mirror of
https://github.com/mvt-project/mvt.git
synced 2026-10-01 21:49:55 +02:00
Merge pull request #946 from va-resident/fix/accessibility-installed-service-count
Carry the accessibility service count the dump states
This commit is contained in:
5 files changed
+452
-23
No files matched your search
@@ -10,8 +10,45 @@ from .artifact import AndroidArtifact
|
||||
|
||||
|
||||
class DumpsysAccessibilityArtifact(AndroidArtifact):
|
||||
# One list for both record shapes — a service record and a count-only
|
||||
# record must stay the same shape.
|
||||
_FIELDS = (
|
||||
"user_id",
|
||||
"component",
|
||||
"package_name",
|
||||
"service_name",
|
||||
"installed",
|
||||
"enabled",
|
||||
"binding",
|
||||
"bound",
|
||||
"crashed",
|
||||
"accessibility_tool",
|
||||
"installed_service_count",
|
||||
"unnamed_service_count",
|
||||
)
|
||||
|
||||
def check_indicators(self) -> None:
|
||||
for result in self.results:
|
||||
# A stated count the dump does not back with component names is a
|
||||
# coverage statement, not a service: low, but not silent.
|
||||
if not result.get("component"):
|
||||
stated = result["installed_service_count"]
|
||||
unnamed = result["unnamed_service_count"]
|
||||
if unnamed == stated:
|
||||
detail = "does not list their component names"
|
||||
else:
|
||||
detail = (
|
||||
f"lists the component names of only {stated - unnamed} "
|
||||
f"of them ({unnamed} unnamed)"
|
||||
)
|
||||
self.alertstore.low(
|
||||
f"The accessibility dump states {stated} installed "
|
||||
f"service(s) for user {result['user_id']} but {detail}",
|
||||
"",
|
||||
result,
|
||||
)
|
||||
continue
|
||||
|
||||
if self.indicators:
|
||||
ioc_match = self.indicators.check_app_id(result["package_name"])
|
||||
if ioc_match:
|
||||
@@ -20,11 +57,22 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
|
||||
)
|
||||
continue
|
||||
|
||||
self.alertstore.medium(
|
||||
f'Found accessibility service: "{result["component"]}"',
|
||||
"",
|
||||
result,
|
||||
# Installed is not enabled. A service can sit installed for years
|
||||
# without ever being switched on, and that is the difference this
|
||||
# channel is read for — an alert that says only "found" makes every
|
||||
# device look equally exposed. A service the dump says is switched
|
||||
# OFF is reported LOW, so it still reaches the analyst without
|
||||
# competing with one that is actually running; a dump that does not
|
||||
# state the enabled state stays MEDIUM, because "not stated" is not
|
||||
# "not enabled".
|
||||
message = (
|
||||
f'Found accessibility service: "{result["component"]}" '
|
||||
f"({self._describe_state(result)})"
|
||||
)
|
||||
if result.get("enabled") is False and not result.get("bound"):
|
||||
self.alertstore.low(message, "", result)
|
||||
else:
|
||||
self.alertstore.medium(message, "", result)
|
||||
|
||||
def parse(self, content: str) -> None:
|
||||
"""
|
||||
@@ -36,6 +84,13 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
|
||||
|
||||
self.results: list[dict[str, Any]] = []
