diff --git a/core/res/AndroidManifest.xml b/core/res/AndroidManifest.xml index c365aaecb6f95..11a5062296543 100644 --- a/core/res/AndroidManifest.xml +++ b/core/res/AndroidManifest.xml @@ -4511,9 +4511,9 @@ android:protectionLevel="signature" /> + @hide --> + android:protectionLevel="signature|privileged|wellbeing" /> diff --git a/services/core/java/com/android/server/pm/UserManagerService.java b/services/core/java/com/android/server/pm/UserManagerService.java index 4d2512c264226..a2aeaf189be5b 100644 --- a/services/core/java/com/android/server/pm/UserManagerService.java +++ b/services/core/java/com/android/server/pm/UserManagerService.java @@ -871,7 +871,7 @@ public class UserManagerService extends IUserManager.Stub { "target should only be specified when we are disabling quiet mode."); } - ensureCanModifyQuietMode(callingPackage, Binder.getCallingUid(), target != null); + ensureCanModifyQuietMode(callingPackage, Binder.getCallingUid(), userId, target != null); final long identity = Binder.clearCallingIdentity(); try { boolean result = false; @@ -903,13 +903,15 @@ public class UserManagerService extends IUserManager.Stub { *
  • Has system UID or root UID
  • *
  • Has {@link Manifest.permission#MODIFY_QUIET_MODE}
  • *
  • Has {@link Manifest.permission#MANAGE_USERS}
  • + *
  • Is the foreground default launcher app
  • * *

    - * If caller wants to start an intent after disabling the quiet mode, it must has + * If caller wants to start an intent after disabling the quiet mode, or if it is targeting a + * user in a different profile group from the caller, it must have * {@link Manifest.permission#MANAGE_USERS}. */ private void ensureCanModifyQuietMode(String callingPackage, int callingUid, - boolean startIntent) { + @UserIdInt int targetUserId, boolean startIntent) { if (hasManageUsersPermission()) { return; } @@ -917,6 +919,10 @@ public class UserManagerService extends IUserManager.Stub { throw new SecurityException("MANAGE_USERS permission is required to start intent " + "after disabling quiet mode."); } + if (!isSameProfileGroupNoChecks(UserHandle.getUserId(callingUid), targetUserId)) { + throw new SecurityException("MANAGE_USERS permission is required to modify quiet mode " + + "for a different profile group."); + } final boolean hasModifyQuietModePermission = hasPermissionGranted( Manifest.permission.MODIFY_QUIET_MODE, callingUid); if (hasModifyQuietModePermission) {