret = sqlite3_exec(GET_DB(cert_db), "COMMIT", NULL, NULL, NULL);
+
+       sqlite3_finalize(stmt);
+
+       return PMINFO_R_OK;
+}
+
+API int pkgmgrinfo_save_certinfo(const char *pkgid, pkgmgrinfo_instcertinfo_h handle, uid_t uid)
+{
+       int ret;
+       sqlite3 *db;
+       char *dbpath;
+       pkgmgr_instcertinfo_x *info = (pkgmgr_instcertinfo_x *)handle;
+
+       if (pkgid == NULL || handle == NULL) {
+               _LOGE("invalid parameter");
+               return PMINFO_R_EINVAL;
+       }
+
+       _check_create_cert_db();
+
+       /* open unified global cert db */
+       dbpath = getUserPkgCertDBPath();
+       if (dbpath == NULL)
+               return PMINFO_R_ERROR;
+
+       ret = __open_db(dbpath, &db, SQLITE_OPEN_READWRITE);
        if (ret != SQLITE_OK) {
-               _LOGE("Failed to commit transaction, Rollback now\n");
-               sqlite3_exec(GET_DB(cert_db), "ROLLBACK", NULL, NULL, NULL);
-               ret = PMINFO_R_ERROR;
-               goto err;
+               _LOGE("failed to open db: %d", ret);
+               free(dbpath);
+               return PMINFO_R_ERROR;
        }
+       free(dbpath);
 
-       ret =  PMINFO_R_OK;
-err:
-       __close_cert_db();
-       if (indexinfo) {
-               free(indexinfo);
-               indexinfo = NULL;
+       ret = sqlite3_exec(db, "BEGIN DEFERRED", NULL, NULL, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("failed to begin transaction");
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
        }
-       return ret;
+
+       if (_pkginfo_save_cert_index_info(db, info->cert_info)) {
+               _LOGE("failed to save cert index info, rollback now");
+               ret = sqlite3_exec(db, "ROLLBACK", NULL, NULL, NULL);
+               if (ret != SQLITE_OK)
+                       LOGE("Rollback is failed. error(%s)", sqlite3_errmsg(db));
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
+       }
+
+       if (_pkginfo_save_cert_info(db, pkgid, info->cert_info)) {
+               _LOGE("failed to save cert info, rollback now");
+               ret = sqlite3_exec(db, "ROLLBACK", NULL, NULL, NULL);
+               if (ret != SQLITE_OK)
+                       LOGE("Rollback is failed. error(%s)", sqlite3_errmsg(db));
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
+       }
+
+       ret = sqlite3_exec(db, "COMMIT", NULL, NULL, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("failed to commit transaction, rollback now");
+               ret = sqlite3_exec(db, "ROLLBACK", NULL, NULL, NULL);
+               if (ret != SQLITE_OK)
+                       LOGE("Rollback is failed. error(%s)", sqlite3_errmsg(db));
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
+       }
+
+       sqlite3_close_v2(db);
+
+       return PMINFO_R_OK;
 }
 
 API int pkgmgrinfo_destroy_certinfo_set_handle(pkgmgrinfo_instcertinfo_h handle)
@@ -975,50 +706,95 @@ API int pkgmgrinfo_destroy_certinfo_set_handle(pkgmgrinfo_instcertinfo_h handle)
        return PMINFO_R_OK;
 }
 
