From fd5170c6927998c76cea283c16f02cba9da08576 Mon Sep 17 00:00:00 2001 From: Roshan Pius Date: Thu, 27 May 2021 12:09:12 -0700 Subject: [PATCH] UwbServiceImpl: Use cleanCallingIdentity to perform permission checks The AIDL callbacks occur with the vendor service context. So, need to use the uwbservice context to perform the permission checks. Bug: 189476827 Test: Manual tests Change-Id: Ie4d64a610483e759d065ee3f466c23bd6016dbf8 --- .../uwb/java/com/android/server/uwb/UwbServiceImpl.java | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/services/uwb/java/com/android/server/uwb/UwbServiceImpl.java b/services/uwb/java/com/android/server/uwb/UwbServiceImpl.java index f34567f83aff1..4dd26a66cf0ef 100644 --- a/services/uwb/java/com/android/server/uwb/UwbServiceImpl.java +++ b/services/uwb/java/com/android/server/uwb/UwbServiceImpl.java @@ -19,6 +19,7 @@ package com.android.server.uwb; import android.annotation.NonNull; import android.content.AttributionSource; import android.content.Context; +import android.os.Binder; import android.os.IBinder; import android.os.PersistableBundle; import android.os.RemoteException; @@ -171,8 +172,10 @@ public class UwbServiceImpl extends IUwbAdapter.Stub implements IBinder.DeathRec RangingReport rangingReport) throws RemoteException { if (!mIsValid) return; - if (!mUwbInjector.checkUwbRangingPermissionForDataDelivery( - mAttributionSource, "uwb ranging result")) { + boolean permissionGranted = Binder.withCleanCallingIdentity( + () -> mUwbInjector.checkUwbRangingPermissionForDataDelivery( + mAttributionSource, "uwb ranging result")); + if (!permissionGranted) { Log.e(TAG, "Not delivering ranging result because of permission denial" + mSessionHandle); return;