|
||||
services: dict[tuple[int | None, str], dict] = {}
|
||||
# Which state sections the dump printed, per user: one user's printed
|
||||
# `enabled services` says nothing about another user's.
|
||||
seen_states: dict[int | None, set[str]] = {}
|
||||
# `installedServiceCount=N` from the user's `attributes:{…}` line is on
|
||||
# most builds the only statement about installed services in the dump:
|
||||
# few print the `installed services: {…}` block.
|
||||
installed_counts: dict[int | None, int] = {}
|
||||
user_id: int | None = None
|
||||
state: str | None = None
|
||||
|
||||
@@ -44,6 +99,10 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
|
||||
if user_match:
|
||||
user_id = int(user_match.group(1))
|
||||
|
||||
count_match = re.search(r"installedServiceCount=(\d+)", line)
|
||||
if count_match:
|
||||
installed_counts[user_id] = int(count_match.group(1))
|
||||
|
||||
stripped = line.strip()
|
||||
state_match = re.match(
|
||||
r"(?i)(installed|enabled|binding|bound|crashed) services\s*:\s*\{(.*)",
|
||||
@@ -51,6 +110,7 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
|
||||
)
|
||||
if state_match:
|
||||
state = state_match.group(1).lower()
|
||||
seen_states.setdefault(user_id, set()).add(self._state_field(state))
|
||||
inline = state_match.group(2)
|
||||
for component in re.findall(
|
||||
r"\{?([\w.$-]+/[\w.$-]+)(?:\s+\(A11yTool\))?\}?", inline
|
||||
@@ -79,24 +139,65 @@ class DumpsysAccessibilityArtifact(AndroidArtifact):
|
||||
service[self._state_field(state)] = True
|
||||
service["accessibility_tool"] = "(A11yTool)" in stripped
|
||||
|
||||
# A section that was never printed is NOT the same as one printed
|
||||
# empty: the first says nothing, the second says nothing is enabled.
|
||||
# Defaulting every flag to False would turn "not stated" into "not
|
||||
# enabled". Flags for sections this dump never printed stay None.
|
||||
named: dict[int | None, int] = {}
|
||||
for (service_user, _component), service in services.items():
|
||||
printed = seen_states.get(service_user, set())
|
||||
for state in ("installed", "enabled", "binding", "bound", "crashed"):
|
||||
if self._state_field(state) not in printed:
|
||||
service[self._state_field(state)] = None
|
||||
service["installed_service_count"] = installed_counts.get(service_user)
|
||||
named[service_user] = named.get(service_user, 0) + 1
|
||||
|
||||
self.results.extend(services.values())
|
||||
|
||||
# A stated count the named services do not add up to would leave no
|
||||
# trace of the rest: the module would log "a total of 0" about a dump
|
||||
# that said five, or "a total of 1" about one that said two.
|
||||
for count_user, count in installed_counts.items():
|
||||
unnamed = count - named.get(count_user, 0)
|
||||
if unnamed > 0:
|
||||
self.results.append(self._new_unlisted(count_user, count, unnamed))
|
||||
|
||||
@staticmethod
|
||||
def _describe_state(result: dict) -> str:
|
||||
if result.get("bound"):
|
||||
return "enabled and bound"
|
||||
if result.get("enabled"):
|
||||
return "enabled"
|
||||
if result.get("enabled") is None:
|
||||
return "installed, enabled state not stated"
|
||||
return "installed, not enabled"
|
||||
|
||||
@staticmethod
|
||||
def _state_field(state: str) -> str:
|
||||
return {"binding": "binding", "bound": "bound"}.get(state, state)
|
||||
|
||||
@staticmethod
|
||||
def _new_unlisted(user_id: int | None, count: int, unnamed: int) -> dict:
|
||||
"""The dump's own count for a user, and how many of those services it
|
||||
did not name.
|
||||
|
||||
Every other field stays unknown: the dump named no service to carry it.
|
||||
"""
|
||||
record: dict[str, Any] = dict.fromkeys(DumpsysAccessibilityArtifact._FIELDS)
|
||||
record["user_id"] = user_id
|
||||
record["installed_service_count"] = count
|
||||
record["unnamed_service_count"] = unnamed
|
||||
return record
|
||||
|
||||
@staticmethod
|
||||
def _new_service(component: str, user_id: int | None) -> dict:
|
||||
package_name, service_name = component.split("/", 1)
|
||||
return {
|
||||
"user_id": user_id,
|
||||
"component": component,
|
||||
"package_name": package_name,
|
||||
"service_name": service_name,
|
||||
"installed": False,
|
||||
"enabled": False,
|
||||
"binding": False,
|
||||
"bound": False,
|
||||
"crashed": False,
|
||||
"accessibility_tool": False,
|
||||
}
|
||||
record: dict[str, Any] = dict.fromkeys(
|
||||
DumpsysAccessibilityArtifact._FIELDS, False
|
||||
)
|
||||
record["user_id"] = user_id
|
||||
record["component"] = component
|
||||
record["package_name"], record["service_name"] = component.split("/", 1)
