From a3efd4745c08fe731ccb94d530c8d61f47676d3a Mon Sep 17 00:00:00 2001 From: Sumedh Sen Date: Wed, 4 May 2022 17:30:00 -0700 Subject: [PATCH] Prevent apps from querying other apps without permission - Apps could query for other apps installed on the device without having adequate visibility. - The PackageInstallerActivity checked the existence of the requested package on behalf of the calling package without ensuring has latter the required visibility. - PackageInstallerActivity now checks if the calling package has the required visibility permissions to query about the requested package, across all users on the device. Fixes: b/197327805 Bug: b/197327805 Change-Id: I703ce4e87c63fcca49c1583ecb3680868b77239a Test: atest CtsPackageSchemeTestsWithVisibility CtsPackageSchemeTestsWithoutVisibility --- .../PackageInstallerActivity.java | 22 +++++++++++++------ 1 file changed, 15 insertions(+), 7 deletions(-) diff --git a/packages/PackageInstaller/src/com/android/packageinstaller/PackageInstallerActivity.java b/packages/PackageInstaller/src/com/android/packageinstaller/PackageInstallerActivity.java index 9c6113ce4b479..2047a159b57b1 100644 --- a/packages/PackageInstaller/src/com/android/packageinstaller/PackageInstallerActivity.java +++ b/packages/PackageInstaller/src/com/android/packageinstaller/PackageInstallerActivity.java @@ -41,6 +41,7 @@ import android.content.pm.PackageInfo; import android.content.pm.PackageInstaller; import android.content.pm.PackageManager; import android.content.pm.PackageManager.NameNotFoundException; +import android.content.pm.UserInfo; import android.net.Uri; import android.os.Bundle; import android.os.Process; @@ -546,20 +547,27 @@ public class PackageInstallerActivity extends AlertActivity { */ private boolean processPackageUri(final Uri packageUri) { mPackageURI = packageUri; - final String scheme = packageUri.getScheme(); + final String packageName = packageUri.getSchemeSpecificPart(); + if (mLocalLOGV) Log.i(TAG, "processPackageUri(): uri=" + packageUri + ", scheme=" + scheme); switch (scheme) { case SCHEME_PACKAGE: { - try { - mPkgInfo = mPm.getPackageInfo(packageUri.getSchemeSpecificPart(), - PackageManager.GET_PERMISSIONS - | PackageManager.MATCH_UNINSTALLED_PACKAGES); - } catch (NameNotFoundException e) { + for (UserInfo info : mUserManager.getUsers()) { + PackageManager pmForUser = createContextAsUser(info.getUserHandle(), 0) + .getPackageManager(); + try { + if (pmForUser.canPackageQuery(mCallingPackage, packageName)) { + mPkgInfo = pmForUser.getPackageInfo(packageName, + PackageManager.GET_PERMISSIONS + | PackageManager.MATCH_UNINSTALLED_PACKAGES); + } + } catch (NameNotFoundException e) { + } } if (mPkgInfo == null) { - Log.w(TAG, "Requested package " + packageUri.getScheme() + Log.w(TAG, "Requested package " + packageUri.getSchemeSpecificPart() + " not available. Discontinuing installation"); showDialogInner(DLG_PACKAGE_ERROR); setPmResult(PackageManager.INSTALL_FAILED_INVALID_APK);