[DO NOT MERGE] [conflict] Merge "Make sure callingPackage belongs to callingUid when checking BG-FGS restrictions." into rvc-dev am: a70add46f3
Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/18356706 Change-Id: Ie110b8cfd17e441789f225ca8743d60a65365a92 Merged-In: Ic14fc331a9b5fbdbcfe6e54a31c8b765513bfd89 Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
This commit is contained in:
@@ -5005,10 +5005,16 @@ public final class ActiveServices {
|
|||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
final boolean isWhiteListedPackage =
|
if (verifyPackage(callingPackage, callingUid)) {
|
||||||
mWhiteListAllowWhileInUsePermissionInFgs.contains(callingPackage);
|
final boolean isWhiteListedPackage =
|
||||||
if (isWhiteListedPackage) {
|
mWhiteListAllowWhileInUsePermissionInFgs.contains(callingPackage);
|
||||||
return true;
|
if (isWhiteListedPackage) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
EventLog.writeEvent(0x534e4554, "215003903", callingUid,
|
||||||
|
"callingPackage:" + callingPackage + " does not belong to callingUid:"
|
||||||
|
+ callingUid);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Is the calling UID a device owner app?
|
// Is the calling UID a device owner app?
|
||||||
@@ -5047,4 +5053,21 @@ public final class ActiveServices {
|
|||||||
r.mAllowWhileInUsePermissionInFgs = false;
|
r.mAllowWhileInUsePermissionInFgs = false;
|
||||||
r.mLastSetFgsRestrictionTime = 0;
|
r.mLastSetFgsRestrictionTime = 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Checks if a given packageName belongs to a given uid.
|
||||||
|
* @param packageName the package of the caller
|
||||||
|
* @param uid the uid of the caller
|
||||||
|
* @return true or false
|
||||||
|
*/
|
||||||
|
private boolean verifyPackage(String packageName, int uid) {
|
||||||
|
if (uid == ROOT_UID || uid == SYSTEM_UID) {
|
||||||
|
//System and Root are always allowed
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
final int userId = UserHandle.getUserId(uid);
|
||||||
|
final int packageUid = mAm.getPackageManagerInternalLocked()
|
||||||
|
.getPackageUid(packageName, PackageManager.MATCH_DEBUG_TRIAGED_MISSING, userId);
|
||||||
|
return UserHandle.isSameApp(uid, packageUid);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user