Merge "Allow Shell to change component enabled state" into nyc-dev am: 19b34eccfe

am: 9db4384118

* commit '9db4384118911abd55ee528e570707be2af3f85b':
  Allow Shell to change component enabled state

Change-Id: I9a309ea4fb46925de793b339896629ca43cb053f
This commit is contained in:
Amith Yamasani
2016-05-17 00:42:43 +00:00
committed by android-build-merger
2 changed files with 28 additions and 0 deletions

View File

@@ -111,6 +111,7 @@
<uses-permission android:name="android.permission.VIBRATE" />
<uses-permission android:name="android.permission.MANAGE_ACTIVITY_STACKS" />
<uses-permission android:name="android.permission.CONNECTIVITY_INTERNAL" />
<uses-permission android:name="android.permission.CHANGE_COMPONENT_ENABLED_STATE" />
<!-- Permission needed to rename bugreport notifications (so they're not shown as Shell) -->
<uses-permission android:name="android.permission.SUBSTITUTE_NOTIFICATION_APP_NAME" />

View File

@@ -17509,6 +17509,14 @@ Slog.v(TAG, ":: stepped forward, applying functor at tag " + parser.getName());
throw new IllegalArgumentException(
"Unknown component: " + packageName + "/" + className);
}
// Don't allow other apps to disable an active profile owner
if (!UserHandle.isSameApp(uid, pkgSetting.appId)) {
final DevicePolicyManagerInternal dpmi = LocalServices
.getService(DevicePolicyManagerInternal.class);
if (dpmi != null && dpmi.hasDeviceOwnerOrProfileOwner(packageName, userId)) {
throw new SecurityException("Cannot disable a device owner or a profile owner");
}
}
// Allow root and verify that userId is not being specified by a different user
if (!allowedByPermission && !UserHandle.isSameApp(uid, pkgSetting.appId)) {
throw new SecurityException(
@@ -17516,6 +17524,25 @@ Slog.v(TAG, ":: stepped forward, applying functor at tag " + parser.getName());
+ Binder.getCallingPid()
+ ", uid=" + uid + ", package uid=" + pkgSetting.appId);
}
if (uid == Process.SHELL_UID) {
// Shell can only change whole packages between ENABLED and DISABLED_USER states
int oldState = pkgSetting.getEnabled(userId);
if (className == null
&&
(oldState == COMPONENT_ENABLED_STATE_DISABLED_USER
|| oldState == COMPONENT_ENABLED_STATE_DEFAULT
|| oldState == COMPONENT_ENABLED_STATE_ENABLED)
&&
(newState == COMPONENT_ENABLED_STATE_DISABLED_USER
|| newState == COMPONENT_ENABLED_STATE_DEFAULT
|| newState == COMPONENT_ENABLED_STATE_ENABLED)) {
// ok
} else {
throw new SecurityException(
"Shell cannot change component state for " + packageName + "/"
+ className + " to " + newState);
}
}
if (className == null) {
// We're dealing with an application/package level state change
if (pkgSetting.getEnabled(userId) == newState) {