Merge "Checking if package belongs to UID before registering broadcast receiver" into sc-qpr1-dev am: cb603fa976

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/20640127

Change-Id: Id2f1cd95122ed0e7fe4302f84f5b925518adb182
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Kunal Malhotra
2023-01-10 22:55:23 +00:00
committed by Automerger Merge Worker

View File

@@ -3201,6 +3201,11 @@ public final class ActiveServices {
throw new SecurityException("BIND_EXTERNAL_SERVICE failed, " throw new SecurityException("BIND_EXTERNAL_SERVICE failed, "
+ className + " is not an isolatedProcess"); + className + " is not an isolatedProcess");
} }
if (AppGlobals.getPackageManager().getPackageUid(callingPackage,
0, userId) != callingUid) {
throw new SecurityException("BIND_EXTERNAL_SERVICE failed, "
+ "calling package not owned by calling UID ");
}
// Run the service under the calling package's application. // Run the service under the calling package's application.
ApplicationInfo aInfo = AppGlobals.getPackageManager().getApplicationInfo( ApplicationInfo aInfo = AppGlobals.getPackageManager().getApplicationInfo(
callingPackage, ActivityManagerService.STOCK_PM_FLAGS, userId); callingPackage, ActivityManagerService.STOCK_PM_FLAGS, userId);