Isolated processes must fail registering BRs.

Broadcast Receivers should not be allowed to be registered by
isolated processes.

Bug: b/263358101
Test: atest SdkSandboxRestrictionsHostTest
Change-Id: I5bb2ee3ce8a447105a18851fdffa5a769cc3fe49
This commit is contained in:
Mugdha Lakhani
2022-12-29 15:18:07 +00:00
parent e190822d5f
commit 43b8a91b05

View File

@@ -13500,12 +13500,17 @@ public class ActivityManagerService extends IActivityManager.Stub
public Intent registerReceiverWithFeature(IApplicationThread caller, String callerPackage,
String callerFeatureId, String receiverId, IIntentReceiver receiver,
IntentFilter filter, String permission, int userId, int flags) {
enforceNotIsolatedCaller("registerReceiver");
// Allow Sandbox process to register only unexported receivers.
if ((flags & Context.RECEIVER_NOT_EXPORTED) != 0) {
enforceNotIsolatedCaller("registerReceiver");
} else if (mSdkSandboxSettings.isBroadcastReceiverRestrictionsEnforced()) {
enforceNotIsolatedOrSdkSandboxCaller("registerReceiver");
boolean unexported = (flags & Context.RECEIVER_NOT_EXPORTED) != 0;
if (mSdkSandboxSettings.isBroadcastReceiverRestrictionsEnforced()
&& Process.isSdkSandboxUid(Binder.getCallingUid())
&& !unexported) {
throw new SecurityException("SDK sandbox process not allowed to call "
+ "registerReceiver");
}
ArrayList<Intent> stickyIntents = null;
ProcessRecord callerApp = null;
final boolean visibleToInstantApps