[automerge] Make sure callingPackage belongs to callingUid when checking BG-FGS restrictions. 2p: eef20391ce

Original change: https://googleplex-android-review.googlesource.com/c/platform/frameworks/base/+/18359892

Bug: 216695100
Bug: 215003903
Change-Id: I4a28a8fe31276c24935a14ad55dacc8101edbccb
Merged-In: Ic14fc331a9b5fbdbcfe6e54a31c8b765513bfd89
This commit is contained in:
Presubmit Automerger Backend
2022-05-17 20:15:40 +00:00

View File

@@ -5992,10 +5992,16 @@ public final class ActiveServices {
}
if (ret == REASON_DENIED) {
final boolean isAllowedPackage =
mAllowListWhileInUsePermissionInFgs.contains(callingPackage);
if (isAllowedPackage) {
ret = REASON_ALLOWLISTED_PACKAGE;
if (verifyPackage(callingPackage, callingUid)) {
final boolean isAllowedPackage =
mAllowListWhileInUsePermissionInFgs.contains(callingPackage);
if (isAllowedPackage) {
ret = REASON_ALLOWLISTED_PACKAGE;
}
} else {
EventLog.writeEvent(0x534e4554, "215003903", callingUid,
"callingPackage:" + callingPackage + " does not belong to callingUid:"
+ callingUid);
}
}
@@ -6378,4 +6384,21 @@ public final class ActiveServices {
/* allowBackgroundActivityStarts */ false)
!= REASON_DENIED;
}
/**
* Checks if a given packageName belongs to a given uid.
* @param packageName the package of the caller
* @param uid the uid of the caller
* @return true or false
*/
private boolean verifyPackage(String packageName, int uid) {
if (uid == ROOT_UID || uid == SYSTEM_UID) {
//System and Root are always allowed
return true;
}
final int userId = UserHandle.getUserId(uid);
final int packageUid = mAm.getPackageManagerInternal()
.getPackageUid(packageName, PackageManager.MATCH_DEBUG_TRIAGED_MISSING, userId);
return UserHandle.isSameApp(uid, packageUid);
}
}