From bb323058dd6c0a69d681242b070a48dd1e00515d Mon Sep 17 00:00:00 2001 From: Jing Ji Date: Tue, 13 Jul 2021 00:43:31 -0700 Subject: [PATCH] Throw SecurityException as if no CLEAR_APP_USER_DATA permission ...if the target package is protected for caller w/o MANAGE_USERS in clearApplicationUserData. Bug: 187956596 Test: Manual - see b/187956596#comment1 Change-Id: I9216201c753b1a5a954202cbde27f1d675cbf839 --- .../server/am/ActivityManagerService.java | 33 ++++++++++++------- 1 file changed, 21 insertions(+), 12 deletions(-) diff --git a/services/core/java/com/android/server/am/ActivityManagerService.java b/services/core/java/com/android/server/am/ActivityManagerService.java index bce46f592efba..daa00ec0ef622 100644 --- a/services/core/java/com/android/server/am/ActivityManagerService.java +++ b/services/core/java/com/android/server/am/ActivityManagerService.java @@ -3458,30 +3458,39 @@ public class ActivityManagerService extends IActivityManager.Stub final long callingId = Binder.clearCallingIdentity(); try { IPackageManager pm = AppGlobals.getPackageManager(); + boolean permitted = true; // Instant packages are not protected if (getPackageManagerInternal().isPackageDataProtected( resolvedUserId, packageName)) { - throw new SecurityException( - "Cannot clear data for a protected package: " + packageName); + if (ActivityManager.checkUidPermission(android.Manifest.permission.MANAGE_USERS, + uid) == PERMISSION_GRANTED) { + // The caller has the MANAGE_USERS permission, tell them what's going on. + throw new SecurityException( + "Cannot clear data for a protected package: " + packageName); + } else { + permitted = false; // fall through and throw the SecurityException below. + } } ApplicationInfo applicationInfo = null; - try { - applicationInfo = pm.getApplicationInfo(packageName, - MATCH_UNINSTALLED_PACKAGES, resolvedUserId); - } catch (RemoteException e) { - /* ignore */ + if (permitted) { + try { + applicationInfo = pm.getApplicationInfo(packageName, + MATCH_UNINSTALLED_PACKAGES, resolvedUserId); + } catch (RemoteException e) { + /* ignore */ + } + permitted = (applicationInfo != null && applicationInfo.uid == uid) // own uid data + || (checkComponentPermission(permission.CLEAR_APP_USER_DATA, + pid, uid, -1, true) == PackageManager.PERMISSION_GRANTED); } - appInfo = applicationInfo; - final boolean clearingOwnUidData = appInfo != null && appInfo.uid == uid; - - if (!clearingOwnUidData && checkComponentPermission(permission.CLEAR_APP_USER_DATA, - pid, uid, -1, true) != PackageManager.PERMISSION_GRANTED) { + if (!permitted) { throw new SecurityException("PID " + pid + " does not have permission " + android.Manifest.permission.CLEAR_APP_USER_DATA + " to clear data" + " of package " + packageName); } + appInfo = applicationInfo; final boolean hasInstantMetadata = getPackageManagerInternal() .hasInstantApplicationMetadata(packageName, resolvedUserId);