Clear binder identity before calling PackageManager API

With the introduction of app enumeration restriction in R,
PackageManager will restrict package visiblity if the caller
is not privileged. This caused regression in existing system
server code where binder identity is not cleared prior to
making PackageManager calls.

Bug: 150398249
Test: com.android.cts.devicepolicy.MixedDeviceOwnerTest#testAlwaysOnVpn
Change-Id: I8744965389883870c569a1b70e75715aafeb7848
Merged-In: I611eb5768bfb73f01c63e6ab02d90f1178f8ec37
(cherry picked from commit f57597c6ef)
This commit is contained in:
Automerger Merge Worker
2020-03-08 23:50:02 +00:00
committed by Rubin Xu
parent 5580360ba8
commit c6a1d93b4f

View File

@@ -951,18 +951,18 @@ public class Vpn {
|| isVpnServicePreConsented(context, packageName);
}
private int getAppUid(String app, int userHandle) {
private int getAppUid(final String app, final int userHandle) {
if (VpnConfig.LEGACY_VPN.equals(app)) {
return Process.myUid();
}
PackageManager pm = mContext.getPackageManager();
int result;
try {
result = pm.getPackageUidAsUser(app, userHandle);
} catch (NameNotFoundException e) {
result = -1;
}
return result;
return Binder.withCleanCallingIdentity(() -> {
try {
return pm.getPackageUidAsUser(app, userHandle);
} catch (NameNotFoundException e) {
return -1;
}
});
}
private boolean doesPackageTargetAtLeastQ(String packageName) {