ActivityManagerService: Allow openContentUri from vendor/system/product.

Apps should not have direct access to this entry point. Check that the
caller is a vendor, system, or product package.

Test: Ran PoC app and CtsMediaPlayerTestCases.
Bug: 236688380
Change-Id: I0335496d28fa5fc3bfe1fecd4be90040b0b3687f
This commit is contained in:
Austin Borger
2023-03-18 12:56:12 -07:00
parent 7206bf0915
commit d0ba7467c2

View File

@@ -6915,7 +6915,7 @@ public class ActivityManagerService extends IActivityManager.Stub
mActivityTaskManager.unhandledBack(); mActivityTaskManager.unhandledBack();
} }
// TODO: Move to ContentProviderHelper? // TODO: Replace this method with one that returns a bound IContentProvider.
public ParcelFileDescriptor openContentUri(String uriString) throws RemoteException { public ParcelFileDescriptor openContentUri(String uriString) throws RemoteException {
enforceNotIsolatedCaller("openContentUri"); enforceNotIsolatedCaller("openContentUri");
final int userId = UserHandle.getCallingUserId(); final int userId = UserHandle.getCallingUserId();
@@ -6944,6 +6944,16 @@ public class ActivityManagerService extends IActivityManager.Stub
Log.e(TAG, "Cannot find package for uid: " + uid); Log.e(TAG, "Cannot find package for uid: " + uid);
return null; return null;
} }
final ApplicationInfo appInfo = mPackageManagerInt.getApplicationInfo(
androidPackage.getPackageName(), /*flags*/0, Process.SYSTEM_UID,
UserHandle.USER_SYSTEM);
if (!appInfo.isVendor() && !appInfo.isSystemApp() && !appInfo.isSystemExt()
&& !appInfo.isProduct()) {
Log.e(TAG, "openContentUri may only be used by vendor/system/product.");
return null;
}
final AttributionSource attributionSource = new AttributionSource( final AttributionSource attributionSource = new AttributionSource(
Binder.getCallingUid(), androidPackage.getPackageName(), null); Binder.getCallingUid(), androidPackage.getPackageName(), null);
pfd = cph.provider.openFile(attributionSource, uri, "r", null); pfd = cph.provider.openFile(attributionSource, uri, "r", null);