Merge "[RESTRICT AUTOMERGE] Pass correct realCallingUid to startActivity() if provided by PendingIntentRecord#sendInner()" into pi-dev
This commit is contained in:
@@ -5607,9 +5607,10 @@ public class ActivityManagerService extends IActivityManager.Stub
|
|||||||
userId = mUserController.handleIncomingUser(Binder.getCallingPid(), Binder.getCallingUid(),
|
userId = mUserController.handleIncomingUser(Binder.getCallingPid(), Binder.getCallingUid(),
|
||||||
userId, false, ALLOW_FULL_ONLY, reason, null);
|
userId, false, ALLOW_FULL_ONLY, reason, null);
|
||||||
// TODO: Switch to user app stacks here.
|
// TODO: Switch to user app stacks here.
|
||||||
int ret = mActivityStartController.startActivities(caller, -1, callingPackage,
|
int ret = mActivityStartController.startActivities(caller, -1, 0,
|
||||||
intents, resolvedTypes, resultTo, SafeActivityOptions.fromBundle(bOptions), userId,
|
UserHandle.USER_NULL, callingPackage, intents, resolvedTypes, resultTo,
|
||||||
reason, null /* originatingPendingIntent */);
|
SafeActivityOptions.fromBundle(bOptions), userId, reason,
|
||||||
|
null /* originatingPendingIntent */);
|
||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -286,20 +286,29 @@ public class ActivityStartController {
|
|||||||
final int startActivitiesInPackage(int uid, String callingPackage, Intent[] intents,
|
final int startActivitiesInPackage(int uid, String callingPackage, Intent[] intents,
|
||||||
String[] resolvedTypes, IBinder resultTo, SafeActivityOptions options, int userId,
|
String[] resolvedTypes, IBinder resultTo, SafeActivityOptions options, int userId,
|
||||||
boolean validateIncomingUser, PendingIntentRecord originatingPendingIntent) {
|
boolean validateIncomingUser, PendingIntentRecord originatingPendingIntent) {
|
||||||
|
return startActivitiesInPackage(uid, 0, UserHandle.USER_NULL,
|
||||||
|
callingPackage, intents, resolvedTypes, resultTo, options, userId,
|
||||||
|
validateIncomingUser, originatingPendingIntent);
|
||||||
|
}
|
||||||
|
|
||||||
|
final int startActivitiesInPackage(int uid, int realCallingPid, int realCallingUid,
|
||||||
|
String callingPackage, Intent[] intents, String[] resolvedTypes, IBinder resultTo,
|
||||||
|
SafeActivityOptions options, int userId, boolean validateIncomingUser,
|
||||||
|
PendingIntentRecord originatingPendingIntent) {
|
||||||
final String reason = "startActivityInPackage";
|
final String reason = "startActivityInPackage";
|
||||||
|
|
||||||
userId = checkTargetUser(userId, validateIncomingUser, Binder.getCallingPid(),
|
userId = checkTargetUser(userId, validateIncomingUser, Binder.getCallingPid(),
|
||||||
Binder.getCallingUid(), reason);
|
Binder.getCallingUid(), reason);
|
||||||
|
|
||||||
// TODO: Switch to user app stacks here.
|
// TODO: Switch to user app stacks here.
|
||||||
return startActivities(null, uid, callingPackage, intents, resolvedTypes, resultTo, options,
|
return startActivities(null, uid, realCallingPid, realCallingUid, callingPackage, intents,
|
||||||
userId, reason, originatingPendingIntent);
|
resolvedTypes, resultTo, options, userId, reason, originatingPendingIntent);
|
||||||
}
|
}
|
||||||
|
|
||||||
int startActivities(IApplicationThread caller, int callingUid, String callingPackage,
|
int startActivities(IApplicationThread caller, int callingUid, int incomingRealCallingPid,
|
||||||
Intent[] intents, String[] resolvedTypes, IBinder resultTo, SafeActivityOptions options,
|
int incomingRealCallingUid, String callingPackage, Intent[] intents, String[] resolvedTypes,
|
||||||
int userId, String reason, PendingIntentRecord originatingPendingIntent) {
|
IBinder resultTo, SafeActivityOptions options, int userId, String reason,
|
||||||
|
PendingIntentRecord originatingPendingIntent) {
|
||||||
if (intents == null) {
|
if (intents == null) {
|
||||||
throw new NullPointerException("intents is null");
|
throw new NullPointerException("intents is null");
|
||||||
}
|
}
|
||||||
@@ -310,9 +319,12 @@ public class ActivityStartController {
|
|||||||
throw new IllegalArgumentException("intents are length different than resolvedTypes");
|
throw new IllegalArgumentException("intents are length different than resolvedTypes");
|
||||||
}
|
}
|
||||||
|
|
||||||
final int realCallingPid = Binder.getCallingPid();
|
final int realCallingPid = incomingRealCallingPid != 0
|
||||||
final int realCallingUid = Binder.getCallingUid();
|
? incomingRealCallingPid
|
||||||
|
: Binder.getCallingPid();
|
||||||
|
final int realCallingUid = incomingRealCallingUid != UserHandle.USER_NULL
|
||||||
|
? incomingRealCallingUid
|
||||||
|
: Binder.getCallingUid();
|
||||||
int callingPid;
|
int callingPid;
|
||||||
if (callingUid >= 0) {
|
if (callingUid >= 0) {
|
||||||
callingPid = -1;
|
callingPid = -1;
|
||||||
|
|||||||
@@ -282,6 +282,8 @@ class ActivityStarter {
|
|||||||
* execution.
