Merge "Fixed UID mismatch in telephony registry"

This commit is contained in:
Hui Wang
2023-04-27 17:27:19 +00:00
committed by Gerrit Code Review

View File

@@ -1578,57 +1578,62 @@ public class TelephonyRegistry extends ITelephonyRegistry.Stub {
return; return;
} }
synchronized (mRecords) { final long callingIdentity = Binder.clearCallingIdentity();
String str = "notifyServiceStateForSubscriber: subId=" + subId + " phoneId=" + phoneId try {
+ " state=" + state; synchronized (mRecords) {
if (VDBG) { String str = "notifyServiceStateForSubscriber: subId=" + subId + " phoneId="
log(str); + phoneId + " state=" + state;
} if (VDBG) {
mLocalLog.log(str); log(str);
// for service state updates, don't notify clients when subId is invalid. This prevents }
// us from sending incorrect notifications like b/133140128 mLocalLog.log(str);
// In the future, we can remove this logic for every notification here and add a // for service state updates, don't notify clients when subId is invalid. This
// callback so listeners know when their PhoneStateListener's subId becomes invalid, but // prevents us from sending incorrect notifications like b/133140128
// for now we use the simplest fix. // In the future, we can remove this logic for every notification here and add a
if (validatePhoneId(phoneId) && SubscriptionManager.isValidSubscriptionId(subId)) { // callback so listeners know when their PhoneStateListener's subId becomes invalid,
mServiceState[phoneId] = state; // but for now we use the simplest fix.
if (validatePhoneId(phoneId) && SubscriptionManager.isValidSubscriptionId(subId)) {
mServiceState[phoneId] = state;
for (Record r : mRecords) { for (Record r : mRecords) {
if (VDBG) { if (VDBG) {
log("notifyServiceStateForSubscriber: r=" + r + " subId=" + subId log("notifyServiceStateForSubscriber: r=" + r + " subId=" + subId
+ " phoneId=" + phoneId + " state=" + state); + " phoneId=" + phoneId + " state=" + state);
} }
if (r.matchTelephonyCallbackEvent( if (r.matchTelephonyCallbackEvent(
TelephonyCallback.EVENT_SERVICE_STATE_CHANGED) TelephonyCallback.EVENT_SERVICE_STATE_CHANGED)
&& idMatch(r, subId, phoneId)) { && idMatch(r, subId, phoneId)) {
try { try {
ServiceState stateToSend; ServiceState stateToSend;
if (checkFineLocationAccess(r, Build.VERSION_CODES.Q)) { if (checkFineLocationAccess(r, Build.VERSION_CODES.Q)) {
stateToSend = new ServiceState(state); stateToSend = new ServiceState(state);
} else if (checkCoarseLocationAccess(r, Build.VERSION_CODES.Q)) { } else if (checkCoarseLocationAccess(r, Build.VERSION_CODES.Q)) {
stateToSend = state.createLocationInfoSanitizedCopy(false); stateToSend = state.createLocationInfoSanitizedCopy(false);
} else { } else {
stateToSend = state.createLocationInfoSanitizedCopy(true); stateToSend = state.createLocationInfoSanitizedCopy(true);
}
if (DBG) {
log("notifyServiceStateForSubscriber: callback.onSSC r=" + r
+ " subId=" + subId + " phoneId=" + phoneId
+ " state=" + stateToSend);
}
r.callback.onServiceStateChanged(stateToSend);
} catch (RemoteException ex) {
mRemoveList.add(r.binder);
} }
if (DBG) {
log("notifyServiceStateForSubscriber: callback.onSSC r=" + r
+ " subId=" + subId + " phoneId=" + phoneId
+ " state=" + state);
}
r.callback.onServiceStateChanged(stateToSend);
} catch (RemoteException ex) {
mRemoveList.add(r.binder);
} }
} }
} else {
log("notifyServiceStateForSubscriber: INVALID phoneId=" + phoneId
+ " or subId=" + subId);
} }
} else { handleRemoveListLocked();
log("notifyServiceStateForSubscriber: INVALID phoneId=" + phoneId
+ " or subId=" + subId);
} }
handleRemoveListLocked(); broadcastServiceStateChanged(state, phoneId, subId);
} finally {
Binder.restoreCallingIdentity(callingIdentity);
} }
broadcastServiceStateChanged(state, phoneId, subId);
} }
public void notifySimActivationStateChangedForPhoneId(int phoneId, int subId, public void notifySimActivationStateChangedForPhoneId(int phoneId, int subId,
@@ -3161,13 +3166,10 @@ public class TelephonyRegistry extends ITelephonyRegistry.Stub {
public static final String ACTION_SIGNAL_STRENGTH_CHANGED = "android.intent.action.SIG_STR"; public static final String ACTION_SIGNAL_STRENGTH_CHANGED = "android.intent.action.SIG_STR";
private void broadcastServiceStateChanged(ServiceState state, int phoneId, int subId) { private void broadcastServiceStateChanged(ServiceState state, int phoneId, int subId) {
final long ident = Binder.clearCallingIdentity();
try { try {
mBatteryStats.notePhoneState(state.getState()); mBatteryStats.notePhoneState(state.getState());
} catch (RemoteException re) { } catch (RemoteException re) {
// Can't do much // Can't do much
} finally {
Binder.restoreCallingIdentity(ident);
} }
// Send the broadcast exactly once to all possible disjoint sets of apps. // Send the broadcast exactly once to all possible disjoint sets of apps.
@@ -3184,8 +3186,7 @@ public class TelephonyRegistry extends ITelephonyRegistry.Stub {
// - Sanitized ServiceState sent to all other apps with READ_PHONE_STATE // - Sanitized ServiceState sent to all other apps with READ_PHONE_STATE
// - Sanitized ServiceState sent to all other apps with READ_PRIVILEGED_PHONE_STATE but not // - Sanitized ServiceState sent to all other apps with READ_PRIVILEGED_PHONE_STATE but not
// READ_PHONE_STATE // READ_PHONE_STATE
if (Binder.withCleanCallingIdentity(() -> if (LocationAccessPolicy.isLocationModeEnabled(mContext, mContext.getUserId())) {
LocationAccessPolicy.isLocationModeEnabled(mContext, mContext.getUserId()))) {
Intent fullIntent = createServiceStateIntent(state, subId, phoneId, false); Intent fullIntent = createServiceStateIntent(state, subId, phoneId, false);
mContext.createContextAsUser(UserHandle.ALL, 0).sendBroadcastMultiplePermissions( mContext.createContextAsUser(UserHandle.ALL, 0).sendBroadcastMultiplePermissions(
fullIntent, fullIntent,