Allow shell uid without checking the package name.

Bug: 230779051
Test: manual
Change-Id: I2867a15840a0987c948179e2f8069e652c4a0c1f
This commit is contained in:
Sudheer Shanka
2022-05-24 12:09:40 -07:00
parent 2a3709618b
commit 6db81c15df

View File

@@ -40,6 +40,7 @@ import android.content.Context;
import android.content.Intent; import android.content.Intent;
import android.content.IntentFilter; import android.content.IntentFilter;
import android.content.pm.PackageManager; import android.content.pm.PackageManager;
import android.content.pm.PackageManagerInternal;
import android.media.AudioManager; import android.media.AudioManager;
import android.media.AudioPlaybackConfiguration; import android.media.AudioPlaybackConfiguration;
import android.media.AudioSystem; import android.media.AudioSystem;
@@ -85,6 +86,7 @@ import android.view.ViewConfiguration;
import com.android.internal.R; import com.android.internal.R;
import com.android.internal.annotations.GuardedBy; import com.android.internal.annotations.GuardedBy;
import com.android.server.LocalManagerRegistry; import com.android.server.LocalManagerRegistry;
import com.android.server.LocalServices;
import com.android.server.SystemService; import com.android.server.SystemService;
import com.android.server.Watchdog; import com.android.server.Watchdog;
import com.android.server.Watchdog.Monitor; import com.android.server.Watchdog.Monitor;
@@ -540,14 +542,19 @@ public class MediaSessionService extends SystemService implements Monitor {
if (TextUtils.isEmpty(packageName)) { if (TextUtils.isEmpty(packageName)) {
throw new IllegalArgumentException("packageName may not be empty"); throw new IllegalArgumentException("packageName may not be empty");
} }
String[] packages = mContext.getPackageManager().getPackagesForUid(uid); if (uid == Process.ROOT_UID || uid == Process.SHELL_UID) {
final int packageCount = packages.length; // If the caller is shell, then trust the packageName given and allow it
for (int i = 0; i < packageCount; i++) { // to proceed.
if (packageName.equals(packages[i])) {
return; return;
} }
final PackageManagerInternal packageManagerInternal =
LocalServices.getService(PackageManagerInternal.class);
final int actualUid = packageManagerInternal.getPackageUid(
packageName, 0 /* flags */, UserHandle.getUserId(uid));
if (!UserHandle.isSameApp(uid, actualUid)) {
throw new IllegalArgumentException("packageName does not belong to the calling uid; "
+ "pkg=" + packageName + ", uid=" + uid);
} }
throw new IllegalArgumentException("packageName is not owned by the calling process");
} }
void tempAllowlistTargetPkgIfPossible(int targetUid, String targetPackage, void tempAllowlistTargetPkgIfPossible(int targetUid, String targetPackage,