From d69b083bc31a02c99c6356fcea1113bb71063430 Mon Sep 17 00:00:00 2001 From: Jeff Sharkey Date: Mon, 23 Jan 2017 11:37:24 -0700 Subject: [PATCH] Fix recent checkPermission() bug. It should be checking if the UID argument passed in has the requested permission; not the calling UID. Test: builds, boots Bug: 34528367 Change-Id: Ie1828f571d9f143ce9f5bdca2eedcf2fa6ccfd79 --- core/java/android/app/ContextImpl.java | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/core/java/android/app/ContextImpl.java b/core/java/android/app/ContextImpl.java index 1658e8261a022..b2c97f64a0711 100644 --- a/core/java/android/app/ContextImpl.java +++ b/core/java/android/app/ContextImpl.java @@ -1591,12 +1591,15 @@ class ContextImpl extends Context { } final IActivityManager am = ActivityManager.getService(); - if (am == null && UserHandle.getAppId(Binder.getCallingUid()) == Process.SYSTEM_UID) { + if (am == null) { // Well this is super awkward; we somehow don't have an active - // ActivityManager instance. If this is the system UID, then we - // totally have whatever permission this is. - Slog.w(TAG, "Missing ActivityManager; assuming system UID holds " + permission); - return PackageManager.PERMISSION_GRANTED; + // ActivityManager instance. If we're testing a root or system + // UID, then they totally have whatever permission this is. + final int appId = UserHandle.getAppId(uid); + if (appId == Process.ROOT_UID || appId == Process.SYSTEM_UID) { + Slog.w(TAG, "Missing ActivityManager; assuming " + uid + " holds " + permission); + return PackageManager.PERMISSION_GRANTED; + } } try {