Merge "Resolve custom printer icon boundary exploit." into sc-dev am: 5f83b3051b
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/24112147 Change-Id: I740c54cb12bb341904a56233c9a6ce1ece26f1e0 Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
@@ -254,12 +254,45 @@ public final class PrintManagerService extends SystemService {
|
||||
}
|
||||
final long identity = Binder.clearCallingIdentity();
|
||||
try {
|
||||
return userState.getCustomPrinterIcon(printerId);
|
||||
Icon icon = userState.getCustomPrinterIcon(printerId);
|
||||
return validateIconUserBoundary(icon);
|
||||
} finally {
|
||||
Binder.restoreCallingIdentity(identity);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Validates the custom printer icon to see if it's not in the calling user space.
|
||||
* If the condition is not met, return null. Otherwise, return the original icon.
|
||||
*
|
||||
* @param icon
|
||||
* @return icon (validated)
|
||||
*/
|
||||
private Icon validateIconUserBoundary(Icon icon) {
|
||||
// Refer to Icon#getUriString for context. The URI string is invalid for icons of
|
||||
// incompatible types.
|
||||
if (icon != null && (icon.getType() == Icon.TYPE_URI
|
||||
|| icon.getType() == Icon.TYPE_URI_ADAPTIVE_BITMAP)) {
|
||||
String encodedUser = icon.getUri().getEncodedUserInfo();
|
||||
|
||||
// If there is no encoded user, the URI is calling into the calling user space
|
||||
if (encodedUser != null) {
|
||||
int userId = Integer.parseInt(encodedUser);
|
||||
// resolve encoded user
|
||||
final int resolvedUserId = resolveCallingUserEnforcingPermissions(userId);
|
||||
|
||||
synchronized (mLock) {
|
||||
// Only the current group members can get the printer icons.
|
||||
if (resolveCallingProfileParentLocked(resolvedUserId)
|
||||
!= getCurrentUserId()) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return icon;
|
||||
}
|
||||
|
||||
@Override
|
||||
public void cancelPrintJob(PrintJobId printJobId, int appId, int userId) {
|
||||
if (printJobId == null) {
|
||||
|
||||
Reference in New Issue
Block a user