Add permission check for RemoteTransition in ActivityOptions

This was omitted which meant that any app could provide one.

Bug: 286882367
Test: atest android.security.cts.ActivityManagerTest#testActivityManager_rejectRemoteTransition
Change-Id: Idbc966578805c9e942ff74bae4945f4b1ccbb190
This commit is contained in:
Evan Rosky
2023-06-21 10:27:32 -07:00
parent 88bcdd1ed9
commit 2875ffc05d

View File

@@ -48,6 +48,7 @@ import android.os.RemoteException;
import android.os.UserHandle;
import android.util.Slog;
import android.view.RemoteAnimationAdapter;
import android.window.RemoteTransition;
import android.window.WindowContainerToken;
import com.android.internal.annotations.VisibleForTesting;
@@ -385,6 +386,18 @@ public class SafeActivityOptions {
throw new SecurityException(msg);
}
// Check permission for remote transitions
final RemoteTransition transition = options.getRemoteTransition();
if (transition != null && supervisor.mService.checkPermission(
CONTROL_REMOTE_APP_TRANSITION_ANIMATIONS, callingPid, callingUid)
!= PERMISSION_GRANTED) {
final String msg = "Permission Denial: starting " + getIntentString(intent)
+ " from " + callerApp + " (pid=" + callingPid
+ ", uid=" + callingUid + ") with remoteTransition";
Slog.w(TAG, msg);
throw new SecurityException(msg);
}
// If launched from bubble is specified, then ensure that the caller is system or sysui.
if (options.getLaunchedFromBubble() && !isSystemOrSystemUI(callingPid, callingUid)) {
final String msg = "Permission Denial: starting " + getIntentString(intent)