Merge "Fix a deadlock in system server" into nyc-dev am: ab0744344d

am: b223c0c6a6

* commit 'b223c0c6a6aa586941fc0704387a8b1739a44dd2':
  Fix a deadlock in system server

Change-Id: I199e172618b9f9885b03051eb1a8c55ec0af6fd3
This commit is contained in:
Amith Yamasani
2016-05-18 20:25:06 +00:00
committed by android-build-merger

View File

@@ -17559,21 +17559,26 @@ Slog.v(TAG, ":: stepped forward, applying functor at tag " + parser.getName());
throw new IllegalArgumentException( throw new IllegalArgumentException(
"Unknown component: " + packageName + "/" + className); "Unknown component: " + packageName + "/" + className);
} }
// Don't allow other apps to disable an active profile owner }
if (!UserHandle.isSameApp(uid, pkgSetting.appId)) {
final DevicePolicyManagerInternal dpmi = LocalServices // Limit who can change which apps
.getService(DevicePolicyManagerInternal.class); if (!UserHandle.isSameApp(uid, pkgSetting.appId)) {
if (dpmi != null && dpmi.hasDeviceOwnerOrProfileOwner(packageName, userId)) { // Don't allow apps that don't have permission to modify other apps
throw new SecurityException("Cannot disable a device owner or a profile owner"); if (!allowedByPermission) {
}
}
// Allow root and verify that userId is not being specified by a different user
if (!allowedByPermission && !UserHandle.isSameApp(uid, pkgSetting.appId)) {
throw new SecurityException( throw new SecurityException(
"Permission Denial: attempt to change component state from pid=" "Permission Denial: attempt to change component state from pid="
+ Binder.getCallingPid() + Binder.getCallingPid()
+ ", uid=" + uid + ", package uid=" + pkgSetting.appId); + ", uid=" + uid + ", package uid=" + pkgSetting.appId);
} }
// Don't allow changing profile and device owners. Calling into DPMS, so no locking.
final DevicePolicyManagerInternal dpmi = LocalServices
.getService(DevicePolicyManagerInternal.class);
if (dpmi != null && dpmi.hasDeviceOwnerOrProfileOwner(packageName, userId)) {
throw new SecurityException("Cannot disable a device owner or a profile owner");
}
}
synchronized (mPackages) {
if (uid == Process.SHELL_UID) { if (uid == Process.SHELL_UID) {
// Shell can only change whole packages between ENABLED and DISABLED_USER states // Shell can only change whole packages between ENABLED and DISABLED_USER states
int oldState = pkgSetting.getEnabled(userId); int oldState = pkgSetting.getEnabled(userId);