Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 11cd7e68 authored by Eric Biggers's avatar Eric Biggers
Browse files

Remove obsolete comment from FileIntegrityService

Since fsverity builtin signatures are no longer being used, the comment
in FileIntegrityService#loadAllCertificates() no longer applies.

Bug: 290064770
Test: comment-only change
Change-Id: I78ca3868dabe3133c7e521a5dc8fcc8cd598ac3c
parent 9add45ee
Loading
Loading
Loading
Loading
+0 −6
Original line number Diff line number Diff line
@@ -125,13 +125,7 @@ public class FileIntegrityService extends SystemService {
    }

    private void loadAllCertificates() {
        // A better alternative to load certificates would be to read from .fs-verity kernel
        // keyring, which fsverity_init loads to during earlier boot time from the same sources
        // below. But since the read operation from keyring is not provided in kernel, we need to
        // duplicate the same loading logic here.

        // Load certificates trusted by the device manufacturer.
        // NB: Directories need to be synced with system/security/fsverity_init/fsverity_init.cpp.
        final String relativeDir = "etc/security/fsverity";
        loadCertificatesFromDirectory(Environment.getRootDirectory().toPath()
                .resolve(relativeDir));