DO NOT MERGE. No direct Uri grants from system. am: b61338ecb3 am: 30a4388481

am: 190511955f

Change-Id: I0a4149d160f990357e4e8ee7229bfbdf68b67a68
This commit is contained in:
Jeff Sharkey
2017-02-03 00:23:44 +00:00
committed by android-build-merger

View File

@@ -8211,7 +8211,12 @@ public final class ActivityManagerService extends ActivityManagerNative
// Third... does the caller itself have permission to access // Third... does the caller itself have permission to access
// this uri? // this uri?
if (UserHandle.getAppId(callingUid) != Process.SYSTEM_UID) { final int callingAppId = UserHandle.getAppId(callingUid);
if ((callingAppId == Process.SYSTEM_UID) || (callingAppId == Process.ROOT_UID)) {
Slog.w(TAG, "For security reasons, the system cannot issue a Uri permission"
+ " grant to " + grantUri + "; use startActivityAsCaller() instead");
return -1;
} else {
if (!checkHoldingPermissionsLocked(pm, pi, grantUri, callingUid, modeFlags)) { if (!checkHoldingPermissionsLocked(pm, pi, grantUri, callingUid, modeFlags)) {
// Require they hold a strong enough Uri permission // Require they hold a strong enough Uri permission
if (!checkUriPermissionLocked(grantUri, callingUid, modeFlags)) { if (!checkUriPermissionLocked(grantUri, callingUid, modeFlags)) {