|
||||
# Filled in after parsing: the count is per user.
|
||||
record["installed_service_count"] = None
|
||||
record["unnamed_service_count"] = None
|
||||
return record
|
||||
@@ -48,9 +48,22 @@ class DumpsysAccessibility(DumpsysAccessibilityArtifact, BugReportModule):
|
||||
)
|
||||
self.parse(content)
|
||||
|
||||
listed = unnamed = 0
|
||||
for result in self.results:
|
||||
self.log.info('Found accessibility service "%s"', result.get("component"))
|
||||
if result.get("component"):
|
||||
listed += 1
|
||||
self.log.info(
|
||||
'Found accessibility service "%s"', result.get("component")
|
||||
)
|
||||
continue
|
||||
# The operator gets this per user as a LOW alert from
|
||||
# check_indicators(); here it only has to survive into the summary,
|
||||
# so that a stated count never reads as "a total of 0".
|
||||
unnamed += result.get("unnamed_service_count") or 0
|
||||
|
||||
self.log.info(
|
||||
"Identified a total of %d accessibility services", len(self.results)
|
||||
"Identified a total of %d accessibility services (%d more stated by "
|
||||
"the dump without a component name)",
|
||||
listed,
|
||||
unnamed,
|
||||
)
|
||||
@@ -35,11 +35,16 @@ class TestDumpsysAccessibilityArtifact:
|
||||
|
||||
assert len(da.results) == 0
|
||||
da.parse(data)
|
||||
assert len(da.results) == 1
|
||||
# One named service, plus one count-only record: the dump states
|
||||
# `installedServiceCount=2` and names only one component.
|
||||
assert len(da.results) == 2
|
||||
assert da.results[0]["package_name"] == "com.malware.accessibility"
|
||||
assert da.results[0]["service_name"] == "com.malware.service.malwareservice"
|
||||
assert da.results[0]["enabled"] is True
|
||||
assert da.results[0]["installed"] is False
|
||||
# This fixture never prints an `installed services:` section, so the
|
||||
# dump does not state the installed status. Reporting False would turn
|
||||
# "not stated" into "not installed", so it reads None here.
|
||||
assert da.results[0]["installed"] is None
|
||||
|
||||
def test_accessibility_service_alert(self):
|
||||
da = DumpsysAccessibilityArtifact()
|
||||
@@ -50,9 +55,11 @@ class TestDumpsysAccessibilityArtifact:
|
||||
|
||||
da.check_indicators()
|
||||
|
||||
assert len(da.alertstore.alerts) == 1
|
||||
assert len(da.alertstore.alerts) == 2
|
||||
assert da.alertstore.alerts[0].level == AlertLevel.MEDIUM
|
||||
assert da.alertstore.alerts[0].event == da.results[0]
|
||||
assert da.alertstore.alerts[1].level == AlertLevel.LOW
|
||||
assert da.alertstore.alerts[1].event == da.results[1]
|
||||
|
||||
def test_same_component_is_kept_for_each_user(self):
|
||||
da = DumpsysAccessibilityArtifact()
|
||||
@@ -84,7 +91,11 @@ User state[attributes:{id=10
|
||||
assert len(da.alertstore.alerts) == 0
|
||||
da.check_indicators()
|
||||
assert len(da.alertstore.alerts) == len(da.results)
