Allow any caller with CONTROL_VPN to disconnect existing VPN

When calling prepare(null, LEGACY_VPN, TYPE_VPN_SERVICE), the caller
wants to disconnect the current VPN. The current code checks to make
sure an IPC caller, and only an IPC caller, with the CONTROL_VPN
permission can do so.

But this doesn't allow for other processes in the system server (which
also have CONTROL_VPN permission) to do so. Expand the check to allow
those callers.

Bug: 284803285
Test: VpnTest in http://aosp/2624812
Change-Id: Ib9baa40d6dc870a548ebf8332f2829f4e49be428
This commit is contained in:
Cassie Wang
2023-06-14 14:53:44 +09:00
parent af2669d656
commit d097d0c4f8

View File

@@ -1389,7 +1389,7 @@ public class Vpn {
}
// Check that the caller is authorized.
enforceControlPermission();
enforceControlPermissionOrInternalCaller();
// Stop an existing always-on VPN from being dethroned by other apps.
if (mAlwaysOn && !isCurrentPreparedPackage(newPackage)) {