Merge "Make sure callingPackage belongs to callingUid when checking BG-FGS restrictions." into rvc-dev

This commit is contained in:
TreeHugger Robot
2022-05-17 23:37:35 +00:00
committed by Android (Google) Code Review

View File

@@ -4983,11 +4983,18 @@ public final class ActiveServices {
return true; return true;
} }
if (verifyPackage(callingPackage, callingUid)) {
final boolean isWhiteListedPackage = final boolean isWhiteListedPackage =
mWhiteListAllowWhileInUsePermissionInFgs.contains(callingPackage); mWhiteListAllowWhileInUsePermissionInFgs.contains(callingPackage);
if (isWhiteListedPackage) { if (isWhiteListedPackage) {
return true; return true;
} }
} else {
EventLog.writeEvent(0x534e4554, "215003903", callingUid,
"callingPackage:" + callingPackage + " does not belong to callingUid:"
+ callingUid);
}
// Is the calling UID a device owner app? // Is the calling UID a device owner app?
final boolean isDeviceOwner = mAm.mInternal.isDeviceOwner(callingUid); final boolean isDeviceOwner = mAm.mInternal.isDeviceOwner(callingUid);
@@ -5025,4 +5032,21 @@ public final class ActiveServices {
r.mAllowWhileInUsePermissionInFgs = false; r.mAllowWhileInUsePermissionInFgs = false;
r.mLastSetFgsRestrictionTime = 0; r.mLastSetFgsRestrictionTime = 0;
} }
/**
* Checks if a given packageName belongs to a given uid.
* @param packageName the package of the caller
* @param uid the uid of the caller
* @return true or false
*/
private boolean verifyPackage(String packageName, int uid) {
if (uid == ROOT_UID || uid == SYSTEM_UID) {
//System and Root are always allowed
return true;
}
final int userId = UserHandle.getUserId(uid);
final int packageUid = mAm.getPackageManagerInternalLocked()
.getPackageUid(packageName, PackageManager.MATCH_DEBUG_TRIAGED_MISSING, userId);
return UserHandle.isSameApp(uid, packageUid);
}
} }