Wellbeing app can enable QUIET_MODE

The designated Wellbeing app now has permission
to toggle the "quiet mode" of a profile.

Additionally, callers can only toggle the quiet mode
of a userId that is of the same profile group as the caller
(unless the caller has MANAGE_PERMISSIONS).

Test: manual
Bug: 140485433
Change-Id: Ie6253799b97113aff7d364f8cf9214c69252f704
This commit is contained in:
Bookatz
2019-10-16 17:20:06 -04:00
parent bbf394bf19
commit 3cb67dffb7
2 changed files with 11 additions and 5 deletions

View File

@@ -4504,9 +4504,9 @@
android:protectionLevel="signature" />
<!-- @SystemApi Allows an application to turn on / off quiet mode.
@hide <p>Not for use by third-party applications. -->
@hide -->
<permission android:name="android.permission.MODIFY_QUIET_MODE"
android:protectionLevel="signature|privileged" />
android:protectionLevel="signature|privileged|wellbeing" />
<!-- Allows internal management of the camera framework
@hide -->

View File

@@ -861,7 +861,7 @@ public class UserManagerService extends IUserManager.Stub {
"target should only be specified when we are disabling quiet mode.");
}
ensureCanModifyQuietMode(callingPackage, Binder.getCallingUid(), target != null);
ensureCanModifyQuietMode(callingPackage, Binder.getCallingUid(), userId, target != null);
final long identity = Binder.clearCallingIdentity();
try {
boolean result = false;
@@ -893,13 +893,15 @@ public class UserManagerService extends IUserManager.Stub {
* <li>Has system UID or root UID</li>
* <li>Has {@link Manifest.permission#MODIFY_QUIET_MODE}</li>
* <li>Has {@link Manifest.permission#MANAGE_USERS}</li>
* <li>Is the foreground default launcher app</li>
* </ul>
* <p>
* If caller wants to start an intent after disabling the quiet mode, it must has
* If caller wants to start an intent after disabling the quiet mode, or if it is targeting a
* user in a different profile group from the caller, it must have
* {@link Manifest.permission#MANAGE_USERS}.
*/
private void ensureCanModifyQuietMode(String callingPackage, int callingUid,
boolean startIntent) {
@UserIdInt int targetUserId, boolean startIntent) {
if (hasManageUsersPermission()) {
return;
}
@@ -907,6 +909,10 @@ public class UserManagerService extends IUserManager.Stub {
throw new SecurityException("MANAGE_USERS permission is required to start intent "
+ "after disabling quiet mode.");
}
if (!isSameProfileGroupNoChecks(UserHandle.getUserId(callingUid), targetUserId)) {
throw new SecurityException("MANAGE_USERS permission is required to modify quiet mode "
+ "for a different profile group.");
}
final boolean hasModifyQuietModePermission = hasPermissionGranted(
Manifest.permission.MODIFY_QUIET_MODE, callingUid);
if (hasModifyQuietModePermission) {