Neither user 10200 nor current process has com.huawei.permission.SECURITY_DIAGNOSE

Viewed 256

While trying to implement SafetyNet, I've added this dependency:

implementation 'com.huawei.hms:safetydetect:6.3.0.301'

And also added the permission to AndroidManifest.xml:

<uses-permission android:name="com.huawei.permission.SECURITY_DIAGNOSE"/>

But this somehow doesn't work as expected:

E/RootDetect: `isRoot` exception : Must have `com.huawei.permission.SECURITY_DIAGNOSE` permission.
Neither user `10200` nor current process has `com.huawei.permission.SECURITY_DIAGNOSE`.

Also below Apps & services > Permissions > View all permissions, it is not listed - all the others are being merged. Are there any further conditions or is the permission possibly being stripped out while merging? The AGP version is 7.1.2.

The strange thing is, that I still get the error message, when commenting out the dependency.

3 Answers

Must have com.huawei.permission.SECURITY_DIAGNOSE permission.

This customized permission does not need to be added to the SafeDetect Kit. In addition, the customized permission is not displayed on the permission management page. Generally, the system-level permission is displayed on the permission management page.

Huawei Safety Detect Kit doesn't require below permission "SECURITYDIAGNOSE", instead it requires only for "INTERNET" AND "ACCESSWIFI_STATE". Pls refer to below URL for sample code example and guide.

uses-permission android:name="com.huawei.permission.SECURITY_DIAGNOSE

<uses-permission android:name="android.permission.INTERNET" />
<!-- Access WiFi State -->
<uses-permission android:name="android.permission.ACCESS_WIFI_STATE" />

https://developer.huawei.com/consumer/en/doc/development/Security-Examples/sample-code-0000001050157020

https://developer.huawei.com/consumer/en/doc/development/Security-Guides/dysintegritydevelopment-0000001050156331

String alg was undefined; here's a working version of the example source:

SafetyDetectClient mClient = SafetyDetect.getClient(this);
// TODO: Change the nonce generation to include your own,
//       used once value, ideally from your remote server.
byte[] nonce = ("Sample" + System.currentTimeMillis()).getBytes();
SysIntegrityRequest sysintegrityrequest = new SysIntegrityRequest();
sysintegrityrequest.setAppId("3*******");  // TODO: set your appId.
sysintegrityrequest.setNonce(nonce);
sysintegrityrequest.setAlg("RS256"); // or "PS256"

Task<SysIntegrityResp> task = mClient.sysIntegrity(sysintegrityrequest);
task.addOnSuccessListener(response -> {

    // Indicates that communication with the service was successful.
    String jwsStr = response.getResult();
    Log.d(LOG_TAG, "SysIntegrityResp: " + jwsStr);

}).addOnFailureListener(e -> {

    // An error occurred during communication with the service.
    if (e instanceof ApiException) {

        // An error with the HMS API contains some additional details.
        ApiException apiException = (ApiException) e;

        // You can retrieve the status code using the apiException.getStatusCode() method.
        Log.e(LOG_TAG, "Error: " + SafetyDetectStatusCodes.getStatusCodeString(
                apiException.getStatusCode()) + ": " + apiException.getMessage()
        );

    } else {
        // A different, unknown type of error occurred.
        Log.e(LOG_TAG, "ERROR: " + e.getMessage());
    }
});

Now I don't know how to get or validate the nonce or what to do with the jwsStr, but I get one SysIntegrityResp - but that's another question. The part of the documentation, which suggests to add the permission seems to be slightly misleading - and the error message in the log as well. Just found this Java server example source, which supports the understanding a lot. When filtering the log for hmssafetydetect, one can see what's happening.

Related