+static int _pkginfo_delete_certinfo(sqlite3 *db, const char *pkgid)
+{
+       static const char query[] =
+               "UPDATE package_cert_info "
+               "SET package_count = package_count - 1 "
+               "WHERE package=?";
+       int ret;
+       sqlite3_stmt *stmt;
+
+       ret = sqlite3_prepare_v2(db, query, strlen(query), &stmt, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("prepare error: %s", sqlite3_errmsg(db));
+               return PMINFO_R_ERROR;
+       }
+
+       ret = sqlite3_bind_text(stmt, 1, pkgid, -1, SQLITE_STATIC);
+       if (ret != SQLITE_OK) {
+               _LOGE("bind error: %s", sqlite3_errmsg(db));
+               sqlite3_finalize(stmt);
+               return PMINFO_R_ERROR;
+       }
+
+       ret = sqlite3_step(stmt);
+       sqlite3_finalize(stmt);
+       if (ret != SQLITE_DONE) {
+               _LOGE("step error: %s", sqlite3_errmsg(db));
+               return PMINFO_R_ERROR;
+       }
+
+       return PMINFO_R_OK;
+}
+
 API int pkgmgrinfo_delete_usr_certinfo(const char *pkgid, uid_t uid)
 {
-       retvm_if(pkgid == NULL, PMINFO_R_EINVAL, "Argument supplied is NULL\n");
-       int ret = -1;
-       /*Open db.*/
-       ret = __open_cert_db(uid, false);
-       if (ret != 0) {
-               _LOGE("connect db [%s] failed!\n", getUserPkgCertDBPathUID(uid));
-               ret = PMINFO_R_ERROR;
-               goto err;
+       int ret;
+       sqlite3 *db;
+       char *dbpath;
+
+       if (pkgid == NULL) {
+               _LOGE("invalid parameter");
+               return PMINFO_R_EINVAL;
        }
-       _check_create_cert_db(GET_DB(cert_db));
-       /*Begin Transaction*/
-       ret = sqlite3_exec(GET_DB(cert_db), "BEGIN EXCLUSIVE", NULL, NULL, NULL);
+
+       /* open unified global cert db */
+       dbpath = getUserPkgCertDBPath();
+       if (dbpath == NULL)
+               return PMINFO_R_ERROR;
+
+       ret = __open_db(dbpath, &db, SQLITE_OPEN_READWRITE);
        if (ret != SQLITE_OK) {
-               _LOGE("Failed to begin transaction\n");
-               ret = PMINFO_R_ERROR;
-               goto err;
+               _LOGE("failed to open db: %d", ret);
+               free(dbpath);
+               return PMINFO_R_ERROR;
        }
-       _LOGE("Transaction Begin\n");
-       ret = __delete_certinfo(pkgid, uid);
-       if (ret < 0) {
-               _LOGE("Certificate Deletion Failed\n");
-       } else {
-               _LOGE("Certificate Deletion Success\n");
+       free(dbpath);
+
+       ret = sqlite3_exec(db, "BEGIN DEFERRED", NULL, NULL, NULL);
+       if (ret != SQLITE_OK) {
+               _LOGE("failed to begin transaction");
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
+       }
+
+       if (_pkginfo_delete_certinfo(db, pkgid)) {
+               _LOGE("failed to delete certinfo of %s, rollback now", pkgid);
+               ret = sqlite3_exec(db, "ROLLBACK", NULL, NULL, NULL);
+               if (ret != SQLITE_OK)
+                       LOGE("Rollback is failed. error(%s)", sqlite3_errmsg(db));
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
        }
-       /*Commit transaction*/
-       ret = sqlite3_exec(GET_DB(cert_db), "COMMIT", NULL, NULL, NULL);
+
+       ret = sqlite3_exec(db, "COMMIT", NULL, NULL, NULL);
        if (ret != SQLITE_OK) {
-               _LOGE("Failed to commit transaction, Rollback now\n");
-               sqlite3_exec(GET_DB(cert_db), "ROLLBACK", NULL, NULL, NULL);
-               ret = PMINFO_R_ERROR;
-               goto err;
+               _LOGE("failed to commit transaction, rollback now");
+               ret = sqlite3_exec(db, "ROLLBACK", NULL, NULL, NULL);
+               if (ret != SQLITE_OK)
+                       LOGE("Rollback is failed. error(%s)", sqlite3_errmsg(db));
+               sqlite3_close_v2(db);
+               return PMINFO_R_ERROR;
        }
-       _LOGE("Transaction Commit and End\n");
-       ret = PMINFO_R_OK;
-err:
-       __close_cert_db();
-       return ret;
-}
 
+       sqlite3_close_v2(db);
+
+       return PMINFO_R_OK;
+}
 
 API int pkgmgrinfo_delete_certinfo(const char *pkgid)
 {
-       return pkgmgrinfo_delete_usr_certinfo(pkgid, GLOBAL_USER);
+       return pkgmgrinfo_delete_usr_certinfo(pkgid, _getuid());
 }