Merge "Only allow the system to bind to the visual query detection service." into udc-dev am: c8114221c0

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/23153163

Change-Id: I9535361d070406e3e5f13eaf2697f224bd5030a2
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
Charles Chen
2023-05-11 20:43:12 +00:00
committed by Automerger Merge Worker

View File

@@ -4504,10 +4504,11 @@ public final class ActiveServices {
+ ", uid=" + callingUid
+ " requires " + r.permission);
return new ServiceLookupResult(r.permission);
} else if (Manifest.permission.BIND_HOTWORD_DETECTION_SERVICE.equals(r.permission)
} else if ((Manifest.permission.BIND_HOTWORD_DETECTION_SERVICE.equals(r.permission)
|| Manifest.permission.BIND_VISUAL_QUERY_DETECTION_SERVICE.equals(r.permission))
&& callingUid != Process.SYSTEM_UID) {
// Hotword detection must run in its own sandbox, and we don't even trust
// its enclosing application to bind to it - only the system.
// Hotword detection and visual query detection must run in its own sandbox, and we
// don't even trust its enclosing application to bind to it - only the system.
// TODO(b/185746653) remove this special case and generalize
Slog.w(TAG, "Permission Denial: Accessing service " + r.shortInstanceName
+ " from pid=" + callingPid