|
||||
assert da.alertstore.count(AlertLevel.MEDIUM) == 3
|
||||
# Every service in this fixture is installed and switched off
|
||||
# (`enabled services:{}` is printed and empty), so the three non-IOC
|
||||
# findings are LOW, not MEDIUM. The IOC match is unaffected by the
|
||||
# state.
|
||||
assert da.alertstore.count(AlertLevel.LOW) == 3
|
||||
assert da.alertstore.count(AlertLevel.CRITICAL) == 1
|
||||
critical_alert = next(
|
||||
alert
|
||||
|
||||
@@ -0,0 +1,149 @@
|
||||
# Mobile Verification Toolkit (MVT)
|
||||
# Copyright (c) 2021-2026 The MVT Authors.
|
||||
# Use of this software is governed by the MVT License 1.1 that can be found at
|
||||
# https://license.mvt.re/1.1/
|
||||
"""The dump's own installed-service count must survive into the artifact.
|
||||
|
||||
Most builds never print the `installed services: {…}` block; they state `installedServiceCount=N` in the user's `attributes:{…}` line and
|
||||
list nothing. Dropping that number makes an artifact that says "no
|
||||
accessibility services" about a dump that said there are five.
|
||||
"""
|
||||
|
||||
from mvt.android.artifacts.dumpsys_accessibility import DumpsysAccessibilityArtifact
|
||||
from mvt.common.alerts import AlertLevel
|
||||
|
||||
from ..utils import get_artifact
|
||||
|
||||
AOSP_NO_LIST = """\
|
||||
ACCESSIBILITY MANAGER (dumpsys accessibility)
|
||||
User state[
|
||||
attributes:{id=0, touchExplorationEnabled=false, installedServiceCount=5}
|
||||
Bound services:{}
|
||||
Enabled services:{}
|
||||
Binding services:{}
|
||||
Crashed services:{}
|
||||
"""
|
||||
|
||||
ONE_UI_WITH_LIST = """\
|
||||
ACCESSIBILITY MANAGER (dumpsys accessibility)
|
||||
User state[attributes:{id=0, installedServiceCount=2}
|
||||
installed services: {
|
||||
0 : com.example.app/com.example.app.Service
|
||||
1 : com.other.app/.Helper
|
||||
}
|
||||
enabled services: {
|
||||
}
|
||||
"""
|
||||
|
||||
TWO_USERS = """\
|
||||
ACCESSIBILITY MANAGER (dumpsys accessibility)
|
||||
User state[attributes:{id=0, installedServiceCount=1}
|
||||
installed services: {
|
||||
0 : com.example.app/com.example.app.Service
|
||||
}
|
||||
User state[attributes:{id=95, installedServiceCount=3}
|
||||
Enabled services:{}
|
||||
"""
|
||||
|
||||
PARTIAL_TWO_USERS = """\
|
||||
ACCESSIBILITY MANAGER (dumpsys accessibility)
|
||||
User state[attributes:{id=0, installedServiceCount=3}
|
||||
Enabled services:{{com.example.app/com.example.app.Service}}
|
||||
User state[attributes:{id=10, installedServiceCount=1}
|
||||
Enabled services:{{com.other.app/.Helper}}
|
||||
"""
|
||||
|
||||
ZERO_COUNT = """\
|
||||
ACCESSIBILITY MANAGER (dumpsys accessibility)
|
||||
User state[attributes:{id=0, installedServiceCount=0}
|
||||
Enabled services:{}
|
||||
"""
|
||||
|
||||
|
||||
def _parse(content):
|
||||
artifact = DumpsysAccessibilityArtifact()
|
||||
artifact.results = []
|
||||
artifact.parse(content)
|
||||
return artifact
|
||||
|
||||
|
||||
class TestAccessibilityInstalledServiceCount:
|
||||
def test_stated_count_without_a_list_is_kept(self):
|
||||
artifact = _parse(AOSP_NO_LIST)
|
||||
assert len(artifact.results) == 1
|
||||
record = artifact.results[0]
