Merge "Add hidden flag for allowing system app to use BAL permission to launch pending intent in background" into tm-dev

This commit is contained in:
TreeHugger Robot
2022-05-26 19:53:34 +00:00
committed by Android (Google) Code Review
3 changed files with 44 additions and 4 deletions

View File

@@ -38,7 +38,15 @@ public class ComponentOptions {
public static final String KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED = public static final String KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED =
"android.pendingIntent.backgroundActivityAllowed"; "android.pendingIntent.backgroundActivityAllowed";
/**
* PendingIntent caller allows activity to be started if caller has BAL permission.
* @hide
*/
public static final String KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED_BY_PERMISSION =
"android.pendingIntent.backgroundActivityAllowedByPermission";
private boolean mPendingIntentBalAllowed = PENDING_INTENT_BAL_ALLOWED_DEFAULT; private boolean mPendingIntentBalAllowed = PENDING_INTENT_BAL_ALLOWED_DEFAULT;
private boolean mPendingIntentBalAllowedByPermission = false;
ComponentOptions() { ComponentOptions() {
} }
@@ -50,6 +58,9 @@ public class ComponentOptions {
setPendingIntentBackgroundActivityLaunchAllowed( setPendingIntentBackgroundActivityLaunchAllowed(
opts.getBoolean(KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED, opts.getBoolean(KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED,
PENDING_INTENT_BAL_ALLOWED_DEFAULT)); PENDING_INTENT_BAL_ALLOWED_DEFAULT));
setPendingIntentBackgroundActivityLaunchAllowedByPermission(
opts.getBoolean(KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED_BY_PERMISSION,
false));
} }
/** /**
@@ -68,9 +79,28 @@ public class ComponentOptions {
return mPendingIntentBalAllowed; return mPendingIntentBalAllowed;
} }
/**
* Set PendingIntent activity can be launched from background if caller has BAL permission.
* @hide
*/
public void setPendingIntentBackgroundActivityLaunchAllowedByPermission(boolean allowed) {
mPendingIntentBalAllowedByPermission = allowed;
}
/**
* Get PendingIntent activity is allowed to be started in the background if the caller
* has BAL permission.
* @hide
*/
public boolean isPendingIntentBackgroundActivityLaunchAllowedByPermission() {
return mPendingIntentBalAllowedByPermission;
}
public Bundle toBundle() { public Bundle toBundle() {
Bundle b = new Bundle(); Bundle b = new Bundle();
b.putBoolean(KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED, mPendingIntentBalAllowed); b.putBoolean(KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED, mPendingIntentBalAllowed);
b.putBoolean(KEY_PENDING_INTENT_BACKGROUND_ACTIVITY_ALLOWED_BY_PERMISSION,
mPendingIntentBalAllowedByPermission);
return b; return b;
} }
} }

View File

@@ -310,6 +310,17 @@ public final class PendingIntentRecord extends IIntentSender.Stub {
requiredPermission, null, null, 0, 0, 0, options); requiredPermission, null, null, 0, 0, 0, options);
} }
/**
* Return true if the activity options allows PendingIntent to use caller's BAL permission.
*/
public static boolean isPendingIntentBalAllowedByPermission(
@Nullable ActivityOptions activityOptions) {
if (activityOptions == null) {
return false;
}
return activityOptions.isPendingIntentBackgroundActivityLaunchAllowedByPermission();
}
public static boolean isPendingIntentBalAllowedByCaller( public static boolean isPendingIntentBalAllowedByCaller(
@Nullable ActivityOptions activityOptions) { @Nullable ActivityOptions activityOptions) {
if (activityOptions == null) { if (activityOptions == null) {

View File

@@ -1365,10 +1365,9 @@ class ActivityStarter {
PendingIntentRecord.isPendingIntentBalAllowedByCaller(checkedOptions); PendingIntentRecord.isPendingIntentBalAllowedByCaller(checkedOptions);
if (balAllowedByPiSender && realCallingUid != callingUid) { if (balAllowedByPiSender && realCallingUid != callingUid) {
// If the caller is a legacy app, we won't check if the caller has BAL permission. final boolean useCallerPermission =
final boolean isPiBalOptionEnabled = CompatChanges.isChangeEnabled( PendingIntentRecord.isPendingIntentBalAllowedByPermission(checkedOptions);
ENABLE_PENDING_INTENT_BAL_OPTION, realCallingUid); if (useCallerPermission && ActivityManager.checkComponentPermission(
if (isPiBalOptionEnabled && ActivityManager.checkComponentPermission(
android.Manifest.permission.START_ACTIVITIES_FROM_BACKGROUND, android.Manifest.permission.START_ACTIVITIES_FROM_BACKGROUND,
realCallingUid, -1, true) realCallingUid, -1, true)
== PackageManager.PERMISSION_GRANTED) { == PackageManager.PERMISSION_GRANTED) {