|
* execution.
|
||||||
*/
|
*/
|
||||||
private static class Request {
|
private static class Request {
|
||||||
|
static final int DEFAULT_REAL_CALLING_PID = 0;
|
||||||
|
static final int DEFAULT_REAL_CALLING_UID = UserHandle.USER_NULL;
|
||||||
private static final int DEFAULT_CALLING_UID = -1;
|
private static final int DEFAULT_CALLING_UID = -1;
|
||||||
private static final int DEFAULT_CALLING_PID = 0;
|
private static final int DEFAULT_CALLING_PID = 0;
|
||||||
|
|
||||||
@@ -296,11 +298,11 @@ class ActivityStarter {
|
|||||||
IBinder resultTo;
|
IBinder resultTo;
|
||||||
String resultWho;
|
String resultWho;
|
||||||
int requestCode;
|
int requestCode;
|
||||||
int callingPid = DEFAULT_CALLING_UID;
|
int callingPid = DEFAULT_CALLING_PID;
|
||||||
int callingUid = DEFAULT_CALLING_PID;
|
int callingUid = DEFAULT_CALLING_UID;
|
||||||
String callingPackage;
|
String callingPackage;
|
||||||
int realCallingPid;
|
int realCallingPid = Request.DEFAULT_REAL_CALLING_PID;
|
||||||
int realCallingUid;
|
int realCallingUid = Request.DEFAULT_REAL_CALLING_UID;
|
||||||
int startFlags;
|
int startFlags;
|
||||||
SafeActivityOptions activityOptions;
|
SafeActivityOptions activityOptions;
|
||||||
boolean ignoreTargetSecurity;
|
boolean ignoreTargetSecurity;
|
||||||
@@ -354,8 +356,8 @@ class ActivityStarter {
|
|||||||
callingPid = DEFAULT_CALLING_PID;
|
callingPid = DEFAULT_CALLING_PID;
|
||||||
callingUid = DEFAULT_CALLING_UID;
|
callingUid = DEFAULT_CALLING_UID;
|
||||||
callingPackage = null;
|
callingPackage = null;
|
||||||
realCallingPid = 0;
|
realCallingPid = Request.DEFAULT_REAL_CALLING_PID;
|
||||||
realCallingUid = 0;
|
realCallingUid = Request.DEFAULT_REAL_CALLING_UID;
|
||||||
startFlags = 0;
|
startFlags = 0;
|
||||||
activityOptions = null;
|
activityOptions = null;
|
||||||
ignoreTargetSecurity = false;
|
ignoreTargetSecurity = false;
|
||||||
@@ -370,7 +372,7 @@ class ActivityStarter {
|
|||||||
mayWait = false;
|
mayWait = false;
|
||||||
avoidMoveToFront = false;
|
avoidMoveToFront = false;
|
||||||
allowPendingRemoteAnimationRegistryLookup = true;
|
allowPendingRemoteAnimationRegistryLookup = true;
|
||||||
filterCallingUid = UserHandle.USER_NULL;
|
filterCallingUid = DEFAULT_REAL_CALLING_UID;
|
||||||
originatingPendingIntent = null;
|
originatingPendingIntent = null;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -488,7 +490,8 @@ class ActivityStarter {
|
|||||||
// for transactional diffs and preprocessing.
|
// for transactional diffs and preprocessing.