|
||||
assert record["installed_service_count"] == 5
|
||||
assert record["component"] is None
|
||||
# Every state flag stays unknown: the dump named no service to which a
|
||||
# state could belong.
|
||||
assert record["installed"] is None
|
||||
assert record["enabled"] is None
|
||||
|
||||
def test_a_stated_count_is_reported_as_low(self):
|
||||
artifact = _parse(AOSP_NO_LIST)
|
||||
artifact.check_indicators()
|
||||
alerts = artifact.alertstore.alerts
|
||||
assert len(alerts) == 1
|
||||
# A count is a coverage statement, not a running service: it must not
|
||||
# compete with a service the dump says is enabled.
|
||||
assert alerts[0].level == AlertLevel.LOW
|
||||
assert "does not list their component names" in alerts[0].message
|
||||
assert "5 installed" in alerts[0].message
|
||||
|
||||
def test_a_listed_user_carries_the_count_on_each_service(self):
|
||||
artifact = _parse(ONE_UI_WITH_LIST)
|
||||
assert len(artifact.results) == 2
|
||||
assert {record["installed_service_count"] for record in artifact.results} == {2}
|
||||
assert all(record["component"] for record in artifact.results)
|
||||
|
||||
def test_only_the_unlisted_user_gets_a_count_record(self):
|
||||
artifact = _parse(TWO_USERS)
|
||||
listed = [record for record in artifact.results if record["component"]]
|
||||
unlisted = [record for record in artifact.results if not record["component"]]
|
||||
assert [record["user_id"] for record in listed] == [0]
|
||||
assert [record["user_id"] for record in unlisted] == [95]
|
||||
assert unlisted[0]["installed_service_count"] == 3
|
||||
|
||||
def test_a_zero_count_adds_nothing(self):
|
||||
# "Zero installed" is a negative result the empty section already
|
||||
# states; a record for it would be noise.
|
||||
assert _parse(ZERO_COUNT).results == []
|
||||
|
||||
def test_a_partly_named_count_reports_the_unnamed_rest(self):
|
||||
# The Android 14 fixture states `installedServiceCount=2` and names one
|
||||
# enabled component. The listing is incomplete, and must not read as
|
||||
# complete.
|
||||
artifact = DumpsysAccessibilityArtifact()
|
||||
artifact.results = []
|
||||
with open(
|
||||
get_artifact("android_data/dumpsys_accessibility_v14_or_later.txt")
|
||||
) as handle:
|
||||
artifact.parse(handle.read())
|
||||
unlisted = [record for record in artifact.results if not record["component"]]
|
||||
assert len(unlisted) == 1
|
||||
assert unlisted[0]["installed_service_count"] == 2
|
||||
assert unlisted[0]["unnamed_service_count"] == 1
|
||||
|
||||
artifact.check_indicators()
|
||||
low = [
|
||||
alert
|
||||
for alert in artifact.alertstore.alerts
|
||||
if alert.level == AlertLevel.LOW
|
||||
]
|
||||
assert len(low) == 1
|
||||
assert "only 1 of them (1 unnamed)" in low[0].message
|
||||
|
||||
def test_the_unnamed_rest_is_counted_per_user(self):
|
||||
# User 0 names one of three, user 10 names its only one: the gap
|
||||
# belongs to user 0 alone.
|
||||
artifact = _parse(PARTIAL_TWO_USERS)
|
||||
unlisted = [record for record in artifact.results if not record["component"]]
|
||||
assert [
|
||||
(record["user_id"], record["unnamed_service_count"]) for record in unlisted
|
||||
] == [(0, 2)]
|
||||
|
||||
def test_a_fully_named_count_adds_nothing(self):
|
||||
artifact = _parse(ONE_UI_WITH_LIST)
|
||||
assert all(
|
||||
record["unnamed_service_count"] is None for record in artifact.results
|
||||
)
|
||||
@@ -0,0 +1,155 @@
|
||||
# Mobile Verification Toolkit (MVT)
|
||||
# Copyright (c) 2021-2026 The MVT Authors.
|
||||
# Use of this software is governed by the MVT License 1.1 that can be found at
|
||||
# https://license.mvt.re/1.1/
|
||||
"""Installed is not the same as enabled, and the dump says which.
