From eee5094f96c630661ca563d70de244ccbbd53579 Mon Sep 17 00:00:00 2001 From: Amith Yamasani Date: Mon, 21 Jul 2014 17:04:44 -0700 Subject: [PATCH] Fix a security exception when checking cross-profile caller-id cap. No need to enforce that the caller is in the system process. We're only checking if the device policy is allowing access. Bug: 16301261 Change-Id: I87a7c808d116c86aa68cebb36631c46d0a54be96 --- .../server/devicepolicy/DevicePolicyManagerService.java | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java index c218d3826b8c9..2a11252d192c7 100644 --- a/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java +++ b/services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java @@ -4030,7 +4030,8 @@ public class DevicePolicyManagerService extends IDevicePolicyManager.Stub { @Override public boolean getCrossProfileCallerIdDisabledForUser(int userId) { - enforceSystemProcess("getCrossProfileCallerIdDisabled can only be called by system"); + // TODO: Should there be a check to make sure this relationship is within a profile group? + //enforceSystemProcess("getCrossProfileCallerIdDisabled can only be called by system"); synchronized (this) { ActiveAdmin admin = getProfileOwnerAdmin(userId); return (admin != null) ? admin.disableCallerId : false;