|
||||||
if (mRequest.mayWait) {
|
if (mRequest.mayWait) {
|
||||||
return startActivityMayWait(mRequest.caller, mRequest.callingUid,
|
return startActivityMayWait(mRequest.caller, mRequest.callingUid,
|
||||||
mRequest.callingPackage, mRequest.intent, mRequest.resolvedType,
|
mRequest.callingPackage, mRequest.realCallingPid, mRequest.realCallingUid,
|
||||||
|
mRequest.intent, mRequest.resolvedType,
|
||||||
mRequest.voiceSession, mRequest.voiceInteractor, mRequest.resultTo,
|
mRequest.voiceSession, mRequest.voiceInteractor, mRequest.resultTo,
|
||||||
mRequest.resultWho, mRequest.requestCode, mRequest.startFlags,
|
mRequest.resultWho, mRequest.requestCode, mRequest.startFlags,
|
||||||
mRequest.profilerInfo, mRequest.waitResult, mRequest.globalConfig,
|
mRequest.profilerInfo, mRequest.waitResult, mRequest.globalConfig,
|
||||||
@@ -999,7 +1002,8 @@ class ActivityStarter {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private int startActivityMayWait(IApplicationThread caller, int callingUid,
|
private int startActivityMayWait(IApplicationThread caller, int callingUid,
|
||||||
String callingPackage, Intent intent, String resolvedType,
|
String callingPackage, int requestRealCallingPid, int requestRealCallingUid,
|
||||||
|
Intent intent, String resolvedType,
|
||||||
IVoiceInteractionSession voiceSession, IVoiceInteractor voiceInteractor,
|
IVoiceInteractionSession voiceSession, IVoiceInteractor voiceInteractor,
|
||||||
IBinder resultTo, String resultWho, int requestCode, int startFlags,
|
IBinder resultTo, String resultWho, int requestCode, int startFlags,
|
||||||
ProfilerInfo profilerInfo, WaitResult outResult,
|
ProfilerInfo profilerInfo, WaitResult outResult,
|
||||||
@@ -1014,8 +1018,12 @@ class ActivityStarter {
|
|||||||
mSupervisor.getActivityMetricsLogger().notifyActivityLaunching();
|
mSupervisor.getActivityMetricsLogger().notifyActivityLaunching();
|
||||||
boolean componentSpecified = intent.getComponent() != null;
|
boolean componentSpecified = intent.getComponent() != null;
|
||||||
|
|
||||||
final int realCallingPid = Binder.getCallingPid();
|
final int realCallingPid = requestRealCallingPid != Request.DEFAULT_REAL_CALLING_PID
|
||||||
final int realCallingUid = Binder.getCallingUid();
|
? requestRealCallingPid
|
||||||
|
: Binder.getCallingPid();
|
||||||
|
final int realCallingUid = requestRealCallingUid != Request.DEFAULT_REAL_CALLING_UID
|
||||||
|
? requestRealCallingUid
|
||||||
|
: Binder.getCallingUid();
|
||||||
|
|
||||||
int callingPid;
|
int callingPid;
|
||||||
if (callingUid >= 0) {
|
if (callingUid >= 0) {
|
||||||
@@ -1242,7 +1250,7 @@ class ActivityStarter {
|
|||||||
*/
|
*/
|
||||||
static int computeResolveFilterUid(int customCallingUid, int actualCallingUid,
|
static int computeResolveFilterUid(int customCallingUid, int actualCallingUid,
|
||||||
int filterCallingUid) {
|
int filterCallingUid) {
|
||||||
return filterCallingUid != UserHandle.USER_NULL
|
return filterCallingUid != Request.DEFAULT_REAL_CALLING_UID
|
||||||
? filterCallingUid
|
? filterCallingUid
|
||||||
: (customCallingUid >= 0 ? customCallingUid : actualCallingUid);
|
: (customCallingUid >= 0 ? customCallingUid : actualCallingUid);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -344,8 +344,8 @@ final class PendingIntentRecord extends IIntentSender.Stub {
|
|||||||
allResolvedTypes[allResolvedTypes.length-1] = resolvedType;
|
allResolvedTypes[allResolvedTypes.length-1] = resolvedType;
|
||||||
|
|
||||||
res = owner.getActivityStartController().startActivitiesInPackage(
|
res = owner.getActivityStartController().startActivitiesInPackage(
|
||||||
uid, key.packageName, allIntents, allResolvedTypes,
|
uid, callingPid, callingUid, key.packageName, allIntents,
|
||||||
resultTo, mergedOptions, userId,
|
allResolvedTypes, resultTo, mergedOptions, userId,
|
||||||
false /* validateIncomingUser */,
|
false /* validateIncomingUser */,
|
||||||
this /* originatingPendingIntent */);
|
this /* originatingPendingIntent */);
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
Reference in New Issue
Block a user