Clear binder identity before calling PackageManager API

With the introduction of app enumeration restriction in R,
PackageManager will restrict package visiblity if the caller
is not privileged. This caused regression in existing system
server code where binder identity is not cleared prior to
making PackageManager calls.

Bug: 150398249
Test: com.android.cts.devicepolicy.MixedDeviceOwnerTest#testAlwaysOnVpn
Change-Id: I611eb5768bfb73f01c63e6ab02d90f1178f8ec37
This commit is contained in:
Rubin Xu
2020-03-05 17:25:00 +00:00
parent 0d05cce083
commit a3b6258e52

View File

@@ -951,18 +951,18 @@ public class Vpn {
|| isVpnServicePreConsented(context, packageName);
}
private int getAppUid(String app, int userHandle) {
private int getAppUid(final String app, final int userHandle) {
if (VpnConfig.LEGACY_VPN.equals(app)) {
return Process.myUid();
}
PackageManager pm = mContext.getPackageManager();
int result;
try {
result = pm.getPackageUidAsUser(app, userHandle);
} catch (NameNotFoundException e) {
result = -1;
}
return result;
return Binder.withCleanCallingIdentity(() -> {
try {
return pm.getPackageUidAsUser(app, userHandle);
} catch (NameNotFoundException e) {
return -1;
}
});
}
private boolean doesPackageTargetAtLeastQ(String packageName) {