From 283c3a37ae2a9f6290f1fe09eeae808fe99f8f43 Mon Sep 17 00:00:00 2001 From: Winson Date: Fri, 5 Mar 2021 14:28:16 -0800 Subject: [PATCH] Only allow forwarding of Intents that MATCH_DEFAULT_ONLY When IntentForwarderActivity is launched by PMS in response to a web URI, the only way it can pass domain verification is by declaring the DEFAULT category. Either explicitly or implicitly through MATCH_DEFAULT_ONLY added by startActivity. This makes the PackageManager API that checks if the Intent forwarding is allowed mirror the web Intent validation so that only DEFAULT marked Intents can be forwarded. Bug: 174688153 Test: manual, debug linked bug Change-Id: Ia87bf657067f2c5c691a07b1e5de35b9f476fde0 --- .../core/java/com/android/server/pm/PackageManagerService.java | 1 + 1 file changed, 1 insertion(+) diff --git a/services/core/java/com/android/server/pm/PackageManagerService.java b/services/core/java/com/android/server/pm/PackageManagerService.java index 727f49ed3ebe6..3eb3e11149d4c 100644 --- a/services/core/java/com/android/server/pm/PackageManagerService.java +++ b/services/core/java/com/android/server/pm/PackageManagerService.java @@ -9991,6 +9991,7 @@ public class PackageManagerService extends IPackageManager.Stub false /*includeInstantApps*/, isImplicitImageCaptureIntentAndNotSetByDpcLocked(intent, parent.id, resolvedType, 0)); + flags |= PackageManager.MATCH_DEFAULT_ONLY; CrossProfileDomainInfo xpDomainInfo = getCrossProfileDomainPreferredLpr( intent, resolvedType, flags, sourceUserId, parent.id); return xpDomainInfo != null;