Merge "Checking if package belongs to UID before registering broadcast receiver" into sc-qpr1-dev am: cb603fa976 am: 0be797c6d7 am: 126a0dc509

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/20640127

Change-Id: I523fa165e52a9f040e398e327074a59349164234
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Kunal Malhotra
2023-01-11 15:20:38 +00:00
committed by Automerger Merge Worker

View File

@@ -3411,6 +3411,11 @@ public final class ActiveServices {
throw new SecurityException("BIND_EXTERNAL_SERVICE failed, " throw new SecurityException("BIND_EXTERNAL_SERVICE failed, "
+ className + " is not an isolatedProcess"); + className + " is not an isolatedProcess");
} }
if (AppGlobals.getPackageManager().getPackageUid(callingPackage,
0, userId) != callingUid) {
throw new SecurityException("BIND_EXTERNAL_SERVICE failed, "
+ "calling package not owned by calling UID ");
}
// Run the service under the calling package's application. // Run the service under the calling package's application.
ApplicationInfo aInfo = AppGlobals.getPackageManager().getApplicationInfo( ApplicationInfo aInfo = AppGlobals.getPackageManager().getApplicationInfo(
callingPackage, ActivityManagerService.STOCK_PM_FLAGS, userId); callingPackage, ActivityManagerService.STOCK_PM_FLAGS, userId);