Merge changes from topic "presubmit-am-77aaf4d1c96d4bd0bf1f886d74ab8a9c" into sc-mainline-prod
* changes:
[automerge] Make sure parallel broadcasts enforce excluded permissions 2p: 0eee4fa476
Make sure parallel broadcasts enforce excluded permissions
This commit is contained in:
committed by
Android (Google) Code Review
commit
ae83695422
@@ -760,6 +760,54 @@ public final class BroadcastQueue {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Check that the receiver does *not* have any excluded permissions
|
||||||
|
if (!skip && r.excludedPermissions != null && r.excludedPermissions.length > 0) {
|
||||||
|
for (int i = 0; i < r.excludedPermissions.length; i++) {
|
||||||
|
String excludedPermission = r.excludedPermissions[i];
|
||||||
|
final int perm = mService.checkComponentPermission(excludedPermission,
|
||||||
|
filter.receiverList.pid, filter.receiverList.uid, -1, true);
|
||||||
|
|
||||||
|
int appOp = AppOpsManager.permissionToOpCode(excludedPermission);
|
||||||
|
if (appOp != AppOpsManager.OP_NONE) {
|
||||||
|
// When there is an app op associated with the permission,
|
||||||
|
// skip when both the permission and the app op are
|
||||||
|
// granted.
|
||||||
|
if ((perm == PackageManager.PERMISSION_GRANTED) && (
|
||||||
|
mService.getAppOpsManager().checkOpNoThrow(appOp,
|
||||||
|
filter.receiverList.uid,
|
||||||
|
filter.packageName)
|
||||||
|
== AppOpsManager.MODE_ALLOWED)) {
|
||||||
|
Slog.w(TAG, "Appop Denial: receiving "
|
||||||
|
+ r.intent.toString()
|
||||||
|
+ " to " + filter.receiverList.app
|
||||||
|
+ " (pid=" + filter.receiverList.pid
|
||||||
|
+ ", uid=" + filter.receiverList.uid + ")"
|
||||||
|
+ " excludes appop " + AppOpsManager.permissionToOp(
|
||||||
|
excludedPermission)
|
||||||
|
+ " due to sender " + r.callerPackage
|
||||||
|
+ " (uid " + r.callingUid + ")");
|
||||||
|
skip = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
// When there is no app op associated with the permission,
|
||||||
|
// skip when permission is granted.
|
||||||
|
if (perm == PackageManager.PERMISSION_GRANTED) {
|
||||||
|
Slog.w(TAG, "Permission Denial: receiving "
|
||||||
|
+ r.intent.toString()
|
||||||
|
+ " to " + filter.receiverList.app
|
||||||
|
+ " (pid=" + filter.receiverList.pid
|
||||||
|
+ ", uid=" + filter.receiverList.uid + ")"
|
||||||
|
+ " excludes " + excludedPermission
|
||||||
|
+ " due to sender " + r.callerPackage
|
||||||
|
+ " (uid " + r.callingUid + ")");
|
||||||
|
skip = true;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Check that the receiver does *not* belong to any of the excluded packages
|
// Check that the receiver does *not* belong to any of the excluded packages
|
||||||
if (!skip && r.excludedPackages != null && r.excludedPackages.length > 0) {
|
if (!skip && r.excludedPackages != null && r.excludedPackages.length > 0) {
|
||||||
if (ArrayUtils.contains(r.excludedPackages, filter.packageName)) {
|
if (ArrayUtils.contains(r.excludedPackages, filter.packageName)) {
|
||||||
|
|||||||
Reference in New Issue
Block a user