|
||||
|
||||
Two things this guards:
|
||||
|
||||
* a section the dump never printed must read as None ("not stated"), not as
|
||||
False ("not enabled");
|
||||
* the alert must name the state, instead of firing identically on a device
|
||||
where nothing is switched on and one where something is bound.
|
||||
"""
|
||||
|
||||
from types import SimpleNamespace
|
||||
|
||||
from mvt.android.artifacts.dumpsys_accessibility import DumpsysAccessibilityArtifact
|
||||
from mvt.common.alerts import AlertLevel
|
||||
|
||||
from ..utils import get_artifact
|
||||
|
||||
NO_STATE_SECTIONS = """\
|
||||
ACCESSIBILITY MANAGER (dumpsys accessibility)
|
||||
User state[attributes:{id=0, currentUser=true}
|
||||
installed services: {
|
||||
0 : com.example.app/com.example.app.Service
|
||||
}
|
||||
"""
|
||||
|
||||
ENABLED_BLOCK = """\
|
||||
ACCESSIBILITY MANAGER (dumpsys accessibility)
|
||||
User state[attributes:{id=0, currentUser=true}
|
||||
installed services: {
|
||||
0 : com.example.app/com.example.app.Service
|
||||
1 : com.other.app/.Helper
|
||||
}
|
||||
enabled services: {
|
||||
0 : com.other.app/.Helper
|
||||
}
|
||||
bound services:{
|
||||
0 : com.other.app/.Helper
|
||||
}
|
||||
"""
|
||||
|
||||
# User 0 prints only `installed services`, user 10 only `Enabled services`.
|
||||
# Neither section speaks for the other user.
|
||||
TWO_USERS_DIFFERENT_SECTIONS = """\
|
||||
ACCESSIBILITY MANAGER (dumpsys accessibility)
|
||||
User state[attributes:{id=0, currentUser=true}
|
||||
installed services: {
|
||||
0 : com.example.app/com.example.app.Service
|
||||
}
|
||||
User state[attributes:{id=10, currentUser=false}
|
||||
Enabled services:{{com.other.app/.Helper}}
|
||||
"""
|
||||
|
||||
|
||||
class _IndicatorsMatching:
|
||||
"""Minimal stand-in: matches one package id, like the STIX2 loader would."""
|
||||
|
||||
def __init__(self, package_name: str) -> None:
|
||||
self.package_name = package_name
|
||||
|
||||
def check_app_id(self, app_id):
|
||||
if app_id != self.package_name:
|
||||
return None
|
||||
return SimpleNamespace(
|
||||
message=f"Found a known suspicious app: {app_id}", ioc={"value": app_id}
|
||||
)
|
||||
|
||||
|
||||
class TestAccessibilityServiceState:
|
||||
def _parse(self, content):
|
||||
artifact = DumpsysAccessibilityArtifact()
|
||||
artifact.results = []
|
||||
artifact.parse(content)
|
||||
return {r["component"]: r for r in artifact.results}
|
||||
|
||||
def test_absent_sections_leave_the_state_unknown(self):
