Add check package belong to caller
For API isWallperSupported, add check that queried package belongs to
the caller.
Bug: 194112606
Test: atest StrictModeTest
atest WallpaperManagerTest
atest NoWallpaperPermissionsTest
atest ScopedStorageTest
atest NoSystemFunctionPermissionTest#testSetWallpaper
Change-Id: I93c1b4b74d8bd1e1e5202cd39038319a3f8a7f23
Merged-In: I93c1b4b74d8bd1e1e5202cd39038319a3f8a7f23
(cherry picked from commit 5bfdc9f658)
This commit is contained in:
@@ -3062,12 +3062,35 @@ public class WallpaperManagerService extends IWallpaperManager.Stub
|
||||
}
|
||||
}
|
||||
|
||||
private boolean packageBelongsToUid(String packageName, int uid) {
|
||||
int userId = UserHandle.getUserId(uid);
|
||||
int packageUid;
|
||||
try {
|
||||
packageUid = mContext.getPackageManager().getPackageUidAsUser(
|
||||
packageName, userId);
|
||||
} catch (PackageManager.NameNotFoundException e) {
|
||||
return false;
|
||||
}
|
||||
return packageUid == uid;
|
||||
}
|
||||
|
||||
private void enforcePackageBelongsToUid(String packageName, int uid) {
|
||||
if (!packageBelongsToUid(packageName, uid)) {
|
||||
throw new IllegalArgumentException(
|
||||
"Invalid package or package does not belong to uid:"
|
||||
+ uid);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Certain user types do not support wallpapers (e.g. managed profiles). The check is
|
||||
* implemented through through the OP_WRITE_WALLPAPER AppOp.
|
||||
*/
|
||||
public boolean isWallpaperSupported(String callingPackage) {
|
||||
return mAppOpsManager.checkOpNoThrow(AppOpsManager.OP_WRITE_WALLPAPER, Binder.getCallingUid(),
|
||||
final int callingUid = Binder.getCallingUid();
|
||||
enforcePackageBelongsToUid(callingPackage, callingUid);
|
||||
|
||||
return mAppOpsManager.checkOpNoThrow(AppOpsManager.OP_WRITE_WALLPAPER, callingUid,
|
||||
callingPackage) == AppOpsManager.MODE_ALLOWED;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user