Merge "Do not verify client app uid and package when stopping the sandbox" into udc-dev
This commit is contained in:
committed by
Android (Google) Code Review
commit
b736edc255
@@ -17279,6 +17279,9 @@ public class ActivityManagerService extends IActivityManager.Stub
|
|||||||
public ComponentName startSdkSandboxService(Intent service, int clientAppUid,
|
public ComponentName startSdkSandboxService(Intent service, int clientAppUid,
|
||||||
String clientAppPackage, String processName) throws RemoteException {
|
String clientAppPackage, String processName) throws RemoteException {
|
||||||
validateSdkSandboxParams(service, clientAppUid, clientAppPackage, processName);
|
validateSdkSandboxParams(service, clientAppUid, clientAppPackage, processName);
|
||||||
|
if (mAppOpsService.checkPackage(clientAppUid, clientAppPackage) != MODE_ALLOWED) {
|
||||||
|
throw new IllegalArgumentException("uid does not belong to provided package");
|
||||||
|
}
|
||||||
// TODO(b/269598719): Is passing the application thread of the system_server alright?
|
// TODO(b/269598719): Is passing the application thread of the system_server alright?
|
||||||
// e.g. the sandbox getting privileged access due to this.
|
// e.g. the sandbox getting privileged access due to this.
|
||||||
ComponentName cn = ActivityManagerService.this.startService(
|
ComponentName cn = ActivityManagerService.this.startService(
|
||||||
@@ -17345,6 +17348,9 @@ public class ActivityManagerService extends IActivityManager.Stub
|
|||||||
String processName, long flags)
|
String processName, long flags)
|
||||||
throws RemoteException {
|
throws RemoteException {
|
||||||
validateSdkSandboxParams(service, clientAppUid, clientAppPackage, processName);
|
validateSdkSandboxParams(service, clientAppUid, clientAppPackage, processName);
|
||||||
|
if (mAppOpsService.checkPackage(clientAppUid, clientAppPackage) != MODE_ALLOWED) {
|
||||||
|
throw new IllegalArgumentException("uid does not belong to provided package");
|
||||||
|
}
|
||||||
if (conn == null) {
|
if (conn == null) {
|
||||||
throw new IllegalArgumentException("connection is null");
|
throw new IllegalArgumentException("connection is null");
|
||||||
}
|
}
|
||||||
@@ -17397,9 +17403,6 @@ public class ActivityManagerService extends IActivityManager.Stub
|
|||||||
if (!UserHandle.isApp(clientAppUid)) {
|
if (!UserHandle.isApp(clientAppUid)) {
|
||||||
throw new IllegalArgumentException("uid is not within application range");
|
throw new IllegalArgumentException("uid is not within application range");
|
||||||
}
|
}
|
||||||
if (mAppOpsService.checkPackage(clientAppUid, clientAppPackage) != MODE_ALLOWED) {
|
|
||||||
throw new IllegalArgumentException("uid does not belong to provided package");
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
@Override
|
@Override
|
||||||
|
|||||||
Reference in New Issue
Block a user