|
||||
# None, not False: a build that does not print the sections says
|
||||
# nothing about what is enabled, and that must not read as "nothing".
|
||||
state = self._parse(NO_STATE_SECTIONS)[
|
||||
"com.example.app/com.example.app.Service"
|
||||
]
|
||||
assert state["installed"] is True
|
||||
assert state["enabled"] is None
|
||||
assert state["bound"] is None
|
||||
|
||||
def test_enabled_and_bound_are_attributed_per_service(self):
|
||||
results = self._parse(ENABLED_BLOCK)
|
||||
installed_only = results["com.example.app/com.example.app.Service"]
|
||||
active = results["com.other.app/.Helper"]
|
||||
assert (installed_only["enabled"], installed_only["bound"]) == (False, False)
|
||||
assert (active["enabled"], active["bound"]) == (True, True)
|
||||
|
||||
def test_alert_message_carries_the_state(self):
|
||||
artifact = DumpsysAccessibilityArtifact()
|
||||
artifact.results = []
|
||||
with open(get_artifact("android_data/dumpsys_accessibility.txt")) as handle:
|
||||
artifact.parse(handle.read())
|
||||
artifact.check_indicators()
|
||||
assert artifact.alertstore.alerts
|
||||
assert all("installed" in alert.message for alert in artifact.alertstore.alerts)
|
||||
|
||||
def test_a_switched_off_service_is_low_and_a_running_one_medium(self):
|
||||
# A service the dump says is OFF still reaches the analyst, but must not
|
||||
# compete with one that is actually bound. "Not stated" is not "off".
|
||||
artifact = DumpsysAccessibilityArtifact()
|
||||
artifact.results = []
|
||||
artifact.parse(ENABLED_BLOCK)
|
||||
artifact.check_indicators()
|
||||
by_level = {}
|
||||
for alert in artifact.alertstore.alerts:
|
||||
by_level.setdefault(alert.level, []).append(alert.message)
|
||||
assert artifact.alertstore.count(AlertLevel.LOW) == 1
|
||||
assert artifact.alertstore.count(AlertLevel.MEDIUM) == 1
|
||||
assert "com.example.app" in by_level[AlertLevel.LOW][0]
|
||||
assert "com.other.app" in by_level[AlertLevel.MEDIUM][0]
|
||||
|
||||
def test_an_unstated_enabled_state_stays_medium(self):
|
||||
artifact = DumpsysAccessibilityArtifact()
|
||||
artifact.results = []
|
||||
artifact.parse(NO_STATE_SECTIONS)
|
||||
artifact.check_indicators()
|
||||
assert artifact.alertstore.count(AlertLevel.MEDIUM) == 1
|
||||
assert artifact.alertstore.count(AlertLevel.LOW) == 0
|
||||
|
||||
def test_a_disabled_service_is_still_matched_against_indicators(self):
|
||||
# The state decides the severity of an ordinary finding, never whether
|
||||
# the package is compared with the IOC feeds.
|
||||
artifact = DumpsysAccessibilityArtifact()
|
||||
artifact.results = []
|
||||
artifact.parse(ENABLED_BLOCK)
|
||||
artifact.indicators = _IndicatorsMatching("com.example.app")
|
||||
artifact.check_indicators()
|
||||
assert artifact.alertstore.count(AlertLevel.CRITICAL) == 1
|
||||
assert artifact.alertstore.count(AlertLevel.LOW) == 0
|
||||
|
||||
def test_printed_sections_are_tracked_per_user(self):
|
||||
artifact = DumpsysAccessibilityArtifact()
|
||||
artifact.results = []
|
||||
artifact.parse(TWO_USERS_DIFFERENT_SECTIONS)
|
||||
by_user = {r["user_id"]: r for r in artifact.results}
|
||||
# User 0's enabled state is not stated, so it is unknown, not off.
|
||||
assert (by_user[0]["installed"], by_user[0]["enabled"]) == (True, None)
|
||||
# User 10's installed state is not stated either.
|
||||
assert (by_user[10]["installed"], by_user[10]["enabled"]) == (None, True)
|
||||
|
||||
artifact.check_indicators()
|
||||
assert artifact.alertstore.count(AlertLevel.LOW) == 0
|
||||
assert artifact.alertstore.count(AlertLevel.MEDIUM) == 2
|
||||
assert not any(
|
||||
"installed, not enabled" in alert.message
|
||||
for alert in artifact.alertstore.alerts
|
||||
)
|
||||
Reference in new issue
Block a user