From 4cfd01d5dffec82d02992cdcb3646292accf3230 Mon Sep 17 00:00:00 2001 From: Leland Miller Date: Mon, 8 Jul 2019 15:31:02 -0700 Subject: [PATCH] Ensure permissions granted for correct SIM This change ensures that the content URI permissions when writing or reading an MMS are set for the carrier services package for the correct SIM. Previously we did not specify the SIM, so the permissions would only be granted to the carrier services package for the default SIM (which would be whichever SIM is set to default voice). This is basically a follow-up to b/128542685, which fixed the issue in MmsService. Fixes: 133514914 Change-Id: I3190961d53a72c3c14c453fcc32503ed579f5959 Test: Manually verified --- .../com/android/server/MmsServiceBroker.java | 22 +++++++++++-------- 1 file changed, 13 insertions(+), 9 deletions(-) diff --git a/services/core/java/com/android/server/MmsServiceBroker.java b/services/core/java/com/android/server/MmsServiceBroker.java index b6fa1570cdb05..c0f10a3c86e1a 100644 --- a/services/core/java/com/android/server/MmsServiceBroker.java +++ b/services/core/java/com/android/server/MmsServiceBroker.java @@ -37,6 +37,7 @@ import android.os.SystemClock; import android.os.UserHandle; import android.service.carrier.CarrierMessagingService; import android.telephony.SmsManager; +import android.telephony.SubscriptionManager; import android.telephony.TelephonyManager; import android.util.Slog; @@ -331,7 +332,7 @@ public class MmsServiceBroker extends SystemService { @Override public void sendMessage(int subId, String callingPkg, Uri contentUri, String locationUrl, Bundle configOverrides, PendingIntent sentIntent) - throws RemoteException { + throws RemoteException { Slog.d(TAG, "sendMessage() by " + callingPkg); mContext.enforceCallingPermission(Manifest.permission.SEND_SMS, "Send MMS message"); if (getAppOpsManager().noteOp(AppOpsManager.OP_SEND_SMS, Binder.getCallingUid(), @@ -341,7 +342,8 @@ public class MmsServiceBroker extends SystemService { } contentUri = adjustUriForUserAndGrantPermission(contentUri, CarrierMessagingService.SERVICE_INTERFACE, - Intent.FLAG_GRANT_READ_URI_PERMISSION); + Intent.FLAG_GRANT_READ_URI_PERMISSION, + subId); getServiceGuarded().sendMessage(subId, callingPkg, contentUri, locationUrl, configOverrides, sentIntent); } @@ -360,7 +362,8 @@ public class MmsServiceBroker extends SystemService { } contentUri = adjustUriForUserAndGrantPermission(contentUri, CarrierMessagingService.SERVICE_INTERFACE, - Intent.FLAG_GRANT_READ_URI_PERMISSION | Intent.FLAG_GRANT_WRITE_URI_PERMISSION); + Intent.FLAG_GRANT_READ_URI_PERMISSION | Intent.FLAG_GRANT_WRITE_URI_PERMISSION, + subId); getServiceGuarded().downloadMessage(subId, callingPkg, locationUrl, contentUri, configOverrides, downloadedIntent); @@ -388,7 +391,7 @@ public class MmsServiceBroker extends SystemService { @Override public Uri importMultimediaMessage(String callingPkg, Uri contentUri, String messageId, long timestampSecs, boolean seen, boolean read) - throws RemoteException { + throws RemoteException { if (getAppOpsManager().noteOp(AppOpsManager.OP_WRITE_SMS, Binder.getCallingUid(), callingPkg) != AppOpsManager.MODE_ALLOWED) { // Silently fail AppOps failure due to not being the default SMS app @@ -496,12 +499,12 @@ public class MmsServiceBroker extends SystemService { * even if the caller is not in the primary user. * * @param contentUri The Uri to adjust - * @param action The intent action used to find the associated carrier app + * @param action The intent action used to find the associated carrier app * @param permission The permission to add * @return The adjusted Uri containing the calling userId. */ private Uri adjustUriForUserAndGrantPermission(Uri contentUri, String action, - int permission) { + int permission, int subId) { final Intent grantIntent = new Intent(); grantIntent.setData(contentUri); grantIntent.setFlags(permission); @@ -521,9 +524,10 @@ public class MmsServiceBroker extends SystemService { // Grant permission for the carrier app. Intent intent = new Intent(action); TelephonyManager telephonyManager = - (TelephonyManager) mContext.getSystemService(Context.TELEPHONY_SERVICE); - List carrierPackages = telephonyManager.getCarrierPackageNamesForIntent( - intent); + (TelephonyManager) mContext.getSystemService(Context.TELEPHONY_SERVICE); + List carrierPackages = + telephonyManager.getCarrierPackageNamesForIntentAndPhone( + intent, SubscriptionManager.getPhoneId(subId)); if (carrierPackages != null && carrierPackages.size() == 1) { LocalServices.getService(UriGrantsManagerInternal.class) .grantUriPermissionFromIntent(callingUid, carrierPackages.get(0),