Merge "DO NOT MERGE Isolated processes must fail registering BRs." into tm-qpr-dev

This commit is contained in:
TreeHugger Robot
2023-03-03 17:48:33 +00:00
committed by Android (Google) Code Review

View File

@@ -13117,12 +13117,17 @@ public class ActivityManagerService extends IActivityManager.Stub
public Intent registerReceiverWithFeature(IApplicationThread caller, String callerPackage, public Intent registerReceiverWithFeature(IApplicationThread caller, String callerPackage,
String callerFeatureId, String receiverId, IIntentReceiver receiver, String callerFeatureId, String receiverId, IIntentReceiver receiver,
IntentFilter filter, String permission, int userId, int flags) { IntentFilter filter, String permission, int userId, int flags) {
enforceNotIsolatedCaller("registerReceiver");
// Allow Sandbox process to register only unexported receivers. // Allow Sandbox process to register only unexported receivers.
if ((flags & Context.RECEIVER_NOT_EXPORTED) != 0) { boolean unexported = (flags & Context.RECEIVER_NOT_EXPORTED) != 0;
enforceNotIsolatedCaller("registerReceiver"); if (mSdkSandboxSettings.isBroadcastReceiverRestrictionsEnforced()
} else if (mSdkSandboxSettings.isBroadcastReceiverRestrictionsEnforced()) { && Process.isSdkSandboxUid(Binder.getCallingUid())
enforceNotIsolatedOrSdkSandboxCaller("registerReceiver"); && !unexported) {
throw new SecurityException("SDK sandbox process not allowed to call "
+ "registerReceiver");
} }
ArrayList<Intent> stickyIntents = null; ArrayList<Intent> stickyIntents = null;
ProcessRecord callerApp = null; ProcessRecord callerApp = null;
final boolean visibleToInstantApps final boolean visibleToInstantApps