Merge "DO NOT MERGE. No direct Uri grants from system." into nyc-dev
This commit is contained in:
@@ -8113,7 +8113,12 @@ public final class ActivityManagerService extends ActivityManagerNative
|
||||
|
||||
// Third... does the caller itself have permission to access
|
||||
// this uri?
|
||||
if (UserHandle.getAppId(callingUid) != Process.SYSTEM_UID) {
|
||||
final int callingAppId = UserHandle.getAppId(callingUid);
|
||||
if ((callingAppId == Process.SYSTEM_UID) || (callingAppId == Process.ROOT_UID)) {
|
||||
Slog.w(TAG, "For security reasons, the system cannot issue a Uri permission"
|
||||
+ " grant to " + grantUri + "; use startActivityAsCaller() instead");
|
||||
return -1;
|
||||
} else {
|
||||
if (!checkHoldingPermissionsLocked(pm, pi, grantUri, callingUid, modeFlags)) {
|
||||
// Require they hold a strong enough Uri permission
|
||||
if (!checkUriPermissionLocked(grantUri, callingUid, modeFlags)) {
|
||||
|
||||
Reference in New Issue
Block a user